PF, The OpenBSD Packet Filter: Building The Network You Need: BSDCan, Ottawa, June 10th 2015 | ||
---|---|---|
Prev | Next |
pflow(4) pseudo-device exports Netflow v5 data (introduced in OpenBSD 4.5)
a sensor, records data on flows: source/destination address, start/end time, # bytes
each connection consists of two flows (one for each direction)
pflow fetches data from the PF state table
Potentially very detailed data on your traffic
Initially only netflow version 5 (IPv4 only), from OpenBSD 5.1 onwards, versions 9 and 10 (aka IPFIX) are supported (with IPv6). Check what your collector side can handle