10-22-2018 10:55 AM - edited 02-21-2020 08:22 AM
Hi, I am having an issue about Elephant flow in my FTD and as per the TAC we need to do flow profiling to pinpoint which traffic is causing it however, it is not an option in my environment because this will have an interruption.
We think of an option to connect another IPS (same model) that will act like a tap. The prod IPS will send a copy of the packet to the other IPS acting as tap then we do the flow profiling there in the tapped IPS?
I would like to know if that is feasible and what configuration should we do for the tapped IPS?
10-22-2018 01:07 PM
10-22-2018 08:43 PM
@gbekmezi-DD, but we want to pinpoint the actual traffic causing the issue and as per TAC we can only determine that when we do flow profiling but it is not an option in our environment that is why if we can put our spare IPS into passive mode then do flow profiling there if it is possible?
You said netflow, we have a netflow collector deployed in the network. is it possible to use that? What parameters should we look in the netflow data for us to find the elephant flow?
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide