[IPFIX] updated IPFIX drafts

Paul Aitken <[email protected]> Fri, 10 Jan 2014 13:55:20 +0000
Newsgroups gmane.ietf.ipfix
Message-ID <[email protected]>
I updated two drafts during the holidays:


http://tools.ietf.org/html/draft-aitken-ipfix-unobserved-fields-02

         The IPFIX protocol is designed to export information about
         observations, and lacks a method for reporting that observations
         are unavailable. This document discusses several methods for
         reporting when fields are unavailable, reviews the advantages
         and disadvantage of each, and recommends methods which should be
         used.


This is a huge hole in IPFIX which we cannot ignore.

eg
     * how can you report that although you observed 1,000 packets, none 
of them contained an IPv4 source address?
     * how can you report the 15-minute average in the (t < 15mins) 
interval ?

Cisco is already using several of the techniques in this draft.


     http://tools.ietf.org/html/draft-aitken-ipfix-equivalent-ies-01

       This document specifies a method for an
       IPFIX Exporting Process to inform an IPFIX Collecting Process
       of equivalence between different Information Elements, so
       that the Collecting Process can understand the equivalence
       and be enabled to process data across a change of
       Information Elements.


This draft provides a mechanism for exporters to migrate from 
enterprise-specific elements to IANA-standard elements with minimal 
collector impact.

Andrew Feren and I identified a surprisingly large list of existing 
duplicate Information Elements to which this draft applies, thus the update.

P.

_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix