All my remote sites have routers connected to the Internet. They connect to the corporate network over DMVPN. Do I want to put my IP flow statements on the tunnel, so I see the un-encrypted session data, or would I want it on the physical interfaces of the router. I would think the later would only show me an aggregate of everything coming through the tunnel. To get both ingress and egress info in NTA, do you need to apply both the ingress and egress commands to, for example Tunnel1?