Best of the Best – NetFlow Blogs

Posted in NetFlow, NetFlow Analyzer, Scrutinizer on December 11th, 2009 by nathanh
best-of-the-best-netflow-blogs

Since the launch of our Systrax community website, we have written over three hundred blogs and generated two unique cases of Carpal Tunnel to bring you informative and sometimes quasi entertaining content.

I think its time though to lasso in some of the highlights over the year into one summary blog for quick and easy reference. This blog will link to others that have answered some of the more commonly asked questions. We hope you enjoy it.

Read more »

Tags: , , , , , , , , , , ,

Riverbed supports NetFlow v9 with Egress

Posted in NetFlow on October 24th, 2009 by mike@plixer.com
riverbed-supports-netflow-v9-with-egress

I saw some good news the other day from Riverbed that NetFlow v9 will be supported albeit in “the upcoming release of version 6.0″. The exact date is not specified.

I decided to investigate this and communicated with a developer over at Riverbed. He explained that egress is supported with v9 enabled by default. Read more »

Michael Patterson
Scrutinizer Product Manager
Follow Me on Twitter
Tags: , , , , , , , , ,

Identify more than just the ingress and egress packet throughput on your ASA Firewall

Posted in ASA, NetFlow, Scrutinizer on October 15th, 2009 by scottr
identify-more-than-just-the-ingress-and-egress-packet-throughput-on-your-asa-firewall

NSEL (NetFlow Security Event Logging) is the type of NetFlow exported from an ASA Firewall. The purpose of NSEL is to track firewall events via NetFlow and to have a summary of all conversations associated with that event type.

The three most popular event types that trigger a NetFlow record are:

                                            * flow-create
                                            * flow-denied
                                            * flow-teardown

Read more »

Tags: , , , , , , , , , , , , , ,

ToS, DSCP and NetFlow…. what the DiffServ? Part 4

Posted in NetFlow on August 18th, 2009 by mike@plixer.com
tos-dscp-and-netflow-what-the-diffserv-part-4

This is part 4 of an 4-part series (so far 4 parts) on the ToS field (i.e. Differentiated Services Field) of IP frames. I finally get into how all this relates to NetFlow in 2009.  Make sure you have already read Part 1, Part 2 and Part 3 of this blog.

ToS and DSCP part 4
At the end of Part 3 of this blog series I digressed very briefly on how CBQoS can be used to modify DSCP values on packets which come into the router.  In other words, VoIP traffic that comes in on ports 4569 and 5060 could enter a router with one DSCP value 0×00 and leave with a completely different one e.g. 0xEF (i.e. 11101111).    Read more »

Michael Patterson
Scrutinizer Product Manager
Follow Me on Twitter
Tags: , , , , , , , , , , , , ,