Re: [IPFIX] [QUAR] Re: Export of long lived flow information

Andrew Feren <[email protected]>
Newsgroups gmane.ietf.ipfix
Message-ID <[email protected]>
Hi Paul,

Interesting observation.   The use of flow in these has never tripped me 
up the same way as the text in the original question.

On 10/29/2012 07:56 AM, Paul Aitken wrote:
> Should we change "this Flow" to "accounted in this Flow Record" 
> throughout the registry?
>
> I counted 67 instances. eg:
>
>
> octetDeltaCount
>
>          The number of octets since the previous report (if any)
>          in incoming packets for this Flow at the Observation Point.

For this I think Flow is correct.  I also think this highlights the 
distinction being made by people between Flow and Flow Record.  If a 
Flow is bounded the same way (has the same start and end time) as a Flow 
Record then there can't have been a previous report for this Flow.  The 
Flow and Flow Record would be the same.

>
>
> tcpControlBits
>
>          TCP control bits observed for packets of this Flow.
>          The information is encoded in a set of bit fields.
>          For each TCP control bit, there is a bit in this
>          set.  A bit is set to 1 if any observed packet of this
>          Flow has the corresponding TCP control bit set to 1.
>          A value of 0 for a bit indicates that the corresponding
>          bit was not set in any of the observed packets
>          of this Flow.
>
>
> flowDurationMilliseconds
>
>          The difference in time between the first observed packet
>          of this Flow and the last observed packet of this Flow.

Eep.  Thinking about this is making me rethink my initial +1, but I do 
still think some rewording is needed.  Using Flow Record works for 
deltas, but not for totals.  I'm not sure yet what the right wording is.

>
>
> ingressInterface
>
>            The index of the IP interface where packets of this Flow
>            are being received.
>
>
> egressInterface
>
>            The index of the IP interface where packets of
>            this Flow are being sent.

I think these last two are typically part of what defines a flow and 
won't change with out changing the Flow.  So I guess Flow is as good as 
Flow Record.
>
> P.

_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.