Some comments on number 2 - that's all universal to network analysis
applications. 

"For Ntop to work, we have to use additional switch features like
Netflow for Ntop to see the traffic or SPAN if we don't have US 3000$ to
buy a Netflow card.". I know of no technology that would allow any
application to get around the way a switched network works. Nor can I
conceive how one would possibly work. Only way around it is to go back
to hubs. 

"In both way activating Netflow or SPAN will generate lot of trafics on
the server" er.....yeah, if you have a lot of data running over your
network you're going to have a lot of data to analyze. 

"A 4 Xeon processors hypertheading with 50GB of RAM on a RAID SCSI
system?" Um.....again, that's how the world works. It takes a lot of
processing power to analyze a lot of data. That's why supercomputers
were invented!

If it's hard to explain why you need serious hardware to run a free
program, try explaining why they need serious hardware to run a $50k
application! 

Actually I think that would be easier and perhaps the way you should go.
People expect to need a $20k box to tun a $50k program. People expect to
use an old clone that's currently holding a door open to run a free
program.

C

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of
[EMAIL PROTECTED]
Sent: Wednesday, September 07, 2005 11:38 AM
To: [email protected]
Subject: [Ntop] My feedbacks on Ntop

Hello list,

This is my feedbacks on Ntop.

1) - It would be nice if we can have an option into configure to enable
or disable XMLDump, by defaut if libxml2, dome, and very OLD glib1 are
not available, then the XML feature is not functional, that's correct
but I don't understand why "libxmldumpPlugin" and "xmldumpPlugin.so" are
still compilled and installed!! Therefore having an option to enable or
disable this feature could be a good addition to the source, also why
you still use glib version 1.x?

2) - Running Ntop for home user or small company using Hub work fine
because they have not lot of trafics on their network and Ntop work nice
on this environement but when we talk about medium or large entreprises
using switches (Cisco, FoundryNetwork), then Ntop become a problem. For
Ntop to work, we have to use additional switch features like Netflow for
Ntop to see the trafic or SPAN if we don't have US 3000$ to buy a
Netflow card. In both way activating Netflow or SPAN will generate lot
of trafics on the server (also on the switch for SPAN) where Ntop is
running and even with an Intel Pro 1000 Ethernet Adapters supporting
Jumbo Frame, NAPI, etc, the server and Ntop are not able to handle the
load. Ntop consume 80% of all CPU resources and all 3GB of RAM + 1GB of
swap in a minute. Since the kernel still need to manage other process,
it will automaticaly kill the process causing the problem by consuming
all resources (yes Ntop). So which server should I have to run it? A 4
Xeon processors hypertheading with 50GB of RAM on a RAID SCSI system? Ok
there is a PF_RING solution that ONLY work with old libpcap version and
old Linux Kernel with old GCC version too, so when you use a new Linux
system to be update and bug fix, you cannot use this solution and even
applying this solution with old software version doesn't fix the above
problem.

Yes ntop is a great software and I like it, but I'm affraid to explain
all of the above in the entreprise when I've to deploy it.

Gerhard,

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop


**********************************************************************
Confidential/Proprietary Note

The information in this email is confidential and may be legally privileged.  
Access to this email by anyone other than the intended addressee is 
unauthorized.  If you are not the intended recipient of this message, any 
review, disclosure, copying, distribution, retention, or any action taken or 
omitted to be taken in reliance on it is prohibited and may be unlawful.  If 
you are not the intended recipient, please reply to or forward a copy of this 
message to the sender and delete the message, any attachments, and any copies 
thereof from your system.  Thank you. 
Guardian Mtg Documents, Inc.
225 Union Boulevard, Suite 200
Lakewood, CO 80228.
**********************************************************************

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to