Friday, April 26, 2024

Traffic Analysis Tools - Part 2

 Network Flow and Data Analyzer

NetFlow - Cisco Product (Rebranded to IPFIX)
This tool collects all the packet metadata, not the entire packet.
A NetFlow exporter can be enabled on network devices such as switches, routers, and firewalls. 
It uses a NetFlow collector to aggregate flows from the exporters. 
Here are some of the items it collects:

• Source and destination MAC addresses

• Source and destination IP addresses

• Source and destination ports

• Packet and byte counts sent and received

• Timestamps

• TCP flags and encapsulated protocols


No comments:

Post a Comment

Network Path Discovery Tools

 Tracert - Traceroute Both of these are command-line tools. Both use ICMP for the discovery. Tracert Windows uses tracert for path discovery...