@csnow wrote:
Thanks, that is what I thought. Is it best practice to use one large filter or seperate smaller filters? I am used to very large ASA ACLs but smaller per function filters are easier to troubleshoot. One last question, should the filter that outputs the jflow be first inline on the list?
I think in that case, "best practice" would just be whatever you prefer, honestly. I try to think of that sort of thing as if I were programming -- if I have filters that will be used in more than one place, I define them once and reference them in multiple places. If I have something very specific or one-off, I simply define that instance individually to accomplish the task at hand.
For the jflow -- putting it last seems logical. I honestly don't know if it would have any effect on what's exported if you put it, say, first, before your other filters are called. I don't know if the jflow export happens as soon as the filter is called, or if it waits until all processing is done and the packet is accepted or forwarded on, etc.