IMC/NTA: sflow based security analysis? (383 Views)
Trusted Contributor
Posts: 239
Registered: ‎06-08-2011
Message 1 of 3 (383 Views)

IMC/NTA: sflow based security analysis?

[ Edited ]



I´m testing sflow collectors with basic security analysis features.I´m asking myself whether those mske sense, i.e. with sflow rates of 1/1000, will this actually work correctly?

If it does it would  be great if I could activate this also on all edge ports. So 27000 ports.

1. Will all HP stackable A-series switches be able to do this?

2. What kind of monster server will I need for sflow analysis?


Having IMC already, so let´s talk about NTA. I haven´t found anything about security analysis with that. I´m asking myself whether those are on roadmap?



Trusted Contributor
Posts: 286
Registered: ‎07-11-2003
Message 2 of 3 (334 Views)

Re: IMC/NTA: sflow based security analysis?

You will probably want to check on the licensing too. Part of the NTA licence is that NTA is licenced per active device - with 27000 ports, it seems like you would have over 500 switches (devices)...


IMC is scalable, so you probably need lots of servers, rather than a single monster one.

Honored Contributor
Posts: 344
Registered: ‎03-21-2011
Message 3 of 3 (253 Views)

Re: IMC/NTA: sflow based security analysis?



I heard about another IMC module UBA (User behavior analysis) which is supposed to analyze the sflow flows for security behaviors. But have no experience with it myself.


NTA can be installed on a dedicated server for performance reasons, the admin guide contains some hardware guidelines I believe,



The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the Terms of Use and Rules of Participation.