Implementing RFC 5610 and IPFIX Collectors

Posted in IPFIX on April 2nd, 2013 by mike@plixer.com
Implementing RFC 5610 and IPFIX Collectors

More and more flow exporting vendors are making the move to IPFIX and at Plixer, we feel that implementing RFC 5610 should be part of the decision.  The reason for this is because IPFIX is capable of exporting everything in NetFlow v5 as well as additional fields such as top multicast addresses, IPv6 addresses, packet lengths, MPLS labels, VLANs, MAC addresses and several other details and performance metrics that the vendor can decide on and even make up. Without RFC 5610, the IPFIX collector doesn’t know how to decipher these sometimes proprietary elements.

Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , ,

Syslogd

Posted in IPFIX, IPFIX Traffic Analysis, NetFlow on March 27th, 2013 by Danny
Syslogd

Syslogd is often used to turn machine messages or syslogs into events for further processing. Ultimately, alarms are generated which can trigger some type of notification.  The problem with the messages created by syslogd, is their nonstandard and loosely structured data format.  This post is about the end of Syslog and the evolution of IPFIX due largely to the fact that the data exported in IPFIX is highly structured.

Read more »

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , ,

Avaya WLAN 8100 Wireless Controller IPFIX Support

Posted in IPFIX on March 6th, 2013 by Ellen
Avaya WLAN 8100 Wireless Controller IPFIX Support

I just finished watching a video by Swasti Verma on the Avaya WLAN 8100 wireless controller IPFIX support and as a result I thought a blog on the Avaya 8100 IPFIX configuration was in order.  The configuration is pretty short, feel free to copy the commands below, edit them and paste them into your console.
Read more »

Ellen

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , ,

Solera IPFIX Support: Network Security Appliance Exports Flows

Posted in IPFIX, network security, syslog ot IPFIX on January 6th, 2013 by tomp@plixer.com
Solera IPFIX Support: Network Security Appliance Exports Flows

Good news: Solera IPFIX support is available in our IPFIX reporting solution.  This is no surprise as Flow Analysis (NetFlow and IPFIX) continue to gain popularity in several key areas of many IT security programs:

  • Data reconnaissance on the source or perpetrator of the threat (i.e. who did what to whom, when and where)
  • Merge with other data sources to gain greater contextual information surrounding the details of the malware
  • Host Reputation look ups

For those of you who need to get this setup fast, here are the instructions that we got from the documentation.
Read more »

- Thomas Pore

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , ,

Exporting NetFlow or IPFIX

Posted in cisco ASA, Cisco NetFlow, IPFIX on December 30th, 2012 by mike@plixer.com
Exporting NetFlow or IPFIX

Is your engineering team trying to decide if you should be exporting NetFlow or IPFIX? This is the area of the technology where many first time vendors make mistakes. Implementing NetFlow or IPFIX is not difficult. But when programmers rely solely on RFCs as an implementation resource, the result is usually an export that many flow reporting vendors won’t support.  For this reason, this blog is largely dedicated to engineers who either want to export these technologies correctly or who need to troubleshoot what is wrong with an export they have been asked to look at.

Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , ,

How to configure VMware vSphere ESX v5.1 IPFIX Support

Posted in IPFIX, Network Monitoring, Virtual NetFlow, VMware NetFlow on December 26th, 2012 by Jimmy W
How to configure VMware vSphere ESX v5.1 IPFIX Support

Now that VMware vSphere ESX v5.1 supports IPFIX you may be wondering how to configure it; in fact, today I’m going to show you just that in a couple easy steps. VMware IPFIX support is a very exciting feature that will help with performance monitoring and can make virtual network management a lot easier to accomplish. Monitoring virtual servers has never been easier! Read more »

Jimmy Wendler

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , ,

Top 13 Network Security Features

Posted in Cisco Performance Monitoring, Flexible NetFlow, IPFIX, NetFlow Security, Network traffic monitoring on December 5th, 2012 by Danny
Top 13 Network Security Features

Our Network security solution is a leader in cutting edge NetFlow collection innovation; here are top 13 features you should know about:

Performance Monitoring

  1. Chosen by Cisco to support their most innovative Flexible NetFlow technologies.  The “Medianet 2.2 Deployment Guide”   can be found on page 7,8,10 & 11.  We were the first to support Cisco Performance Monitoring (PfR) FnF exports which help secure that business related traffic receives priority. Read more »

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , ,

NetFlow Generators: Enabling NetFlow Without NetFlow Support (Part #1)

Posted in application aware netflow, Cisco NetFlow, IPFIX, netflow probe, network security, network threat detection on November 27th, 2012 by Adam Powers
NetFlow Generators: Enabling NetFlow Without NetFlow Support (Part #1)

Introducing NetFlow and IPFIX

This article covers the benefits and capabilities provided by a new class of network monitoring technology called a NetFlow generator. But before we get too far into NetFlow generation details, let’s do a quick review of NetFlow itself for those that are new to the topic.

NetFlow and IPFIX are network monitoring technologies providing deep visibility into network traffic. NetFlow was originally developed by Cisco and later standardized into IPFIX by RFC 5101. Traditionally, NetFlow was included as a feature of routers, switches, firewalls, and other network devices. It’s even found in virtualization platforms such as VMWare’s vSphere 5.0 and above. Any device that can generate NetFlow packets is called an exporter. As packets travel through the exporter the device records information about the flow of traffic. Data elements such as packet count, source and destination IP, MAC address, and much more are stored in a memory resident data structure within the exporter called a cache. As the flows time out they are placed into a UDP datagram and sent across the network to a NetFlow Collector. The diagram below illustrates the process.

How NetFlow works

Once enabled NetFlow is used for a variety of network operations and security tasks including:

Read more »

Adam Powers
@adampowers22

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Cisco ASA 8.4(5) NetFlow Support

Posted in cisco ASA, IPFIX, NAT Reporting on November 22nd, 2012 by mike@plixer.com
Cisco ASA 8.4(5) NetFlow Support

Have you upgraded your Cisco ASA to version 8.4(5) for the latest and greatest security features and NetFlow (NSEL) enhancements from Cisco Systems? Well, if you have, you may have noticed that the NetFlow reporting broke.  Have no fear, we fixed this issue in Scrutinizer version 10.1 which is being released in a couple of days.  But, WAIT! There’s more!

Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , ,

EM7 NetFlow Support: 3 Key Features

Posted in IPFIX, Jitter, NetFlow Analyzer, Network traffic monitoring, Packet Loss on November 4th, 2012 by Ryan
EM7 NetFlow Support: 3 Key Features

Many Network Management Solutions on the market lack support for sFlow, NetFlow and IPFIX reporting and threat detection.  If you are looking for EM7 NetFlow support, our NetFlow solution easily integrates with EM7 from ScienceLogic and we do it in 3 ways to provide the best network traffic monitoring solution.
Read more »

Ryan

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , ,