Some comments on number 2 - that's all universal to network analysis applications.
"For Ntop to work, we have to use additional switch features like Netflow for Ntop to see the traffic or SPAN if we don't have US 3000$ to buy a Netflow card.". I know of no technology that would allow any application to get around the way a switched network works. Nor can I conceive how one would possibly work. Only way around it is to go back to hubs. "In both way activating Netflow or SPAN will generate lot of trafics on the server" er.....yeah, if you have a lot of data running over your network you're going to have a lot of data to analyze. "A 4 Xeon processors hypertheading with 50GB of RAM on a RAID SCSI system?" Um.....again, that's how the world works. It takes a lot of processing power to analyze a lot of data. That's why supercomputers were invented! If it's hard to explain why you need serious hardware to run a free program, try explaining why they need serious hardware to run a $50k application! Actually I think that would be easier and perhaps the way you should go. People expect to need a $20k box to tun a $50k program. People expect to use an old clone that's currently holding a door open to run a free program. C -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Wednesday, September 07, 2005 11:38 AM To: [email protected] Subject: [Ntop] My feedbacks on Ntop Hello list, This is my feedbacks on Ntop. 1) - It would be nice if we can have an option into configure to enable or disable XMLDump, by defaut if libxml2, dome, and very OLD glib1 are not available, then the XML feature is not functional, that's correct but I don't understand why "libxmldumpPlugin" and "xmldumpPlugin.so" are still compilled and installed!! Therefore having an option to enable or disable this feature could be a good addition to the source, also why you still use glib version 1.x? 2) - Running Ntop for home user or small company using Hub work fine because they have not lot of trafics on their network and Ntop work nice on this environement but when we talk about medium or large entreprises using switches (Cisco, FoundryNetwork), then Ntop become a problem. For Ntop to work, we have to use additional switch features like Netflow for Ntop to see the trafic or SPAN if we don't have US 3000$ to buy a Netflow card. In both way activating Netflow or SPAN will generate lot of trafics on the server (also on the switch for SPAN) where Ntop is running and even with an Intel Pro 1000 Ethernet Adapters supporting Jumbo Frame, NAPI, etc, the server and Ntop are not able to handle the load. Ntop consume 80% of all CPU resources and all 3GB of RAM + 1GB of swap in a minute. Since the kernel still need to manage other process, it will automaticaly kill the process causing the problem by consuming all resources (yes Ntop). So which server should I have to run it? A 4 Xeon processors hypertheading with 50GB of RAM on a RAID SCSI system? Ok there is a PF_RING solution that ONLY work with old libpcap version and old Linux Kernel with old GCC version too, so when you use a new Linux system to be update and bug fix, you cannot use this solution and even applying this solution with old software version doesn't fix the above problem. Yes ntop is a great software and I like it, but I'm affraid to explain all of the above in the entreprise when I've to deploy it. Gerhard, _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop ********************************************************************** Confidential/Proprietary Note The information in this email is confidential and may be legally privileged. Access to this email by anyone other than the intended addressee is unauthorized. If you are not the intended recipient of this message, any review, disclosure, copying, distribution, retention, or any action taken or omitted to be taken in reliance on it is prohibited and may be unlawful. If you are not the intended recipient, please reply to or forward a copy of this message to the sender and delete the message, any attachments, and any copies thereof from your system. Thank you. Guardian Mtg Documents, Inc. 225 Union Boulevard, Suite 200 Lakewood, CO 80228. ********************************************************************** _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
