NetFlow的一些知识

2017-03-09  本文已影响187人  丁不想被任何狗咬

NetFlow如何决定方向:

NetFlow Direction and it’s Value to Troubleshooting
https://www.plixer.com/blog/netflow-and-ipfix-2/netflow-direction-and-its-value-to-troubleshooting/

Strategies used that attempt to determine flow direction but, aren’t entirely reliable include:

  • Comparison of flow start times

总结:基于硬件,比较准确。

官方文档:

IP Flow Information Export (IPFIX) Entities
http://www.iana.org/assignments/ipfix/ipfix.xhtml
Bidirectional Flow Export Using IP Flow Information Export (IPFIX)
https://tools.ietf.org/html/rfc5103

Wikipedia:
NetFlow
https://en.wikipedia.org/wiki/NetFlow

pcap转NetFlow以及时间戳问题
https://sourceforge.net/p/nfdump/mailman/message/23791576/

>>  $ nfcapd -p9995 -l ./netflow/
>>  $ softflowd -n 127.0.0.1:9995 -r dump.pcap

时间戳不太对。而且一个双向流会被拆分成两个。

nfcapd -f pcap #办不到

tshark读取pcap

tcpreplay,centos

上一篇 下一篇

猜你喜欢

热点阅读