>  but why is it showing up in the netflow exports?

Because that's how NetFlow is supposed to work on a real router, vs. the broken implementation on 6500/7600 with current hardware.


It's of great operational significance to know that even though you're dropping traffic on your side of a link via uRPF, S/RTBH, ACLs, whatever, said traffic is still pummeling your router.  You can then work with your peer/upstream/downstream/customer to get the traffic squelched closer to the actual source(s).

