Hello-
I am a long time user of Flowscan [http://www.eng.wiscnet.net/stats/]
but am looking at more modern/flexible/faster software to do flow
processing. I have installed nfdump/nfsen in a test enviornment and it
is handling some sample flows from our production network, but to the
untrained eye nfsen appears to be more focused to transit providers than
edge providers like us [AS 2381].
There are a couple of things that I'm doing with Flowscan that it is not
obvious if there is a way to do inside of Nfsen.
1) Seperate inbound/outbound flows into flows/pkts/bytes graphs by IP
protocol based on a list of CIDRs that we originate and advertise to our
upstream providers.
I have seen some discussion about using profiles and matching inindexes,
however, ifindexes are less stable than CIDRs and I want a global view,
not a per interface view.
2) Flowscan is also able to ignore flows that pass through multiple
exporters in our network via a list of {exporter,ifindex tuples} but I
don't see a way to do that with nfsen.
Hoping to find someone here who has moved from flowscan to nfsen to chat
with.
Thanks!
-Michael
------------------------------------------------------------------------------
_______________________________________________
Nfsen-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfsen-discuss