We have Cisco (series 800, 1800, 2800 and 3800) routers from the ISP. (MPLS). The traffic we can see on the NFA is more than double. When I check traffic sent and traffic received using Wireshark, I can see much lower than indicated in NFA. I can understand about 15% overhead and so on.... but 150% more??
Routers has some physical and virtual interfaces. I don't know the exactly the netflow configuration on the router, but are using ingress and egress, ip route cache flow, .... Anyway, what is the recommended configuration in that topology? What interface can see all the inbound and outbound traffic, so can I apply there the license?