Re: [IPFIX] TCP flags?
Paul Aitken <[email protected]>
| Newsgroups | gmane.ietf.ipfix |
|---|---|
| Message-ID | <[email protected]> |
Brian, > 've got on my list of things to do in my copious free time having a look at improving the wireshark dissector for IPFIX. +1 > I mainly use ripfix / python-ipfix for debugging IPFIX because of bad experiences with the wireshark dissector years ago, and I wasn't aware that anyone was trying to use it / that it was still maintained at all. I do - though I'm aware of several caveats and don't blindly trust what wireshark says. >> I still like option 2, but could be persuaded that 3 is the better option. > Option 2 would be my preferred option; Option 3 (deprecation) seems like a whole lot of procedural effort (especially when at least n EP vendors are already exporting the high two bits regardless of the spec). The tcpHighControlBits option was a hack I proposed in case option 2 was somehow unacceptable. +1 I'm reading this as 3 votes for option 2: extended the existing IE to 16 bits. _______________________________________________ IPFIX mailing list [email protected] https://www.ietf.org/mailman/listinfo/ipfix