Table of Contents

Configuring Export and Template of DPI Traffic Processing Events in IPFIX Format

DPI traffic processing events (for example, triggering of CG-NAT limits) are exported via a dedicated IPFIX channel — ipfix_reporting.

Export Configuration

Event export is configured with the following parameters:

ipfix_reporting_udp_collectors=1.2.3.4:1500
ipfix_reporting_tcp_collectors=1.2.3.6:9418
reporting_events=2
reporting_events_min_queue=512
reporting_events_rate_limit=100/s

where

IPFIX Template

The IPFIX record structure is defined by the reporting_ipv4 and reporting_ipv6 templates.

Standard IANA fields:

ID Name Description
323 observationTimeMilliseconds Event time
8 / 27 sourceIPv4Address / sourceIPv6Address Source address
12 / 28 destinationIPv4Address / destinationIPv6Address Destination address
7 sourceTransportPort Source port
11 destinationTransportPort Destination port
4 protocolIdentifier Protocol identifier
56 sourceMacAddress Source MAC address
80 destinationMacAddress Destination MAC address
58 vlanId Inner VLAN
243 dot1qVlanId Outer VLAN (QinQ)

Enterprise fields (PEN 43823):

ID Name Description
3300 event_type Event type
3301 event_count Total number of events of this type since startup
3302 sample_rate Number of events suppressed by the rate limiter since the previous record
Event types with the same set of fields share a common template and are distinguished by the event_type field. Separate templates will be added for event types that have their own set of fields.