<?xml version="1.0" encoding="utf-8"?>
<!-- name="GENERATOR" content="github.com/mmarkdown/mmark Mmark Markdown Processor - mmark.nl" -->
<!DOCTYPE rfc SYSTEM 'rfc2629.dtd' []>
<rfc ipr="trust200902" submissionType="IETF" category="std" xml:lang="en" consensus="yes" obsoletes="6728" docName="draft-boydseda-ipfix-psamp-bulk-data-yang-model-00">
<?rfc toc="yes"?><?rfc symrefs="yes"?><?rfc sortrefs="yes"?><?rfc compact="yes"?><?rfc subcompact="no"?><?rfc comments="no"?>
<front>
<title abbrev="IPFIX/PSAMP/Bulk Data Export Data Models">Data Models for the IP Flow Information Export (IPFIX) Protocol, Packet Sampling (PSAMP) Protocol, and Bulk Data Export</title><author initials="J." surname="Boyd" fullname="Joey Boyd"><organization abbrev="ADTRAN">ADTRAN</organization><address><postal><street></street>
<city></city>
<code></code>
<country></country>
<region></region>
</postal><phone></phone>
<email>joey.boyd@adtran.com</email>
<uri></uri>
</address></author>
<author initials="M." surname="Seda" fullname="Marta Seda"><organization abbrev="Calix">Calix</organization><address><postal><street></street>
<city></city>
<code></code>
<country></country>
<region></region>
</postal><phone></phone>
<email>marta.seda@calix.com</email>
<uri></uri>
</address></author>
<date/>
<area>Internet</area><workgroup></workgroup>
<abstract><t>This document defines a flexible modular alternative YANG model for bulk data collection and export via the IPFIX protocol to the model defined in <xref target="RFC6728"></xref> &quot;Configuration Data Model for the IP Flow Information Export (IPFIX) and Packet Sampling (PSAMP) Protocols&quot;.  The model defined in this RFC configures the IPFIX exporter and collector (if applicable) and refers to the bulk data monitoring configuration.  Optionally, the model can be configured to support PSAMP export of data via IPFIX.</t>
<t>This document obsoletes <xref target="RFC6728"></xref> (if approved).</t>
</abstract>

</front>

<middle>

<section anchor="introduction" title="Introduction">
<t>Bulk data collection is an automated collection of data from a device that is packaged together and delivered to an IPFIX collector. The IPFIX protocol may be used to transport bulk data such as:</t>
<t>
<list style="symbols">
<t>Sampled (metered) Packet SAMPling (PSAMP) data: <xref target="RFC5476"></xref> defines PSAMP operations that a device may implement to sample packets passing a network element for reporting purposes.</t>
<t>Statistics from interfaces, subinterfaces and sessions: YANG models define statistics that can be retrieved via protocols such as NETCONF <xref target="RFC6241"></xref> or RESTCONF <xref target="RFC8040"></xref>.  These statistics can be streamed using an IPFIX transport to an IPFIX collector that supports analytics tools.  An operator may wish to take the bulk data and analyze it for trend analysis purposes or other usages (e.g., collect octet counts every 5 minutes for service level agreement purposes or collect reported device temperature for network health purposes).</t>
</list>
</t>
<t>IPFIX can also be used to meet the bulk transport requirements of other protocols.  For example:
* <xref target="BBF.TR-352"></xref> ICTP (Inter-Channel Transport Protocol): ICTP uses IPFIX to transport dynamic data (e.g., lease information) across participating NGPON2 (Next-Generation Passive Optical Network 2) systems.</t>

<section anchor="historical-perspective" title="Historical Perspective">
<t>Below is a historical timeline of IETF IPFIX and YANG RFCs:</t>
<t>
<list style="symbols">
<t>RFC 5101 (2008), obsoleted by <xref target="RFC7011"></xref> (2013), defines the IPFIX protocol.</t>
<t><xref target="RFC5476"></xref> (2009) defines the PSAMP operations of selection (random selection, deterministic selection or hash-based selection) for capturing or metering packets arriving on a device.</t>
<t>RFC 6020 (2010) and <xref target="RFC7950"></xref> (2016) define v1.0 and v1.1 of the YANG data modeling language (respectively), and <xref target="RFC8342"></xref> (2018) updates RFC 7950 to define NMDA (Network Management Datastore Architecture).</t>
<t><xref target="RFC6728"></xref> (2012) defines a Packet SAMPling (PSAMP) YANG model for devices that use PSAMP for capturing (for metering purposes) a subset of all packets traversing a device.</t>
<t>RFC 7223 (2014), obsoleted by <xref target="RFC8343"></xref> (2018), defines a YANG data model for interfaces.</t>
<t>IETF, IEEE, BBF etc. (2015 to 2018) have incorporated reporting of statistics into corresponding YANG models (G.fast, PON, etc.).</t>
</list>
</t>
<t><xref target="RFC6728"></xref> defines a single YANG module that performs PSAMP sampling.  The collection process (PSAMP) and the IPFIX exporting process are part of the same YANG module.  The PSAMP YANG model defines a variety of features.  However, it only supports a PSAMP meter and it assumes a device supports SCTP (minimally).  Both constructs prove challenging to other applications that use IPFIX for transport of bulk data:</t>
<t>
<list style="symbols">
<t><xref target="BBF.TR-352"></xref> supports only TCP and TLS as IPFIX transport protocols.  The <xref target="RFC6728"></xref> YANG model does not allow for explicit non-support for SCTP, therefore requiring the need for YANG deviations to announce non-support.
<list style="symbols">
<t>A preferable solution is one that is more flexible (e.g., allows different underlying transport options and avoids the need for deviations to announce non-support for features which an access node is not required to support).</t>
</list></t>
<t>The PSAMP meter does not need to be configured if the observation point is already defined by other YANG models. One could attempt to augment PSAMP YANG to reference where the observation point is being configured (but then would have to express feature &quot;non-support&quot; on features unlikely to be needed or required by access devices).</t>
</list>
</t>
<t>Rather than these approaches, it would be preferable that a new YANG model be developed where functionality is separated into different modules such that the functions can be independently leveraged.</t>
<t>These are some of the other issues with the current model:</t>
<t>
<list style="symbols">
<t>The PSAMP YANG model defines the frequency of export in the PSAMP cache. Bulk data needs the export frequency to be controlled by the exporting process.
<list style="symbols">
<t>It would be preferable that these cache functions be moved closer to the function performing the export.</t>
<t>If a new YANG model is developed, the bulk data and PSAMP collection processes can be modeled independently.</t>
</list></t>
<t>The PSAMP YANG model supports IPFIX mediators. Access nodes may need to support large IPFIX mediation functions.
<list style="symbols">
<t>If a new YANG model is developed, the transport sessions should be modeled such that they can be retrieved individually in addition to retrieving the entire list (which may be quite large for access devices such as an NG-PON2 OLT).</t>
</list></t>
<t>The PSAMP YANG model contains references which correlate to MIB definitions.  For example, interfaces are referenced via ifIndex. For most NETCONF managed devices, interfaces are referenced by name as defined in <xref target="RFC8343"></xref>.
<list style="symbols">
<t>If a new YANG model is developed, options should be provided to allow use of either MIB or newer reference methods.</t>
</list></t>
</list>
</t>
</section>

<section anchor="relationship-with-rfc-6728" title="Relationship with RFC 6728">
<t>This RFC uses the general principles defined in <xref target="RFC6728"></xref> with the following exceptions:</t>
<t>
<list style="symbols">
<t><xref target="RFC6728"></xref> was developed prior to <xref target="RFC8407"></xref> YANG guidelines publication.  This RFC adopts and conforms to the latest YANG guidelines for identifier naming conventions and is therefore not backwards compatible with RFC 6728.</t>
<t>The YANG model adds support for <xref target="RFC8343"></xref> interface references.</t>
<t>The YANG model is separated into the following three modules:
<list style="symbols">
<t>ietf-ipfix: Describes the IPFIX collector and exporter functions.</t>
<t>ietf-psamp: Describes the PSAMP functions for configuring a device to sample/meter a subset of packets from the network.</t>
<t>ietf-bulk-data-export: Describes the bulk data IPFIX templates and filtering functions to apply to bulk data (outside PSAMP bulk data application).</t>
</list></t>
<t>SCTP data nodes are made optional via the sctp feature for applications not requiring to support SCTP.</t>
<t>IPFIX transport sessions allow transport session information to be retrieved individually.</t>
<t>Source and destination address type choice statements are added to improve extensibility of the model.</t>
</list>
</t>
<t>Bulk data applications that use this RFC are expected to only need to import the applicable YANG modules.  For example:</t>
<t>
<list style="symbols">
<t>PSAMP uses the ietf-ipfix and ietf-psamp modules.</t>
<t>Statistics use the ietf-ipfix and ietf-bulk-data-export modules.</t>
<t>TR-352 ICTP applications use only the ietf-ipfix module.</t>
</list>
</t>
</section>

<section anchor="terminology" title="Terminology">
<t>The key words &quot;MUST&quot;, &quot;MUST NOT&quot;, &quot;REQUIRED&quot;, &quot;SHALL&quot;, &quot;SHALL NOT&quot;, &quot;SHOULD&quot;, &quot;SHOULD NOT&quot;, &quot;RECOMMENDED&quot;, &quot;NOT RECOMMENDED&quot;, &quot;MAY&quot;, and &quot;OPTIONAL&quot; in this document are to be interpreted as described in BCP 14 <xref target="RFC2119"></xref> <xref target="RFC8174"></xref> when, and only when, they appear in all capitals, as shown here.</t>
<t>The following terms are defined in <xref target="RFC7950"></xref> and are not redefined here:</t>
<t>
<list style="symbols">
<t>TBD</t>
</list>
</t>
</section>

<section anchor="tree-diagrams" title="Tree Diagrams">
<t>Tree diagrams used in this document follow the notation defined in <xref target="RFC8340"></xref>.</t>
</section>
</section>

<section anchor="objectives" title="Objectives">
<t>This document defines a YANG data model for the configuration and state retrieval of bulk data collection and export via IPFIX.  The YANG module in this document conforms to the Network Management Datastore Architecture (NMDA) <xref target="RFC8342"></xref> and <xref target="RFC8407"></xref> YANG guidelines.</t>
</section>

<section anchor="yang-modules" title="YANG Modules">
<t>This document defines three YANG modules:</t>
<t>
<list style="symbols">
<t>ietf-ipfix</t>
<t>ietf-psamp</t>
<t>ietf-bulk-data-export</t>
</list>
</t>

<section anchor="ietf-ipfix" title="ietf-ipfix">

<section anchor="ietf-ipfix-module-structure" title="ietf-ipfix Module Structure">
<t>This document defines the YANG module &quot;ietf-ipfix&quot;, which has the following structure:</t>

<figure><artwork type="tree">module: ietf-ipfix
  +--rw ipfix
     +--rw collecting-process* [name] {collector}?
     |  +--rw name                 name-type
     |  +--rw tcp-collector* [name] {tcp-transport}?
     |  |  +--rw name                        name-type
     |  |  +--rw local-port?                 inet:port-number
     |  |  +--rw transport-layer-security!
     |  |  |  +--rw local-certification-authority-dn*    string
     |  |  |  +--rw local-subject-dn*                    string
     |  |  |  +--rw local-subject-fqdn*                  inet:domain-name
     |  |  |  +--rw remote-certification-authority-dn*   string
     |  |  |  +--rw remote-subject-dn*                   string
     |  |  |  +--rw remote-subject-fqdn*                 inet:domain-name
     |  |  +--rw (local-address-method)?
     |  |  |  +--:(local-address)
     |  |  |     +--rw local-ip-address*     inet:ip-address
     |  |  +--ro transport-session* [name]
     |  |     +--ro name                                    name-type
     |  |     +--ro ipfix-version?                          uint16
     |  |     +--ro source-ip-address?                      inet:ip-address
     |  |     +--ro destination-ip-address?                 inet:ip-address
     |  |     +--ro source-port?                            inet:port-number
     |  |     +--ro destination-port?                       inet:port-number
     |  |     +--ro status?                                 transport-session-status
     |  |     +--ro rate?                                   yang:gauge32
     |  |     +--ro bytes?                                  yang:counter64
     |  |     +--ro messages?                               yang:counter64
     |  |     +--ro discarded-messages?                     yang:counter64
     |  |     +--ro records?                                yang:counter64
     |  |     +--ro templates?                              yang:counter32
     |  |     +--ro options-templates?                      yang:counter32
     |  |     +--ro transport-session-start-time?           yang:date-and-time
     |  |     +--ro transport-session-discontinuity-time?   yang:date-and-time
     |  |     +--ro template* []
     |  |        +--ro observation-domain-id?         uint32
     |  |        +--ro template-id?                   uint16
     |  |        +--ro set-id?                        uint16
     |  |        +--ro access-time?                   yang:date-and-time
     |  |        +--ro template-data-records?         yang:counter64
     |  |        +--ro template-discontinuity-time?   yang:date-and-time
     |  |        +--ro field* []
     |  |           +--ro ie-id?                  ie-id-type
     |  |           +--ro ie-length?              uint16
     |  |           +--ro ie-enterprise-number?   uint32
     |  |           +--ro is-flow-key?            empty
     |  |           +--ro is-scope?               empty
     |  +--rw exporting-process*   -&gt; /ipfix/exporting-process/name {exporter}?
     +--rw exporting-process* [name] {exporter}?
        +--rw name                    name-type
        +--rw export-mode?            identityref
        +--rw destination* [name]
        |  +--rw name                  name-type
        |  +--rw (destination-parameters)
        |     +--:(tcp-exporter)
        |        +--rw tcp-exporter {tcp-transport}?
        |           +--rw ipfix-version?               uint16
        |           +--rw destination-port?            inet:port-number
        |           +--rw send-buffer-size?            uint32
        |           +--rw rate-limit?                  uint32
        |           +--rw transport-layer-security!
        |           |  +--rw local-certification-authority-dn*    string
        |           |  +--rw local-subject-dn*                    string
        |           |  +--rw local-subject-fqdn*                  inet:domain-name
        |           |  +--rw remote-certification-authority-dn*   string
        |           |  +--rw remote-subject-dn*                   string
        |           |  +--rw remote-subject-fqdn*                 inet:domain-name
        |           +--rw (source-method)?
        |           |  +--:(source-address)
        |           |     +--rw source-address?        inet:ip-address
        |           +--rw (destination-method)
        |           |  +--:(destination-address)
        |           |     +--rw destination-address?   inet:host
        |           +--ro transport-session
        |              +--ro ipfix-version?                          uint16
        |              +--ro source-ip-address?                      inet:ip-address
        |              +--ro destination-ip-address?                 inet:ip-address
        |              +--ro source-port?                            inet:port-number
        |              +--ro destination-port?                       inet:port-number
        |              +--ro status?                                 transport-session-status
        |              +--ro rate?                                   yang:gauge32
        |              +--ro bytes?                                  yang:counter64
        |              +--ro messages?                               yang:counter64
        |              +--ro discarded-messages?                     yang:counter64
        |              +--ro records?                                yang:counter64
        |              +--ro templates?                              yang:counter32
        |              +--ro options-templates?                      yang:counter32
        |              +--ro transport-session-start-time?           yang:date-and-time
        |              +--ro transport-session-discontinuity-time?   yang:date-and-time
        |              +--ro template* []
        |                 +--ro observation-domain-id?         uint32
        |                 +--ro template-id?                   uint16
        |                 +--ro set-id?                        uint16
        |                 +--ro access-time?                   yang:date-and-time
        |                 +--ro template-data-records?         yang:counter64
        |                 +--ro template-discontinuity-time?   yang:date-and-time
        |                 +--ro field* []
        |                    +--ro ie-id?                  ie-id-type
        |                    +--ro ie-length?              uint16
        |                    +--ro ie-enterprise-number?   uint32
        |                    +--ro is-flow-key?            empty
        |                    +--ro is-scope?               empty
        +--rw options* [name]
        |  +--rw name               name-type
        |  +--rw options-type       identityref
        |  +--rw options-timeout?   uint32
        +--ro exporting-process-id?   uint32
</artwork></figure>

</section>

<section anchor="ietf-ipfix-yang-module" title="ietf-ipfix YANG Module">
<t>This YANG Module imports typedefs from <xref target="RFC6991"></xref>.</t>

<figure><artwork>&lt;CODE BEGINS&gt; file &quot;ietf-ipfix@2018-10-22.yang&quot;
</artwork></figure>


<figure><artwork type="yang">module ietf-ipfix {
  yang-version 1.1;

  namespace &quot;urn:ietf-params:xml:ns:yang:ietf-ipfix&quot;;

  prefix ietf-ipfix;

  import ietf-inet-types {
    prefix inet;
  }

  import ietf-yang-types {
    prefix yang;
  }

  organization
    &quot;TBD&quot;;

  contact
    &quot;TBD&quot;;

  description
    &quot;TBD.

     Copyright (c) 2018 IETF Trust and the persons identified
     as authors of the code.  All rights reserved.

     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject
     to the license terms contained in, the Simplified BSD License
     set forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
      (http://trustee.ietf.org/license-info).

     This version of this YANG module is part of XXX; see the RFC
     itself for full legal notices.&quot;;

  revision 2018-10-22 {
    description
      &quot;Initial revision.&quot;;
    reference
      &quot;Internet draft: draft-ipfix-psamp-bulk-data-yang-model-00&quot;;
  }

  feature exporter {
    description
      &quot;If supported, the Monitoring Device can be used as
       an Exporter. Exporting Processes can be configured.&quot;;
  }

  feature tcp-transport {
    description
      &quot;If supported, the Monitoring Device supports TCP
       as the transport protocol.&quot;;
  }

  feature collector {
    description
      &quot;If supported, the Monitoring Device can be used as
      a Collector.  Collecting Processes can be configured.&quot;;
  }


  identity export-mode {
    description
      &quot;Base identity for different usages of export
       destinations configured for an Exporting Process.&quot;;
  }

  identity parallel {
    base export-mode;
    description
      &quot;Parallel export of Data Records to all
       destinations configured for the Exporting Process.&quot;;
  }

  identity load-balancing {
    base export-mode;
    description
      &quot;Load-balancing between the different destinations
       configured for the Exporting Process.&quot;;
  }

  identity fallback {
    base export-mode;
    description
      &quot;Export to the primary destination (i.e., the first
       destination configured for the Exporting Process). If the
       export to the primary destination fails, the Exporting Process
       tries to export to the secondary destination.  If the
       secondary destination fails as well, it continues with the
       tertiary, etc.&quot;;
  }

  identity options-type {
    description
      &quot;Base identity for report types exported with
       options templates.&quot;;
  }

  identity metering-statistics {
    base options-type;
    description
      &quot;Metering Process Statistics.&quot;;
    reference
      &quot;RFC 5101, Section 4.1.&quot;;
  }

  identity metering-reliability {
    base options-type;
    description
      &quot;Metering Process Reliability Statistics.&quot;;
    reference
      &quot;RFC 5101, Section 4.2.&quot;;
  }

  identity exporting-reliability {
    base options-type;
    description
      &quot;Exporting Process Reliability Statistics.&quot;;
    reference
      &quot;RFC 5101, Section 4.3.&quot;;
  }

  identity flow-keys {
    base options-type;
    description
      &quot;Flow Keys.&quot;;
    reference
      &quot;RFC 5101, Section 4.4.&quot;;
  }

  identity selection-sequence {
    base options-type;
    description
      &quot;Selection Sequence and Selector Reports.&quot;;
    reference
      &quot;RFC 5476, Sections 6.5.1 and 6.5.2.&quot;;
  }

  identity selection-statistics {
    base options-type;
    description
      &quot;Selection Sequence Statistics Report.&quot;;
    reference
      &quot;RFC 5476, Sections 6.5.3.&quot;;
  }

  identity accuracy {
    base options-type;
    description
      &quot;Accuracy Report.&quot;;
    reference
      &quot;RFC 5476, Section 6.5.4.&quot;;
  }

  identity reducing-redundancy {
    base options-type;
    description
      &quot;Enables the utilization of Options Templates to
       reduce redundancy in the exported Data Records.&quot;;
    reference
      &quot;RFC 5473.&quot;;
  }

  identity extended-type-information {
    base options-type;
    description
      &quot;Export of extended type information for
       enterprise-specific Information Elements used in the
       exported Templates.&quot;;
    reference
      &quot;RFC 5610.&quot;;
  }

  typedef ie-name-type {
    type string {
      length &quot;1..max&quot;;
      pattern '\S+';
    }
    description
      &quot;Type for Information Element names. Whitespaces
       are not allowed.&quot;;
  }

  typedef name-type {
    type string {
      length &quot;1..max&quot;;
      pattern '\S(.*\S)?';
    }
    description
      &quot;Type for 'name' leafs, which are used to identify
       specific instances within lists, etc.
       Leading and trailing whitespaces are not allowed.&quot;;
  }

  typedef ie-id-type {
    type uint16 {
      range &quot;1..32767&quot;;
    }
    description
      &quot;Type for Information Element identifiers.&quot;;
  }

  typedef transport-session-status {
    type enumeration {
      enum &quot;inactive&quot; {
        value 0;
        description
          &quot;This value MUST be used for Transport Sessions
           that are specified in the system but currently not active.
           The value can be used for Transport Sessions that are
           backup (secondary) sessions.&quot;;
      }
      enum &quot;active&quot; {
        value 1;
        description
          &quot;This value MUST be used for Transport Sessions
           that are currently active and transmitting or receiving
           data.&quot;;
      }
      enum &quot;unknown&quot; {
        value 2;
          description
            &quot;This value MUST be used if the status of the
             Transport Sessions cannot be detected by the device.
             This value should be avoided as far as possible.&quot;;
      }
    }
    description
      &quot;Status of a Transport Session.&quot;;
    reference
      &quot;RFC 6615, Section 8 (ipfixTransportSessionStatus).&quot;;
  }


  grouping transport-layer-security-parameters {
    description
      &quot;TLS or DTLS parameters.&quot;;

    leaf-list local-certification-authority-dn {
      type string;
      description
        &quot;Distinguished names of certification authorities
         whose certificates may be used to identify the local
         endpoint.&quot;;
      reference
        &quot;RFC 5280.&quot;;
    }

    leaf-list local-subject-dn {
      type string;
      description
        &quot;Distinguished names that may be used in the
         certificates to identify the local endpoint.&quot;;
      reference
        &quot;RFC 5280.&quot;;
    }

    leaf-list local-subject-fqdn {
      type inet:domain-name;
      description
        &quot;Fully qualified domain names that may be used to
         in the certificates to identify the local endpoint.&quot;;
      reference
        &quot;RFC 5280.&quot;;
    }

    leaf-list remote-certification-authority-dn {
      type string;
      description
        &quot;Distinguished names of certification authorities
         whose certificates are accepted to authorize remote
         endpoints.&quot;;
      reference
        &quot;RFC 5280.&quot;;
    }

    leaf-list remote-subject-dn {
      type string;
      description
        &quot;Distinguished names which are accepted in
         certificates to authorize remote endpoints.&quot;;
      reference
        &quot;RFC 5280.&quot;;
    }

    leaf-list remote-subject-fqdn {
      type inet:domain-name;
      description
        &quot;Fully qualified domain names that are accepted in
         certificates to authorize remote endpoints.&quot;;
      reference
        &quot;RFC 5280.&quot;;
    }
  }

  grouping transport-session-state-parameters {
    description
      &quot;State parameters of a Transport Session originating
       from an Exporting Process or terminating at a Collecting
       Process.  Parameter names and semantics correspond to the
       managed objects in IPFIX-MIB.&quot;;
    reference
      &quot;RFC 5101; RFC 6615, Section 8
       (ipfixTransportSessionEntry,
        ipfixTransportSessionStatsEntry).&quot;;

    leaf ipfix-version {
      type uint16;
      description
        &quot;Used for Exporting Processes, this parameter
         contains the version number of the IPFIX protocol that the
         Exporter uses to export its data in this Transport Session.

