nanog mailing list archives
Re: Open source Netflow analysis for monitoring AS-to-AS traffic
From: Nick Hilliard <nick () foobar org>
Date: Fri, 29 Mar 2024 00:15:03 +0000
Tom Beecher wrote on 28/03/2024 18:35:
Fundamentally I've always disagreed with how sFlow aggregates flow data with network state data.
"can aggregate" rather than "aggregates" - this is implementation dependent and most implementations don't bother with it.
Overall, sflow has one major advantage over netflow/ipfix, namely that it's a stateless sampling mechanism. Once you have hardware that can reliably pick out one in N frames, the rest of the protocol is straightforward enough, which means that it's cheap to implement in hardware. If you're ok with 1. sampling and 2. the set of data that sflow provides, then sflow is great.
Netflow / ipfix, on the other hand, assumes that it's learning about flow state. For this, you need both a flow lookup mechanism and flow storage memory. Usually the flow lookup mechanism is implemented using the same technology as the packet forwarding lookup mechanism due to performance requirements, i.e. expensive. Similarly, the storage mechanism needs to be fast, which often precludes being large. Often both the lookup and storage mechanism are linked, e.g. tcam.
Obviously, not all netflow/ipfix implementations implement flow state, but most do; some implement stateless sampling ala sflow. Also many netflow implementations don't export mac address information, which limits usefulness in certain situations. But this is an implementation gap rather than a protocol weakness.
Tools should be chosen to fit the job. There are plenty of situations where sflow is ideal. There are others where netflow is preferable.
Nick
Current thread:
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic, (continued)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Andrew Hoyos (Mar 26)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Marinos Dimolianis (Mar 27)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Pascal Masha (Mar 26)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic John Stitt (Mar 27)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Joe Loiacono (Mar 27)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Peter Phaal (Mar 27)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Saku Ytti (Mar 27)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Peter Phaal (Mar 28)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Saku Ytti (Mar 28)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Tom Beecher (Mar 28)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Nick Hilliard (Mar 28)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Saku Ytti (Mar 28)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Steven Bakker (Mar 29)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Peter Phaal (Mar 29)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Steven Bakker (Mar 31)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Saku Ytti (Mar 29)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Saku Ytti (Mar 27)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Andrew Hoyos (Mar 26)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Peter Phaal (Mar 28)
- Re: Open source Netflow analysis for monitoring AS-to-AS traffic Saku Ytti (Mar 28)