Experience with Netlfow probes

by 
 on 01-Mar-2005 10:53 PM.
  in  NetFlow Analyzer 
I was wondering if your product works with netflow probes (nprobe by ntop.org, Cyclades Nquirer)

Since Netflow Analyzer won't be able do an SNMP poll on the device, how does it figure out the interfaces?

Here is what i am thinking. I would be mirroring a port through which the traffic flows and the probe would "sniff" all the packets. The application will convert that into netflow v5 flows and send them to the netflow analyzer. The reason i need to pursue this is because there are no cisco router between these networks.
  • No status

Re: Experience with Netlfow probes

by 
 on 02-Mar-2005 08:39 AM
Dear Kim,

Thank you for your interest in NetFlow Analyzer. NetFlow Analyzer
would work with the netflow packets exported from netflow probes
like nProbe. NetFlow Analyzer depends on snmp of the exporting
device only to get the interface name and speed. However, with
nProbe, the concept of interface is "virtual", which means that
nProbe will not know through which interface of the router the
packet was routed.
So,if you have nProbe running on a machine A's interface1, all
the traffic (both in and out) of the network will be accounted
for in the Device A's interface1. If you would like to monitor
the in and out traffic to the network(which is being port
mirrored) you will have to tap them separately and use two
interfaces to sniff the in and out traffic separately.

Do mail us incase you have further questions in this regard.

Thanks
Meera

Re: Experience with Netlfow probes

by 
 on 01-Feb-2010 12:25 PM
How would we tap them separately?  Using  Netflow Analyzer or do we need to put a second interface on the PC running the software?

The nprobe imagestream router we are using has the abiity to send streams from any of it's interfaces.  Are you saying to send them both to the collector?

Re: Experience with Netlfow probes

by 
 on 01-Feb-2010 01:32 PM
Oh I think you mean I'd have to wireshark it  etc and .. oh man what a pain 

Re: Experience with Netlfow probes

by 
 on 02-Feb-2010 08:16 AM
Hi,

NetFlow Analyzer classifies traffic based on the interface information in the exported NetFlow packets. The NetFlow packets exported by routers or such will have the input interface (interface through which packets came) and the output interface (the interface through which packets left the device) and based on this the IN and OUT traffic information is classified.

As for as nProbe or such software based flow generators are considered, since all the packets are exported out of a single NIC, the IN and OUT is accounted together.

But we do have a number of customers using nProbe without issues. You may have to explore options on nProbe for separating packets based on IN and OUT or for how to assign the IN and OUT interface information to the exported packets from nProbe itself.

Regards,
Don Thomas Jacob

Post Actions
Statistics
  • 4
     Replies
  • 2589
     Views
  • 0
     Followers
Tags for the post
No tags available for this topic.
© 2009 Corp. All rights reserved. Trademarks | Privacy Policy | Site Map | Contact Us | Careers

Edit Link Delete Link

Edit Link Delete Link

LoadingImage