Hi,

Does anybody know anything about configuring netflow/sflow/? on HP Procurve switches?

I've got a piece of software (statseeker) that can recieve the flows, what i want to pick up is all the traffic to/from our firewall.

Our ISP (JANET) has been in touch, and provided flow information that we have some malware trying to communicate externally, and i've been arguing with the firewall logs for an hour trying to find it. If i had the flow information i could identify the internal source IP very quickly and isolate it from the network.

Ta

Skr