Whether you could actually monitor 600 NetFlow sensors depends on the amoount of flows received. Would this entail one NetFlow stream that would split the data into 600 entries by filters or would you actually want to monitor 600 routes, each with one stream? In the latter case you would need to test if this would be able to achieve, seeing as flow sensors do use up a large amount of resources. Accordingly, it would require a very powerful machine.
If the 600 sensors were to be too much for a single node, you would have to distribute the load over multiple remote probes. However, the only way to be certain if this is possible would be to try directly on the actual system / network.
What would not be possible, however, is to monitor this type of environment via virtual machines. In such scenarios it is almost imperative that physicaly servers are used.
Add comment