On Fri, 10 Jan 2014, Paolo Lucente wrote:
> To clarify: no traffic at all, both originated from and delivered
> to your address blocks listed, gets tagged with 612/613/712/713.
> Correct? Or some is and some is not?

Most is classified correctly, but about 7% doesn't match our filter.

    tag  packets       bytes
    ---  -------  ----------
    612   719349   479823644
    613   819891   343327581
    712  1782905  1944587590
    713  1181386  1350451186
    901   760620   297936088
    902   154509    55994369

When aggregated on tag, src_host and dst_host shows they should fit the filters
filter.

    901  94.18.227.134  198.51.100.92  29  1963

> Any chance the traffic is VLAN-tagged and/or MPLS-labelled and
> VLAN tag and/or MPLS labels are exposed to pmacct via IPFIX? In
> such a case you should reflect this in the filter, ie. 'vlan
> and ...', 'mpls and ...' or 'vlan and mpls and ...'.

This appears to be the case. If all rules are duplicated with
"vlan or (...)" everyting seems to work, only expected non-classified
traffic remains with tag 901 and 902.

How come the vlan expression is needed?

-- 
Kind regards,
Martin Topholm

Attachment: pgp9j4TNHcz5I.pgp
Description: PGP signature

_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to