ntop / ntop/nProbe

ToS working?

Open
#480 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Lua
Stars
1.8k
Forks
51
PR merge metrics
No merged PRs in 30d

Description

Looking into a network congestion issue , possible in correctly classified dscp/tos markings

nprobe is running on a debian "network management" machine that has multiple nics for monitoring cisco span ports, with flow data (v9) default templates being sent to plixer scrutinizer.

wireshark capture on the monitoring ports on the debian machine shows DSCP/ToS markings on the customer network flows

looking at captured wireshark flow data being sent from nprobe to scrutinizer we can see the field IP ToS is present but the data is always 0x00.

there was a similar issue posted #92

Is this to be expected?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file or test is named. Start by reviewing the related issue #92 and comparing the customer-flow capture with the NetFlow v9 data sent to Scrutinizer, focusing on the IP ToS field. Done means establishing whether the zero value is expected and, if not, identifying a reproducible correction.

Written by the indexing model from the issue text.

Assessment

Tech stack
debian
Domain
networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.