From owner-freebsd-questions@FreeBSD.ORG Tue Oct 31 11:47:01 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B3B7B16A412 for ; Tue, 31 Oct 2006 11:47:01 +0000 (UTC) (envelope-from nino80@gmail.com) Received: from ug-out-1314.google.com (ug-out-1314.google.com [66.249.92.170]) by mx1.FreeBSD.org (Postfix) with ESMTP id 648AD43D76 for ; Tue, 31 Oct 2006 11:46:55 +0000 (GMT) (envelope-from nino80@gmail.com) Received: by ug-out-1314.google.com with SMTP id m2so1207289uge for ; Tue, 31 Oct 2006 03:46:55 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=EoUcezZpGLNq/ILfORdZNqUnZ4zKuR4ukhqLq9vKeS/pW5rJrs3d694uaCALGdIN6PQBsST5x6AJtto36FI/FqDdTmyi2q2u2uAwlh9C7HhSXPFGUBwzn+cOqkueZy0SQBc1UI1mb3SJGC4Vn2rrCMrU5f1DJvGu/niUdO0rWqY= Received: by 10.78.188.19 with SMTP id l19mr6590492huf; Tue, 31 Oct 2006 03:46:54 -0800 (PST) Received: by 10.78.105.11 with HTTP; Tue, 31 Oct 2006 03:46:54 -0800 (PST) Message-ID: <92bcbda50610310346q2af6c110o94a46c111986dec3@mail.gmail.com> Date: Tue, 31 Oct 2006 12:46:54 +0100 From: "n j" To: freebsd-questions@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline Subject: Netflow sensor/generator for Freebsd X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 31 Oct 2006 11:47:01 -0000 Hello everyone, I'd like to inspect the flows in and out of my fbsd boxes. In order to closely simulate a true netflow-capable router, I found out I need three components: flow sensors, flow collector and flow analyzer. There are quite a few solutions for collecting and analyzing flows, even some written in Java. My question is what should I use for a flow sensor. I did some research and googled quite a bit to find out the following tools capable of exporting netflow records: softflowd fprobe ipcad ng_netflow pfflowd (in combination with pf) Since the feedback information is rather scarce on these tools, could you share your experiences with any of these tools? Have I missed some good ones? Which one should I prefer? Thanks for any response! Nino