Probe for non NetFlow Capable Gear

Posted in NetFlow, Scrutinizer on January 26th, 2009 by mike@plixer.com
probe-for-non-netflow-capable-gear

Overview
Seems like everyday we have someone uninstall Scrutinizer because they didn’t realize their routers and switches don’t support NetFlow or sFlow.  About 3 years ago we released a software package called nProbeLive that was similar to nProbe.

nProbe can be installed on a computer which sits on a mirrored or spanned port of a switch.  Basically, it converts the packets seen into NetFlow v5, v9 or IP FIX.

Big Problem
A mirrored port may send in and out traffic ‘OUT’ the spanned port so the nProbe sees it all as ‘IN’ traffic.  What’s the problem? It will generally over state utilization on the interface and it is difficult to determine what was sent Vs. received.  Explaining this issue became exhausting so we posted a nProbe FAQ on it.

Wireshark or nProbe ?
NetFlow Analysis does not give nearly the insight as Packet Analysis however, it causes much less traffic.  If you need archiving of high level information (i.e who is talking with who and with what), use nProbe.  If you are trying to get juicy details like URLs, etc. use Wireshark.

Scrutinizer Vs. Wireshark
We look at Scrutinizer as being to NetFlow what Wireshark is to packet analysis.  The archiving capabilities of NetFlow and sFlow are much more efficient.  The details however, are left to packet analysis.

Michael Patterson
Scrutinizer Product Manager
Follow Me on Twitter
Share and Enjoy:
  • Digg
  • StumbleUpon
  • Reddit
  • del.icio.us
  • Facebook
  • Yahoo! Buzz
  • Google Bookmarks
  • Technorati
  • Twitter
  • email
  • Print
Tags: ,

One Response to “Probe for non NetFlow Capable Gear”

  1. A Great Free NetFlow Collector - NetFlow & sFlow Network Monitoring - Systrax Blog Says:

    [...] talks about how to flash your lower end router and enable NetFlow. My Product Manager wrote one on using nProbe, which gives you the ability to generate NetFlow traffic from just about any router or switch. [...]

Leave a Reply