Replies: 2 comments 2 replies
-
|
This file is a valid ipfix stream, too. It contains mainly a lot of Network Based Application Recognition (NBAR) records. The collected flows however, do not map into these nbar records - maybe the collection period was too short. A raw record looks like this: |
Beta Was this translation helpful? Give feedback.
-
|
Your file Digging into the ipfix flows of nfd.pcap you can see:
So it sees for some reason your devices do not really send netflow records. I am not a CISCO SDWAN expert, you I cannot help with the configuration. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
nfd.zip
I am testing nfcapd in a cisco SDWAN and the netflow packets coming from Edge devices sample is attached in this question. I was unable to get anything decoded in nfcapd with this ipfix netflow traffic, i checked the pcap in wireshark and the templates and netflow data doesnot seem to contain valid flow 4 tuples so i seem to suspsect the issue is on edge device side, but the people operating the sdwan showed us the netflow configuration in cisco vmanager and there seems to very little to configure in cisco vmanager - there is cflowd configuration and just export configuration but nothing to configure like a template or content of a template. they seem to say the configuration on their side is correct and there is nothing more to be done. Can someone analyze the pcap and let me know if my assessment is correct.
Beta Was this translation helpful? Give feedback.
All reactions