The following restrictions apply to flow-tap services:
You cannot configure dynamic flow capture (DFC) and flow-tap
features on the same router simultaneously.
When the DFC process or the AS or MultiServices PIC configured
for flow-tap processing restarts, all filters are deleted and the
mediation devices are disconnected.
Only the first fragment of an IPv4 fragmented packet stream
is sent to the content destination.
Port mirroring might not work in conjunction with flow-tap
processing.
If flow-tap is configured, you cannot configure the filter
action then syslog for any firewall filter running on the
same platform.
Running the flow-tap application over an IPSec tunnel
on the same router can cause packet loops and is not supported.