PFR_ING FT does not recognize most of the flows in the sample PCAP. (fragmented IP packets)
It recognize only 5 TCP flows out of 98
This is a big issue for us as this simulates port swift/scan and we don't see all flows
fragmented_scan_port_23.txt
Please rename .txt to .pcap
./ftflow_pcap -i /home/ubuntu/fragmented_scan_port_23.pcap
#########################################################################
ERROR: You do not seem to have a valid PF_RING FT 9.2.0.260824 license [L68A734F876086A8F--OL]
#########################################################################
PF_RING FT running in demo mode (flow processing limited to 5 minutes)
#########################################################################
Capturing from /home/ubuntu/fragmented_scan_port_23.pcap without (see -7) nDPI support
[Flow] srcIp: 10.201.217.171, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.354483, Last: 1787755208.354483 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.180, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.562719, Last: 1787755208.562719 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.183, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.563262, Last: 1787755208.563262 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.184, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.563678, Last: 1787755208.563678 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.181, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.563697, Last: 1787755208.563697 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.185, dstIp: 10.201.217.179, srcPort: 0, dstPort: 781, protocol: 1, tcpFlags: 0x00, c2s: { Packets: 1, Bytes: 86, First: 1787755208.571029, Last: 1787755208.571029 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
PFR_ING FT does not recognize most of the flows in the sample PCAP. (fragmented IP packets)
It recognize only 5 TCP flows out of 98
This is a big issue for us as this simulates port swift/scan and we don't see all flows
fragmented_scan_port_23.txt
Please rename .txt to .pcap
./ftflow_pcap -i /home/ubuntu/fragmented_scan_port_23.pcap
#########################################################################
ERROR: You do not seem to have a valid PF_RING FT 9.2.0.260824 license [L68A734F876086A8F--OL]
ERROR: Please get one at http://shop.ntop.org/.
#########################################################################
PF_RING FT running in demo mode (flow processing limited to 5 minutes)
#########################################################################
Capturing from /home/ubuntu/fragmented_scan_port_23.pcap without (see -7) nDPI support
[Flow] srcIp: 10.201.217.171, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.354483, Last: 1787755208.354483 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.180, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.562719, Last: 1787755208.562719 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.183, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.563262, Last: 1787755208.563262 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.184, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.563678, Last: 1787755208.563678 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.181, dstIp: 10.201.217.179, srcPort: 23, dstPort: 49198, protocol: 6, tcpFlags: 0x14, c2s: { Packets: 1, Bytes: 60, First: 1787755208.563697, Last: 1787755208.563697 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }
[Flow] srcIp: 10.201.217.185, dstIp: 10.201.217.179, srcPort: 0, dstPort: 781, protocol: 1, tcpFlags: 0x00, c2s: { Packets: 1, Bytes: 86, First: 1787755208.571029, Last: 1787755208.571029 }, s2c: { Packets: 0, Bytes: 0, First: 0.0, Last: 0.0 }