Hi all. I just want to confirm a theory here. I'm looking at NTA and seeing that switching my Top XX Applications between Netflow and NBAR2 shows vastly different data in terms of numbers, i.e., the total amount of data in GB that's passed through an interface.
Am I correct in assuming that NBAR2 will not identify as much traffic as Netflow, so that's why I'll see TB of data under Netflow while only GB of data under NBAR2?
If that's the case, where does the traffic that NBAR can't identify go?
Is it that all the traffic is sent to NTA, but only the traffic that could be ID'd by NBAR2 protocol packs show up in the NBAR2 graph?
I would've expected that the "unknown" category under NBAR2 would hold all the unidentifiable traffic so the total numbers for each graph would match.
OR, is it just that NBAR2 can only ID traffic at L7?
Please help me understand this, thank you.