Wireshark-users: Re: [Wireshark-users] cflow v9 dissector oddity

From: Yann Berthier <yb@xxxxxxxxxxxxxx>
Date: Tue, 19 Dec 2006 23:19:17 -0500
   Hi,

On Wed, 20 Dec 2006, at 01:23, Motonori Shindo wrote:

> I have addressed this issue. Please find attached the patch against
> the current svn repository. 

   Thanks ! I applied your patch (on the 0.99.4 rel btw), and it decodes
   the capture i have at hand in a perfectly orthodoxal fashion

> As per NetFlow V9 protocol, Template ID is guaranteed to be unique per
> Observation Domain (identified by Source ID) and the Exporter
> (identified by the source IP address of NetFlow PDU).

   the funny thing is that i stumbled upon this behavior while trying to
   track some odd traffic reported by a commercial netflow
   analysis-and-all product. And it appeared that said oddity was
   exhibited also by my network-troubleshooter of choice. Hysterical
   laugh followed ;)

   Thanks again,

      - yann