Re: [Nfsen-discuss] duplicate flows
Netflow visualisation and investigation tool
Brought to you by:
phaag
|
From: Ivan A. B. <iv...@li...> - 2006-07-25 09:43:43
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 25/07/2006 10:01, Cédric Delaunay wrote: > hy nf-users, > Using nfsen and nfcapd from a few weeks, I'm now trying to install a scan > detector on my network. Ipflow's one seems an efficient one. > As i still want to use nfsen, i need to duplicate the flows I receive to 2 > others ports. If all you want to do is duplicate netflow data (which is UDP), you should be able to use something simple like UDP samplicator: http://www.switch.ch/tf-tant/floma/sw/samplicator/ Also flowtools (netflow tools) comes with a fanout application (flow-fanout) I haven't used either of these (because I use sflow ... and I use sflowtool to do the fanout at the moment). Cheers Ivan - -- Ivan Beveridge <iv...@li...> http://www.linx.net/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFExeehQQZN5jq7vncRAt6zAJ9uaFWVzKNmNzPLBuTJepuTS1kLagCdGskc 5vCvKSZMeollW0wykSCqIiI= =WWUK -----END PGP SIGNATURE----- |