Symptom
The Netflow update sent by the ISR has Output interface is set to 0 for those flows that match the crypto map.
Conditions
IOS configured with Flexible Netflow, And the Flex record is configured with the following among other attributes:
flow record FREC
collect interface input
collect interface output
This Router also has crypto map configured, and Flexible Netflow needs to send records for traffic that matches a given crypto access-list
Further Problem Description
Note that this limitation exists for traffic matching crypto map when crypto is an output interface feature - i.e crypto map applied on a physical interface.
When crypto traffic is a post-encapsulation feature i.e. in case of tunnel protection, output interface is correctly marked as the respective tunnel interface.
Note: A hidden CLI command has been introduced to enable/disable the FNF/Crypto support
"flow platform crypto"