![]() |
||||
| -Edit Basic Profile | -Inbox | -Blog |





(2 votes)
ars@chrisforesman.com (Chris Foresman)
Clean Edge News
We were using the S-Flow MIB to mirror the incoming packets which theoretically did not slow the network down other than for the samples being sent to the security engine. Other technologies like C-Flow won’t permit monitoring of each port. I suspect VMware is counting on using the resident CPU’s to do the deep packet inspection. I’d like to hear from them
The idea of using a VMware virtual machine environment is to get 60% to 80% or even 90% utilization out of each CPU and then create an additional virtual machine on the next CPU. How can you do this if you are probably using over half of your CPU cycles for security?
Saying you are going to inspect every packet in layers 1-4 and the application layer is akin to getting a freighter full of coffee beans and inspecting each bean at the port.
We have learned that statistical analysis will do an adequate job. Is it five nines? Probably not, but it still works by checking each layer perhaps five percent of the time.