         Used for Collecting Processes, this parameter contains the
         version number of the IPFIX protocol it receives for
         this Transport Session. If IPFIX Messages of different
         IPFIX protocol versions are received, this parameter
         contains the maximum version number.

         Note that this parameter corresponds to
         ipfixTransportSessionIpfixVersion in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
        (ipfixTransportSessionIpfixVersion).&quot;;
    }

    leaf source-ip-address {
      type inet:ip-address;
      description
        &quot;The source address of the Exporter of the
         IPFIX Transport Session.  &quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionSourceAddressType,
         ipfixTransportSessionSourceAddress);
         RFC 4960, Section 6.4.&quot;;
    }

    leaf destination-ip-address {
      type inet:ip-address;
      description
        &quot;The destination IP address of the
         path that is selected by the Exporter to
         send IPFIX messages to the Collector.

         In the case of TCP, it is possible
         that if an FQDN address is configured it
         resolves into many IP addresses.

         Note that this parameter functionally corresponds to
         ipfixTransportSessionDestinationAddressType and
         ipfixTransportSessionDestinationAddress in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionDestinationAddressType,
         ipfixTransportSessionDestinationAddress);
         RFC 4960, Section 6.4.&quot;;
    }

    leaf source-port {
      type inet:port-number;
      description
        &quot;The transport-protocol port number of the
         Exporter of the IPFIX Transport Session.

         Note that this parameter corresponds to
         ipfixTransportSessionSourcePort in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionSourcePort).&quot;;
    }

    leaf destination-port {
      type inet:port-number;
      description
        &quot;The transport-protocol port number of the
         Collector of the IPFIX Transport Session.

         Note that this parameter corresponds to
         ipfixTransportSessionDestinationPort in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionDestinationPort).&quot;;
    }

    leaf status {
      type transport-session-status;
      description
        &quot;Status of the Transport Session.

         Note that this parameter corresponds to
         ipfixTransportSessionStatus in the IPFIX MIB module.&quot;;
        reference
         &quot;RFC 6615, Section 8 (ipfixTransportSessionStatus).&quot;;
    }

    leaf rate {
      type yang:gauge32;
      units &quot;bytes per second&quot;;
      description
        &quot;The number of bytes per second transmitted by the
         Exporting Process or received by the Collecting Process.
         This parameter is updated every second.

         Note that this parameter corresponds to
         ipfixTransportSessionRate in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8 (ipfixTransportSessionRate).&quot;;
    }

    leaf bytes {
      type yang:counter64;
      units &quot;bytes&quot;;
      description
        &quot;The number of bytes transmitted by the
         Exporting Process or received by the Collecting Process.
         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         transportSessionDiscontinuityTime.

         Note that this parameter corresponds to
         ipfixTransportSessionBytes in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8 (ipfixTransportSessionBytes).&quot;;
    }

    leaf messages {
       type yang:counter64;
       units &quot;IPFIX Messages&quot;;
       description
         &quot;The number of messages transmitted by the
          Exporting Process or received by the Collecting Process.
          Discontinuities in the value of this counter can occur at
          re-initialization of the management system, and at other
          times as indicated by the value of
          transportSessionDiscontinuityTime.

          Note that this parameter corresponds to
          ipfixTransportSessionMessages in the IPFIX MIB module.&quot;;
       reference
         &quot;RFC 6615, Section 8
          (ipfixTransportSessionMessages).&quot;;
    }

    leaf discarded-messages {
      type yang:counter64;
      units &quot;IPFIX Messages&quot;;
      description
        &quot;Used for Exporting Processes, this parameter
         indicates the number of messages that could not be sent due
         to internal buffer overflows, network congestion, routing
         issues, etc.  Used for Collecting Process, this parameter
         indicates the number of received IPFIX Message that are
         malformed, cannot be decoded, are received in the wrong
         order or are missing according to the sequence number.
         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         transport-session-discontinuity-time.

         Note that this parameter corresponds to
         ipfixTransportSessionDiscardedMessages in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionDiscardedMessages).&quot;;
    }

    leaf records {
      type yang:counter64;
      units &quot;Data Records&quot;;
      description
        &quot;The number of Data Records transmitted by the
         Exporting Process or received by the Collecting Process.
         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         transportSessionDiscontinuityTime.

         Note that this parameter corresponds to
         ipfixTransportSessionRecords in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionRecords).&quot;;
    }

    leaf templates {
      type yang:counter32;
      units &quot;Templates&quot;;
      description
        &quot;The number of Templates transmitted by the
         Exporting Process or received by the Collecting Process.
         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         transportSessionDiscontinuityTime.

         Note that this parameter corresponds to
         ipfixTransportSessionTemplates in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8
        (ipfixTransportSessionTemplates).&quot;;
    }

    leaf options-templates {
      type yang:counter32;
      units &quot;Options Templates&quot;;
      description
        &quot;The number of Option Templates transmitted by the
         Exporting Process or received by the Collecting Process.
         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         transportSessionDiscontinuityTime.

         Note that this parameter corresponds to
         ipfixTransportSessionOptionsTemplates in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionOptionsTemplates).&quot;;
    }

    leaf transport-session-start-time {
      type yang:date-and-time;
      description
        &quot;Timestamp of the start of the given Transport
         Session.

         This state parameter does not correspond to any object in
         the IPFIX MIB module.&quot;;
    }

    leaf transport-session-discontinuity-time {
      type yang:date-and-time;
      description
        &quot;Timestamp of the most recent occasion at which
         one or more of the Transport Session counters suffered a
         discontinuity.

         Note that this parameter functionally corresponds to
         ipfixTransportSessionDiscontinuityTime in the IPFIX MIB
         module. In contrast to
         ipfixTransportSessionDiscontinuityTime, the time is
         absolute and not relative to sysUpTime.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTransportSessionDiscontinuityTime).&quot;;
    }

    list template {
      description
        &quot;This list contains the Templates and Options
         Templates that are transmitted by the Exporting Process
         or received by the Collecting Process.

         Withdrawn or invalidated (Options) Templates MUST be removed
         from this list.&quot;;

      uses template-parameters-state;
    }
  }

  grouping template-parameters-state {
    description
      &quot;State parameters of a Template used by an Exporting
       Process or received by a Collecting Process in a specific
       Transport Session. Parameter names and semantics
       correspond to the managed objects in IPFIX-MIB&quot;;
    reference
      &quot;RFC 5101; RFC 6615, Section 8 (ipfixTemplateEntry,
       ipfixTemplateDefinitionEntry, ipfixTemplateStatsEntry)&quot;;

    leaf observation-domain-id {
      type uint32;
      description
        &quot;The ID of the Observation Domain for which this
         Template is defined.

         Note that this parameter corresponds to
         ipfixTemplateObservationDomainId in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTemplateObservationDomainId).&quot;;
    }

    leaf template-id {
      type uint16 {
        range &quot;256..65535&quot;;
      }
      description
        &quot;This number indicates the Template ID in the IPFIX
         message.
         Note that this parameter corresponds to ipfixTemplateId in
         the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8 (ipfixTemplateId).&quot;;
    }

    leaf set-id {
      type uint16;
      description
        &quot;This number indicates the Set ID of the Template.
         Currently, there are two values defined.  The value 2
         is used for Sets containing Template definitions.
         The value 3 is used for Sets containing Options
         Template definitions.  Note that this parameter
         corresponds to ipfixTemplateSetId
         in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8 (ipfixTemplateSetId).&quot;;
    }

    leaf access-time {
      type yang:date-and-time;
      description
        &quot;Used for Exporting Processes, this parameter
         contains the time when this (Options) Template was last
         sent to the Collector(s) or written to the file.
         Used for Collecting Processes, this parameter contains the
         time when this (Options) Template was last received from the
         Exporter or read from the file.
         Note that this parameter corresponds to
         ipfixTemplateAccessTime in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8 (
         ipfixTemplateAccessTime).&quot;;
    }

    leaf template-data-records {
      type yang:counter64;
      description
        &quot;The number of transmitted or received Data
         Records defined by this (Options) Template.
         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         templateDiscontinuityTime.
         Note that this parameter corresponds to
         ipfixTemplateDataRecords in the IPFIX MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8 (ipfixTemplateDataRecords).&quot;;
    }

    leaf template-discontinuity-time {
      type yang:date-and-time;
      description
        &quot;Timestamp of the most recent occasion at which
         the counter templateDataRecords suffered a discontinuity.
         Note that this parameter functionally corresponds to
         ipfixTemplateDiscontinuityTime in the IPFIX MIB module.
         In contrast to ipfixTemplateDiscontinuityTime, the time
         is absolute and not relative to sysUpTime.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixTemplateDiscontinuityTime).&quot;;
    }

    list field {
      description
        &quot;This list contains the (Options) Template
         fields of which the (Options) Template is defined.
         The order of the list corresponds to the order of the fields
         in the (Option) Template Record.&quot;;

      leaf ie-id {
        type ie-id-type;
        description
          &quot;This parameter indicates the Information
           Element identifier of the field.

           Note that this parameter corresponds to
           ipfixTemplateDefinitionIeId in the IPFIX MIB module.&quot;;
        reference
          &quot;RFC 5101; RFC 6615, Section 8
           (ipfixTemplateDefinitionIeId).&quot;;
      }

      leaf ie-length {
        type uint16;
        units &quot;octets&quot;;
        description
          &quot;This parameter indicates the length of the
           Information Element of the field.

           Note that this parameter corresponds to
           ipfixTemplateDefinitionIeLength in the IPFIX MIB
           module.&quot;;
        reference
          &quot;RFC 5101; RFC 6615, Section 8
           (ipfixTemplateDefinitionIeLength).&quot;;
      }

      leaf ie-enterprise-number {
        type uint32;
        description
          &quot;This parameter indicates the IANA enterprise
           number of the authority defining the Information Element
           identifier.
           If the Information Element is not enterprise-specific,
           this state parameter is zero.

           Note that this parameter corresponds to
           ipfixTemplateDefinitionIeEnterpriseNumber in the IPFIX
           MIB module.&quot;;
        reference
          &quot;RFC 6615, Section 8
           (ipfixTemplateDefinitionIeEnterpriseNumber);
           IANA registry for Private Enterprise Numbers,
           http://www.iana.org/assignments/enterprise-numbers.&quot;;
      }

      leaf is-flow-key {
        when &quot;../../set-id = 2&quot; {
        description
          &quot;This parameter is available for non-Options
           Templates (Set ID is 2).&quot;;
        }
        type empty;
        description
          &quot;If present, this is a Flow Key field.

           Note that this corresponds to flowKey(1) being set in
           ipfixTemplateDefinitionFlags.&quot;;
        reference
          &quot;RFC 6615, Section 8
           (ipfixTemplateDefinitionFlags).&quot;;
      }

      leaf is-scope {
        when &quot;../../set-id = 3&quot; {
        description
          &quot;This parameter is available for Options
           Templates (Set ID is 3).&quot;;
        }
        type empty;
        description
          &quot;If present, this is a scope field.

           Note that this corresponds to scope(0) being set in
           ipfixTemplateDefinitionFlags.&quot;;
        reference
          &quot;RFC 6615, Section 8
           (ipfixTemplateDefinitionFlags).&quot;;
      }
    }
  }


  grouping common-collector-parameters {
    description
      &quot;Parameters of a Collecting Process that are
       common to all transport protocols.&quot;;

    leaf local-port {
      type inet:port-number;
      description
        &quot;If not configured, the Monitoring Device uses the
         default port number for IPFIX, which is 4739 without
         TLS or DTLS and 4740 if TLS or DTLS is activated.&quot;;
    }

    container transport-layer-security {
      presence
        &quot;The presence of this container indicates TLS is enabled.&quot;;
      description
        &quot;TLS or DTLS configuration.&quot;;

      uses transport-layer-security-parameters;
    }
  }

  grouping common-collector-parameters-state {
    description
      &quot;Parameters of a Collecting Process that are
       common to all transport protocols.&quot;;

    list transport-session {
      key name;
      config false;
      description
        &quot;This list contains the currently established
         Transport Sessions terminating at the given socket.&quot;;

      leaf name {
        type name-type;
        description
          &quot;The name of the transporter session.&quot;;
      }

      uses transport-session-state-parameters;
    }
  }

  grouping tcp-collector-parameters {
    description
      &quot;Parameters of a listening TCP socket at a
       Collecting Process.&quot;;

    uses common-collector-parameters;

    choice local-address-method {
      description
        &quot;Method to configure the local IP address
         of the collecting process.  Note that it is
         expected that other methods be available.  Those
         method can augment this choice.&quot;;

      case local-address {
        leaf-list local-ip-address {
          type inet:ip-address;
          description
            &quot;List of local IP addresses on which the Collecting
             Process listens for IPFIX Messages.&quot;;
        }
      }
    }
  }

  grouping collecting-process-parameters {
    description
      &quot;Parameters of a Collecting Process.&quot;;

    list tcp-collector {
      if-feature tcp-transport;
      key &quot;name&quot;;
      description
        &quot;List of TCP receivers (sockets) on which the
         Collecting Process receives IPFIX Messages.&quot;;

      leaf name {
        type name-type;
        description
          &quot;Name of the TCP collector.&quot;;
      }

      uses tcp-collector-parameters;

      uses common-collector-parameters-state;
    }
  }


  grouping exporting-process-parameters {
    description
      &quot;Parameters of an Exporting Process.&quot;;

    leaf export-mode {
      type identityref {
        base export-mode;
      }
      default 'parallel';
      description
        &quot;This parameter determines to which configured
         destination(s) the incoming Data Records are exported.&quot;;
    }

    list destination {
      key &quot;name&quot;;
      min-elements 1;
      description
        &quot;List of export destinations.&quot;;

      leaf name {
        type name-type;
        description
          &quot;Export destination name.&quot;;
      }

      choice destination-parameters {
        mandatory true;
        description
          &quot;Destination configuration.&quot;;

        container tcp-exporter {
          if-feature tcp-transport;
          description
            &quot;TCP parameters.&quot;;

          uses tcp-exporter-parameters;

          container transport-session {
            config false;
            description
              &quot;Transport session state data.&quot;;

            uses transport-session-state-parameters;
          }
        }
      }
    }

    list options {
      key &quot;name&quot;;
      description
        &quot;List of options reported by the Exporting Process.&quot;;

      leaf name {
        type name-type;
        description
          &quot;Name of the option.&quot;;
      }
      uses options-parameters;
    }
  }

  grouping common-exporter-parameters {
    description
      &quot;Parameters of en export destination that are
       common to all transport protocols.&quot;;

    leaf ipfix-version {
      type uint16;
      default '10';
      description
        &quot;IPFIX version number.&quot;;
      reference
         &quot;RFC 5101.&quot;;
    }

    leaf destination-port {
      type inet:port-number;
      description
        &quot;If not configured by the user, the Monitoring
         Device uses the default port number for IPFIX, which is
         4739 without TLS or DTLS and 4740 if TLS or DTLS is
         activated.&quot;;
    }

    leaf send-buffer-size {
      type uint32;
      units &quot;bytes&quot;;
      description
        &quot;Size of the socket send buffer.

         If not configured by the user, this parameter is set by
         the Monitoring Device.&quot;;
    }

    leaf rate-limit {
      type uint32;
      units &quot;bytes per second&quot;;
      description
        &quot;Maximum number of bytes per second the Exporting
         Process may export to the given destination.  The number of
         bytes is calculated from the lengths of the IPFIX Messages
         exported. If not configured, no rate limiting is
         performed.&quot;;
      reference
        &quot;RFC 5476, Section 6.3.&quot;;
    }

    container transport-layer-security {
      presence
        &quot;The presence of this container indicates TLS is enabled.&quot;;
      description
        &quot;TLS or DTLS configuration.&quot;;

      uses transport-layer-security-parameters;
    }
  }

  grouping tcp-exporter-parameters {
    description
      &quot;Parameters of a TCP export destination.&quot;;

    uses common-exporter-parameters;

    choice source-method {
      description
        &quot;Method to configure the source IP address
         of the exporter.

         Note that it is expected that other methods be available.
         Those methods can augment this choice.&quot;;

      case source-address {
        leaf source-address {
          type inet:ip-address;
          description
            &quot;Select the source IP address used by the Exporting
             Process.&quot;;
        }
      }
    }

    choice destination-method {
      mandatory true;
      description
        &quot;Method to configuring the IP address destination
         of the Collection Process to which IPFIX Messages are sent.

         Note it is expected that if other methods are available
         that they would augment from this statement.&quot;;

      case destination-address {
        leaf destination-address {
          type inet:host;
          description
            &quot;Destination IP address or hostname. A hostname may
             resolve to one or more IP addresses.&quot;;
        }
      }
    }
  }

  grouping options-parameters {
    description
      &quot;Parameters specifying the data export using an
       Options Template.&quot;;

    leaf options-type {
      type identityref {
        base options-type;
      }
      mandatory true;
      description
        &quot;Type of the exported options data.&quot;;
    }

    leaf options-timeout {
      type uint32;
      units &quot;milliseconds&quot;;
      description
        &quot;Time interval for periodic export of the options
         data. If set to zero, the export is triggered when the
         options data has changed.

         If not configured by the user, this parameter is set by the
         Monitoring Device.&quot;;
    }
  }

  container ipfix {
    description
     &quot;IPFIX Exporter and/or Collector data nodes.&quot;;

    list collecting-process {
      if-feature collector;
      key &quot;name&quot;;
      description
        &quot;Collecting Process of the Monitoring Device.&quot;;

      leaf name {
        type name-type;
        description
          &quot;Name of the collecting process.&quot;;
      }

      uses collecting-process-parameters;

      leaf-list exporting-process {
        if-feature exporter;
        type leafref {
          path &quot;/ietf-ipfix:ipfix&quot;
             + &quot;/ietf-ipfix:exporting-process&quot;
             + &quot;/ietf-ipfix:name&quot;;
        }
        description
          &quot;Export of received records without any
           modifications.  Records are processed by all Exporting
           Processes in the list.&quot;;
      }
    }

    list exporting-process {
      if-feature exporter;
      key &quot;name&quot;;
      description
        &quot;List of Exporting Processes of the IPFIX Monitoring Device
         for which configuration will be applied.&quot;;

      leaf name {
        type name-type;
        description
          &quot;Name of the exporting process.&quot;;
      }

      uses exporting-process-parameters;

      leaf exporting-process-id {
        type uint32;
        config false;
        description
          &quot;The identifier of the Exporting Process.
           This parameter corresponds to the Information Element
           exportingProcessId. Its occurrence helps to associate
           Exporting Process parameters with Exporing Process
           statistics exported by the Monitoring Device using the
           Exporting Process Reliability Statistics Template as
           defined by the IPFIX protocol specification.&quot;;
        reference
          &quot;RFC 5101, Section 4.3; IANA registry for IPFIX
           Entities, http://www.iana.org/assignments/ipfix.&quot;;
      }
    }
  }
}
</artwork></figure>


<figure><artwork>&lt;CODE ENDS&gt;
</artwork></figure>

</section>
</section>

<section anchor="ietf-psamp" title="ietf-psamp">

<section anchor="ietf-psamp-module-structure" title="ietf-psamp Module Structure">
<t>This document defines the YANG module &quot;ietf-psamp&quot;, which has the following structure:</t>

<figure><artwork type="tree">
module: ietf-psamp
  augment /ietf-ipfix:ipfix:
    +--rw psamp
       +--rw observation-point* [name] {meter}?
       |  +--rw name                     ietf-ipfix:name-type
       |  +--rw observation-domain-id    uint32
       |  +--rw interface-ref*           if:interface-ref
       |  +--rw ent-physical-name*       string
       |  +--rw direction?               direction
       |  +--rw selection-process*       -&gt; /ietf-ipfix:ipfix/psamp/selection-process/name
       +--rw selection-process* [name] {meter}?
       |  +--rw name                  ietf-ipfix:name-type
       |  +--rw selector* [name]
       |  |  +--rw name                           ietf-ipfix:name-type
       |  |  +--rw (method)
       |  |  |  +--:(select-all)
       |  |  |  |  +--rw select-all?              empty
       |  |  |  +--:(samp-count-based)
       |  |  |  |  +--rw samp-count-based {psamp-samp-count-based}?
       |  |  |  |     +--rw packet-interval    uint32
       |  |  |  |     +--rw packet-space       uint32
       |  |  |  +--:(samp-time-based)
       |  |  |  |  +--rw samp-time-based {psamp-samp-time-based}?
       |  |  |  |     +--rw time-interval    uint32
       |  |  |  |     +--rw time-space       uint32
       |  |  |  +--:(samp-rand-out-of-n)
       |  |  |  |  +--rw samp-rand-out-of-n {psamp-samp-rand-out-of-n}?
       |  |  |  |     +--rw size          uint32
       |  |  |  |     +--rw population    uint32
       |  |  |  +--:(samp-uni-prob)
       |  |  |  |  +--rw samp-uni-prob {psamp-samp-uni-prob}?
       |  |  |  |     +--rw probability    decimal64
       |  |  |  +--:(filter-match)
       |  |  |  |  +--rw filter-match {psamp-filter-match}?
       |  |  |  |     +--rw (name-or-id)
       |  |  |  |     |  +--:(ie-name)
       |  |  |  |     |  |  +--rw ie-name?          ietf-ipfix:ie-name-type
       |  |  |  |     |  +--:(ie-id)
       |  |  |  |     |     +--rw ie-id?            ietf-ipfix:ie-id-type
       |  |  |  |     +--rw ie-enterprise-number?   uint32
       |  |  |  |     +--rw value                   string
       |  |  |  +--:(filter-hash)
       |  |  |     +--rw filter-hash {psamp-filter-hash}?
       |  |  |        +--rw hash-function?       identityref
       |  |  |        +--rw initializer-value?   uint64
       |  |  |        +--rw ip-payload-offset?   uint64
       |  |  |        +--rw ip-payload-size?     uint64
       |  |  |        +--rw digest-output?       boolean
       |  |  |        +--rw selected-range* [name]
       |  |  |        |  +--rw name    ietf-ipfix:name-type
       |  |  |        |  +--rw min?    uint64
       |  |  |        |  +--rw max?    uint64
       |  |  |        +--ro output-range-min?    uint64
       |  |  |        +--ro output-range-max?    uint64
       |  |  +--ro packets-observed?              yang:counter64
       |  |  +--ro packets-dropped?               yang:counter64
       |  |  +--ro selector-discontinuity-time?   yang:date-and-time
       |  +--rw cache?                -&gt; /ietf-ipfix:ipfix/psamp/cache/name
       |  +--ro selection-sequence* []
       |     +--ro observation-domain-id?   uint32
       |     +--ro selection-sequence-id?   uint64
       +--rw cache* [name] {meter}?
          +--rw name                        ietf-ipfix:name-type
          +--ro metering-process-id?        uint32
          +--ro data-records?               yang:counter64
          +--ro cache-discontinuity-time?   yang:date-and-time
          +--rw (cache-type)
          |  +--:(immediate-cache)
          |  |  +--rw immediate-cache {immediate-cache}?
          |  |     +--rw cache-layout
          |  |        +--rw cache-field* [name]
          |  |           +--rw name                    ietf-ipfix:name-type
          |  |           +--rw (name-or-id)
          |  |           |  +--:(ie-name)
          |  |           |  |  +--rw ie-name?          ietf-ipfix:ie-name-type
          |  |           |  +--:(ie-id)
          |  |           |     +--rw ie-id?            ietf-ipfix:ie-id-type
          |  |           +--rw ie-length?              uint16
          |  |           +--rw ie-enterprise-number?   uint32
          |  |           +--rw is-flow-key?            empty
          |  +--:(timeout-cache)
          |  |  +--rw timeout-cache {timeout-cache}?
          |  |     +--rw max-flows?              uint32
          |  |     +--rw active-timeout?         uint32
          |  |     +--rw idle-timeout?           uint32
          |  |     +--rw export-interval?        uint32
          |  |     +--rw cache-layout
          |  |     |  +--rw cache-field* [name]
          |  |     |     +--rw name                    ietf-ipfix:name-type
          |  |     |     +--rw (name-or-id)
          |  |     |     |  +--:(ie-name)
          |  |     |     |  |  +--rw ie-name?          ietf-ipfix:ie-name-type
          |  |     |     |  +--:(ie-id)
          |  |     |     |     +--rw ie-id?            ietf-ipfix:ie-id-type
          |  |     |     +--rw ie-length?              uint16
          |  |     |     +--rw ie-enterprise-number?   uint32
          |  |     |     +--rw is-flow-key?            empty
          |  |     +--ro active-flows?           yang:gauge32
          |  |     +--ro unused-cache-entries?   yang:gauge32
          |  +--:(natural-cache)
          |  |  +--rw natural-cache {natural-cache}?
          |  |     +--rw max-flows?              uint32
          |  |     +--rw active-timeout?         uint32
          |  |     +--rw idle-timeout?           uint32
          |  |     +--rw export-interval?        uint32
          |  |     +--rw cache-layout
          |  |     |  +--rw cache-field* [name]
          |  |     |     +--rw name                    ietf-ipfix:name-type
          |  |     |     +--rw (name-or-id)
          |  |     |     |  +--:(ie-name)
          |  |     |     |  |  +--rw ie-name?          ietf-ipfix:ie-name-type
          |  |     |     |  +--:(ie-id)
          |  |     |     |     +--rw ie-id?            ietf-ipfix:ie-id-type
          |  |     |     +--rw ie-length?              uint16
          |  |     |     +--rw ie-enterprise-number?   uint32
          |  |     |     +--rw is-flow-key?            empty
          |  |     +--ro active-flows?           yang:gauge32
          |  |     +--ro unused-cache-entries?   yang:gauge32
          |  +--:(permanent-cache)
          |     +--rw permanent-cache {permanent-cache}?
          |        +--rw max-flows?              uint32
          |        +--rw active-timeout?         uint32
          |        +--rw idle-timeout?           uint32
          |        +--rw export-interval?        uint32
          |        +--rw cache-layout
          |        |  +--rw cache-field* [name]
          |        |     +--rw name                    ietf-ipfix:name-type
          |        |     +--rw (name-or-id)
          |        |     |  +--:(ie-name)
          |        |     |  |  +--rw ie-name?          ietf-ipfix:ie-name-type
          |        |     |  +--:(ie-id)
          |        |     |     +--rw ie-id?            ietf-ipfix:ie-id-type
          |        |     +--rw ie-length?              uint16
          |        |     +--rw ie-enterprise-number?   uint32
          |        |     +--rw is-flow-key?            empty
          |        +--ro active-flows?           yang:gauge32
          |        +--ro unused-cache-entries?   yang:gauge32
          +--rw exporting-process*          -&gt; /ietf-ipfix:ipfix/exporting-process/name {ietf-ipfix:exporter}?
</artwork></figure>

</section>

<section anchor="ietf-psamp-yang-module" title="ietf-psamp YANG module">
<t>This YANG Module imports typedefs from <xref target="RFC6991"></xref>.</t>

<figure><artwork>&lt;CODE BEGINS&gt; file &quot;ietf-psamp@2018-10-22.yang&quot;
</artwork></figure>


<figure><artwork type="yang">module ietf-psamp {
  yang-version 1.1;

  namespace &quot;urn:ietf-params:xml:ns:yang:ietf-psamp&quot;;

  prefix ietf-psamp;

  import ietf-yang-types {
    prefix yang;
  }

  import ietf-ipfix {
    prefix ietf-ipfix;
  }

  import ietf-interfaces {
    prefix if;
  }

  organization
    &quot;TBD&quot;;

  contact
    &quot;TBD&quot;;

  description
    &quot;TBD.

     Copyright (c) 2018 IETF Trust and the persons identified
     as authors of the code.  All rights reserved.

     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject
     to the license terms contained in, the Simplified BSD License
     set forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
      (http://trustee.ietf.org/license-info).

     This version of this YANG module is part of XXX; see the RFC
     itself for full legal notices.&quot;;

  revision 2018-10-22 {
    description
      &quot;Initial revision.&quot;;
    reference
      &quot;Internet draft: draft-ipfix-psamp-bulk-data-yang-model-00&quot;;
  }


  feature meter {
    description
      &quot;If supported, Observation Points, Selection
       Processes, and Caches can be configured.&quot;;
  }

  feature psamp-samp-count-based {
    description
      &quot;If supported, the Monitoring Device supports
       count-based Sampling. The Selector method sampCountBased can
       be configured.&quot;;
  }

  feature psamp-samp-time-based {
    description
      &quot;If supported, the Monitoring Device supports
       time-based Sampling. The Selector method sampTimeBased can
       be configured.&quot;;
  }

  feature psamp-samp-rand-out-of-n {
    description
      &quot;If supported, the Monitoring Device supports
       random n-out-of-N Sampling. The Selector method
       sampRandOutOfN can be configured.&quot;;
  }

  feature psamp-samp-uni-prob {
    description
      &quot;If supported, the Monitoring Device supports
       uniform probabilistic Sampling. The Selector method
       sampUniProb can be configured.&quot;;
  }

  feature psamp-filter-match {
    description
      &quot;If supported, the Monitoring Device supports
       property match Filtering. The Selector method filterMatch
       can be configured.&quot;;
  }

  feature psamp-filter-hash {
    description
      &quot;If supported, the Monitoring Device supports
       hash-based Filtering. The Selector method filterHash can be
       configured.&quot;;
  }

  feature immediate-cache {
    description
      &quot;If supported, the Monitoring Device supports
       Caches generating PSAMP Packet Reports by configuration with
       immediateCache.&quot;;
  }

  feature timeout-cache {
    description
      &quot;If supported, the Monitoring Device supports
       Caches generating IPFIX Flow Records by configuration with
       timeoutCache.&quot;;
  }

  feature natural-cache {
    description
      &quot;If supported, the Monitoring Device supports
       Caches generating IPFIX Flow Records by configuration with
       naturalCache.&quot;;
  }

  feature permanent-cache {
    description
      &quot;If supported, the Monitoring Device supports
       Caches generating IPFIX Flow Records by configuration with
       permanentCache.&quot;;
  }

  identity bob {
    base hash-function;
    description
      &quot;BOB hash function.&quot;;
    reference
      &quot;RFC 5475, Section 6.2.4.1.&quot;;
  }

  identity ipsx {
    base hash-function;
    description
      &quot;IPSX hash function.&quot;;
    reference
      &quot;RFC 5475, Section 6.2.4.1.&quot;;
  }

  identity crc {
    base hash-function;
    description
      &quot;CRC hash function.&quot;;
    reference
      &quot;RFC 5475, Section 6.2.4.1.&quot;;
  }

  identity hash-function {
    description
      &quot;Base identity for all hash functions used for
       hash-based packet Filtering.&quot;;
  }

  typedef if-name-type {
    type string {
      length &quot;1..255&quot;;
    }
    description
      &quot;This corresponds to the DisplayString textual
       convention of SNMPv2-TC, which is used for ifName in the IF
       MIB module.&quot;;
    reference
      &quot;RFC 2863 (ifName).&quot;;
  }

  typedef direction {
    type enumeration {
      enum &quot;ingress&quot; {
        value 0;
        description
          &quot;This value is used for monitoring incoming packets.&quot;;
      }
      enum &quot;egress&quot; {
        value 1;
        description
          &quot;This value is used for monitoring outgoing packets.&quot;;
      }
      enum &quot;both&quot; {
        value 2;
        description
          &quot;This value is used for monitoring incoming and
           outgoing packets.&quot;;
      }
    }
    description
      &quot;Direction of packets going through an interface.&quot;;
  }

  grouping observation-point-parameters {
    description
      &quot;Interface as input to Observation Point.&quot;;
    leaf observation-domain-id {
      type uint32;
      mandatory true;
      description
        &quot;The Observation Domain ID associates the
         Observation Point to an Observation Domain. Observation
         Points with identical Observation Domain IDs belong to the
         same Observation Domain.

         Note that this parameter corresponds to
         ipfixObservationPointObservationDomainId in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 5101; RFC 6615, Section 8
         (ipfixObservationPointObservationDomainId).&quot;;
    }

    leaf-list interface-ref {
      type if:interface-ref;
      description
        &quot;List of names identifying interfaces of the
         Monitoring Device. The Observation Point observes packets at
         the specified interfaces.&quot;;
    }

    leaf-list ent-physical-name {
      type string;
      description
        &quot;List of names identifying physical entities of the
         Monitoring Device. The Observation Point observes packets at
         the specified entities.&quot;;
    }

    leaf direction {
      type direction;
      default &quot;both&quot;;
      description
        &quot;Direction of packets. If not applicable (e.g., in
         the case of a sniffing interface in promiscuous mode), this
         parameter is ignored.&quot;;
    }
  }

  grouping samp-count-based-parameters {
    description
      &quot;Configuration parameters of a Selector applying
       systematic count-based packet Sampling to the packet
       stream.&quot;;
    reference
      &quot;RFC 5475, Section 5.1; RFC 5476, Section 6.5.2.1.&quot;;

    leaf packet-interval {
      type uint32;
      units &quot;packets&quot;;
      mandatory true;
      description
        &quot;The number of packets that are consecutively
         sampled between gaps of length packetSpace.

         This parameter corresponds to the Information Element
         samplingPacketInterval and to psampSampCountBasedInterval
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.2.2; RFC 6727, Section 6
         (psampSampCountBasedInterval).&quot;;
    }

    leaf packet-space {
      type uint32;
      units &quot;packets&quot;;
      mandatory true;
      description
        &quot;The number of unsampled packets between two
         Sampling intervals.

         This parameter corresponds to the Information Element
         samplingPacketSpace and to psampSampCountBasedSpace
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.2.3; RFC 6727, Section 6
         (psampSampCountBasedSpace).&quot;;
    }
  }

  grouping samp-time-based-parameters {
    description
      &quot;Configuration parameters of a Selector applying
       systematic time-based packet Sampling to the packet
       stream.&quot;;
    reference
      &quot;RFC 5475, Section 5.1; RFC 5476, Section 6.5.2.2.&quot;;

    leaf time-interval {
      type uint32;
      units &quot;microseconds&quot;;
      mandatory true;
      description
        &quot;The time interval in microseconds during
         which all arriving packets are sampled between gaps
         of length timeSpace.

         This parameter corresponds to the Information Element
         samplingTimeInterval and to psampSampTimeBasedInterval
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.2.4; RFC 6727, Section 6
         (psampSampTimeBasedInterval).&quot;;
    }

    leaf time-space {
      type uint32;
      units &quot;microseconds&quot;;
      mandatory true;
      description
        &quot;The time interval in microseconds during
         which no packets are sampled between two Sampling
         intervals specified by timeInterval.

         This parameter corresponds to the Information Element
         samplingTimeInterval and to psampSampTimeBasedSpace
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.2.5; RFC 6727, Section 6
         (psampSampTimeBasedSpace).&quot;;
    }
  }

  grouping samp-rand-out-of-n-parameters {
    description
      &quot;Configuration parameters of a Selector applying
       n-out-of-N packet Sampling to the packet stream.&quot;;
    reference
      &quot;RFC 5475, Section 5.2.1; RFC 5476, Section 6.5.2.3.&quot;;

    leaf size {
      type uint32;
      units &quot;packets&quot;;
      mandatory true;
      description
        &quot;The number of elements taken from the parent
         population.

         This parameter corresponds to the Information Element
         samplingSize and to psampSampRandOutOfNSize in the PSAMP
         MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.2.6; RFC 6727, Section 6
         (psampSampRandOutOfNSize).&quot;;
    }

    leaf population {
      type uint32;
      units &quot;packets&quot;;
      mandatory true;
      description
        &quot;The number of elements in the parent
         population.

         This parameter corresponds to the Information Element
         samplingPopulation and to psampSampRandOutOfNPopulation
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.2.7; RFC 6727, Section 6
         (psampSampRandOutOfNPopulation).&quot;;
    }
  }

  grouping samp-uni-prob-parameters {
    description
      &quot;Configuration parameters of a Selector applying
       uniform probabilistic packet Sampling (with equal
       probability per packet) to the packet stream.&quot;;
    reference
      &quot;RFC 5475, Section 5.2.2.1;
       RFC 5476, Section 6.5.2.4.&quot;;

    leaf probability {
      type decimal64 {
        fraction-digits 18;
        range &quot;0..1&quot;;
      }
      mandatory true;
      description
        &quot;Probability that a packet is sampled,
         expressed as a value between 0 and 1.  The probability
         is equal for every packet.

         This parameter corresponds to the Information Element
         samplingProbability and to psampSampUniProbProbability
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.2.8; RFC 6727, Section 6
         (psampSampUniProbProbability).&quot;;
    }
  }

  grouping filter-match-parameters {
    description
      &quot;Configuration parameters of a Selector applying
       property match Filtering to the packet stream.

       The field to be matched is specified as an Information
       Element.&quot;;
    reference
      &quot;RFC 5475, Section 6.1; RFC 5476, Section 6.5.2.5.&quot;;

    choice name-or-id {
      mandatory true;
      description
        &quot;The field to be matched is specified by
         either the name or the identifier of the Information
         Element.&quot;;

      leaf ie-name {
        type ietf-ipfix:ie-name-type;
        description
          &quot;Name of the Information Element.&quot;;
      }

      leaf ie-id {
        type ietf-ipfix:ie-id-type;
        description
          &quot;Identifier of the Information Element.&quot;;
      }
    }

    leaf ie-enterprise-number {
      type uint32;
      default '0';
      description
        &quot;If this parameter is zero, the Information
         Element is registered in the IANA registry of IPFIX
         Information Elements.

         If this parameter is configured with a non-zero private
         enterprise number, the Information Element is
         enterprise-specific.&quot;;
      reference
        &quot;IANA registry for Private Enterprise Numbers,
         http://www.iana.org/assignments/enterprise-numbers;
         IANA registry for IPFIX Entities,
         http://www.iana.org/assignments/ipfix.&quot;;
    }

    leaf value {
      type string;
      mandatory true;
      description
        &quot;Matching value of the Information Element.&quot;;
    }
  }

  grouping filter-hash-parameters {
    description
      &quot;Configuration parameters of a Selector applying
       hash-based Filtering to the packet stream.&quot;;
    reference
      &quot;RFC 5475, Section 6.2; RFC 5476, Section 6.5.2.6.&quot;;

    leaf hash-function {
      type identityref {
        base hash-function;
      }
      default 'bob';
      description
        &quot;Hash function to be applied.  According to
         RFC 5475, Section 6.2.4.1, 'BOB' must be used in order to
         be compliant with PSAMP.

         This parameter functionally corresponds to
         psampFiltHashFunction in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 6727, Section 6 (psampFiltHashFunction)&quot;;
    }

    leaf initializer-value {
      type uint64;
      description
        &quot;Initializer value to the hash function.
         If not configured by the user, the Monitoring Device
         arbitrarily chooses an initializer value.

         This parameter corresponds to the Information Element
         hashInitialiserValue and to psampFiltHashInitializerValue
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.3.9; RFC 6727, Section 6
         (psampFiltHashInitializerValue).&quot;;
    }

    leaf ip-payload-offset {
      type uint64;
      units &quot;octets&quot;;
      default '0';
      description
        &quot;IP payload offset indicating the position of
         the first payload byte considered as input to the hash
         function.
         Default value 0 corresponds to the minimum offset that
         must be configurable according to RFC 5476, Section
         6.5.2.6.

         This parameter corresponds to the Information Element
         hashIPPayloadOffset and to psampFiltHashIpPayloadOffset
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.3.2; RFC 6727, Section 6
         (psampFiltHashIpPayloadOffset).&quot;;
    }

    leaf ip-payload-size {
      type uint64;
      units &quot;octets&quot;;
      default '8';
      description
        &quot;Number of IP payload bytes used as input to
         the hash function, counted from the payload offset.
         If the IP payload is shorter than the payload range,
         all available payload octets are used as input.
         Default value 8 corresponds to the minimum IP payload
         size that must be configurable according to RFC 5476,
         Section 6.5.2.6.

         This parameter corresponds to the Information Element
         hashIPPayloadSize and to psampFiltHashIpPayloadSize
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.3.3; RFC 6727, Section 6
         (psampFiltHashIpPayloadSize).&quot;;
    }

    leaf digest-output {
      type boolean;
      default 'false';
      description
        &quot;If true, the output from this Selector is
         included in the Packet Report as a packet digest.
         Therefore, the configured Cache Layout needs to contain
         a digestHashValue field.

         This parameter corresponds to the Information Element
         hashDigestOutput.&quot;;
      reference
        &quot;RFC 5477, Section 8.3.8.&quot;;
    }

    list selected-range {
      key &quot;name&quot;;
      min-elements 1;
      description
        &quot;List of hash function return ranges for
         which packets are selected.&quot;;

      leaf name {
        type ietf-ipfix:name-type;
        description
          &quot;Name of the selected range.&quot;;
      }

      leaf min {
        type uint64;
        description
          &quot;Beginning of the hash function's selected
           range.

           This parameter corresponds to the Information Element
           hashSelectedRangeMin and to psampFiltHashSelectedRangeMin
           in the PSAMP MIB module.&quot;;
        reference
          &quot;RFC 5477, Section 8.3.6; RFC 6727, Section 6
           (psampFiltHashSelectedRangeMin).&quot;;
      }

      leaf max {
        type uint64;
        description
          &quot;End of the hash function's selected range.

           This parameter corresponds to the Information Element
           hashSelectedRangeMax and to psampFiltHashSelectedRangeMax
           in the PSAMP MIB module.&quot;;
        reference
          &quot;RFC 5477, Section 8.3.7; RFC 6727, Section 6
           (psampFiltHashSelectedRangeMax).&quot;;
      }
    }
  }

  grouping filter-hash-parameters-state {
    description
      &quot;Configuration parameters of a Selector applying
       hash-based Filtering to the packet stream.&quot;;
    reference
      &quot;RFC 5475, Section 6.2; RFC 5476, Section 6.5.2.6.&quot;;

    leaf output-range-min {
      type uint64;
      config false;
      description
        &quot;Beginning of the hash function's potential
         range.

         This parameter corresponds to the Information Element
         hashOutputRangeMin and to psampFiltHashOutputRangeMin
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.3.4; RFC 6727, Section 6
         (psampFiltHashOutputRangeMin).&quot;;
    }

    leaf output-range-max {
      type uint64;
      config false;
      description
        &quot;End of the hash function's potential range.

         This parameter corresponds to the Information Element
         hashOutputRangeMax and to psampFiltHashOutputRangeMax
         in the PSAMP MIB module.&quot;;
      reference
        &quot;RFC 5477, Section 8.3.5; RFC 6727, Section 6
         (psampFiltHashOutputRangeMax).&quot;;
    }
  }

  grouping selector-parameters {
    description
      &quot;Configuration and state parameters of a Selector.&quot;;

    choice method {
      mandatory true;
      description
        &quot;Packet selection method applied by the Selector.&quot;;

      leaf select-all {
        type empty;
        description
          &quot;Method that selects all packets.&quot;;
      }

      container samp-count-based {
        if-feature psamp-samp-count-based;
        description
          &quot;Systematic count-based packet Sampling.&quot;;

        uses samp-count-based-parameters;
      }

      container samp-time-based {
        if-feature psamp-samp-time-based;
        description
          &quot;Systematic time-based packet Sampling.&quot;;

        uses samp-time-based-parameters;
      }

      container samp-rand-out-of-n {
         if-feature psamp-samp-rand-out-of-n;
         description
           &quot;n-out-of-N packet Sampling.&quot;;

         uses samp-rand-out-of-n-parameters;
      }

      container samp-uni-prob {
        if-feature psamp-samp-uni-prob;
        description
          &quot;Uniform probabilistic packet Sampling.&quot;;

        uses samp-uni-prob-parameters;
      }

      container filter-match {
        if-feature psamp-filter-match;
        description
          &quot;Property match Filtering.&quot;;

        uses filter-match-parameters;
      }

      container filter-hash {
        if-feature psamp-filter-hash;
        description
          &quot;Hash-based Filtering.&quot;;

        uses filter-hash-parameters;
        uses filter-hash-parameters-state;
      }
    }
  }

  grouping selector-parameters-state {
    description
      &quot;Configuration and state parameters of a Selector.&quot;;

    leaf packets-observed {
      type yang:counter64;
      config false;
      description
        &quot;The number of packets observed at the input of
         the Selector.

         If this is the first Selector in the Selection Process,
         this counter corresponds to the total number of packets in
         all Observed Packet Streams at the input of the Selection
         Process.  Otherwise, the counter corresponds to the total
         number of packets at the output of the preceding Selector.
         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         selectorDiscontinuityTime.

         Note that this parameter corresponds to
         ipfixSelectorStatsPacketsObserved in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixSelectorStatsPacketsObserved).&quot;;
    }

    leaf packets-dropped {
      type yang:counter64;
      config false;
      description
        &quot;The total number of packets discarded by the
         Selector.

         Discontinuities in the value of this counter can occur at
         re-initialization of the management system, and at other
         times as indicated by the value of
         selectorDiscontinuityTime.

         Note that this parameter corresponds to
         ipfixSelectorStatsPacketsDropped in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixSelectorStatsPacketsDropped).&quot;;
    }

    leaf selector-discontinuity-time {
      type yang:date-and-time;
      config false;
      description
        &quot;Timestamp of the most recent occasion at which
         one or more of the Selector counters suffered a
         discontinuity.

         Note that this parameter functionally corresponds to
         ipfixSelectionProcessStatsDiscontinuityTime in the IPFIX
         MIB module. In contrast to
         ipfixSelectionProcessStatsDiscontinuityTime, the time is
         absolute and not relative to sysUpTime.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixSelectionProcessStatsDiscontinuityTime).&quot;;
    }
  }

  grouping cache-layout-parameters {
    description
      &quot;Cache Layout parameters used by immediateCache,
       timeoutCache, naturalCache, and permanentCache.&quot;;

    container cache-layout {
      description
        &quot;Cache Layout parameters.&quot;;

      list cache-field {
        key &quot;name&quot;;
        min-elements 1;
        description
          &quot;Superset of fields that are included in the
           Packet Reports or Flow Records generated by the Cache.&quot;;

        leaf name {
          type ietf-ipfix:name-type;
          description
            &quot;Name of the cache field.&quot;;
        }

        choice name-or-id {
          mandatory true;
          description
            &quot;Name or identifier of the Information
             Element.&quot;;
          reference
            &quot;RFC 5102, Section 2; IANA registry for IPFIX
             Entities, http://www.iana.org/assignments/ipfix.&quot;;

          leaf ie-name {
            type ietf-ipfix:ie-name-type;
            description
              &quot;Name of the Information Element.&quot;;
          }

          leaf ie-id {
            type ietf-ipfix:ie-id-type;
            description
              &quot;Identifier of the Information Element.&quot;;
          }
        }

        leaf ie-length {
          type uint16;
          units &quot;octets&quot;;
          description
            &quot;Length of the field in which the Information
             Element is encoded.  A value of 65535 specifies a
             variable-length Information Element. For Information
             Elements of integer and float type, the field length MAY
             be set to a smaller value than the standard length of
             the abstract data type if the rules of reduced size
             encoding are fulfilled.

             If not configured by the user, this parameter is set by
             the Monitoring Device.&quot;;
          reference
            &quot;RFC 5101, Section 6.2.&quot;;
        }

        leaf ie-enterprise-number {
          type uint32;
          default '0';
          description
            &quot;If this parameter is zero, the Information
             Element is registered in the IANA registry of IPFIX
             Information Elements.

             If this parameter is configured with a non-zero private
             enterprise number, the Information Element is
             enterprise-specific.

             If the enterprise number is set to 29305, this field
             contains a Reverse Information Element.  In this case,
             the Cache MUST generate Data Records in accordance to
             RFC 5103.&quot;;
          reference
            &quot;RFC 5101; RFC 5103;
             IANA registry for Private Enterprise Numbers,
             http://www.iana.org/assignments/enterprise-numbers;
             IANA registry for IPFIX Entities,
             http://www.iana.org/assignments/ipfix.&quot;;
        }

        leaf is-flow-key {
          when
            &quot;(name(../../..) != 'immediate-cache')
             and
             ((count(../ie-enterprise-number) = 0)
             or
             (../ie-enterprise-number != 29305))&quot; {
            description
              &quot;This parameter is not available for
               Reverse Information Elements (which have enterprise
               number 29305).  It is also not available for
               immediateCache.&quot;;
          }
          type empty;
          description
            &quot;If present, this is a flow key.&quot;;
        }
      }
    }
  }

  grouping flow-cache-parameters {
    description
      &quot;Configuration parameters of a Cache generating Flow Records.&quot;;

    leaf max-flows {
      type uint32;
      units &quot;flows&quot;;
      description
        &quot;This parameter configures the maximum number of
         Flows in the Cache, which is the maximum number of Flows
         that can be measured simultaneously.

         The Monitoring Device MUST ensure that sufficient resources
         are available to store the configured maximum number of
         Flows.

         If the maximum number of Flows is measured, an additional
         Flow can be measured only if an existing entry is removed.
         However, traffic that pertains to existing Flows can
         continue to be measured.&quot;;
    }

    leaf active-timeout {
      when &quot;(name(..) = 'timeout-cache') or
            (name(..) = 'natural-cache')&quot; {
        description
          &quot;This parameter is only available for
           timeoutCache and naturalCache.&quot;;
      }
      type uint32;
      units &quot;seconds&quot;;
      description
        &quot;This parameter configures the time in
         seconds after which a Flow is expired even though packets
         matching this Flow are still received by the Cache.
         The parameter value zero indicates infinity, meaning that
         there is no active timeout.

         If not configured by the user, the Monitoring Device sets
         this parameter.

         Note that this parameter corresponds to
         ipfixMeteringProcessCacheActiveTimeout in the IPFIX
         MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixMeteringProcessCacheActiveTimeout).&quot;;
    }

    leaf idle-timeout {
      when
        &quot;(name(..) = 'timeout-cache') or
         (name(..) = 'natural-cache')&quot; {
        description
         &quot;This parameter is only available for
          timeoutCache and naturalCache.&quot;;
      }
      type uint32;
      units &quot;seconds&quot;;
      description
        &quot;This parameter configures the time in
         seconds after which a Flow is expired if no more packets
         matching this Flow are received by the Cache.

         The parameter value zero indicates infinity, meaning that
         there is no idle timeout.

         If not configured by the user, the Monitoring Device sets
         this parameter.

         Note that this parameter corresponds to
         ipfixMeteringProcessCacheIdleTimeout in the IPFIX
         MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixMeteringProcessCacheIdleTimeout).&quot;;
    }

    leaf export-interval {
      when &quot;name(..) = 'permanent-cache'&quot; {
      description
        &quot;This parameter is only available for permanentCache.&quot;;
      }
      type uint32;
      units &quot;seconds&quot;;
      description
        &quot;This parameter configures the interval (in
         seconds) for periodical export of Flow Records.
         If not configured by the user, the Monitoring Device sets
         this parameter.&quot;;
    }
  }

  grouping flow-cache-parameters-state {
    description
      &quot;State parameters of a Cache generating Flow Records.&quot;;

    leaf active-flows {
      type yang:gauge32;
      units &quot;flows&quot;;
      config false;
      description
        &quot;The number of Flows currently active in this Cache.

         Note that this parameter corresponds to
         ipfixMeteringProcessCacheActiveFlows in the IPFIX MIB
         module.&quot;;
      reference
        &quot;RFC 6615, Section 8
         (ipfixMeteringProcessCacheActiveFlows).&quot;;
    }

    leaf unused-cache-entries {
      type yang:gauge32;
      units &quot;flows&quot;;
      config false;
      description
        &quot;The number of unused Cache entries in this
         Cache.

         Note that this parameter corresponds to
         ipfixMeteringProcessCacheUnusedCacheEntries in the IPFIX
         MIB module.&quot;;
      reference
        &quot;RFC 6615, Section 8
        (ipfixMeteringProcessCacheUnusedCacheEntries).&quot;;
    }
  }

  augment '/ietf-ipfix:ipfix' {
    description
      &quot;Augment IPFIX transport to add PSAMP.&quot;;

    container psamp {
      description
        &quot;Container for PSAMP configuration.&quot;;

      list observation-point {
        if-feature meter;
        key &quot;name&quot;;
        description
          &quot;Observation Point of the Monitoring Device.&quot;;

        leaf name {
          type ietf-ipfix:name-type;
          description &quot;Name of the observation point.&quot;;
        }

        uses observation-point-parameters;

        leaf-list selection-process {
          type leafref {
            path &quot;/ietf-ipfix:ipfix/psamp/selection-process/name&quot;;
          }
          description
            &quot;Selection Processes in this list process
             packets in parallel.&quot;;
        }
      }

      list selection-process {
        if-feature meter;
        key &quot;name&quot;;
        description
          &quot;Selection Process of the Monitoring Device.&quot;;

        leaf name {
          type ietf-ipfix:name-type;
          description
            &quot;Name of the selection process.&quot;;
        }

        list selector {
          key &quot;name&quot;;
          min-elements 1;
          ordered-by user;
          description
            &quot;List of Selectors that define the action of the
             Selection Process on a single packet.  The Selectors
             are serially invoked in the same order as they appear
             in this list.&quot;;

          leaf name {
            type ietf-ipfix:name-type;
            description
              &quot;Name of the selector.&quot;;
          }

          uses selector-parameters;

          uses selector-parameters-state;
        }

        leaf cache {
          type leafref {
            path &quot;/ietf-ipfix:ipfix/psamp/cache/name&quot;;
          }
          description
            &quot;Cache that receives the output of the
             Selection Process.&quot;;
        }

        list selection-sequence {
          config false;
          description
            &quot;This list contains the Selection Sequence IDs
             that are assigned by the Monitoring Device to
             distinguish different Selection Sequences passing
             through the Selection Process.

             As Selection Sequence IDs are unique per Observation
             Domain, the corresponding Observation Domain IDs are
             included as well.

             With this information, it is possible to associate
             Selection Sequence (Statistics) Report Interpretations
             exported according to the PSAMP protocol with a
             Selection Process in the configuration data.&quot;;
          reference
            &quot;RFC 5476.&quot;;

          leaf observation-domain-id {
            type uint32;
            description
              &quot;Observation Domain ID for which the
               Selection Sequence ID is assigned.&quot;;
          }

          leaf selection-sequence-id {
            type uint64;
            description
              &quot;Selection Sequence ID used in the Selection
               Sequence (Statistics) Report Interpretation.&quot;;
          }
        }
      }

      list cache {
        if-feature meter;
        key &quot;name&quot;;
        description
          &quot;Cache of the Monitoring Device.&quot;;

        leaf name {
          type ietf-ipfix:name-type;
          description
            &quot;Name of the cache.&quot;;
        }

        leaf metering-process-id {
          type uint32;
          config false;
          description
            &quot;The identifier of the Metering Process this
             Cache belongs to.

             This parameter corresponds to the Information Element
             meteringProcessId.  Its occurrence helps to associate
             Cache parameters with Metering Process statistics
             exported by the Monitoring Device using the Metering
             Process (Reliability) Statistics Template as
             defined by the IPFIX protocol specification.&quot;;
          reference
            &quot;RFC 5101, Sections 4.1 and 4.2;
             IANA registry for IPFIX Entities,
             http://www.iana.org/assignments/ipfix.&quot;;
        }

        leaf data-records {
          type yang:counter64;
          units &quot;Data Records&quot;;
          config false;
          description
            &quot;The number of Data Records generated by this
             Cache.

             Discontinuities in the value of this counter can occur
             at re-initialization of the management system, and at
             other times as indicated by the value of
             cacheDiscontinuityTime.

             Note that this parameter corresponds to
             ipfixMeteringProcessDataRecords in the IPFIX MIB
             module.&quot;;
          reference
            &quot;RFC 6615, Section 8
             (ipfixMeteringProcessDataRecords).&quot;;
        }

        leaf cache-discontinuity-time {
          type yang:date-and-time;
          config false;
          description
            &quot;Timestamp of the most recent occasion at which
             the counter dataRecords suffered a discontinuity.

             Note that this parameter functionally corresponds to
             ipfixMeteringProcessDiscontinuityTime in the IPFIX MIB
             module. In contrast to
             ipfixMeteringProcessDiscontinuityTime, the time is
             absolute and not relative to sysUpTime.&quot;;
          reference
            &quot;RFC 6615, Section 8
             (ipfixMeteringProcessDiscontinuityTime).&quot;;
        }

        choice cache-type {
          mandatory true;
          description
            &quot;Type of Cache and specific parameters.&quot;;

          container immediate-cache {
            if-feature immediate-cache;
            description
              &quot;Flow expiration after the first packet;
               generation of Packet Records.&quot;;

            uses cache-layout-parameters;
          }

          container timeout-cache {
            if-feature timeout-cache;
            description
              &quot;Flow expiration after active and idle
               timeout; generation of Flow Records.&quot;;

            uses flow-cache-parameters;
            uses cache-layout-parameters;
            uses flow-cache-parameters-state;

          }

          container natural-cache {
            if-feature natural-cache;
            description
              &quot;Flow expiration after active and idle
               timeout, or on natural termination (e.g., TCP FIN or
               TCP RST) of the Flow; generation of Flow Records.&quot;;
            uses flow-cache-parameters;
            uses cache-layout-parameters;
            uses flow-cache-parameters-state;
          }

          container permanent-cache {
            if-feature permanent-cache;
            description
              &quot;No flow expiration, periodical export with
               time interval exportInterval; generation of Flow
               Records.&quot;;
            uses flow-cache-parameters;
            uses cache-layout-parameters;
            uses flow-cache-parameters-state;
          }
        }

        leaf-list exporting-process {
          if-feature ietf-ipfix:exporter;
          type leafref {
            path &quot;/ietf-ipfix:ipfix&quot;
               + &quot;/ietf-ipfix:exporting-process&quot;
               + &quot;/ietf-ipfix:name&quot;;
          }
          description
            &quot;Records are exported by all Exporting Processes
             in the list.&quot;;
        }
      }
    }
  }
}
</artwork></figure>


<figure><artwork>&lt;CODE ENDS&gt;
</artwork></figure>

</section>
</section>

<section anchor="ietf-bulk-data-export" title="ietf-bulk-data-export">

<section anchor="ietf-bulk-data-export-module-structure" title="ietf-bulk-data-export Module Structure">
<t>This document defines the YANG module &quot;ietf-bulk-data-export&quot;, which has the following tentative structure:</t>

<figure><artwork>TBD
</artwork></figure>

</section>

<section anchor="ietf-bulk-data-export-yang-module" title="ietf-bulk-data-export YANG module">
<t>This YANG Module imports typedefs from <xref target="RFC6991"></xref>.</t>

<figure><artwork>TBD
</artwork></figure>

</section>
</section>
</section>

<section anchor="iana-considerations" title="IANA Considerations">
<t>This document registers a URI in the &quot;IETF XML Registry&quot;. <xref target="RFC3688"></xref>. Following the format in RFC 3688, the following registration has been made.</t>

<figure><artwork>URI: urn:ietf:params:xml:ns:yang:ietf-TBD
Registrant Contact: The IESG.
XML: N/A, the requested URI is an XML namespace.
</artwork></figure>

<t>This document registers a YANG module in the &quot;YANG Module Names&quot; registry.  Following the format in <xref target="RFC7950"></xref>, the following has been registered.</t>

<figure><artwork>Name: ietf-TBD
Namespace: urn:ietf:params:xml:ns:yang:ietf-TBD
Prefix: TBD
Reference: TBD
</artwork></figure>

</section>

<section anchor="security-considerations" title="Security Considerations">
<t>The YANG module specified in this document defines a schema for data that is designed to be accessed via network management protocols such as NETCONF <xref target="RFC6241"></xref> or RESTCONF <xref target="RFC8040"></xref>.  The lowest NETCONF layer is the secure transport layer, and the mandatory-to-implement secure transport is Secure Shell (SSH) <xref target="RFC6242"></xref>.  The lowest RESTCONF layer is HTTPS, and the mandatory-to-implement secure transport is TLS <xref target="RFC5246"></xref>.</t>
<t>The NETCONF access control model <xref target="RFC6536"></xref> provides the means to restrict access for particular NETCONF or RESTCONF users to a preconfigured subset of all available NETCONF or RESTCONF protocol operations and content.</t>
<t>There are a number of data nodes defined in this YANG module that are writable/creatable/deletable (i.e., config true, which is the default).  These data nodes may be considered sensitive or vulnerable in some network environments.  Write operations (e.g., edit-config) to these data nodes without proper protection can have a negative effect on network operations.  These are the subtrees and data nodes and their sensitivity/vulnerability:</t>
<t>
<list style="symbols">
<t>/ipfix/psamp/observation-point: The configuration parameters in this subtree specify where packets are observed and by which Selection Processes they will be processed. Write access to this subtree allows observing packets at arbitrary interfaces or linecards of the Monitoring Device and may thus lead to the export of sensitive traffic information.</t>
<t>/ipfix/psamp/selection-process: The configuration parameters in this subtree specify for which packets information will be reported in Packet Reports or Flow Records. Write access to this subtree allows changing the subset of packets for which information will be reported and may thus lead to the export of sensitive traffic information.</t>
<t>/ipfix/psamp/cache: The configuration parameters in this subtree specify the fields included in Packet Reports or Flow Records. Write access to this subtree allows adding fields which may contain sensitive traffic information, such as IP addresses or parts of the packet payload.</t>
<t>/ipfix/exporting-process:  The configuration parameters in this subtree specify to which Collectors Packet Reports or Flow Records are exported. Write access to this subtree allows exporting potentially sensitive traffic information to illegitimate Collectors. Furthermore, TLS/DTLS parameters can be changed, which may affect the mutual authentication between Exporters and Collectors as well as the encrypted transport of the data.</t>
<t>/ipfix/collecting-process: The configuration parameters in this subtree may specify that collected Packet Reports and Flow Records are reexported to another Collector or written to a file. Write access to this subtree potentially allows reexporting or storing the sensitive traffic information.</t>
</list>
</t>
<t>Some of the readable data nodes in this YANG module may be considered sensitive or vulnerable in some network environments. It is thus important to control read access (e.g., via get, get-config, or notification) to these data nodes. These are the subtrees and data nodes and their sensitivity/vulnerability:</t>
<t>
<list style="symbols">
<t>/ipfix/psamp/observation-point: Parameters in this subtree may be sensitive because they reveal information about the Monitoring Device itself and the network infrastructure.</t>
<t>/ipfix/psamp/selection-process: Parameters in this subtree may be sensitive because they reveal information about the Monitoring Device itself and the observed traffic. For example, the counters packetsObserved and packetsDropped inferring the number of observed packets.</t>
<t>/ipfix/psamp/cache: Parameters in this subtree may be sensitive because they reveal information about the Monitoring Device itself and the observed traffic. For example, the counters activeFlows and dataRecords allow inferring the number of measured Flows or packets.</t>
<t>/ipfix/exporting-process: Parameters in this subtree may be sensitive because they reveal information about the network infrastructure and the outgoing IPFIX Transport Sessions. For example, it discloses the IP addresses of Collectors as well as the deployed TLS/DTLS configuration, which may facilitate the interception of outgoing IPFIX Messages.</t>
<t>/ipfix/collecting-process: Parameters in this subtree may be sensitive because they reveal information about the network infrastructure and the incoming IPFIX Transport Sessions. For example, it discloses the IP addresses of Exporters as well as the deployed TLS/DTLS configuration, which may facilitate the interception of incoming IPFIX Messages.</t>
</list>
</t>
<t>(The section needs to be expanded to include bulk data export YANG.)</t>
</section>

<section anchor="acknowledgments" title="Acknowledgments">
<t>TBD</t>
</section>

</middle>

<back>
<references title="Normative References">
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6728.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7011.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8342.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.3688.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.5476.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8343.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7950.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6991.xml"?>
</references>
<references title="Informative References">
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8340.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6241.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8040.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.5246.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6536.xml"?>
<reference  anchor='BBF.TR-352' target='https://www.broadband-forum.org/technical/download/TR-352.pdf'>
  <front>
    <title>Multi-wavelength PON Inter-Channel-Termination Protocol (ICTP) Specification</title>
    <author><organization>Broadband Forum</organization></author>
    <date year='2017' month='May'/>
  </front>
</reference>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8407.xml"?>
<?rfc include="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6242.xml"?>
</references>

<section anchor="example-ietf-ipfix-usage" title="Example: ietf-ipfix Usage">
<t>This configuration example configures an IPFIX exporter for a BBF TR-352 ICTP Proxy.</t>

<figure><artwork>&lt;ipfix&gt;
    &lt;exporting-process&gt;
        &lt;name&gt;TR352-exporter&lt;/name&gt;
        &lt;destination&gt;
            &lt;name&gt;ICTP-Proxy1-collector&lt;/name&gt;
            &lt;tcp-exporter&gt;
                &lt;source-method&gt;source-address
                    &lt;source-address&gt;192.0.2.1&lt;/source-address&gt;
                &lt;/source-method&gt;
                &lt;destination-method&gt;destination-address
                    &lt;destination-address&gt;ictp-proxy-1.ngpon2-system1.com&lt;/destination-address&gt;
                &lt;/destination-method&gt;
            &lt;/tcp-exporter&gt;
        &lt;/destination&gt;
        &lt;options&gt;
            &lt;name&gt;Options 1&lt;/name&gt;
            &lt;options-type&gt;extended-type-information&lt;/options-type&gt;
            &lt;options-timeout&gt;0&lt;/options-timeout&gt;
        &lt;/options&gt;
    &lt;/exporting-prrocess&gt;
&lt;/ipfix&gt;
</artwork></figure>

<t>This configuration example configures an IPFIX mediator.</t>

<figure><artwork>&lt;ipfix&gt;
    &lt;collecting-process&gt;
      &lt;name&gt;OLT-collector&lt;/name&gt;
      &lt;tcp-collector&gt;
        &lt;name&gt;myolt-tcp-collector&lt;/name&gt;
        &lt;local-address-method&gt;local-ip-address
          &lt;local-ip-address&gt;192.100.2.1&lt;/local-ip-address&gt;
        &lt;/local-address-method&gt;
      &lt;/tcp-collector&gt;
      &lt;exporting-process&gt;OLT-exporter&lt;/exporting-process&gt;
    &lt;/collecting-process&gt;
    &lt;exporting-process&gt;
        &lt;name&gt;OLT-exporter&lt;/name&gt;
        &lt;destination&gt;
            &lt;name&gt;big-collector&lt;/name&gt;
            &lt;tcp-exporter&gt;
                &lt;source-method&gt;source-address
                    &lt;source-address&gt;192.100.2.1&lt;/source-address&gt;
                &lt;/source-method&gt;
                &lt;destination-method&gt;destination-address
                    &lt;destination-address&gt;big-collector1.system.com&lt;/destination-address&gt;
                &lt;/destination-method&gt;
        &lt;options&gt;
            &lt;name&gt;Options 1&lt;/name&gt;
            &lt;options-type&gt;extended-type-information&lt;/options-type&gt;
            &lt;options-timeout&gt;0&lt;/options-timeout&gt;
        &lt;/options&gt;
    &lt;/exporting-process&gt;
&lt;/ipfix&gt;
</artwork></figure>

</section>

<section anchor="example-ietf-psamp-usage" title="Example: ietf-psamp Usage">

<figure><artwork>TBD
</artwork></figure>

</section>

<section anchor="example-ietf-bulk-data-export-usage" title="Example: ietf-bulk-data-export Usage">
<t>The configuration example configures a field-layout template:</t>

<figure><artwork>TBD
</artwork></figure>

</section>

</back>

</rfc>
