In one of our sites we have the following network layout.
User VLANS ---------> MS ISA --------> 4500 Sup 6E Switch ----------> 5520 ASA (7.2) -------------> 2821 Router ----------> INTERNET
I want to use NETFLOW services to monitor top talkers on my LAN. Since sup 6E does not support netflow, my only choice is
to use the 2821 router. I have 3 Questions?
1) Is it a best practise to keep the Netflow collector Server (SW Orion) on the inside (Core Switch) or on a DMZ?
2) Since all users in their respective VLANS are forced through MS ISA, the only IP that is NATted is the MS ISA one connected to the PIX. Will NETFLOW show the internal users as top talkers or it will simply show the ISA server IP as the source for all traffic, thus making this setup useful for port and destination monitoring, not for source per user?
3) Any better ideas to monitor top talkers for such a setup?
All Help is appreciated,