Re: [IPFIX] rfc5103 lite
Andrew Feren <[email protected]>
| Newsgroups | gmane.ietf.ipfix |
|---|---|
| Message-ID | <[email protected]> |
On 03/06/2012 04:50 PM, Paul Aitken wrote: > Andrew, > >> I am seeing many NetFlow v9 exporters that >> >> * send IEs above 127 > > Of course. It's a 16-bit number space. Agreed. I was mostly responding to Brian's "not in v9 space" comment. I assumed he was referring to "Information Element identifier values in the sub-range of 1-127 are compatible with field types used by NetFlow version 9" from RFC 5102. >> (As long as they keep the the IPFIX datatype and semantics this is >> not a problem) > > Note that NFv9 and IPFIX are two different protocols, so there's no > requirement for the IPFIX datatype and semantics to apply to the same > field ID in NFv9. Understood. > > - although in our case, we've endeavoured to do this as much as > possible, assuming virtual equality between the two infomodels. And I appreciate that effort. Since NFv9 is Cisco's protocol I tend to treat what Cisco does for v9 as "standard", but point taken that there is no actual requirement. >> * implement vendor specific IEs without a PEN. (I know of hundreds >> of vendor IEs above 32,767 defined by at least 5 vendors) > > NFv9 doesn't have any vendor-specific IEs. It's a cisco protocol, and > we might define any field to have any meaning at any time. OK, but I wasn't sure what else to call an IE that isn't in any standard, is sent only from one vendor, and is sent using a protocol that looks suspiciously like NetFlow v9. :-) > > Also, there's no requirement for non-cisco vendors to use IDs > 32768. > They could use any ID in the NFv9 range. Agreed. My bias toward keeping v9 IEs that are not also standard IPFIX in a range that won't conflict with an eventual IPFIX IE leaked through. > > After discussing with Mike, I recently allocated some blocks of IDs > within the NFv9 range for different vendors, in an effort to prevent > us re-defining the same fields for different purposes. > It's only a pity that the vendors didn't approach me first. > > Vendors, reach out to me if you're exporting your own NFv9 fields so > we can avoid ID collisions. Thanks for taking that on. -Andrew _______________________________________________ IPFIX mailing list [email protected] https://www.ietf.org/mailman/listinfo/ipfix