Folks,
Cisco has recently released (in 15.0.1) support for integration
between Network Based Application Recognition (NBAR)
and Flexible Netflow (FNF). This allows NBAR-recognized applications to be
identified in the Netflow output. To do so, 3 new template fields were
added:
94: APPLICATION_DESC
95: APPLICATION_ID
96: APPLICATION_NAME
I've created a patch to add these fields to packet-netflow.c, and
submitted it as bug #4345:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4345
I'd love it if someone could review the patch, as I haven't done much
hacking on wireshark, and am not familiar with all general coding
style preferences, nor dissector best practices.
Thanks,
---
Kirby Files
ksfiles@xxxxxxxxx