Problem with pflow interface not sending data

Jayson Henkel <[email protected]> Thu, 29 Aug 2019 18:29:42 -0700
Newsgroups gmane.os.openbsd.pf
Message-ID <CAJ8TOW-ArvPVW49P0fqYrmNkFaLO1BRnLY67_mc8Bw7FU-PPpA@mail.gmail.com>
--000000000000536a0a05914b9060
Content-Type: text/plain; charset="UTF-8"

Hello,
I am troubleshooting an issue where I have 3 pf boxes that have (apart from
different flowsrc and flowdst port info) the exact same configuration. I am
only receiving data from one of them. I have created firewall rules for the
netflow traffic to transit the network, and validated the path is
unfiltered using netcat (nc -s <flowsrc ip> -u <flowdst ip> <dst port>
)while running tcpdump to capture the data on the collector. I can see the
nc test as well as the working data arriving on the collector fine. I have
also tcpdumped on the sensor itself and on the working pflow sensor, I can
see the traffic leaving for the collector. On the other 2 I see no traffic
matching a tcpdump filter to the collector. I used the set state-defaults
pflow statement in all 3 pf.conf files and reloaded the files via pfctl -f
/etc/pf.conf. I have also validated that pfctl -sr now shows (pflow)
indicators for rules. Lastly I have ifconfig'd the interfaces up/down.

At this point I am completely uncertain what could possibly be wrong, why I
am not seeing any data being generated, and am nearly at the point where I
suspect it might be rectified by a reboot. Is there something else I can
troubleshoot? I should note that I haven't Flushed the ruleset, and wanted
to do that and or a reboot as a last resort.

Can anyone suggest how to go about identifying the issue?

--000000000000536a0a05914b9060
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hello, <br></div><div>I am troubleshooting an issue w=
here I have 3 pf boxes that have (apart from different flowsrc and flowdst =
port info) the exact same configuration. I am only receiving data from one =
of them. I have created firewall rules for the netflow traffic to transit t=
he network, and validated the path is unfiltered using netcat (nc -s &lt;fl=
owsrc ip&gt; -u &lt;flowdst ip&gt; &lt;dst port&gt; )while running tcpdump =
to capture the data on the collector. I can see the nc test as well as the =
working data arriving on the collector fine. I have also tcpdumped on the s=
ensor itself and on the working pflow sensor, I can see the traffic leaving=
 for the collector. On the other 2 I see no traffic matching a tcpdump filt=
er to the collector. I used the set state-defaults pflow statement in all 3=
 pf.conf files and reloaded the files via pfctl -f /etc/pf.conf. I have als=
o validated that pfctl -sr now shows (pflow) indicators for rules. Lastly I=
 have ifconfig&#39;d the interfaces up/down.<br></div><div><br></div><div>A=
t this point I am completely uncertain what could possibly be wrong, why I =
am not seeing any data being generated, and am nearly at the point where I =
suspect it might be rectified by a reboot. Is there something else I can tr=
oubleshoot? I should note that I haven&#39;t Flushed the ruleset, and wante=
d=C2=A0 to do that and or a reboot as a last resort.</div><div><br></div><d=
iv>Can anyone suggest how to go about identifying the issue?</div><div><br>=
</div><div><br></div></div>

--000000000000536a0a05914b9060--