Is Netflow secure if sent over the Internet?

Unanswered Question
May 13th, 2008

Hi-

How secure is Netflow if the stats are sent over the Internet? I have a Netflow collector in the HQ and wish to monitor the branch router. It supports version 5 only.

Thanks.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
sirdudesly Tue, 05/13/2008 - 15:30

I'm not sure how inheretly secure it is but I assume you would be using an ACL etc to restrict access

robertdm1973 Tue, 05/13/2008 - 15:40

Thanks for the reply. I'm just wondering, since from "show ip cache flow", all the info are in plain text.

Is the router sending the Netflow stats as is? Or there are some encryption taking place before sending, which the collector will then decrypt?

Some will say site-to-site VPN is the answer but we can't use it to this particular branch only.

Thanks.

Jan Nejman Thu, 05/15/2008 - 03:03

Hello,

netflow is not secured. Anybody on the line can read all information that is exported in netflow. The only one solution is use a secured (IPSEC, VPN tunnel) line.

Jan

PS.: I don't know if it is security problem, but in netflow there is not any information about data part of packets, only who communicate with who.

Actions

This Discussion