Hi!
An update:
Dont ask me why, but now I'm only having less than 2% of packet loss.
Now, I have a 1.3Gb pcap file captured from nTop.
At this moment, the unknow traffic is arround 58%, http is 35% and, for
example, bittorrent is like 0.something%
How can I send you the file, or how can I give you a download link to
take it and inspect why nDPI is marking so much traffic as unknow.
Thanks you!
--Daniel
El 19/10/2012 10:08, Dpto. Datos Television Costa Blanca escribió:
Hello!
Thank you very much for your answer.
The problem is that I really need to know whats happening and I need
the DPI to know it.
How can I do it? Maybe PF_RING with DNA?
Thank you!
--Daniel
El 19/10/2012 9:24, Alex DEKKER escribió:
Note sure where this email went originally, as I didn't see it:
El 17/10/2012 21:23, Dpto. Datos Television Costa Blanca escribió:
Hi Alexd
I know what Luca is suggesting me, but as I said my router actually
is sending me the newflows. But dunno if by misconfiguration or if
it is that way, the netflow dont send me the "full" packet for
analyzing with nDPI-nTop.
Any clue on this?
That's the point of Netflow! It sends a summary of the packet, rather
than the entire packet. The upside is that the processing load on the
collector is smaller, the downside is that you can't go deeper into
the packet than whatever is summarised by the probe.
alexd
_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop