in More Search Options

Netflow Proxy/Probe

Last post 08-13-2008 10:41 by Network_Guru. 7 replies.
Page 1 of 1 (8 items)
Sort Posts:
  • 08-11-2008 4:11 PM

    • tkelly
    • Top 500 Contributor
    • Joined on 05-21-2008
    • Oklahoma City
    • Posts 18
    • Points 36

    Netflow Proxy/Probe

    I have a question that has problem been answered and more importantly the answer is probably right in front of my face.  Our initial interests in using Netflow was to monitor internal/WAN traffic.  However, the need has arisen that we are wanting to monitor the traffic going into/out of our DMZ from our Internet connection.  Because of security restrictions we are not allowed to send netflows directly from our public facing DMZ into our internal netflow collector.  What options does the Orion package offer to allow me to put something like a netflow proxy or probe in a zone of our DMZ that the public facing side would send to and then that proxy would send the netflow into our internal collector?  I know there are packages out there that can do it but I'm hoping I can do it with our current setup.  We have Orion NPM with NTA.  Thank you in advance.

    • Post Points: 3
  • 08-11-2008 5:20 PM In reply to

    • mcbridea
    • Top 25 Contributor
    • Joined on 03-24-2008
    • Austin, TX
    • Posts 282
    • Points 636
    • Moderator
      SolarWinds Employee

    Re: Netflow Proxy/Probe

    Hi tkelly,

    We have a NetFlow remote receiver for just this case. Sales can give you all the info.

     Andy

    Andy McBride
    Product Manager
    SolarWinds
    • Post Points: 5
  • 08-12-2008 7:57 In reply to

    • tkelly
    • Top 500 Contributor
    • Joined on 05-21-2008
    • Oklahoma City
    • Posts 18
    • Points 36

    Re: Netflow Proxy/Probe

    Thank you.  I'll contact sales.

    • Post Points: 1
  • 08-12-2008 12:26 PM In reply to

    • tkelly
    • Top 500 Contributor
    • Joined on 05-21-2008
    • Oklahoma City
    • Posts 18
    • Points 36

    Re: Netflow Proxy/Probe

    OK, so I spoke with sales and they told me they don't have a "Netflow Remote Receiver" and that the only way to get what I need using our current setup would be to purchase a small license for NPM and NTA.  I really don't see this as being a viable response to this scenario.  So having said that, I'd be interested to see how other people are doing this.

    • Post Points: 1
  • 08-13-2008 7:01 In reply to

    • bbusbey
    • Top 75 Contributor
    • Joined on 06-13-2007
    • Posts 84
    • Points 240

    Re: Netflow Proxy/Probe

    Andy,

     

    We need a receiver for the DMZ as well, is there a product to to this without buying a new car again?

    BBusbey
    EPCO, Inc.
    ⌐ Orion SLX 8.5.1SP3
    ⌐ Hot Standby
    ⌐ Application Monitor
    ⌐ NetFlow 3 SP4
    ⌐ VOIP
    • Post Points: 3
  • 08-13-2008 9:32 In reply to

    • mcbridea
    • Top 25 Contributor
    • Joined on 03-24-2008
    • Austin, TX
    • Posts 282
    • Points 636
    • Moderator
      SolarWinds Employee

    Re: Netflow Proxy/Probe

    The extra NPM/NTA works as a remote reciever. That's how it is done.

    Andy McBride
    Product Manager
    SolarWinds
    • Post Points: 5
  • 08-13-2008 9:54 In reply to

    • tkelly
    • Top 500 Contributor
    • Joined on 05-21-2008
    • Oklahoma City
    • Posts 18
    • Points 36

    Re: Netflow Proxy/Probe

    That's exactly what sales told me.  I just found it hard to believe that someone who designed a product like this didn't have some sort of remote probe or collector that could be provided.  Especially since all it's needing to be is a Netflow forwarder and really doesn't have to do a whole heck of a lot more.  I can't justify the expense of several thousand dollars for something like that.  I doubt I could justify much of any expense just for something like that. 

    • Post Points: 1
  • 08-13-2008 10:41 In reply to

    Re: Netflow Proxy/Probe

    There are a couple of ways to do this securely.

    Method one:
    Use a /30 private IP address as the loopback on your DMZ/Internet router.
    Add the /30 private IP subnet as a secondary interface on the FW interface which has your Netflow router in it.
    Setup the Netflow source as the new private loopback IP to send flows to to the private IP interface on the FW.
    Setup a NAT rule on the FW to NAT this private IP to your Netflow server IP.
    Create a FW rule which only allows the single UDP port from the private loopback IP of the router to the Netflow server.
    (you could do PAT as well, if you subscribe to the security by obscurity methodology).

    Method two:

    Use 802.1Q trunking between your router and FW to isolate the netflow traffic in it's own Vlan.
    This keeps the Netflow traffic out of band between the router and FW.
    Using Cisco's Private VLAN technology will add additional security to this design.


    -=Cheers=-
    NG

    ---Orion V8.1 SLX, SLX secondary poller, SQL2005 x64 SE, 14GB Ram, 12k+ elements and counting--
    --Orion V9 Sp1 SL2000, SQL2005 Express 866 elements and counting---
    • Post Points: 1
Page 1 of 1 (8 items)