On CHOW: Easy Thanksgiving for beginners
BNET Business Network:
BNET
TechRepublic
ZDNet

August 17th, 2006

Can you do this?

Posted by Richard Stiennon @ 9:53 am

Categories: Secure Network Fabric, Security, Security Industry News

Tags:

 

The raging debate over NAC included one aspect that I want to dwell on. That is the perception held by some that NetFlow is a tool for countering denial of service attacks. Certainly, the original NetFlow vendors, Arbor and Mazu, got their starts by countering denial of service attacks and a large percentage of their revenue still comes from ISPs that use their tools to identify sources of attacks and block them at the edge.  But NetFlow is much too powerful a tool to be pigeon holed in the DoS defense category. Read my just published column at DarkReading: Getting to Know NetFlow.  

And look at this output from a NetFlow management console that Lancope provided me with.  Can you get this kind of image of your network?

 

 netflowsmall.jpg

 

Click here for full size image.   

It is not surprising that web traffic is the bulk of what this large corporation sees on their network. The RTSP, real time streaming protocol, is more revealing, it indicates that video and audio is making up a lot of the bandwidth utilization.  With a good NetFlow console you can drill in to find a lot of interesting detail.  I can’t imagine doing any capacity planning or even network debugging without the power of NetFlow.  Read my article for the internal security benefits that come from NetFlow

Richard Stiennon is an industry consultant. See his full profile and disclosure of his industry affiliations.

Talkback

Add your opinion

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
    advertisement
    Click Here

    Archives

    Favorite Links

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    Meet Doc

    • Here to help you with your Document Management Needs
    • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
    • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
    • Produced by
      ZDNet and