Project

General

Profile

Actions

Feature #15039

closed

GUI to configure Packet Flow Data (``pflow``) export

Added by Jim Pingle 8 months ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Rules / NAT
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Release Notes:
Default

Description

Following #15038 the GUI will need a set of options to configure pflow(4) behavior

It will need at least the following options:

  • Flow source IP address (optional) - Can be an interface address, IP alias VIP, CARP VIP.
  • Flow source port (optional, but if set, source IP address must also be set)
  • Flow destination IP address (required)
  • Flow destination port (required)
  • Flow protocol select between:
    • 5 - Netflow v5
    • 10 - IPFIX

See also: https://man.openbsd.org/ifconfig.8#PFLOW

It's not abundantly clear where the best place in the UI would be for this. It's a feature of PF and not a daemon/service. It's related to traffic monitoring but it isn't a graph or log of its own. So it may fit under Firewall > Traffic Flows or maybe System > Traffic Flows for example. Exact location is open for ideas/debate.


Related issues

Follows Feature #15038: Operating System support for PF ``pflow`` packet data flow exportClosedKristof Provost

Actions
Actions

Also available in: Atom PDF