Subject: Re: [flow-tools] Networks
From: Mark Fullmer (maf@splintered.net)
Date: Tue Dec 02 2003 - 13:42:51 CST
Redirected to the FlowScan mailing list.... mark On Dec 1, 2003, at 9:16 AM, Samson Martinez wrote: > Hello, > > > I've configured flow-tools with Flowscan & CUFlow and, so far, > everything appears to be working well. However, I'm trying to identify > traffic that is showing up as a substantial part of the reported flows. > Our network, in a nutshell, is as follows: > > 2 Cisco 7204VXRs that sit on our network boundary, both exporting > version 5 flows to a Sun Solaris server. > > I have configured 7 subnets as local as these are networks that sit > behind the 7204s. I then added these same subnets in their subnetted > form to the "Networks Interested In" portion of the configuration. > > All the traffic appears to be properly accounted for but when I show > the > graphs I see 20% In & 41% Out traffic identified as "Other networks". > > What is the best way to isolate and identify those "Other Networks"? > > Many thanks for all your assistance. > > By the way, the same is occurring with the "Services" and "Protocols". > > Regards, > > -Samson Martinez > > > _______________________________________________ > flow-tools@splintered.net > http://www.splintered.net/sw/flow-tools > -- Help mailto:majordomo@net.doit.wisc.edu and say "help" in message body Unsubscribe mailto:majordomo@net.doit.wisc.edu and say "unsubscribe flowscan" in message body Archive http://net.doit.wisc.edu/~plonka/list/flowscan/archive/
This archive was generated by hypermail 2b25 : Tue Dec 02 2003 - 13:47:26 CST