Network World
Tuesday, December 2, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

SFlow for traffic monitoring, and security snooping

Related links

LANs / Routers Notes RSS feed

E-mail Phil Hochmuth

LANs / Routers Notes archive.

Security forum
Discuss LANs / Routers Notes and other LANs/Routers topics.


A network monitoring and management technology called sFlow may not be the most widely-known IETF draft standard, but its proving to be a versatile tool for some network managers.

RFC 3176, known as sFlow, is an embedded MIB technology on some brands of network switches which allows users to view network traffic as if they had a probe installed on every port on the device. SFlow works by taking random samples of network traffic from all ports, then running the samples through an algorithm to generate a complete network map, which is updated in real time.

In addition to using sFlow as a network management tool, it can also be used as a way to detect network intrusions, such as unauthorized NAT devices - like WLAN hubs - that may be on a network. Peter Phaal, an engineer at InMon Corp, which makes sFlow-based hardware and software products, wrote a detailed document on this security technique.

Find out how to use sFlow to detect rogue WLAN end points:
www.sflow.org/detectNAT/

More on sFlow in general:
www.sflow.org

Back to LANs / Routers Notes

Comments

Post a comment

Name:


E-mail address:


URL:


Comments:


Remember info?