[nsp] Sup720 and ACL/netflow processing

Iva Cabric ivac at iskon.hr
Thu Dec 18 03:38:44 EST 2003


On Thu, Dec 18, 2003 at 11:07:56AM +0300, Sergey V. Artjushkin wrote:
> Hello
> 
> Hm, I see that my Sup720 is working different. For example, I have
> input acl on this interface:
> 

[...]

> And in netflow I see the following packets:
> 
> flow #55 received from router 217.23.151.44, IP protocol 1
>   input ifIndex:     18
>   source IP address: 62.215.85.110
>   source port:       0
>   source AS:         FAST-TELCO(21050)
>   output ifIndex:    0
>   dest IP address:   62.213.67.228
>   dest port:         2048
>   dest AS:           <unknown>(0)
>   nexthop:           0.0.0.0
>   bytes in flow:       92
>   packets in flow:   1
> 
> This is icmp echo-rquest scanning.

>From where do you export flows (MSFC, or Supervisor) and are you getting
flows for each ICMP packet? 



More information about the cisco-nsp mailing list