[c-nsp] Traffic destined to IPs that are null routed, Netflow, and you!
Sven Huster
sven at huster.me.uk
Fri Mar 12 13:16:08 EST 2010
On 12 Mar 2010, at 17:43, Dobbins, Roland wrote:
>
> On Mar 13, 2010, at 12:37 AM, Sven Huster wrote:
>
>> Interesting that you say that given that last time round I saw 600Mbps drop off of ingress on a E3 GE port in my NetFlow data once the dst had been blackholed,
>
> What collection/analysis tools were you using? Did you have the chance to check the NetFlow cache on the relevant LCs for entries related to this traffic?
nfdump/nfsen
We didn't get around to check on the LC at the time
>
> Both E3 and E5 should all expected normal NetFlow behaviors, including showing stats on dropped traffic as having a destination ifindex of 0.
This would be very nice, indeed.
--
Sven
More information about the cisco-nsp
mailing list