Hi,
I have the folowing scenario one HQ VPN router and one Branch router connecte with an IPSec-GRE tunnel. All interface for each router (HQ and Branch router) are configure to export netflow to NetFlow Manage engine server. I compare traffic from OUT tunnel traffic from Branch router -> IN tunnel traffic from HQ router and IN tunnel traffic from Branch router -> OUT tunnel traffic from HQ router. The traffic should be almost the same out->in and in->out from Branch->HQ but:
1. I saw that ntp, snmp or netflow OUT traffic from Branch router(originated from the Branch router) is not counted from Netflow but is counted on IN traffic on the HQ router. I think that this is because the the traffic is counted only on ingress but i am not sure that this is the answer. It this normal?
2. I made a test ,and transfer a file from Branch LAN to HQ LAN (file size1.2 M ) and the out tunnel traffic from Branch router shows 1.6M out traffic and IN tunnel traffic from HQ shows 1.4M in traffic for that transfer. This happens also for other application like HTTP and more the OUT traffic is bigger the IN traffic. This could happend because Application level retransmit,Transport level retransmit(TCP) or paket loss between Branch and HQ but i am not sure. Have you seen such behaviour?
Thanks for your answer