Discussion:
[Ntop] IP version mismatch: client:4 server:0 - flow will be ignored
Marek Des
2018-05-16 17:13:57 UTC
Permalink
Hello,

I am using pmacct as NetFlow v9 exporter and nprobe as collector and
in ntopng logs I am getting this error:"WARNING: IP version mismatch:
client:4 server:0 - flow will be ignored".

Here's a captured flow it's obvious that IPVersion is set in flow record.

Flow 1
[Duration: 0.778000000 seconds (switched)]
Octets: 4724
Packets: 31
IPVersion: 4
InputInt: 0
OutputInt: 0
Direction: Ingress (0)
SrcAddr: 192.168.111.9
DstAddr: 191.234.99.47
SrcPort: 51101
DstPort: 2222
IP ToS: 0x00
TCP Flags: 0x1f, ACK, PSH, RST, SYN, FIN
Protocol: TCP (6)


nProbe v.8.5.180512 (r6153)

/usr/local/bin/nprobe --zmq tcp://127.0.0.1:20001 -i none -n none
--collector-port 20001 -V 9 --disable-cache --zmq-disable-buffering
-T%IPV4_SRC_ADDR %IPV4_DST_ADDR %IN_BYTES %L4_SRC_PORT %L4_DST_PORT
%TCP_FLAGS %PROTOCOL %SRC_TOS %SRC_AS %DST_AS %IN_SRC_MAC %OUT_DST_MAC
%IPV6_SRC_ADDR %IPV6_DST_ADDR %FIRST_SWITCHED %LAST_SWITCHED %IPV4_NEXT_HOP
%INPUT_SNMP %OUTPUT_SNMP %IN_PKTS %IN_BYTES %EXPORTER_IPV4_ADDRESS
Marek Des
2018-05-23 16:18:03 UTC
Permalink
Hello,

I removed exporter IP address from -T and added quotes after -T and it's
working.
That was only 2 differencies between other nprobe configurations I have.

Marek
Marek
is there any chance to mail ma (in private) a pcap file with template+flow
I can use to reproduce the bug?
Luca
Hello,
I am using pmacct as NetFlow v9 exporter and nprobe as collector and
client:4 server:0 - flow will be ignored".
Here's a captured flow it's obvious that IPVersion is set in flow record.
Flow 1
[Duration: 0.778000000 seconds (switched)]
Octets: 4724
Packets: 31
IPVersion: 4
InputInt: 0
OutputInt: 0
Direction: Ingress (0)
SrcAddr: 192.168.111.9
DstAddr: 191.234.99.47
SrcPort: 51101
DstPort: 2222
IP ToS: 0x00
TCP Flags: 0x1f, ACK, PSH, RST, SYN, FIN
Protocol: TCP (6)
nProbe v.8.5.180512 (r6153)
/usr/local/bin/nprobe --zmq tcp://127.0.0.1:20001 -i none -n none
--collector-port 20001 -V 9 --disable-cache --zmq-disable-buffering
-T%IPV4_SRC_ADDR %IPV4_DST_ADDR %IN_BYTES %L4_SRC_PORT %L4_DST_PORT
%TCP_FLAGS %PROTOCOL %SRC_TOS %SRC_AS %DST_AS %IN_SRC_MAC %OUT_DST_MAC
%IPV6_SRC_ADDR %IPV6_DST_ADDR %FIRST_SWITCHED %LAST_SWITCHED %IPV4_NEXT_HOP
%INPUT_SNMP %OUTPUT_SNMP %IN_PKTS %IN_BYTES %EXPORTER_IPV4_ADDRESS
_______________________________________________
Ntop mailing list
http://listgateway.unipi.it/mailman/listinfo/ntop
_______________________________________________
Ntop mailing list
http://listgateway.unipi.it/mailman/listinfo/ntop
Continue reading on narkive:
Search results for '[Ntop] IP version mismatch: client:4 server:0 - flow will be ignored' (Questions and Answers)
3
replies
I Need Packet Sniffing Help!?
started 2010-03-11 18:54:04 UTC
security
Loading...