<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Pfflowd generates somtetimes double records]]></title><description><![CDATA[<p dir="auto">Hi!</p>
<p dir="auto">I use pfSense 1.2.1 with pfflowd package together with nfcapd and nfdump for collecting and viewing the netflow records.</p>
<p dir="auto">Sometimes there are double records where there should only be one.</p>
<p dir="auto">Here are two examples:</p>
<pre><code>
2009-01-04 11:00:26.556  5167.000 TCP          10.0.3.34:4147  -&gt;    80.140.195.57:30730     8118    9.4 M     1
2009-01-04 11:00:26.556  5167.000 TCP      80.140.195.57:30730 -&gt;        10.0.3.34:4147      4583   188560     1
2009-01-04 11:00:25.990  5178.000 TCP          10.0.3.34:4147  -&gt;    80.140.195.57:30730     8118    9.4 M     1
2009-01-04 11:00:25.990  5178.000 TCP      80.140.195.57:30730 -&gt;        10.0.3.34:4147      4583   188560     1

</code></pre>
<pre><code>
2009-01-04 14:25:26.720   800.000 TCP          10.0.3.50:1942  -&gt;    87.248.217.89:80       19858   802352     1
2009-01-04 14:25:26.720   800.000 TCP      87.248.217.89:80    -&gt;        10.0.3.50:1942     38147   53.9 M     1
2009-01-04 14:25:25.720   801.000 TCP          10.0.3.50:1942  -&gt;    87.248.217.89:80       19858   802352     1
2009-01-04 14:25:25.720   801.000 TCP      87.248.217.89:80    -&gt;        10.0.3.50:1942     38147   53.9 M     1

</code></pre>
<p dir="auto">Is it a bug in pfflowd or is there something wrong with my configuration?</p>
<p dir="auto">Thanks for your help,<br />
Franz</p>
]]></description><link>https://forum.netgate.com/topic/12618/pfflowd-generates-somtetimes-double-records</link><generator>RSS for Node</generator><lastBuildDate>Fri, 14 Aug 2026 16:29:52 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/12618.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 04 Jan 2009 14:20:08 GMT</pubDate><ttl>60</ttl></channel></rss>