netflow differs from snmp interface accounting

From: Christian Hammers (ch@westend.com)
Date: Tue Feb 27 2001 - 02:54:17 PST

  • Next message: Darren Ward: "RE: cflowd-2-1-b1.tar.gz - tar: directory checksum error?"

    Hello list

    We're currently deploying a self written netflow server software and
    experiencing differences in the byte values between our accounting
    data and the one our old snmp software based on the interface counters
    gives us.

    The values are nearly equal (1-5% difference) for some hosts but sometimes
    have huge differences in both directions.

    Sadly I have no clue in which circumstances it differs. Whenever I try to
    test a host it seams to be ok, e.g. I can watch a flow regarding this host
    coming to my db and get inserted.

    Does anybody have had this troubles before, too? Any idea under which
    circumstances both accounting methods could divert? We already took
    filtering of spoofed addresses and interface counter which count ethernet
    and not ip packets into account.

    thanks,

     -christian-

    -- 
    Christian Hammers    WESTEND GmbH - Aachen und Dueren     Tel 0241/701333-0
    ch@westend.com     Internet & Security for Professionals    Fax 0241/911879
               WESTEND ist CISCO Systems Partner - Premium Certified
    --
    cflowd mailing list
    cflowd@caida.org
    



    This archive was generated by hypermail 2b29 : Tue Feb 27 2001 - 03:04:36 PST