FastNetMon Advanced: navigating all available telemetry protocols for different vendors

Home FastNetMon Advanced Technical Documentation FastNetMon Advanced: navigating all available telemetry protocols for different vendors
Contents

FastNetMon Advanced has comprehensive support for variety of telemetry protocols and it may not be easy to find out protocol which is the best in your particular case

You can find full table with all vendors and telemetry protocols supported by FastNetMon, recommended protocols highlighted by star:

Port MirrorNetfow v9IPFIXIPFIX 315sFlow v5Vendor specific
Juniper MXYesYesYesYesYes, has issues
Juniper PTXYesYesYesYesYes
Juniper EX, QFXYesNoNoNoYes
Nokia SRYesYesYesYesYes ⭐SHIM
Cisco ASR 1000NoYesYesNoNo
Cisco ASR 9000YesYesYesYesYes
Cisco NCSYesYesYesYesYes
Cisco NexusYesNoNoNoYes
AristaYesYesYesNoYes
HuaweiYesYesYesNoYes
ExtremeYesNoNoNoYes
MikrotikNoYesYesNoNo
OcNOSYesNoNoNoYes
VyOSNoNo, buggyNo, buggyNoYes
Netgate TNSRNoNoYesNoNo
A-10 NetworksNoYesYesNoNo
Amazon AWSNoNoNoNoNoVPC Flow Logs
Google CloudNoNoNoNoNoVPC Flow Logs

According to this page we can make conslusions:

  • If your support supports IPFIX 315 (also known as ie315 and inline monitoring services) then it's the best protocol for DDoS detection
  • If your platform supports sFlow then it's second best protocol for DDoS detection

Port mirror is fully supported by FastNetMon but we recommend it only in cases when no other options are available due to complexity of operations