|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
The Exporting Process (PROTOCORE_ENABLE_FLOW_EXPORT): builds IPFIX Messages (RFC 7011), NetFlow Version 9 Export Packets (RFC 3954), and vendor NetFlow Version 5 packets. More...
#include "protocore_config.h"Go to the source code of this file.
The Exporting Process (PROTOCORE_ENABLE_FLOW_EXPORT): builds IPFIX Messages (RFC 7011), NetFlow Version 9 Export Packets (RFC 3954), and vendor NetFlow Version 5 packets.
RFC 7011 sec 3 "IPFIX Message Format": a Message is a Message Header (sec 3.1) followed by one or more Sets (sec 3.3). RFC 3954 sec 5 "Export Packet Format" is the same shape one revision earlier: a Header (sec 5.1) followed by FlowSets. Every field is network byte order.
Template-then-data. A Template Record (RFC 7011 sec 3.4.1, RFC 3954 sec 5.2) lists the Field Specifiers a record carries and is given a Template ID; Data Records (RFC 7011 sec 3.4.3, RFC 3954 sec 5.3) then travel in a Set whose Set ID is that Template ID. RFC 7011 sec 3.3.2: "A value of 2 is reserved for Template Sets... Values 256 and above are used for Data Sets." RFC 3954 sec 5.2 uses FlowSet ID 0 for the Template FlowSet and reserves IDs 0-255.
A Field Specifier (RFC 7011 sec 3.2) is an Information Element identifier plus a Field Length. The identifier is the elementId of RFC 7012 sec 2.1, from the IANA "IPFIX Information Elements" registry (RFC 7012 sec 7.1). The E bit stays zero here, so no Enterprise Number follows.
NetFlow Version 5 has no IETF specification. It is a vendor-defined fixed export format (Cisco Systems NetFlow Version 5); RFC 3954 specifies Version 9 only and does not describe Version 5. The layout built here is that vendor format: a 24-octet header then N 48-octet records.
One message is under construction at a time: ipfix_begin or v9_begin, then template_set, data_set_begin, data_record, data_set_end, then message_finish, which patches the IPFIX Message Length (RFC 7011 sec 3.1) or the v9 Count (RFC 3954 sec 5.1) and reports the octets. This is the wire codec only; the flow cache is the app's and the datagram send is Udp.client->sendto.
Definition in file flow_export.h.