[nsp] Sup720 and ACL/netflow processing
Iva Cabric
ivac at iskon.hr
Thu Dec 18 03:38:44 EST 2003
On Thu, Dec 18, 2003 at 11:07:56AM +0300, Sergey V. Artjushkin wrote:
> Hello
>
> Hm, I see that my Sup720 is working different. For example, I have
> input acl on this interface:
>
[...]
> And in netflow I see the following packets:
>
> flow #55 received from router 217.23.151.44, IP protocol 1
> input ifIndex: 18
> source IP address: 62.215.85.110
> source port: 0
> source AS: FAST-TELCO(21050)
> output ifIndex: 0
> dest IP address: 62.213.67.228
> dest port: 2048
> dest AS: <unknown>(0)
> nexthop: 0.0.0.0
> bytes in flow: 92
> packets in flow: 1
>
> This is icmp echo-rquest scanning.
>From where do you export flows (MSFC, or Supervisor) and are you getting
flows for each ICMP packet?
More information about the cisco-nsp
mailing list