When using flow-print to print the netflows into ASCII, I get 3 different values for protocols, ie protocol 1,6,17 ? What does that mean ? Thanks
+1
A:
Probably 1 is for ICMP, 6 is for TCP and 17 is for UDP. Refer to the List of IP protocol numbers.
Yasir Arsanukaev
2010-05-09 15:24:04