What is Cisco NBAR

Posted in NetFlow on November 28th, 2009 by mike@plixer.com
What is Cisco NBAR

With the barrage of applications today sharing similar behavior characteristics at the protocol level, it becomes necessary to take deep packet inspection steps to determine what the actual application is that is causing the traffic.  Thankfully, Cisco already does this for us with something called Network-Based Application Recognition (NBAR) .   We explained NBAR support in a recent blog and how it allows us to improve on network traffic analysis.

Once you enable NBAR exports with NetFlow you will notice that since it supports Flexible NetFlow, a few different templates get kicked out.

One of the templates seen below kicks out all of the applications NBAR is performing deep packet inspection for:

nbarApps

 

 

 

Notice above that the pagination is showing only the first 25 of 24 pages!  Another template kicked out by NBAR NetFlow is the actual flows with the new “NBAR Application”  field.  These are the flows that we use for our reporting as shown below:

nbarReport

Cisco allows us to define NBAR Applications using Packet Description Language Modules (PDLM).  They are built to match on unclassified traffic or traffic that is not specifically supported as a match protocol statement. Building PDLMs requires more than basic knowledge of Cisco IOS. If you are an ambitious person, you can build your own then set thresholds in Scrutinizer Flow Analytics for your defined NBAR application.

If you need help with NBAR or NetFlow, contact us.

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , , ,

3 Responses to “What is Cisco NBAR”

  1. NetFlow Analysis and the Top Ten IOS Services You Should Be Using Now! - NetFlow & sFlow Network Monitoring - Systrax Says:

    [...] NetFlow and sFlow Analysis tool led the way in providing NBAR support in its network traffic analysis reporting. Mike Patterson recently talked about the [...]

  2. SIEM NetFlow Support: Don't Sell Yourself Short - Systrax - NetFlow & sFlow Network Monitoring - Systrax Says:

    [...] just the last two years we’ve seen such NetFlow innovations as MediaNet, NBAR, PaloAlto’s application-aware flows, and Cisco’s ASA NAT tables all make their way [...]

  3. NetFlow vs. sFlow for Network Monitoring and Security: The Final Say - NetFlowKnights.com - NetFlow & sFlow Network Monitoring - NetFlowKnights.com Says:

    [...] one, they have really put a lot of effort into NetFlow over the last few years. Flexible NetFlow, NBAR, MediaNet, ASA NAT export, PfR, the list of extended fields goes on and [...]

Leave a Reply

*