Re: ng_netflow: testers are welcome
From: Gleb Smirnoff (glebius_at_cell.sick.ru)
Date: 02/24/04
- Previous message: Julian Elischer: "Re: ng_netflow: testers are welcome"
- In reply to: Vasenin Alexander aka BlackSir: "RE: ng_netflow: testers are welcome"
- Next in thread: Vasenin Alexander aka BlackSir: "RE: ng_netflow: testers are welcome"
- Reply: Vasenin Alexander aka BlackSir: "RE: ng_netflow: testers are welcome"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Tue, 24 Feb 2004 12:01:52 +0300 To: Vasenin Alexander aka BlackSir <blacksir@number.ru>
On Tue, Feb 24, 2004 at 10:46:44AM +0300, Vasenin Alexander aka BlackSir wrote:
V> > I'd be glad if you show me your current netgraph setup script. Surely
V> > I can reproduce it myself, but live example would be better than
V> > imaginary.
V>
V> Here it is(latest version - 'echotee'):
Thanks for netgraph setup script. Could you please also send important parts
of your firewall config, where packets are diverted towards netgraph?
It is important to divert only _incoming_ traffic on _particular_ interface,
otherwise netflow exports will contain some incorrect data.
V> This config assumes that packets needed to catch via ng_netflow is simply
V> diverted by ipfw rule:
V> divert 8888 ip from any to any in - or something like that
V> Seems everything works fine! (I'm using ipfw2 in 4.9) Packets going throught
V> divert and reinjected in ipfw ;-)
V> but I've not tested this in production yet...
And also it is important to check that ng_ksocket reinjects packet
into the ipfw with rule number set (see Julian's mail).
-- Totus tuus, Glebius. GLEBIUS-RIPN GLEB-RIPE _______________________________________________ freebsd-isp@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-isp To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
- Previous message: Julian Elischer: "Re: ng_netflow: testers are welcome"
- In reply to: Vasenin Alexander aka BlackSir: "RE: ng_netflow: testers are welcome"
- Next in thread: Vasenin Alexander aka BlackSir: "RE: ng_netflow: testers are welcome"
- Reply: Vasenin Alexander aka BlackSir: "RE: ng_netflow: testers are welcome"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|
|