Configuring Discard Accounting
Discard accounting is similar to traffic sampling, but varies from it in two ways:
In discard accounting, the packet is intercepted by the monitoring PIC and is not forwarded to its destination.
Traffic sampling allows you to limit the number of packets sampled by configuring the
max-packets-per-second,rate, andrun-lengthstatements. Discard accounting does not provide these options, and a high packet count can potentially overwhelm the monitoring PIC.
A discard instance is a named entity that specifies collector
information under the accounting name statement. Discard instances are referenced in firewall filter term statements by including the then discard accounting name statement.
Most of the other statements are also found at the [edit
forwarding-options sampling] hierarchy level. For information
on cflowd, see Enabling Flow Aggregation. The flow-active-timeout and flow-inactive-timeout statements are described in Configuring
Flow Monitoring.
To direct sampled traffic to a flow-monitoring interface, include
the interface statement. The engine-id and engine-type statements specify the accounting interface used
on the traffic, and the source-address statement specifies
the traffic source.
You cannot use rate-limiting with discard accounting; however,
you can specify the duration of the interval for exporting aggregated
accounting information by including the aggregate-export-interval statement in the configuration. This enables you to put a boundary
on the amount of traffic exported to a flow-monitoring interface.