Re: About NetFlow/IPFIX and DPI

2014-05-10 Thread Antoine Meillet
Thank you Matt (offlist), Dan, Roland and Paolo for your answers ! Antoine. On 7 mai 2014, at 18:43, Paolo Lucente wrote: > Please note NBAR/NetFlow integration wanted to be an example of > using NetFlow/ IPFIX as a transport for DPI classification info > (where classification could be performe

Re: About NetFlow/IPFIX and DPI

2014-05-07 Thread Paolo Lucente
Please note NBAR/NetFlow integration wanted to be an example of using NetFlow/ IPFIX as a transport for DPI classification info (where classification could be performed with any other in-line technology than NBAR). Whether NBAR works or does not as a classification technology is out of scope for m

Re: About NetFlow/IPFIX and DPI

2014-05-07 Thread Dobbins, Roland
On May 7, 2014, at 10:45 PM, Paolo Lucente wrote: > This model is supported on the export side by Cisco with their NetFlow/NBAR > integration and on the collection side by some > collector. As you'll note in reading that report, NBAR didn't seem to work very well for them; I haven't run acro

Re: About NetFlow/IPFIX and DPI

2014-05-07 Thread Paolo Lucente
Another role for IPFIX/NetFlow in the context of DPI (on top of PSAMP that was already mentioned by Roland) is to serve as a transport mechanism to travel flow data along with their DPI classification from probes to remote collectors, for persistent storage, analysis, etc. This model is supported

Re: About NetFlow/IPFIX and DPI

2014-05-07 Thread Dobbins, Roland
On May 7, 2014, at 8:11 PM, Antoine Meillet wrote: > Should those protocols be considered as tools to perform DPI ? No - they're flow telemetry exported by routers and switches, and they provide layer-4 information. It's possible with Cisco Flexible NetFlow and with PSAMP exported over IPFIX

Re: About NetFlow/IPFIX and DPI

2014-05-07 Thread Dan White
On 05/07/14 15:11 +0200, Antoine Meillet wrote: Hello, I'm currently writing a paper for school and I talk about net neutrality which brings the subject of NetFlow/IPFIX. Should those protocols be considered as tools to perform DPI ? That question can be taken a couple of ways. Netflow is use