Hello list
We're currently deploying a self written netflow server software and
experiencing differences in the byte values between our accounting
data and the one our old snmp software based on the interface counters
gives us.
The values are nearly equal (1-5% difference) for some hosts but sometimes
have huge differences in both directions.
Sadly I have no clue in which circumstances it differs. Whenever I try to
test a host it seams to be ok, e.g. I can watch a flow regarding this host
coming to my db and get inserted.
Does anybody have had this troubles before, too? Any idea under which
circumstances both accounting methods could divert? We already took
filtering of spoofed addresses and interface counter which count ethernet
and not ip packets into account.
thanks,
-christian-
-- Christian Hammers WESTEND GmbH - Aachen und Dueren Tel 0241/701333-0 ch@westend.com Internet & Security for Professionals Fax 0241/911879 WESTEND ist CISCO Systems Partner - Premium Certified -- cflowd mailing list cflowd@caida.org
This archive was generated by hypermail 2b29 : Tue Feb 27 2001 - 03:04:36 PST