Hi everybody, I'm new of NetFlow and ManageEngine NetFlow Analyzer.
Right some days ago, I started to study NetFlow protocol and related software like probes and collectors.
I need to implement a bandwidth monitoring for several sites of a customer and we do not have any routers access (we must consider them as black boxes): each site is VPN connected to a cetralized site and we have to generate NetFlow traffic from each site and send it to a centralized collector.
The idea is to install a probe appliance with 2 ethernet interface for each site: the first NIC in promiscuos mode capturing all traffic and the second one that send NetFlow traffic to ManageEngine NetFlow Analyzer; the first NIC is plugged on a mirrored port switch port from gateway LAN switch port.
I'm testing this kind of configuration right now in to my labo, but I notice that NetFlow Analyzer report my probe's netflow information as a Ingress traffic only: I think that I would be correct but it's not the expected behavior and wanted a confirmation from you guys.
Thnaks a lot!