-
-
Notifications
You must be signed in to change notification settings - Fork 206
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Is it possible to know if a flow contained fragmented traffic? #497
Comments
Up to now it does not. If you think, this may be useful, I can certainly check for an implementation. It would definitely help, if you habe such an exporter, exporting these flags, to send me a few minutes worth of pcaps, sent to the collector for proper testing and for other options to implement. If this works for you, send it to my email in the AUTHORS file. All data is treated confidential.. |
Are you asking for pcaps of fragmented IP traffic or a NetFlow pcap export with information that would indicate that flows contained fragmented traffic? The latter I am not sure how I would go about acquiring. Is ‘fragmentFlags’ the correct way to indicate this information? |
Sorry for being not clear enough. It's a pcap of the traffic sent to the collector. For example, if it listens on port 12335 coming in through eth0 it would be |
I unfortunately do not have or know of an exporter capable of indicating whether the flows it is producing contain fragmented traffic. To be clear, |
No - nfpcapd does not. However, if I would implement the fragmentation flags tag #197 - then this would also apply to nfpcapd as a consequence. If this would help, I am glad to do so. |
Thank you. I would not want to waste your time with this as this it is not deeply important to me. I’m going to close this issue since you have answered my question. |
There's
fragmentFlags
but I'm not sure how to access this field through nfdump or any other tool. Does nfdump collect IP flags?The text was updated successfully, but these errors were encountered: