Hi,
I have a netflow v9 feed to nfacctd from a juniper router (JUNOS
9.6R2.11), using a service pic. According to a packet capture, records
include ingress and egress interface and they seem to be properly
defined in the corresponding template. I've tried to use the snmp
ifindex numbers in pre_tag_map keys, but they never match. Matching in
pre_tag_map with other keys seems to work fine. Any ideas how to debug?
I also noticed that proto and ToS are not available as pre_tag_map
keys. Any particular reason for that? DSCP matching would be handy in
my case.
On a somewhat different note: the particular juniper can also export
ipv6 flows, using a different template. I've noticed it includes an
IP_PROTOCOL_VERSION (60) field in this template.
If we send the ipv6 feed to the same instance of nfacctd which
receives the ipv4 feed, how can we tell apart ipv6 from ipv4 traffic
if we're doing AS aggregation? It would be handy to have an ip_proto
aggregation primitive, or at least to be able to match by 'IPVersion'
in a pre_tag_map.
Cheers,
Z.
_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists