aragon said:Not sure, but I think you should still experiment with ng_netflow. It looks like it just needs to see traffic entering an interface, and if you're sniffing, the traffic is entering the interface.
mkpeer dmz: netflow lower iface0
name dmz:lower nfdmz
connect dmz: nfdmz: upper out0
mkpeer nfdmz: ksocket export inet/dgram/udp
msg nfdmz:export connect inet/my_nfsen_host:9994