sflow
sflow
OK, that all makes sense so far except that it's not clear to me exactly when the MAC address is changed from 1e:43:be:d9:9c:90 to 80:7f:f8:74:c8:db. I would have guessed that...
With this kind of pcap sampling hsflowd only has the MAC addresses to go on, and it looks like the various eth0. sub interfaces all have the same MAC so...
I think I may have misunderstood the problem. We should always be able to fill in at least one of the src or destination ports. It may be as simple...
Where VyOS uses a VPP dataplane, the solution is to use the sFlow module in VPP and include mod_vpp in hsflowd. But if VyOS is still used without VPP then...
Wireshark does not have all the sFlow decodes. Better to use sflowtool to view the output. ...but the capture you uploaded only contains counter samples. Please grab another while generating...