NETFLOW COLLECTION

Enabling NetFlow and directing it to a NetFlow collector for collection can be easily accomplished by using three simple commands.

ip flow ingress

ip route-cache flow

ip flow-export destination <collector ip address><collector port>

NetFlow provides network and security benefits beyond that provided by traditional security controls through two additional layers of intelligence: visibility into host-based conversations and traffic pattern analysis. NetFlow-enabled routers generate NetFlow records, export them to a NetFlow collector once the flow has finished and then purge the data from their memory NetFlow cache.  These NetFlow records are exported in UDP or SCTP packets in different formats.

Lancope offers StealthWatch XE for NetFlow, a NetFlow collector which collects data that leverages NetFlow traffic information from Cisco, Juniper and other leading network infrastructure vendors to provide cost-effective, behavior-based network protection for distributed enterprise environments.

StealthWatch XE for NetFlow Features:

  • Leverages existing investment in NetFlow technology

  • Stops threats that are visible only at the enterprise level

  • Provides real-time traffic analysis for billing, bandwidth accounting and network performance troubleshooting

  • Proves ideal for distributed WAN environments
To learn more about NetFlow collection in the enterprise, visit Lancope’s Download Center to read the White Paper: “Role of Network Behavior Analysis (NBA) and Response Systems in the Enterprise”.