I’m looking at using the Traffic Flow to transmit data for usage based billing. I have inspected the Traffic Flow streams coming from my MT router and it seems to have a pretty limited field set. Right now I’m getting these fields:
1 - In Bytes
2 - InPkts
4 - Protocol
5 - SrcTOS
6 - TCPFlags
7 - Src Port
8 - Src Address
10 - InputSNMP
11 - L4 Dst Port
12 - Dst Addr
13 - Dst Mask
14 - Output SNMP
15 - IPV4 Next Hop
21 - last switched
22 - first switched
These are a nice start, but I would also like some more…espcially 9 - Src MAC. Since I run DHCP, it is difficult to track usage simply by IP. It would be better to track by MAC. Any chance of including some more fields in the NetFlow stream coming out?