ipt-netflow icon indicating copy to clipboard operation
ipt-netflow copied to clipboard

Missing postNAT fields in netflow v9 flow records

Open gnought opened this issue 4 years ago • 1 comments

Adding netflow capture on PREROUTING and POSTROUTING chains, I found that the netflow v9 flow record does not contain postNAT fields. They are only in NAT events.

Is it by design? Can those fields be added to get pre-snat and post-dnat information in flow records?

gnought avatar May 31 '21 02:05 gnought

This is consequence of what information is available at the time of reporting a flow (in the iptables target).

aabc avatar May 31 '21 15:05 aabc