nProbe: an Open Source NetFlow Probe for Gigabit Networks

Cisco NetFlow is an industry standard protocol suitable for monitoring network traffic. Although most of high-end network routers support NetFlow, very often flows are computed only on a small portion of the overall traffic due to performance limitation of NetFlow probe implementations. This paper covers the design and implementation of an open source software NetFlow probe designed for handling Gigabit traffic. As nProbe uses little CPU and memory, it has been successfully used to monitor high-speed networks at full wire speed without packet sampling in scenarios where commercial NetFlow probes could not be used due to their limitations. Finally, the paper shows how nProbe has been successfully integrated into an embedded computer named nBox.

[1]  Luca Deri,et al.  Monitoring networks using ntop , 2001, 2001 IEEE/IFIP International Symposium on Integrated Network Management Proceedings. Integrated Network Management VII. Integrated Management Strategies for the New Millennium (Cat. No.01EX470).

[2]  Marshall T. Rose,et al.  Management Information Base for network management of TCP/IP-based internets , 1990, RFC.