Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Is Netflow secure if sent over the Internet?

Hi-

How secure is Netflow if the stats are sent over the Internet? I have a Netflow collector in the HQ and wish to monitor the branch router. It supports version 5 only.

Thanks.

3 REPLIES
New Member

Re: Is Netflow secure if sent over the Internet?

I'm not sure how inheretly secure it is but I assume you would be using an ACL etc to restrict access

New Member

Re: Is Netflow secure if sent over the Internet?

Thanks for the reply. I'm just wondering, since from "show ip cache flow", all the info are in plain text.

Is the router sending the Netflow stats as is? Or there are some encryption taking place before sending, which the collector will then decrypt?

Some will say site-to-site VPN is the answer but we can't use it to this particular branch only.

Thanks.

Bronze

Re: Is Netflow secure if sent over the Internet?

Hello,

netflow is not secured. Anybody on the line can read all information that is exported in netflow. The only one solution is use a secured (IPSEC, VPN tunnel) line.

Jan

PS.: I don't know if it is security problem, but in netflow there is not any information about data part of packets, only who communicate with who.

449
Views
0
Helpful
3
Replies