On Fri, Apr 18, 2008 at 8:55 AM, Gert Doering <[EMAIL PROTECTED]> wrote: > Hi, > > > On Fri, Apr 18, 2008 at 08:39:53AM -0400, Tim Durack wrote: > > Sounds like an argument for doing something stateless like sFlow for > > statistics instead of flogging the NetFlow horse. > > This very much depends on your needs. If you need detailed records for > billing purposes, sFlow (or sampled NetFlow) is just not good enough. > > For basic "what's going on?" detection, sflow/sampled netflow is fine.
Yup, interface counters for billing, sFlow for everything else (I agree that probably doesn't work for everybody. We manage to collect data on 12k switch ports using XRMON/sFlow and Inmon's Traffic Sentinel without too much trouble.) Cisco's argument against sFlow seems to be: it's not as accurate as Netflow. Then they introduced sampled netflow because scaling netflow on router hardware is challenging. I find that reasoning hard to follow. Tim:> _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
