惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Improve Your Microsoft ExpressRoute Resilience with Megaport Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024 Top 5 Cloud and Networking Announcements From Cisco Live 2024
Maximizing Peering Through Flow Analysis
2025-07-23 · via Megaport Blog

By Rob Parker, Interconnection Director

Discover how to use flow data to pinpoint your most valuable traffic, identify missing peer opportunities, and make smarter peering choices across your internet exchanges.

In previous peering blogs, we’ve shared how you can maximize the value of your connection to an IX by peering with the IX route servers, and identify and contact specific peers via bilateral sessions. But as traffic over your new IX connection grows, you may want to start digging a little deeper on which peers are involved in your most important traffic flows – or which ones are present at the IX, but aren’t exchanging traffic with you via the IX.

In order to start identifying traffic like this, you’ll need to explore tools and network configurations that allow you to analyze traffic flows.

Flow data exporters: Netflow, jFlow, sFlow, IPFIX

The first step of any flow analysis tool is to configure the collection of flow data. Available flow data formats and standards depend on your routing hardware vendor, although Netflow (Cisco), jFlow (Juniper), and sFlow (a relatively open “generic” flow format) are all relatively similar in structure and capability.

IPFIX is a similar IETF-defined standard that allows some level of vendor interoperability. Any and all of these standards operate in a similar way and will give you similar insight into your traffic; which one you choose will mostly depend on your hardware vendor and use case.

How flow data exporters work

At a high level, flow data is collected by your hardware on a sampled basis – typically one in every two thousand packets would be inspected and a flow record created. This provides a relatively representative view of traffic sources, destinations, and protocols, along with a few other pieces of data that might be useful for network monitoring (packet size distribution, Ethertype, etc.). Those samples are then batched and exported to a collector.

Flow export should be enabled on all “edge” interfaces on your network. If you want a complete view, this data should be enabled for internet exchanges, upstream transit providers, private network interconnects, and the like. Enabling on only some devices will only give you a view of traffic traversing those devices.

There are many situations where enabling flow export on other interfaces within your network will also make sense, so this isn’t an extensive blog.

Flow collectors

Once collected, the batched flow data is then sent by your network hardware to a flow collector. A flow collector is a piece of software running on a server—ideally located within your own network and close to flow-data-exporting hardware—which aggregates and analyzes the contents of the flow records exported to it.

Flow collectors come in both open-source and proprietary systems – some examples of flow collectors are pmacct, Cflowd, and Akvorado. Vendors often have their own tools, too. There are also third parties who will collect and analyze the data for you in an “as a service” fashion, such as Kentik.

Flow visualization and enrichment

The best flow analysis tools (such as Akvorado and Kentik) will enrich the collected data and visually present it to allow you to see what’s actually happening within traffic flows through your network.

This allows you to easily take a look at top talkers on each interface – for example, you could identify the top ten sources and destinations for traffic to and from your upstream transit providers, then try to find those top ten networks at a local internet exchange in order to peer. This process improves the experience for your end users, and reduces both your transit use and costs.

Similarly, you can review top talkers across your internet exchange connections and make sure they’re the networks you expect. Ensure that you see traffic to/from bigger CDNs or ISPs; if not, this is a good sign you may need to reach out to those networks for bilateral sessions because they’re often not present on route servers (as we’ve previously discussed).

Once you’ve optimized the top ten talkers, you can start on the next ten, and so on. There will always be the so-called “long tail” of source/destination networks where optimizing will not make sense, because flows are smaller and/or less valuable – this is normal.

The aim is simply to optimize the biggest or most valuable traffic flows in your network for performance and cost, while keeping an eye on up-and-coming networks that make their way up your “top talkers to optimize” list.

Third-party flow analysis

You’ll find that some networks or internet exchanges you connect with may offer you a way to see flow data from “their side” of the connection. This highly valuable data allows you to directly gain insight into traffic without building a flow collection and analysis platform, or exporting your own flows.

Megaport offers third-party flow analysis at all MegaIX locations. You can find this feature in the Megaport Portal under the “Tools” menu for each of your MegaIX connections, or via the graph icon “IX Telemetry” against an IX service. It looks like this in our portal:

MegaIX flow analysis
MegaIX flow analysis

This will present you with a view of in and out traffic, sorted by top five networks by default. Here’s an example taken from a real peer and anonymized for use here. (Normally, you’d see the name of the networks you’re exchanging with and not “PeerX”.)

Partner flow analysis
Partner flow analysis

Our MegaIX partners LINX and AMS-IX offer flow analysis via their portals as well.

Other platforms such as Kentik also exist; Kentik offers a turnkey, fully managed flow analysis platform and can also assist in configuring your network hardware correctly, too.

In summary, flow data can bring great insight into your traffic, allowing you to further optimize and get the absolute most out of each and every peering relationship and transit upstream.

Although the initial setup can be tricky, you can always leverage third-party flow analysis tools where offered—such as those built into the Megaport Portal—or work with a provider like Kentik to save time and effort.