[IPFIX] rfc5103 lite
Andrew Feren <[email protected]>
| Newsgroups | gmane.ietf.ipfix |
|---|---|
| Message-ID | <[email protected]> |
While reviewing the ie-doctors draft part of "4.10. Avoiding Bad Ideas
in Information Element Design" caught my attention.
"Specific examples of
such Information Elements include initiatorOctets and responderOctets
(which duplicate octetDeltaCount and its reverse per [RFC5103]) and
initiatorPackets and responderPackets (the same, for
packetDeltaCount)."
I agree that the initiatorOctets and initiatorPackets are redundant. I
also agree that in the context of IPFIX that responderOctets and
responderPackets are made redundant by RFC 5103. However, I think there
is a valid use for the responderOctets and responderPackets IEs.
I see a lot of interest in implementing biflows, but many exporters are
still exporting NetFlow v9 (RFC 3954). The IEs for responderOctets and
responderPackets allow a limited version of 5103 to be exported until
the exporter can support IPFIX. I'm not sure we want to paint these two
IEs with the "bad idea" brush. Maybe we could add a couple sentences to
clarify the situation.
Something along the lines of
For 3954 use of responderOctets and responderPackets is OK, but don't
expect new responder/reverse IEs to be added. If you need more reverse
IEs then IPFIX and 5103 should be implemented.
We should also fix initiatorPackets and responderPackets to not have
"identifier" semantics.
-Andrew
_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix