Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

summary of points which need to be improved #2

Open
maplewf opened this issue Nov 16, 2021 · 0 comments
Open

summary of points which need to be improved #2

maplewf opened this issue Nov 16, 2021 · 0 comments
Assignees
Labels
bug Something isn't working

Comments

@maplewf
Copy link

maplewf commented Nov 16, 2021

Common issue

  1. L4 packet size doesn't include IP header
  2. GRE tunnel traffic is leaked to underlay interface
  3. GRE traffic can't be detected in underlay interface
  4. ESP(ipsec) traffic can't be decoded in underlay interface
  5. decode failure should be recorded in debug log

NFLOG

  1. for now, nflog engine is started per interface per direction which will waste resources. use --nflog-prefix with convention direction_interface in iptables to distinguish direction and interface with same nflog group like below:
-A FLOW_EXPORTER_IN -i eth0 -j NFLOG --nflog-prefix  in_eth0 --nflog-group 101 --nflog-range 64 --nflog-threshold 10
  1. duration is not accurate
    image

Libpcap

  1. vti tunnel traffic can't be collected
  2. openvpn tunnel traffic can't be collected

Afpkt

  1. GRE tunnel traffic can't be collected
  2. vti tunnel traffic can't be collected
  3. openvpn tunnel traffic can't be collected
  4. dmvpn tunnel traffic can't be collected
@fs714 fs714 self-assigned this Nov 17, 2021
@fs714 fs714 added the bug Something isn't working label Nov 17, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants