All detecting advanced persistent threats

Cisco Nexus 7000 NetFlow Sampling

With most devices that sample NetFlow, there is an export of the sample rate in the flow record or an option template. The collector...

How Accurate is Sampled NetFlow?

I have been working with a number of customers recently who are required to use sampled NetFlow because of vendor configuration rules. In just...

Detecting Rogue DHCP Servers

A rogue DHCP server on a network is one that is not under the administrative control of the network staff. It can be a...

Sampled NetFlow Accuracy

Sampled NetFlow accuracy is often a concern when network administrators find that sampling is their only NetFlow network traffic monitoring option. High volume flow...

Fortinet IPFIX Support

Did you know there is Fortinet IPFIX support on their FortiSwitch-1000 switch?  The other day I was working with a customer who mentioned configuring...

Astaro IPFIX Reporting: Astaro NetFlow Support

Apparently some of our customers are calling in asking for Astaro IPFIX Reporting support.  It’s always fun to work with a new flow vendor...