[Ntop-misc] ntop and protocol identification

2015-07-08 Thread Pavel Odintsov
Hello, folks! We have really huge network with ~1Tbps of traffic with sFLOW monitoring enabled. And we want to build traffic statistics from sFLOW data. Could we use deep protocol detection for sFLOW? As I know, we have packet headers inside sFLOW packet. Could we use it for deep protocol

Re: [Ntop-misc] Possible bug on rss rehash

2015-07-08 Thread Alfredo Cardigliano
Hi Amir I am able to receive all the packets also with RSS=6,6,6,6 with the pcap you provided and pfcount_multichannel -r Alfredo On 02 Jul 2015, at 18:08, Amir Kaduri akadur...@gmail.com wrote: Hi Alfredo, I would like to add that I repeated the test with RSS=8,8,8,8,8,8,8,8 like you,

Re: [Ntop-misc] ntop and protocol identification

2015-07-08 Thread Luca Deri
Pavel yes we can do DPI on sflow but being the traffic sampled, you cannot expect us to be able to do too much in terms of prediction Cheers Luca On 08 Jul 2015, at 05:11, Pavel Odintsov pavel.odint...@gmail.com wrote: Hello, folks! We have really huge network with ~1Tbps of traffic

Re: [Ntop-misc] ntop and protocol identification

2015-07-08 Thread Pavel Odintsov
Very good news! We could try and will share experience! Thank you for awesome software! On Thursday, July 9, 2015, Luca Deri d...@ntop.org wrote: Pavel yes we can do DPI on sflow but being the traffic sampled, you cannot expect us to be able to do too much in terms of prediction Cheers Luca