Blog

Your Cisco UDP Director Is End-of-Life. Here’s the Drop-In Replacement.

Plixer Replicator dashboard displayed on a laptop.

Cisco Secure Network Analytics UDP Director — the product that started life as the Lancope Flow Replicator and spent a decade as the Stealthwatch UDP Director — is end-of-sale and end-of-life. If you are running one, you are running unsupported software on a clock that ends October 31, 2028, with no engineering fixes since late 2024. Plixer Replicator imports your existing UDP Director configuration directly, so the migration is a configuration import and a destination change, not a rebuild.

This post covers what Cisco announced, what your options actually are, and how the import works.

Cisco UDP Director End-of-Life: The Dates That Matter

Cisco published the end-of-life bulletin for the Secure Network Analytics UDP Director Virtual Edition (EOL15053) on August 1, 2023. The milestones:

End of sale: October 31, 2023 — you can no longer buy it

  • End of software maintenance: October 30, 2024 — no more bug fixes or maintenance releases
  • End of service contract renewal: October 31, 2025 — you can no longer extend support
  • Last date of support: October 31, 2028 — the product is obsolet

The hardware went first. The UCS M5 appliances covering Flow Collector, Flow Sensor, UDP Director, Management Console, and Data Store went end-of-sale October 9, 2023, following the M4 generation in 2019. There is no M6-generation UDP Director appliance at all. Cisco’s July 2026 M6 bulletin lists Flow Collector, Flow Sensor, Manager, Data Nodes, and the Telemetry Broker node — UDP Director is simply absent.

Cisco’s designated replacement is Cisco Telemetry Broker.

Why Teams Are Looking for a UDP Director Alternative

Telemetry Broker is a capable product, but it is not the same product. UDP Director did one job: take UDP datagrams in, replicate them out to multiple destinations, preserve the original source IP so downstream collectors still believe the traffic came from the exporter. Telemetry Broker is a larger telemetry pipeline platform with filtering, protocol transformation, and cloud log ingestion, sold on a consumption subscription.

If your requirement is "fan out NetFlow and syslog to four collectors without reconfiguring three hundred routers," you are being asked to adopt a heavier platform and a new licensing model to keep doing the thing you were already doing.

The other friction point is the configuration itself. A mature UDP Director deployment represents years of accumulated rules — forwarding profiles, per-exporter policies, port mappings, destination groups. Nobody wants to transcribe that by hand into a new tool and then spend a month finding the three rules they fat-fingered.

What Plixer Replicator Is

Plixer Replicator is a purpose-built UDP replication tool. It receives UDP datagrams from exporting devices, duplicates them, rewrites the destination address, and forwards them to as many collectors as you need — while leaving the original source IP intact.

That last detail is the whole point. Your NetFlow collector, your SIEM, and your NDR platform all need to believe they are receiving data directly from the original router, switch, or firewall. If they need to reach back out to that device over SNMP for interface names or device context, they have to query the real exporter, not the replicator.

Replicator handles the UDP telemetry formats that actually show up in enterprise networks:

  • NetFlow (v5, v9)
  • IPFIX
  • sFlow
  • Syslog
  • SNMP trap

Replication is controlled through granular policies based on exporter, destination port, and configurable profiles, so you can send full fidelity to your flow collector while sending a filtered subset to the SIEM you pay for by ingest volume. Configuration happens in one place through the UI rather than device by device. Vitals reports and alarms cover UDP sources, destinations, and rates, so you find out when an exporter goes quiet instead of discovering it during an investigation three weeks later.

Because it operates on flow-level metadata rather than full packet payloads, it does not carry the cost and infrastructure load of a packet broker or TAP deployment.

The UDP Director Configuration Import

This is what makes Replicator a drop-in replacement rather than a migration project.

Replicator can ingest an existing Stealthwatch/Secure Network Analytics UDP Director configuration and translate its forwarding rules into Replicator profiles and policies. Your rule set comes across as a rule set — exporters, destinations, port mappings, and forwarding relationships preserved — instead of being retyped from a spreadsheet.

The practical result: the migration is a cutover, not a rebuild.

How the Cutover Works

  • Step 1: Stand Replicator up alongside the UDP Director. Nothing changes on your exporters yet. The existing appliance keeps running.
  • Step 2: Import the UDP Director configuration. Your profiles, policies, and destinations land in Replicator as working configuration.
  • Step 3: Review the imported rules. This is the step worth not skipping. Confirm the destination list is current — most long-lived deployments have at least one forwarding rule pointing at a collector that was decommissioned two years ago.
  • Step 4: Switch IPs. Disable networking or shut down the UDP Director. Configure the IP on your new Plixer Replicator. For high availability, this would be a matter of moving the VIP (Virtual IP) to the new Plixer Replicator setup.

Key Takeaways

  • Cisco UDP Director is end-of-sale, out of software maintenance since October 2024, and fully unsupported after October 31, 2028
  • Cisco’s replacement path is Telemetry Broker — a larger platform and a new licensing model for a job you are already doing
  • Plixer Replicator does the core UDP Director job: replicate NetFlow, IPFIX, sFlow, syslog, and SNMP traps to multiple collectors with source IP preservation
  • The UDP Director configuration import means your existing forwarding rules carry over rather than being rebuilt by hand
  • Exporters only need a destination IP change — no device-by-device reconfiguration

Next Steps

Understand the difference between replication and forwarding. If you are still mapping the terminology, start here: Flow Replicator vs. UDP Forwarder.

Review Replicator’s full capability set. Plixer Replicator product page.

See the configuration import against your actual rule set. The fastest way to scope this is to walk through your current UDP Director configuration with a sales engineer.

Book a Demo

FAQ: Replacing Cisco UDP Director

Is the Stealthwatch UDP Director the same thing as the Flow Replicator?

Yes. Lancope sold it as the FlowReplicator. Cisco acquired Lancope in 2015 and rebranded it as the Stealthwatch UDP Director, then Secure Network Analytics UDP Director. Cisco documentation still writes it as "Flow Replicator/UDP Director" in places. It is one product under three names.

When exactly does UDP Director support end?

The last date of support for the Virtual Edition is October 31, 2028. But software maintenance ended October 30, 2024, which means no new fixes for anything found after that date, and you have not been able to renew a service contract since October 31, 2025.

Do I have to move to Cisco Telemetry Broker?

No. Telemetry Broker is Cisco’s designated replacement part number, but the function — UDP replication with source IP preservation — is not Cisco-specific. If replication is what you need, a purpose-built replicator is a more direct fit than a telemetry pipeline platform.

Will I have to reconfigure my exporters?

Only the destination address. Your NetFlow, sFlow, and syslog export configuration on each device stays as it is; it just points at the Replicator instead of the UDP Director.

Does Replicator preserve the original source IP address?

Yes. Downstream collectors and SIEMs see the traffic as coming from the original exporter, so SNMP enrichment and device identification continue to work normally.

Can Replicator handle more than NetFlow?

Yes — NetFlow, IPFIX, sFlow, syslog, and SNMP traps. Anything unidirectional over UDP.

What if I am also replacing Stealthwatch itself?

Many teams evaluating a UDP Director replacement are looking at the whole Secure Network Analytics stack. Plixer Scrutinizer covers the flow collection and analysis side, and the two are designed to work together.

Paul Piccard headshot photo for website.

Paul Piccard

CTO & SVP of Engineering at Plixer

Paul Piccard is CTO & SVP of Engineering at Plixer, where he leads product strategy and development for network visibility and security. With over two decades of experience in network security and infrastructure, Paul has extensive experience working with enterprise organizations to improve how teams detect, investigate, and respond to network events.