Re: netflow srcip and dstip reversed for redirected traffic

2014-06-01 Thread Marko Cupańá
On Sat, 31 May 2014 20:01:25 +0200 Sebastian Benoit benoit-li...@fb12.de wrote: The simple answer: It's complicated. The complicated answer: the pf state is used to keep track of both directions of the traffic flow. When the state times out, _two_ flows are created, one for each direction

Re: netflow srcip and dstip reversed for redirected traffic

2014-05-31 Thread Sebastian Benoit
Marko Cupa??(marko.cu...@mimar.rs) on 2014.05.31 13:03:18 +0200: Hi, I'm trying to understand and measure traffic on relatively large and complicated pf firewall, and for this purpose I am exporting netflow data with pflow to nfsen/nfdump. For the time being, I have set pflow on external