The need to detect and mitigate denial-of-service attacks is nothing new to network and security administrators. DoS attacks on enterprise networks have been occurring for years.
Read moreAuthor: Scott
How can I load balance my NetFlow traffic across multiple collectors?
Do you find that you are constantly modifying NetFlow configurations to balance collector workloads? The latest release of Scrutinizer introduces an option to load balance the collector workload across multiple, distributed-collector clusters by automatically modifying Plixer Replicator profiles based on the number of exporters and flow volume processed at each collector.
Read moreHow to detect suspicious ICMP traffic
A few years ago, we added a behavioral algorithm to Plixer Scrutinizer that looked at all the flow data that was collected and determined if there was possible ICMP tunneling taking place. That algorithm alarmed if it determined that packet sizes were abnormal for ICMP traffic from a Windows or Linux platform.
Read moreHow to avoid NetFlow sampling
As resource demands and bandwidth speeds in many of today’s network infrastructures continue to increase, many network administrators believe that NetFlow sampling is the only way to deal with the high flow volume sent across the network. In fact, setting a NetFlow sample rate of 1 in 100 can cut flow volumes as much as 50%.
Read moreTroubleshooting NetFlow over VPN tunnel
I was working with a customer last week who had configured NetFlow on four of their Cisco routers. They had applied basically the same configuration to each of the routers, but only saw exported flows from three of them arrive at the collector.
Read moreCan your network survive the coronavirus lockdown?
Lately, I have seen an increase in support calls regarding the increase in bandwidth consumption and the degradation of application performance seen when employees started working from home because of the coronavirus outbreak.
Read moreWhich NetFlow collection process is better: duplicated or deduplicated NetFlow?
Questions regarding deduplicated NetFlow often come up when beginning to research NetFlow solutions. This blog will address some of the reasons why deduplication might not be the best way to go.
Read moreIs there a way to track and locate a private host behind NAT routers?
A common question that has been coming up on product demonstrations over the last few weeks is, using NetFlow, is there a way to track and locate a private host IP address behind my NAT routers?
Read moreCisco Catalyst 9400 NetFlow configuration
I am seeing a lot more of the Cisco Catalyst 9400 switches at my customer sites these days. I have also had a number of requests for configuration help. I figured that I would take this opportunity to walk through the Cisco Catalyst 9400 NetFlow configuration, and provide a sample reference document for you.

There is not much new here on configuring NetFlow. If you are familiar with the 3850 NetFlow configuration, it is very much the same.
Read moreWatchGuard NetFlow Configuration
“Does my WatchGuard firewall support NetFlow?” Customers who have WatchGuard firewalls have asked me this question many times over the years.
The answer is YES! We can finally put WatchGuard on the list of firewalls that support flow technologies.