Closed johanteekens closed 8 years ago
@johanteekens please send deri@ntop.org and mainardi@ntop.org the pcap for debugging.
@johanteekens I have looked at your problem. The flows ASA generate do not have both the start and the end time (they look like flows but are not properly exported)
This means that the only thing nprobe can do is to assume that the flow has lasted just the time specified. As exports happen periodically, you see a period of nothing and a short export period where all traffic is packet in a couple of seconds. This causes the spikes that you have reported. So the issue is definitively on the ASA side, but I don't think you can do much as ASA is not a real netflow probe but a firewall that exports flows when the communication has been processed.
Bottom line, feel free to suggest us a way to circumvent the issue (the only think that comes to my mind is to compute flow throughput every min instead of every sec, but this is not a solution but rather a sort of workaround). Beside these peaks I believe that all the rest works as expected and so you can probably survive with these limitations.
Pls someone help me. How to calculate throughput of a flow using nprobe?