6 messages in net.nether.puck.cisco-nsp[c-nsp] NETFLOW or Alternatives??
FromSent OnAttachments
Vandy HamidiJan 3, 2005 9:12 pm 
Roland DobbinsJan 3, 2005 9:21 pm 
Olav LangelandJan 4, 2005 3:44 am 
RH ListsJan 6, 2005 9:56 am 
Earls, MichaelJan 6, 2005 10:34 am 
Chris MooreJan 6, 2005 10:46 am 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:[c-nsp] NETFLOW or Alternatives??Actions...
From:Earls, Michael (Mich@53.com)
Date:Jan 6, 2005 10:34:41 am
List:net.nether.puck.cisco-nsp

Check out http://vermeer.org/display_doc.php?doc_id=6

Graphing Cisco Systems (NBAR) Network-based application recognition with MRTG:

Michael

PGP Info: KeyID 0x0DFD993C Fingerprint F903 0325 5105 2CDB 4BF4 C88B 72F7 BA7A 28CC 598A

-----Original Message----- From: RH Lists [mailto:lis@101.net] Sent: Thursday, January 06, 2005 9:56 AM To: cisc@puck.nether.net Subject: RE: [c-nsp] NETFLOW or Alternatives??

NBAR protocol discovery may also help in this situation.

On Jan 3, 2005, at 6:13 PM, Vandy Hamidi wrote:

All, I'm looking for a way to determine the type of traffic and the amounts of each Flow (SIP, DIP, Sport, DPort).

When my internet traffic or WAN traffic hits 99%, I want to be able to identify the cause. Right now, it's a total uneducated guess.

Requirements: 1) Identify traffic flows 2) Flow Kbps 3) Preferably use a Windows Server for collection and reporting 4) Prefer Trending 5) Easy ramp up (trying to avoid needing to learn a whole no discipline)

I'm not very familiar with NetFlow, but it looks like it needs a Solaris Data Collector.

Equipment will range from 6500, 4500, 3745, 7206, etc. Thanks in advance,

-=Vandy=-