S
S
sanhces72013-04-02 13:51:53
NetFlow
sanhces7, 2013-04-02 13:51:53

NetFlow Analyzer does not parse part of the traffic?

Good day!
The problem is the following - in a corporate network, consisting of a large number of routers and moving a fairly large amount of traffic, ManageEngine NetFlow Analyzer, honestly bought by the company, is used as a collector for NetFlow. The system - the collector is located on a separate server dedicated for this purpose under Win2008.
For different routers on the server, in the statistics section, the amount of unparsed traffic varies from 5 to 95 percent (traffic is marked as "unaccounted"). All other traffic is perfectly sorted by IP addresses, VLANs, traffic type, other features, with beautiful graphs, etc. - everything is stable.
Standard solution like simple and more enchantingThey don't help, and they don't explain what's going on.
I could not catch at least some connection between unidentified traffic and the settings of different network segments.
I took a separate clean router, whipped up the interface, NetFlow sensor and address for sending updates. The server saw it, included it in the statistics. I pinged the network, wound up 50 Kb of traffic, of which the server did not recognize 20 Kb.
I ask for help in finding lost traffic, and thanks in advance, gentlemen!

Answer the question

In order to leave comments, you need to log in

3 answer(s)
J
JDima, 2013-04-02
@JDima

I'm embarrassed to ask - can't a vendor get a case?

S
sanhces7, 2013-04-03
@sanhces7

Looks like I found the answer here , caption to the second picture.
"growing portion applications use dynamics ports, complicating traffic characterization" - An increasing number of applications use dynamic ports, which makes it difficult to recognize traffic.
The version is plausible, it seems to be true, which means that nothing can be done with unidentified traffic. It's unfortunate.

A
Alexander Chekalin, 2013-12-04
@achekalin

Where is the traffic picture taken from? Some pieces of hardware can help classify traffic (well, Network Analyzer can accept this help). Take the same NBAR ciskin as an example .

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question