# Bug confirmation needed: Netflow module v7.6 doesn't support 4-7 byte pad in IPFIX template sets

**URL:** <https://discuss.elastic.co/t/bug-confirmation-needed-netflow-module-v7-6-doesnt-support-4-7-byte-pad-in-ipfix-template-sets/230245>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 28, 2020, 7:36pm UTC](https://discuss.elastic.co/t/bug-confirmation-needed-netflow-module-v7-6-doesnt-support-4-7-byte-pad-in-ipfix-template-sets/230245 "2020-04-28T19:36:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bortok](https://avatars.discourse-cdn.com/v4/letter/b/0ea827/32.png) [@bortok](https://discuss.elastic.co/u/bortok)\
**Post date:** [April 28, 2020, 7:36pm UTC](https://discuss.elastic.co/t/bug-confirmation-needed-netflow-module-v7-6-doesnt-support-4-7-byte-pad-in-ipfix-template-sets/230245/1 "2020-04-28T19:36:21Z")

</div>

Can somebody confirm this is a bug before I submit it on github?

The Filebeat Netflow module ver 7.6 doesn't support 4-7 byte pad in template sets when parsing IPFIX. I have Ixia Vision E10S packet broker that can export IPFIX and the module is not compatible with the padding E10S uses for template with ID 256 - which is 4 byte long. Looking at the [decoder.go](https://github.com/elastic/beats/blob/master/x-pack/filebeat/input/netflow/decoder/v9/decoder.go) code, maximum padding length allowed is 3 bytes:

```auto
140 if buf.Len() < 4 {
141 return templates, nil
142 }

```

While RFC 7011, Section 3.3.1 allows Padding to be shorter than any allowable record in the set. The smallest allowable template record has a Record Header and at least one Field inside. This leads to minimum size of 8 bytes. Hence any bytes following a valid template in a set which are less than 8 should be unequivocally considered as pad.

I have two pcap files, one original which filebeat fails to parse, and another edited with padding removed. The original pcap causes the following error while parsing the template packet:

```auto
2020-04-20T13:29:32.605-0700 DEBUG [netflow] netflow/input.go:80 [ipfix] Unable to read V9 header: EOF
2020-04-20T13:29:32.605-0700 WARN [netflow] netflow/input.go:244 Error parsing NetFlow packet of length 138 from 172.20.100.132:47404: error reading header: EOF

```

While edited pcap works just fine

```auto
2020-04-20T14:51:39.583-0700 DEBUG [netflow] netflow/input.go:80 [ipfix] Packet from:172.20.100.132:43922 src:1 seq:438237
2020-04-20T14:51:39.583-0700 DEBUG [netflow] netflow/input.go:80 [ipfix] FlowSet ID 2 length 57
2020-04-20T14:51:39.583-0700 DEBUG [netflow] netflow/input.go:80 [ipfix] state 0xc0000c4740 addTemplate 256 0xc0000c4800
2020-04-20T14:51:39.583-0700 DEBUG [netflow] netflow/input.go:80 [ipfix] FlowSet ID 2 length 57
2020-04-20T14:51:39.583-0700 DEBUG [netflow] netflow/input.go:80 [ipfix] state 0xc0000c4740 addTemplate 257 0xc0000c4c80

```

Wireshark seem to have similar problem, as it interprets 4-byte padding as another template with ID=0.

Summary of my environment:

- Version: 7.6
- Operating System: Debian 10

Steps to Reproduce:

Enable netflow module

```auto
sudo filebeat modules enable netflow

```

Configure an available network interface with an IP used in the provided pcaps. This is what I have on my system

```auto
3: ens2f1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:1e:67:6d:d0:7f brd ff:ff:ff:ff:ff:ff
    inet 172.20.100.132/24 brd 172.20.100.255 scope global dynamic ens2f1
       valid_lft 544sec preferred_lft 544sec

```

Configure netflow module in `/etc/filebeat/modules.d/netflow.yml` with the IP and port used in the provided pcaps

```auto
- module: netflow
  log:
    enabled: true
    var:
      netflow_host: 172.20.100.132
      netflow_port: 2055

```

Configure filebeat with console output in `/etc/filebeat/filebeat.yml`

```auto
output.console:
  pretty: true

```

Run filebeat in foreground with debug on

```auto
sudo filebeat -d netflow -e -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat

```

Replay original and fixed pcap files using udpreplay (change -i parameter to the NIC with 172.20.100.132):

```auto
sudo udpreplay -i ens2f1 -l e10s.netflow.orig.pcap
sudo udpreplay -i ens2f1 -l e10s.netflow.fixed.pcap

```

PCAP files  
[e10s.netflow.orig.pcap](https://www.dropbox.com/s/3hf89m2xu586aae/e10s.netflow.orig.pcap?dl=0)  
[e10s.netflow.fixed.pcap](https://www.dropbox.com/s/t3cll8g43lh9wqz/e10s.netflow.fixed.pcap?dl=0)

Thanks!  
Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2020, 7:36pm UTC](https://discuss.elastic.co/t/bug-confirmation-needed-netflow-module-v7-6-doesnt-support-4-7-byte-pad-in-ipfix-template-sets/230245/2 "2020-05-26T19:36:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
