[TEST/REVIEW] Netflow implementation

Bjoern A. Zeeb bzeeb-lists at lists.zabbadoz.net
Thu Sep 9 11:05:11 PDT 2004


On Thu, 9 Sep 2004, Andre Oppermann wrote:

> The only thing the kernel *may* know about is the right- and leftmost AS.
> It may be more efficient to send the netflow data through a small helper
> application that just fills in the two AS number based on a mrt dump.

where and when ? that's not really possible I guess.
Gleb currently sends the flows directly via a ksocket. Of course one
could pass them to userspace but ...

One would need sth like a "callback hook" into userspace to query a
(routing) daemon before sending the flow.
I once did an ugly posix local socket based lookup patch to zebra so
traceroute could extract AS#s.

and an extra hook, if connected ask the userspace daemon (be it
the routing daemon or an intermediate) at the other end for the
AS# once the flow starts and if you get an answer fill it in;
if you don't leave it empty.


What I'd like to ask but did not because I didn't really have a
chance to view more than documentation is:
- what is the memory impact of this node ?
- can it cope with 50++ Mbit/s UDP worms scanning large subnets ?

-- 
Bjoern A. Zeeb				bzeeb at Zabbadoz dot NeT


More information about the freebsd-net mailing list