?
Solved

quick Netflow question

Posted on 2009-05-04
3
Medium Priority
?
339 Views
Last Modified: 2012-05-06
Is it best practice to enable netflow on internal or external interfaces.
Also, which direction?

We have a few remote sites connecting back to us via MPLS. I am monitoring their serial interfaces (in the ingress direction). Is this sufficient to analyze bandwidth utilization? Or should I montior egress too?

thanks
0
Comment
Question by:dissolved
  • 2
3 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 2000 total points
ID: 24295850
Typically you enable Netflow on both the internal (LAN) and external (WAN) interfaces since it collects ingress.  You can enable egress collection on newer IOS but it does the same thing as collecting inbound on both the LAN and WAN interfaces.

So, either monitor ingress and egress on the serial or monitor ingress on the LAN and WAN interfaces.  When monitoring bandwidth, you should monitor both ingress and egress so you can monitor upload and download bandwidth utilization.
0
 

Author Closing Comment

by:dissolved
ID: 31577566
great, thanks
0
 

Author Comment

by:dissolved
ID: 24297438
J, can you please look at this? I posted the config from our headend ASA. Can you tell me if there is anything in this config, which would cause the ASA to drop all VPN connections every hour or so?

http://www.experts-exchange.com/Security/Software_Firewalls/Enterprise_Firewalls/Cisco_PIX_Firewall/Q_24378722.html
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question