cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2332
Views
0
Helpful
3
Replies

Is Netflow secure if sent over the Internet?

robertdm1973
Level 1
Level 1

Hi-

How secure is Netflow if the stats are sent over the Internet? I have a Netflow collector in the HQ and wish to monitor the branch router. It supports version 5 only.

Thanks.

3 Replies 3

sirdudesly
Level 2
Level 2

I'm not sure how inheretly secure it is but I assume you would be using an ACL etc to restrict access

Thanks for the reply. I'm just wondering, since from "show ip cache flow", all the info are in plain text.

Is the router sending the Netflow stats as is? Or there are some encryption taking place before sending, which the collector will then decrypt?

Some will say site-to-site VPN is the answer but we can't use it to this particular branch only.

Thanks.

Hello,

netflow is not secured. Anybody on the line can read all information that is exported in netflow. The only one solution is use a secured (IPSEC, VPN tunnel) line.

Jan

PS.: I don't know if it is security problem, but in netflow there is not any information about data part of packets, only who communicate with who.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: