We're having a running discussion [argument?] on which devices should be configured as Netflow sources. I've just started at a new job and my first assigned task is rebuilding the existing SW box [NPM, NTA, APM, IPAM, NCM]. The existing set up has all 16 IDF switches [Cisco 65xx] configured as sources [ingress only] along with the two core switches and two server farm switches, also ingress only and only on the vlans, not ports.
I contend that as all traffic passes through the two core switches that's the only place we need to collect Netflow data from. My colleague contends that to examine traffic within a vlan that exists only on an IDF switch [but still talks through the core switches] we need to have the IDF switch as a collector.
Something that's confusing both of us is the ingress/egress part. The NTA admin guide doesn't do enough explaining to shed light on this whole design discussion [argument?]. The forum posts, especially ones with "best practice" in their subject lines, don't come near to addressing/defining these terms much less the concepts of collector placement.
Can I get guidance on where to focus? Pls/Thnx...