Hello Nfdump-discuss,
I'm trying to capture Smartedge Redback NAT Logging flows, however
this seems unsupported, are there any patches to support SmartEdge
router flows ? - they are v9 compatible.
If this is not done yet, are there any possibility to support this ?
Details of redback field types:
SmartEdge Router Specific Logging Field Types
The export entity uses Cisco Systems NetFlow export format version 9 (v9) to
export flow records. When you use this format, NAT records are made up of a
header and a sequence of flow data or template FlowSets. The data template
describes the fields that are present in data FlowSets.
The data FlowSets might occur later in the same export packet or in subsequent
export packets.
To use your own collector, you might need to modify the collector (the NetFlow
collector's configuration) to accept the following new SmartEdge router
specific field types.
Table 1 SmartEdge Router Specific Logging Field Types Field Type
Value
Length
(bytes)
Description
NAT_LOG_FIELD_IDX_CONTEXT_ID = 0
24628
4
Internal context ID
NAT_LOG_FIELD_IDX_CONTEXT_NAME
24629
64
Zero terminated context Name
NAT_LOG_FIELD_IDX_ASSIGN_TS_SEC
24630
4
Seconds of UNIX timestamp for assign
NAT_LOG_FIELD_IDX_UNASSIGN_TS_SEC
24631
4
Seconds of UNIX timestamp for unassign
NAT_LOG_FIELD_IDX_IPV4_INT_ADDR
24632
4
Internal IPv4 address
NAT_LOG_FIELD_IDX_IPV4_EXT_ADDR
24633
4
External IPv4 address
NAT_LOG_FIELD_IDX_EXT_PORT_FIRST
24634
2
External L4 port start
NAT_LOG_FIELD_IDX_EXT_PORT_LAST
24635
2
External L4 port end
--
Best regards,
Ozga Rafal mailto:[email protected]
------------------------------------------------------------------------------
Android is increasing in popularity, but the open development platform that
developers love is also attractive to malware creators. Download this white
paper to learn more about secure code signing practices that can help keep
Android apps secure.
http://pubads.g.doubleclick.net/gampad/clk?id=65839951&iu=/4140/ostg.clktrk
_______________________________________________
Nfdump-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfdump-discuss