On Mon, Apr 13, 2015 at 10:20:58AM -0400, Adam Greene wrote:
> Hmm ... SPANing the traffic ... there's about 125Mbps going
> through that regularly, so analyzing the mirrored traffic may be
> a challenge. I suspect the encapsulation failures are basically
> from the continual flood of hack attempts coming in from the
> Internet.

Can you feed the span into Argus? [0] We have it monitoring
several 1Gbps links in to a server (generally flat out), and some
10Gbps lines. While those data rates need some driver setting
tuning to stop packets being dropped, I don't believe you should
have any problem analyzing 125Mbps.

Cheers,

Matthew


[0] http://qosient.com/argus/

-- 
Matthew Newton, Ph.D. <[email protected]>

Systems Specialist, Infrastructure Services,
I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom

For IT help contact helpdesk extn. 2253, <[email protected]>
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to