On Mon, Apr 13, 2015 at 10:20:58AM -0400, Adam Greene wrote: > Hmm ... SPANing the traffic ... there's about 125Mbps going > through that regularly, so analyzing the mirrored traffic may be > a challenge. I suspect the encapsulation failures are basically > from the continual flood of hack attempts coming in from the > Internet.
Can you feed the span into Argus? [0] We have it monitoring several 1Gbps links in to a server (generally flat out), and some 10Gbps lines. While those data rates need some driver setting tuning to stop packets being dropped, I don't believe you should have any problem analyzing 125Mbps. Cheers, Matthew [0] http://qosient.com/argus/ -- Matthew Newton, Ph.D. <[email protected]> Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, <[email protected]> _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
