I have a standard monitoring suite with graphs and port monitoring and all that jazz. My boss, however, wants to know what all this traffic is. He wants to see what sort of traffic is chewing up our bandwidth.
I've used the SDM and the pie chart is made up of mostly "unknown protocol".
Now, I'm sure I can turn up the logging, but I don't really want to peg the CPU of the router that badly.
Do you guys know of any deeper monitoring techniques than just the graphs and what not?
If you have a spare server running linux or freebsd you can stick inline on an ethernet segment, you can configure NTOP. I have used a transparent inline NTOP and SNORT setup to inspect a great deal of traffic over the years.