Re: [pmacct-discussion] Empty bgp attributes ( src/dst_as, as_path, med, etc)

2017-11-09 Thread Varga Tamas
Hi Paolo, the config is now simplified as you suggested, but for me it seems that the bgp attributes are still not merged with the netflow. In order to make sure, that the peers are up and running when netflow hits nfacctd, I waited 18+ hours before checking the logs. Thanks, Tamas

[pmacct-discussion] Monitor IP fragmentation

2017-11-09 Thread Hidde van der Heide
Hi, While looking into pmacct to monitor our Internet edge, we are also testing is we can detect malicious activity, primarily DDoS traffic. With the current aggregators we can gather most of the required data but the one thing really missing is IP fragmentation. I noticed there is already

Re: [pmacct-discussion] Empty bgp attributes ( src/dst_as, as_path, med, etc)

2017-11-09 Thread Paolo Lucente
Hi Tamas, Thanks to make things extra sure with the 18+ hours wait :D Let me know if it's a possibility to have a look at the issue myself on the box in order to support you further. Paolo On Thu, Nov 09, 2017 at 12:25:24PM +0100, Varga Tamas wrote: > Hi Paolo, > > the config is now

Re: [pmacct-discussion] Monitor IP fragmentation

2017-11-09 Thread Paolo Lucente
Hi Hidde, Yes, there is plenty of defragmentation code and you are right that there is no 'external visibility' into it. I'm curious what you'd have in mind to give such visibility, a bool like fragmented traffic yes/no of some sort? Paolo On Thu, Nov 09, 2017 at 04:26:37PM +0100, Hidde van