Hello,
I recently bought Nprobe pro. I collect Netflow V9 and then sent it back in V5 to a server.
I need to blacklist some networks, so i used the « --black-list » argument, but it does not seems to works.
Here is the command i use :
nprobe -n udp://10.11.1.140:2055 -i none -t 20 -d 20 -a 0 -e 1 -b 2 -w 128000 -z 0 -S 1:1 -u 1 -Q 1 -3 9995 --zmq tcp://127.0.0.1:5556 -V5 -G --black-list 10.7.0.0/16,10.1.0.0/16,10.11.0.0/16,192.168.0.0/16
And here is somes logs of networks that i dont want to send back to my server :
23/May/2016 09:55:43 [engine.c:2541] Emitting Flow: [->][icmp] 10.1.1.104:2048 -> 10.2.1.41:0 [1 pkt/60 bytes][ifIdx 22273->111][0.0 sec][ECHO REPLY][init Unknown][AS: 0 -> 0]
23/May/2016 09:55:46 [engine.c:2568] Emitting Flow: [<-][icmp] 10.2.1.42:0 -> 10.1.1.48:2048 [2 pkt/120 bytes][ifIdx 111->22273][0.0 sec][AS: 0 -> 0]
23/May/2016 09:55:42 [engine.c:2361] New Flow: [icmp] 10.1.1.104:2048 -> 10.2.1.1:0 [00:00:00:00:00:00 -> 00:00:00:00:00:00][vlan 65535][tos 0][ifIdx: 22273 -> 111][subflowId: 0/0x0000][idx=69225]
What did i do wrong ?
Thanks for you help !
CRUCHADE Loïc
05.82.52.22.02
Service Exploitation Informatique
Direction des Systèmes d'information
[logo]
I recently bought Nprobe pro. I collect Netflow V9 and then sent it back in V5 to a server.
I need to blacklist some networks, so i used the « --black-list » argument, but it does not seems to works.
Here is the command i use :
nprobe -n udp://10.11.1.140:2055 -i none -t 20 -d 20 -a 0 -e 1 -b 2 -w 128000 -z 0 -S 1:1 -u 1 -Q 1 -3 9995 --zmq tcp://127.0.0.1:5556 -V5 -G --black-list 10.7.0.0/16,10.1.0.0/16,10.11.0.0/16,192.168.0.0/16
And here is somes logs of networks that i dont want to send back to my server :
23/May/2016 09:55:43 [engine.c:2541] Emitting Flow: [->][icmp] 10.1.1.104:2048 -> 10.2.1.41:0 [1 pkt/60 bytes][ifIdx 22273->111][0.0 sec][ECHO REPLY][init Unknown][AS: 0 -> 0]
23/May/2016 09:55:46 [engine.c:2568] Emitting Flow: [<-][icmp] 10.2.1.42:0 -> 10.1.1.48:2048 [2 pkt/120 bytes][ifIdx 111->22273][0.0 sec][AS: 0 -> 0]
23/May/2016 09:55:42 [engine.c:2361] New Flow: [icmp] 10.1.1.104:2048 -> 10.2.1.1:0 [00:00:00:00:00:00 -> 00:00:00:00:00:00][vlan 65535][tos 0][ifIdx: 22273 -> 111][subflowId: 0/0x0000][idx=69225]
What did i do wrong ?
Thanks for you help !
CRUCHADE Loïc
05.82.52.22.02
Service Exploitation Informatique
Direction des Systèmes d'information
[logo]