NETFLOW
U
SER
G
UIDE
293
NETFLOW
F
EATURES
The NetFlow service is used for the passive monitoring of the network flows. It has the task to:
Filter packets to associate them with specific flows
Create flow records
Prepare and export NetFlow packets
The main features are relative to the association of each packet to a flow, so that the evaluation will
be done on the entire flow and not on the single packet.
A NetFlow flow can be characterized by the following elements:
IP source address
IP address of the destination
source port
destination port
protocol
ToS
interface logic input
NB
: It does not perform packet inspection and is not a technology IDS / IPS
Target
Some network anomalies are detectable by processing the data provided by Fprobe.
search results for "pattern"
a host that many in a short contact time (P2P, worms)
lows of long duration (VPN, covert channels)
use of unauthorized ports
abnormal bandwidth usage (DoS warez)
unauthorized communications
Architecture
Actions to be taken to implement an infrastructure based on NetFlow monitoring:
decide which interfaces to enable the control
decide what you want to achieve from NetFlow
setup of one or more collector
C
ONFIGURATION
To use the probe Fprobe on Imola is necessary to activate the service. The verification of the
activation can be done by typing the following command:
show system