You may use sampled port mirroring for fast attack detection. It works pretty well for very short burst attacks. Em sáb., 1 de ago. de 2026, 08:05, Vincent Bernat via NANOG < nanog@lists.nanog.org> escreveu:
On 2026-08-01 10:06, Saku Ytti wrote:
IPFIX. But sampling rate is making things tricky, as very short term attacks are a thing.
IPFIX IE 315 fixes this. It also makes it easier to grab any field from
How does IE 315 fix sampling issues? You can use 1:1 with or without IE 315? Only thing IE 315 allows you to send sflow style raw frames?
My issue with 1:1 isn't that my platform doesn't support it, it's that it increases backend costs in a way that I cannot justify.
I was focused on the very short attacks. The issue is not sampling, but the flow cache adding some latency, even when tuned down. That's the part IE 315 fixes: there is no cache anymore and the sampled packets are sent directly. _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/TALTTNNV...