This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Netflow Collector Behind NAT

We are trying to get the Netflow traffic analyzer setup.  The Netflow collector is on a NATed network.  We have several inter-office users on the same LAN as this collector.  Whenever we start the Solar Winds Netflow service, all local users are unable to accomplish any web browsing.  They are able to access cached pages, but nothing else. The moment we stop the service, things return to normal.

 Any ideas?
 

  • Can you explain your topology in more detail?  Specifically, where are the NetFlow Router(s), SQL database, DNS server(s), etc. in relation to your NAT?  A diagram would be most helpful.

     At first glance, I can't see how starting & stopping the NetFlow collector could possibly have any impact on other hosts' connectivity.  The only things that the NetFlow collector are doing on the network are:

    1. Receiving NetFlow packets.  These packets are already being sent, though, so starting the service would, in some cases, actually be lowering the total traffic across the network because there wouldn't be ICMP port unreachable messages.
    2. Doing DNS requests.
    3. Communicating with the SQL database.
    None of these should be affecting other hosts' connectivity.
  •  What other apps or services are running on the netflow collector server?

  • Here is the diagram of our network.  We are not running any other applications on the netflow collector. 

  • Does the utilization of any of the interfaces on 192.168.99.1 get out-of-control when you start the service?  Is the DNS server getting overwhelmed when you start the service? The first thing that jumps out at me when looking at that diagram is perhaps the collector is doing DNS requests across that wireless P2P link and using that same DNS server as the user network.