Problem with pflow interface not sending data
Jayson Henkel <[email protected]> Thu, 29 Aug 2019 18:29:42 -0700
| Newsgroups | gmane.os.openbsd.pf |
|---|---|
| Message-ID | <CAJ8TOW-ArvPVW49P0fqYrmNkFaLO1BRnLY67_mc8Bw7FU-PPpA@mail.gmail.com> |
--000000000000536a0a05914b9060 Content-Type: text/plain; charset="UTF-8" Hello, I am troubleshooting an issue where I have 3 pf boxes that have (apart from different flowsrc and flowdst port info) the exact same configuration. I am only receiving data from one of them. I have created firewall rules for the netflow traffic to transit the network, and validated the path is unfiltered using netcat (nc -s <flowsrc ip> -u <flowdst ip> <dst port> )while running tcpdump to capture the data on the collector. I can see the nc test as well as the working data arriving on the collector fine. I have also tcpdumped on the sensor itself and on the working pflow sensor, I can see the traffic leaving for the collector. On the other 2 I see no traffic matching a tcpdump filter to the collector. I used the set state-defaults pflow statement in all 3 pf.conf files and reloaded the files via pfctl -f /etc/pf.conf. I have also validated that pfctl -sr now shows (pflow) indicators for rules. Lastly I have ifconfig'd the interfaces up/down. At this point I am completely uncertain what could possibly be wrong, why I am not seeing any data being generated, and am nearly at the point where I suspect it might be rectified by a reboot. Is there something else I can troubleshoot? I should note that I haven't Flushed the ruleset, and wanted to do that and or a reboot as a last resort. Can anyone suggest how to go about identifying the issue? --000000000000536a0a05914b9060 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hello, <br></div><div>I am troubleshooting an issue w= here I have 3 pf boxes that have (apart from different flowsrc and flowdst = port info) the exact same configuration. I am only receiving data from one = of them. I have created firewall rules for the netflow traffic to transit t= he network, and validated the path is unfiltered using netcat (nc -s <fl= owsrc ip> -u <flowdst ip> <dst port> )while running tcpdump = to capture the data on the collector. I can see the nc test as well as the = working data arriving on the collector fine. I have also tcpdumped on the s= ensor itself and on the working pflow sensor, I can see the traffic leaving= for the collector. On the other 2 I see no traffic matching a tcpdump filt= er to the collector. I used the set state-defaults pflow statement in all 3= pf.conf files and reloaded the files via pfctl -f /etc/pf.conf. I have als= o validated that pfctl -sr now shows (pflow) indicators for rules. Lastly I= have ifconfig'd the interfaces up/down.<br></div><div><br></div><div>A= t this point I am completely uncertain what could possibly be wrong, why I = am not seeing any data being generated, and am nearly at the point where I = suspect it might be rectified by a reboot. Is there something else I can tr= oubleshoot? I should note that I haven't Flushed the ruleset, and wante= d=C2=A0 to do that and or a reboot as a last resort.</div><div><br></div><d= iv>Can anyone suggest how to go about identifying the issue?</div><div><br>= </div><div><br></div></div> --000000000000536a0a05914b9060--