[netflow-tools] CISCO HDLC Pcap format

Damien Miller djm at mindrot.org
Thu Mar 29 22:47:39 EST 2007


On Thu, 29 Mar 2007, Guanqun Lu wrote:

> > Adding a new frame type to softflowd is as simple as adding an entry to
> > this array.
> 
> I'm wondering whether it's easy to collect other packet information such as
> MPLS
> and VPN.

If it is in the packet, and there exist NetFlow fields in which to export
it, then softflowd can be modified to collect and report it. It doesn't
support either of these at present, but MPLS wouldn't be too difficult to
add I imagine. 

You would need to be more specific about what you mean by "VPN". If you
mean IPsec, then there is not much more additional information available
beyond what is already reported (endpoints and IP protocol) unless you
give softflowd the keys to the phase-2 IPsec SAs, which I think is a
pretty scary proposition.

-d


More information about the netflow-tools mailing list