Hi Peter,

Thanks for the reply.

I am not arguing about later-2 info in netflow implementation.
What I mean to say is there can be an option where a user can
add layer-2 header details which can be considered to compute
data rate.

At present we need to calculate it manually considering
the total no. of packets and adding (L2 header*no.of packets).
This helps especially when computing the bandwidth usage over
WAN.

About your guess...you got it right !
Temporarily we have created shadow profiles to monitor specific class
of traffic.

Venu

On Tue, Mar 4, 2008 at 3:57 PM, Peter Haag <[EMAIL PROTECTED]> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
>
> - --On March 4, 2008 14:09:55 +0530 Venu Gopal <[EMAIL PROTECTED]> wrote:
>
> | Thats OK Peter !
> | I'm trying to tweak the nfdump to do this.
> | I'll let you know once its done.
> |
> | We have been using ndump+nfsen for quite sometime and found it very
> useful.
> | We have some requests and ideas if you like.
> | It is possible to have option to add layer-2 headers (fixed) for data
> rate
> | calculation.
> | They may include HDLC/Cisco-HDLC encapsulations over WAN.
>
> well - nfdump in the next version will include many more v9 tags. However,
> as not even the CISCO boxes have adequate
> implementation of v9 I doubt that layer 2 header will be a point a near
> future.
>
> nfdump will also include a command line real time monitor, but with
> instant data, but most likely without the top n stat
> options ( not yet decided ) a kind of tcpdump for incoming netflow data.
> But I guess this is not what you need here.
>
>    - Peter
>
>
> |
> | Venu
> |
> | On Tue, Mar 4, 2008 at 1:58 PM, Peter Haag <[EMAIL PROTECTED]> wrote:
> |
> | > -----BEGIN PGP SIGNED MESSAGE-----
> | > Hash: SHA1
> | >
> | >
> | >
> | > - --On March 4, 2008 13:38:22 +0530 Venu Gopal <[EMAIL PROTECTED]>
> wrote:
> | >
> | > | Hi Peter,
> | > |
> | > | I do understand your point.
> | > | But as an administrator we may use various filters online
> | > | just like tcpdump. Instead of creating profiles in prior it would be
> | > | useful if we can have this feature online.
> | >
> | > So use shadow profiles! They only create the graphs, and do not use
> disk
> | > space for flows.
> | > There are currently no other plans.
> | >
> | >    - Peter
> | >
> | > |
> | > | Venu
> | > |
> | > | On Tue, Mar 4, 2008 at 12:43 PM, Peter Haag <[EMAIL PROTECTED]>
> | > wrote:
> | > |
> | > | > -----BEGIN PGP SIGNED MESSAGE-----
> | > | > Hash: SHA1
> | > | >
> | > | >
> | > | >
> | > | > - --On March 4, 2008 9:59:48 +0530 venu gopal <[EMAIL PROTECTED]>
> | > wrote:
> | > | >
> | > | > | Hi,
> | > | > |
> | > | > | Nfsen shows the following statistics graphically
> | > | > | 1. Packets
> | > | > | 2. Traffic
> | > | > | 3. Flows
> | > | > |
> | > | > | Is it possible to show these statistics for the filtered traffic
> | > | > | with out creating the specific profiles ?
> | > | >
> | > | > You'll have all these graphs with profiles.
> | > | > Filtered traffic are profiles - so what's wrong with profiles?
> | > | >
> | > | >    - Peter
> | > | >
> | > | > |
> | > | > | Venu
> | > | >
> | > | >
> | > | >
> | > | > - --
> | > | > _______ SWITCH - The Swiss Education and Research Network ______
> | > | > Peter Haag,  Security Engineer,  Member of SWITCH CERT
> | > | > PGP fingerprint: D9 31 D5 83 03 95 68 BA  FB 84 CA 94 AB FC 5D D7
> | > | > SWITCH, Werdstrasse 2, P.O. Box,  CH-8021   Zurich, Switzerland
> | > | > E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/
> | > | > -----BEGIN PGP SIGNATURE-----
> | > | > Version: GnuPG v1.4.3 (Darwin)
> | > | >
> | > | > iQCVAwUBR8z2nf5AbZRALNr/AQLfpAP/TfIJ7+Wm9diIlG3dR/smDzPTL/fCSRy8
> | > | > gsud5ST5C8hUjgfbXdNqLbH4eaUIG9PUOdWlqbwtvOfpmblis7ySc1FCn0hNlKxV
> | > | > uBVseGx39naKLIvPNQOtJRYwRFHt+6PPXMbyiNZxb1h1eHbEuYxCZNu1apRKejer
> | > | > 0McgXcQFK4o=
> | > | > =ZsmD
> | > | > -----END PGP SIGNATURE-----
> | > | >
> | > | >
> | >
> | >
> | >
> | > - --
> | > _______ SWITCH - The Swiss Education and Research Network ______
> | > Peter Haag,  Security Engineer,  Member of SWITCH CERT
> | > PGP fingerprint: D9 31 D5 83 03 95 68 BA  FB 84 CA 94 AB FC 5D D7
> | > SWITCH, Werdstrasse 2, P.O. Box,  CH-8021   Zurich, Switzerland
> | > E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/
> | > -----BEGIN PGP SIGNATURE-----
> | > Version: GnuPG v1.4.3 (Darwin)
> | >
> | > iQCVAwUBR80IRv5AbZRALNr/AQIGdwP/fZf78cGOoeEQYvnBZIMR0VRp8pqwZzdk
> | > e2zWMFmM+BrfASAXzfEZ+zZggXLjOskuWsDEhLuFa8An4yZHrSOvTSbmx2akTZtD
> | > XHMajL6QyO8ciNw2YwcZ4AX6EMdlNpUSR1C2gxL4GPyxp16Z1/NRIu5KpA8pMmUD
> | > /wTr5h6IawY=
> | > =agDD
> | > -----END PGP SIGNATURE-----
> | >
> | >
>
>
>
> - --
> _______ SWITCH - The Swiss Education and Research Network ______
> Peter Haag,  Security Engineer,  Member of SWITCH CERT
> PGP fingerprint: D9 31 D5 83 03 95 68 BA  FB 84 CA 94 AB FC 5D D7
> SWITCH, Werdstrasse 2, P.O. Box,  CH-8021   Zurich, Switzerland
> E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.3 (Darwin)
>
> iQCVAwUBR80kLv5AbZRALNr/AQLeawQAo2H6ltFsaDkybIj5MJht64ru9ykVCS8E
> ChEV0Bah3AMFlGBzvUkgAVe8BWa5ivkxEHCQnABxzCxNr0qNJKgX53pt7u4rmuss
> z9w5BNGtl44YxAOWv2LtZ4t2Itx19UtN6Ra59jbREepq6X6LrJW+42XFESyMvK5A
> jWJ5wrT48/8=
> =yhT6
> -----END PGP SIGNATURE-----
>
>
-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Nfsen-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfsen-discuss

Reply via email to