Configure Parsing of Network Packets
Overview
Configuration
parser {
# Tunnel port detection
geneve_port = 6081
vxlan_port = 4789
wireguard_port = 51820
}Configuration Options
Tunnel Port Detection
geneve_port
geneve_portvxlan_port
vxlan_portwireguard_port
wireguard_portHow Tunnel Parsing Works
Packet Processing Flow
Tunnel Detection Benefits
CNI-Specific Configurations
Flannel with VXLAN
Calico with VXLAN
Cilium with Geneve
WireGuard Encryption
NSX-T
Determining Your Configuration
Identifying VXLAN Port
Identifying Geneve Port
Identifying WireGuard Port
Multiple Tunnel Types
Performance Considerations
Impact of Tunnel Parsing
When to Disable
Validation
Check Flow Records
Compare With/Without Tunnel Parsing
eBPF Verifier Considerations
Understanding Verifier Complexity
Recommended Configurations by Environment
Complete Configuration Example
Troubleshooting
Seeing Only Tunnel Endpoints in Flows
Incorrect Tunnel Detection
Multiple Ports for Same Protocol
Best Practices
Next Steps
Need Help?
Last updated