Configuring Export and Template of DPI Traffic Processing Events in IPFIX Format
DPI traffic processing events (for example, triggering of CG-NAT limits) are exported via a dedicated IPFIX channel — ipfix_reporting.
Export Configuration
Event export is configured with the following parameters:
ipfix_reporting_udp_collectors=1.2.3.4:1500 ipfix_reporting_tcp_collectors=1.2.3.6:9418 reporting_events=2 reporting_events_min_queue=512 reporting_events_rate_limit=100/s
where
ipfix_reporting_udp_collectors— addresses of UDP collectors.ipfix_reporting_tcp_collectors— addresses of TCP collectors.reporting_events— bit mask of the event types to be exported. Default is 0 (the subsystem is disabled and no memory is allocated for events). The bit number corresponds to the event type:2— CG-NAT session limit triggered
Example:reporting_events=2
reporting_events_min_queue— capacity of the worker thread's event queue, in messages. The actual capacity is at least the specified value: the buffer size is rounded up to a power of two. Default is 512.reporting_events_rate_limit— event export rate limit in the format<number>[/[<number>]<s|ms>]; the default period is one second. Default is 0 (no limit). Example values:100,100/s,10/100ms,50/2s.
IPFIX Template
The IPFIX record structure is defined by the reporting_ipv4 and reporting_ipv6 templates.
Standard IANA fields:
| ID | Name | Description |
|---|---|---|
| 323 | observationTimeMilliseconds | Event time |
| 8 / 27 | sourceIPv4Address / sourceIPv6Address | Source address |
| 12 / 28 | destinationIPv4Address / destinationIPv6Address | Destination address |
| 7 | sourceTransportPort | Source port |
| 11 | destinationTransportPort | Destination port |
| 4 | protocolIdentifier | Protocol identifier |
| 56 | sourceMacAddress | Source MAC address |
| 80 | destinationMacAddress | Destination MAC address |
| 58 | vlanId | Inner VLAN |
| 243 | dot1qVlanId | Outer VLAN (QinQ) |
Enterprise fields (PEN 43823):
| ID | Name | Description |
|---|---|---|
| 3300 | event_type | Event type |
| 3301 | event_count | Total number of events of this type since startup |
| 3302 | sample_rate | Number of events suppressed by the rate limiter since the previous record |
Event types with the same set of fields share a common template and are distinguished by the
event_type field. Separate templates will be added for event types that have their own set of fields.
Was this information helpful?