Solved

quick Netflow question

Posted on 2009-05-04
3
316 Views
Last Modified: 2012-05-06
Is it best practice to enable netflow on internal or external interfaces.
Also, which direction?

We have a few remote sites connecting back to us via MPLS. I am monitoring their serial interfaces (in the ingress direction). Is this sufficient to analyze bandwidth utilization? Or should I montior egress too?

thanks
0
Comment
Question by:dissolved
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 24295850
Typically you enable Netflow on both the internal (LAN) and external (WAN) interfaces since it collects ingress.  You can enable egress collection on newer IOS but it does the same thing as collecting inbound on both the LAN and WAN interfaces.

So, either monitor ingress and egress on the serial or monitor ingress on the LAN and WAN interfaces.  When monitoring bandwidth, you should monitor both ingress and egress so you can monitor upload and download bandwidth utilization.
0
 

Author Closing Comment

by:dissolved
ID: 31577566
great, thanks
0
 

Author Comment

by:dissolved
ID: 24297438
J, can you please look at this? I posted the config from our headend ASA. Can you tell me if there is anything in this config, which would cause the ASA to drop all VPN connections every hour or so?

http://www.experts-exchange.com/Security/Software_Firewalls/Enterprise_Firewalls/Cisco_PIX_Firewall/Q_24378722.html
0

Featured Post

How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
What problem can Native VLAN mismatch causes 4 62
BGP prefix and routing 3 88
Router Question 12 75
Upgrading from Sonicwall Tz210 6 37
This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question