Hello all, sorry for the OT but I wanted to ask some general strategies for monitoring traffic. My issue is that if I have standard monitor station setup and I want to monitor multiple vlans then I often see the same traffic twice and this really screws up wireshark and other tools. Wireshark sees alot of the duplicate packets as tcp retransmits. So if I need to do a one off capture I can get around this by only monitoring one interface, but if I want to run an application like nTOP I need to capture all vlans etc. I realize netflow may be a better choice than nTOP, but it isn't available in all areas of my network.
-- Marc Abel CCIE #35470 (Routing and Switching) _______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com Are you a CCNP or CCIE and looking for a job? Check out www.PlatinumPlacement.com http://onlinestudylist.com/mailman/listinfo/ccie_rs
