
Today there are just a network of abnormal situations occur,Please help as VPN vendors understand why after,Try to view it sFlow records,See if I can find out the results consistent with the manufacturer。The following is your view:
1. Open sFlowTrend,Click on "Network" under the "Top N",In the "Chart" select [Top connections],Units can be changed [Bits / s]

2. Click "funnel icon",In the "Filter" to filter IP input range,Here an example of two segments,
enter" (clientAddress >= “192.168.3.1” && clientAddress <= "192.168.3.254") || (clientAddress >= “192.168.20.1” && clientAddress <= "192.168.20.254")”
按下OK後,就可以在下方檢視兩個網段前五名的流量的IP及port情形。以下圖來說,主要是 pop3 收信流量佔了較大比例。

Tips.
Filter parameters can press the Edit on the right to see all the available parameters and usage。

Check out this conclusion,Consistent with the results of the investigation vendor,Feeling quite good,So the next time Chaxiu,A lot easier。
[Links]
- InMon: sFlowTrend