Hi Jordan, not sure what you mean with “equipment that cannot separate inbound/outbound traffic” but as long as you have direction in your flow data you can add a pre-tag map like
! ! tag=1 - inbound IPv4 traffic ! tag=2 - outbound IPv4 traffic ! tag=3 - inbound IPv6 traffic ! tag=4 - outbound IPv6 traffic ! set_tag=1 ip=0.0.0.0/0 direction=0 filter='ip' set_tag=2 ip=0.0.0.0/0 direction=1 filter='ip' set_tag=3 ip=0.0.0.0/0 direction=0 filter='ip6' set_tag=4 ip=0.0.0.0/0 direction=1 filter='ip6' set_tag=0 ip=0.0.0.0/0 ! and filter e.g. the ingress flows with ! pre_tag_filter[ingress]: 1,3 aggregate[ingress]: … ! Regards, Mario From: pmacct-discussion [mailto:pmacct-discussion-boun...@pmacct.net] On Behalf Of Jordan Sent: Wednesday, July 27, 2016 5:06 PM To: pmacct-discussion@pmacct.net Subject: [pmacct-discussion] sfacct feature suggestion - traffic in/out direction Hello, We're having issues with equipment that cannot separate inbound/outbound traffic using sflow V5. Looking at the sflow V5 protocol it's having the following fields. Usually they match the snmp interface indexes. source_id interface input interface output What I suggest as a new feature are the following cases: Match_all_traffic(by default) - matches all packets (as it currently works) Match_input_only - (if source_id==interface input permit, else drop the rest of the samples) Match_output_only - (if source_id==interface output permit, else drop the rest of the samples) Please let me know if such feature would be possible? If there is any other already implemented solution I would be glad to know. Thank you in advance. Best Regards, -- --- Jordan
_______________________________________________ pmacct-discussion mailing list http://www.pmacct.net/#mailinglists