From owner-freebsd-questions@FreeBSD.ORG Thu Jul 23 12:12:47 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B3A89106564A for ; Thu, 23 Jul 2009 12:12:47 +0000 (UTC) (envelope-from reinhard.haller@interactive-net.de) Received: from moutng.kundenserver.de (moutng.kundenserver.de [212.227.126.171]) by mx1.freebsd.org (Postfix) with ESMTP id 40F028FC13 for ; Thu, 23 Jul 2009 12:12:47 +0000 (UTC) (envelope-from reinhard.haller@interactive-net.de) Received: from interactive.dnsalias.net (ppp-93-104-65-198.dynamic.mnet-online.de [93.104.65.198]) by mrelayeu.kundenserver.de (node=mreu2) with ESMTP (Nemesis) id 0MKv5w-1MTxAD3mnZ-000lQa; Thu, 23 Jul 2009 14:12:46 +0200 Received: from scalix.interactive.de ([fd08:e8a3:4825:0:20c:29ff:feaa:3622]) by interactive.dnsalias.net with esmtp (Exim 4.69 (FreeBSD)) (envelope-from ) id 1MTxAD-0002dg-7V for freebsd-questions@freebsd.org; Thu, 23 Jul 2009 14:12:45 +0200 Received: from scalix.interactive.de (localhost.localdomain [127.0.0.1]) by scalix.interactive.de (8.13.8/8.13.8) with ESMTP id n6NCAr6c011193 for ; Thu, 23 Jul 2009 14:10:54 +0200 Received: from [127.0.0.1] (Core2Duo.interactive.de [192.168.0.196]) by scalix.interactive.de (Scalix SMTP Relay 11.4.2.12068) via ESMTP; Thu, 23 Jul 2009 14:10:53 +0200 (CEST) Date: Thu, 23 Jul 2009 14:12:42 +0200 From: Reinhard Haller To: freebsd-questions@freebsd.org Message-ID: <4A6853BA.5070308@interactive-net.de> x-scalix-Hops: 1 User-Agent: Thunderbird 2.0.0.22 (Windows/20090605) MIME-Version: 1.0 Content-Type: text/plain; charset="US-ASCII" Content-Disposition: inline X-ACL-rcpt: freebsd-questions@freebsd.org X-ACL-Send: reinhard.haller@interactive-net.de X-Provags-ID: V01U2FsdGVkX1+Znf032F+TcbP7Hwj/oVG/RmS7e1OAsQWTf8/ /AAx3aoXca0W7+9bzKvMjluK3GtATmc7JRi50D0AVvXS0S86U3 4bRBxFyb9Hn3FNGaCayxmcvdr8HNN03crmXJ+j3BmtvcByu0U8 hiw== Subject: ng_netflow and ipv6 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 23 Jul 2009 12:12:47 -0000 Hi, I'm monitoring the network traffic with ng_netflow and collecting/displaying it with nfsen. I'm missing ipv6 traffic (all ssh-traffic is going over ipv6) in the filtered netflow output. I've checked the netflow data with tcpdump/wireshark, there is no ipv6 netflow monitored. My config: FreeBSD 7.2 with netgraph included in kernel configuration ngctl -f /usr/local/etc/netflow.conf is started after boot with the following config: mkpeer em0: netflow lower iface0 name em0:lower netflow connect em0: netflow: upper out0 mkpeer netflow: ksocket export inet/dgram/udp msg netflow:export connect inet/192.168.0.31:9996 connect em1: netflow: lower iface1 connect em1: netflow: upper out1 connect nfe0: netflow: lower iface2 connect nfe0: netflow: upper out2 msg netflow: setconfig {iface=0 conf=7} msg netflow: setconfig {iface=1 conf=7} msg netflow: setconfig {iface=2 conf=7} Any suggestions? Thanks Reinhard Haller