for my router/firewall i'm using the pfsence product, and pfflowd to export flow data from it.
This is the only device i am collecting flow data from. There is only 2 physical (and logical) interfaces in the box which I wish to monitor.
When I view the interfaces, I see thousands. If we go into the license area and attempt to 'unmanage' the ones I don't wish to see or monitor, they come back just as quickly. Last count there was about 10 thousand of them.
pfflowd is being started with this command: /usr/local/sbin/pfflowd -n 192.168.2.8:9996 -s 10.101.111.11 -S any -v 9
What I would like to learn to do is have NetFlow only monitor the interfaces I wish (in this case the two physical interfaces bce0 and bce1) and ignore any others it discovers. Is this possible?
There are so many interfaces being discovered my machine ran out of file handles. I had to increase ulimit just so the interface would load.
thanks for your time with this,
greg