Community discussions

MikroTik App
 
User avatar
Eising
Member Candidate
Member Candidate
Topic Author
Posts: 272
Joined: Mon Oct 27, 2008 10:21 am
Location: Copenhagen, Denmark

Traffic-flow sends bogus data

Tue Oct 20, 2009 6:33 pm

Hi there,
I enabled traffic-flow on two of my border BGP routers, running RouterOS 3.25 and 4.1. It have set it up to send data as Netflow version 5, but the data I receive is useless. All netflow packets contain information about packets from source address 0.0.0.0 to destination address 0.0.0.0, in fact all fields in the netflow payload is set to 0.

Is this a known bug, or am I doing something wrong?
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Traffic-flow sends bogus data

Tue Oct 20, 2009 6:40 pm

is connection-tracking on or off? I wonder if its related to that.
 
User avatar
Eising
Member Candidate
Member Candidate
Topic Author
Posts: 272
Joined: Mon Oct 27, 2008 10:21 am
Location: Copenhagen, Denmark

Re: Traffic-flow sends bogus data

Tue Oct 20, 2009 7:39 pm

It's off, and it's going to stay off, since there is no way I can be certain that the traffic is symmetrical...
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Traffic-flow sends bogus data

Tue Oct 20, 2009 7:40 pm

yep, im in the same situation. Im guessing traffic-flow probably requires connection-tracking. Another item to add to the wiki for connection-tracking : )
 
User avatar
Eising
Member Candidate
Member Candidate
Topic Author
Posts: 272
Joined: Mon Oct 27, 2008 10:21 am
Location: Copenhagen, Denmark

Re: Traffic-flow sends bogus data

Tue Oct 20, 2009 7:42 pm

Have you tested that?
 
User avatar
Eising
Member Candidate
Member Candidate
Topic Author
Posts: 272
Joined: Mon Oct 27, 2008 10:21 am
Location: Copenhagen, Denmark

Re: Traffic-flow sends bogus data

Tue Oct 20, 2009 8:25 pm

I just tested it myself with another router running 3.27. I get my netflow data correct from that one. I'll do some more testing and see at what version it breaks.
 
User avatar
Eising
Member Candidate
Member Candidate
Topic Author
Posts: 272
Joined: Mon Oct 27, 2008 10:21 am
Location: Copenhagen, Denmark

Re: Traffic-flow sends bogus data

Tue Oct 20, 2009 10:06 pm

Hmm, this is indeed weird. I cannot reproduce this bug with any other system other than my BGP border routers, so my guess is that this issue cannot be solved easily here on the forum, so I'm contacting support with a sup-out.
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: Traffic-flow sends bogus data

Wed Oct 21, 2009 6:14 pm

I have added NetFlow Target on my BGP router (NF was enabled already) - and have seen zeroed flows, then all became normal, and I can't repeat it now... v3.27...

Who is online

Users browsing this forum: Bing [Bot] and 106 guests