[c-nsp] Traffic destined to IPs that are null routed, Netflow, and you!

Sven Huster sven at huster.me.uk
Fri Mar 12 13:16:08 EST 2010


On 12 Mar 2010, at 17:43, Dobbins, Roland wrote:

> 
> On Mar 13, 2010, at 12:37 AM, Sven Huster wrote:
> 
>> Interesting that you say that given that last time round I saw 600Mbps drop off of ingress on a E3 GE port in my NetFlow data once the dst had been blackholed, 
> 
> What collection/analysis tools were you using?  Did you have the chance to check the NetFlow cache on the relevant LCs for entries related to this traffic?

nfdump/nfsen
We didn't get around to check on the LC at the time

> 
> Both E3 and E5 should all expected normal NetFlow behaviors, including showing stats on dropped traffic as having a destination ifindex of 0. 

This would be very nice, indeed.

--
Sven



More information about the cisco-nsp mailing list