-
-
Notifications
You must be signed in to change notification settings - Fork 206
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
missing ip ttl/ip frag #580
Comments
looking at pcap, i see MinTTL/MaxTTL showing up in wireshark which looks like field 52/53 per: |
As of As of ttl/fragments - Please send me a pcap to check for proper decoding. So far these fields are not yet decoded in v9/ipfix and are used only by |
Box is ubuntu 20.04, just emailed you some pcaps of flows coming into the box for a few different platforms. |
running latest from git
Saw alert about fragments to a host in one system and was curious to see what nfsen/nfdump saw.
I do not see any ip fragment or ip ttl info.. tried using fmt output or raw output
Per nfdump source I see that it should the info... but is there some sort of requirement before that it is exposed?
BTW, trying to nfanon file in place fails but works if giving it a new name:
providing sample output data:
this was from a juniper 23.x box, but also see the lack of ttl/frag from cisco iox 7.x and others.
The text was updated successfully, but these errors were encountered: