On Feb 12, "To [EMAIL PROTECTED]" wrote:

> > That's basically all I can do for you.  If it's truly important to you,
> > contact me off-list and let's discuss paid support.
> 
> This info was just what I was looking for to get me started.  I'll let you
> know what I come up with.  Thanks again for the help.

I figured out that it was indeed "invalid" sflow packets.

Apparently, sflow sends COUNTERSAMPLE and FLOWSAMPLE packets.
COUNTERSAMPLE packets give a quick look at interface counters on the
machine, whereas FLOWSAMPLE packets are actual packet fragments from IP
connections.  Ntop seems to simply parse, debug_print, and discard
COUNTERSAMPLE packets...which made it confusing to look at the debug
output and say "wow, lots of sflow coming in!" when in fact it was just
for show, as Burton suggested.  I added more switches (with active
connections) to the switches sending sflow packets and I now have hosts
with pretty graphs.

Anyway, thanks for the help and sorry for the noise.

Trapped in a dungeon of my own dumbassness,

Mike
_______________________________________________
Ntop mailing list
[EMAIL PROTECTED]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to