<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Code Mule</title>
    <link>/</link>
    <description>Recent content on Code Mule</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 03 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Understanding IPFIX, IE 315 &amp; SPM: Complementary Telemetry for Modern Networks</title>
      <link>/posts/ipfix-ie315-spm/</link>
      <pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate>
      <guid>/posts/ipfix-ie315-spm/</guid>
      <description>&lt;h2 id=&#34;executive-summary&#34;&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;Modern networks require both depth and speed in visibility. Traditional &lt;strong&gt;IPFIX (NetFlow v10)&lt;/strong&gt; delivers rich flow context but with inherent latency. &lt;strong&gt;Sampled Port Mirroring (SPM)&lt;/strong&gt; provides near real-time packet samples with payload visibility. &lt;strong&gt;IPFIX IE 315&lt;/strong&gt; bridges the two by exporting sampled packet data inside standard IPFIX records.&lt;/p&gt;
&lt;p&gt;These technologies are &lt;strong&gt;not competitors&lt;/strong&gt; — they are powerful complements, especially in high-speed DDoS protection scenarios.&lt;/p&gt;
&lt;h2 id=&#34;what-is-ipfix&#34;&gt;What is IPFIX?&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;IPFIX&lt;/strong&gt; (IP Flow Information Export) is the standardized evolution of NetFlow. It collects metadata about network flows — conversations defined by the 5-tuple (source/destination IP, ports, protocol).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
