[IPFIX] updated IPFIX drafts
Paul Aitken <[email protected]> Fri, 10 Jan 2014 13:55:20 +0000
| Newsgroups | gmane.ietf.ipfix |
|---|---|
| Message-ID | <[email protected]> |
I updated two drafts during the holidays:
http://tools.ietf.org/html/draft-aitken-ipfix-unobserved-fields-02
The IPFIX protocol is designed to export information about
observations, and lacks a method for reporting that observations
are unavailable. This document discusses several methods for
reporting when fields are unavailable, reviews the advantages
and disadvantage of each, and recommends methods which should be
used.
This is a huge hole in IPFIX which we cannot ignore.
eg
* how can you report that although you observed 1,000 packets, none
of them contained an IPv4 source address?
* how can you report the 15-minute average in the (t < 15mins)
interval ?
Cisco is already using several of the techniques in this draft.
http://tools.ietf.org/html/draft-aitken-ipfix-equivalent-ies-01
This document specifies a method for an
IPFIX Exporting Process to inform an IPFIX Collecting Process
of equivalence between different Information Elements, so
that the Collecting Process can understand the equivalence
and be enabled to process data across a change of
Information Elements.
This draft provides a mechanism for exporters to migrate from
enterprise-specific elements to IANA-standard elements with minimal
collector impact.
Andrew Feren and I identified a surprisingly large list of existing
duplicate Information Elements to which this draft applies, thus the update.
P.
_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix