Hi Oliver,

> Ok, so have I completely misunderstood the purpose of sFlow? Currently
> we
> are using pmacctd to record every single byte and packet that crosses
> our
> network via mirror ports on the switches. Does sFlow only generate a
> "summary" of the traffic? For our purposes it will need to report
> every byte
> and packet, just as our pmacctd setup currently does.
> 
> Maybe I am just not understanding the purpose of sFlow...

  I'm not a sFlow expert and surelly Paolo will be able to help you more on 
this BUT in general neither NetFlow nor sFlow are valid for this. Both of them 
are more "flow" based than "packet" based and in general they will only report 
on header information, not complete payload (actually trying to get all payload 
information will surelly kill the performance of the link itself).

  After that you have the option of using sampling or not, and different kinds 
of them. NetFlow allows to work without sampling, and this is valid in low 
speed links or high end hardware, but i think sFlow itself is always sampled. 
At the same time the sampling can be just dumb (1 out of tenth) or intelligent 
(they consider size) but in both cases they loose precision.

  And last, you have to consider were to store all this info. If the probe 
doesnt sample, will you in the server? etc etc

  Hope it helps

--------------------------------------------
Jaime Nebrera - [EMAIL PROTECTED]
Consultor TI - ENEO Tecnologia SL
Pol. PISA - C/ Manufactura 6, P1, 3B
Mairena del Aljarafe - 41927 - Sevilla
Telf.- (+34) 955 60 11 60 / 619 04 55 18

_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to