Answer the question
In order to leave comments, you need to log in
Where is it correct to insert -j NETFLOW?
There is a firewall on the router (with a hard policy drop), a little nat, a few services.
I would like to take into account all the actual received, sent and forwarded traffic, with its actual src / dst (that is, before SNAT and after DNAT).
How to correctly arrange -j netflow so that the traffic is distinguishable and not confused?
Is there any difference between inserting into *filter (input, output, forward) or into *nat (prerouting, postrouting)?
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question