Re: [IPFIX] Export of long lived flow information

Andrew Feren <[email protected]>
Newsgroups gmane.ietf.ipfix
Message-ID <[email protected]>
Hi Gerhard,

On 10/25/2012 02:26 PM, Gerhard Muenz wrote:
>
> Hi,
>
[ snip ]
>
> My understanding is that both, deltaCounts and totalCounts contain the 
> number of packets or octets observed in the indicated time interval. 
> So, for identical flowStart* and flowEnd* timestamps, the values are 
> the same.
This is my understanding as well.
>
> However, the description of totalCounts says that you report the 
> number of packets or octets observed for this Flow since 
> re-initialization. So, you must never reset the counter for this Flow, 
> even after observing a FIN or RST.
> If you reset flow counters, or if you remove Flows from your Cache, 
> you cannot use totalCounts any more unless you re-initialize the 
> Metering Process (e.g. after flushing the entire permanent Cache).

I can try some tests later, but from what I have seen (and been told) 
many totals being exported are in fact just a delta sent once at the end 
of the flow.  If a later flow had the same IPs, protocol, and ports as 
an earlier flow I'm pretty sure a new start time will be sent rather 
than the the first time that flow was seen since reinitializing the 
metering process.  Or to put it an other way I think deltas are being 
sent, but called totals by the implementation because it seemed like the 
right thing to do for a value being sent once at the end of the flow.

I suspect that totals reporting on the export process (eg 
exportedOctetTotalCount, exportedMessageTotalCount) are, however, 
reported with a start time that is only reset on reinitialization.

-Andrew
_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.