Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown
Open, NormalPublic

Description

Hi,

Enabling NetFlow accounting under Vyos Beta fails:

vyos@vyos# commit
[ system flow-accounting interface eth0 ]
iptables: No chain/target/match by that name.
Error: [iptables -t raw -I VYATTA_CT_PREROUTING_HOOK 1 -i eth0 -j ULOG --ulog-nlgroup 2 --ulog-cprange 64 --ulog-qthreshold 10] failed - 256

system flow-accounting failed
Commit failed
[edit]
vyos@vyos#

system {

config-management {
    commit-revisions 20
}
domain-name xxxx.xxx

+ flow-accounting {
+ interface eth0
+ netflow {
+ engine-id 50
+ sampling-rate 1
+ server x.x.x.x {
+ port 2055
+ }
+ server x.x.x.x {
+ port 2055
+ }
+ timeout {
+ expiry-interval 60
+ flow-generic 3600
+ icmp 300
+ max-active-life 300
+ tcp-fin 300
+ tcp-generic 3600
+ tcp-rst 120
+ udp 300
+ }
+ version 9
+ }
+ syslog-facility daemon
+ }

host-name XXXXXXX

Details

Difficulty level
Normal (likely a few hours)
Version
VyOS 999.201704052137
Why the issue appeared?
Other
LordNikon set Version to VyOS 999.201704052137.
syncer claimed this task.Apr 6 2017, 6:19 PM
syncer triaged this task as Normal priority.
syncer removed syncer as the assignee of this task.
syncer added subscribers: syncer, VyOS 1.2.x.
tdale added a subscriber: tdale.EditedSep 18 2017, 6:50 AM

Any updates on this? I can't seem to win. On 1.1.7 snmp is broken due to my intel 10g nics and now on beta snmp works but netflow doesnt work :(

vyos@vyos# commit
[ system flow-accounting interface eth4 ]
iptables: No chain/target/match by that name.
Error: [iptables -t raw -I VYATTA_CT_PREROUTING_HOOK 1 -i eth4 -j ULOG --ulog-nlgroup 2 --ulog-cprange 64 --ulog-qthreshold 10] failed - 256

system flow-accounting failed
Commit failed
[edit]
vyos@vyos#

Seems that 'ULOG' is missing.