Which is better for flow export pfSense or Switch?
im trying to implement some kind of traffic measurement. We are using pfSense (via kvm emulated guest, pci passthrough for nics) in a bridged mode (vlan wan to vlan servers and virtual bridge to lan on the host). Now my question: is it better to collect flows via the switch (single lacp uplink on the switch) or is it better to use our pfSense to export?
BTW: Switch is an HP ProCurve which can export sFlow's.
We only want to collect upstream traffic.
Technically speaking they should be equivalent. Especially if you're only interested in the upstream traffic.
The pfflowd package, IIRC, uses data from pf, so it's possible there could be more data on the wire than is reported by pfflowd, in which case the switch would be more accurate.