Interesting...  I'll check out the interfaceID thing.

As for throughput / processing concerns: Do you think a single netflow
device can handle the netflow streams from 200 sources?  I know -
depends on the total pps I'm sure.  I have not modeled any of these
location to that extent.  From what I've seen netflow is pretty light
weight and requires FAR fewer resources than a true packet capture using
libpcap.

Thanks for the prompt response!

Gary


-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of
Luca Deri
Sent: Wednesday, October 03, 2007 3:38 AM
To: [email protected]
Subject: Re: [Ntop] netflow device (interface) needed for each netflow
source?

Gary
one device is enough, unless you want to keep data unmerged. If you play
with interfaceId (in netflow) you can send all data to the same ntop nf
device and at the same time be able to know the source of such
information.

Cheers, Luca

Gary Gatten wrote:
> Hello,
>
> I currently have (4) netflow devices configured in nTop - each
listening
> on a different udp port, 2055 - 2058.
>
> We're changing our network design and now I'll need.... 180 - 200
> netflow sources.  So, do I need to create a unique netflow device in
> nTop listening on a unique port?  Or, can I create a single device and
> have all sources point to this?  OR, since these 200'ish sources are
> logically grouped by "regions, can I create (4) netflow devices with
> 50'ish sources per device?
>
> I'm thinking I only "need" a single netflow device for any number of
> sources, but I'm wondering what the pros/cons of this setup would be
vs.
> a unique device for each source?
>
> I plan to play around with these different configs a little and find
one
> that works, but if anyone has a similar deployment with some thoughts
> that'd be great.
>
> Gary
>
>
>
========================================================================
===
>
>
>
>
>
> "This email is intended to be reviewed by only the intended recipient
>  and may contain information that is privileged and/or confidential.
>  If you are not the intended recipient, you are hereby notified that
>  any review, use, dissemination, disclosure or copying of this email
>  and its attachments, if any, is strictly prohibited.  If you have
>  received this email in error, please immediately notify the sender by
>  return email and delete this email from your system."
>
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop
>   


-- 
Luca Deri <[EMAIL PROTECTED]>   http://luca.ntop.org/
                                skype://lucaderi/
Don't be encumbered by past history. Go off and do
something wonderful - Robert Noyce

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

===========================================================================





"This email is intended to be reviewed by only the intended recipient
 and may contain information that is privileged and/or confidential.
 If you are not the intended recipient, you are hereby notified that
 any review, use, dissemination, disclosure or copying of this email
 and its attachments, if any, is strictly prohibited.  If you have
 received this email in error, please immediately notify the sender by
 return email and delete this email from your system."

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to