When In Doubt, Capture Packets
While NetFlow--the subject of my last three posts--is a tool that I use constantly for getting visibility into network traffic, sometimes you need to look at complete packet contents. I have a saying at work: "When in doubt, capture...
NetFlow Part 3
In the previous post, we looked at the NetFlow top-talkers feature, which is probably the quickest way to get traffic-level details about what's happening on a router in real time. There have been a couple of comments from people...
NetFlow Top Talkers
In the last post, we discussed some of the basic ideas behind NetFlow, which is sort of like the Swiss Army Knife of network visibility tools. In this post, keeping with the spirit of "quick-and-easy" ways to improve your...
NetFlow Part 1
NetFlow is one of those tools that's been around forever, but until the last few years it hasn't received a lot of attention outside of service provider and large enterprise networks. Recently, there have been a lot of NetFlow...
Finding IP Addresses
One of my favorite writers in the IT world in general, and in the security world in particular, is Richard Bejtlich of Taosecurity and General Electric. One of the main points that Richard makes again and again in his books and blog...
More Useful Output Modifiers
In my introductory post, we looked at some of the more obscure output modifiers, such as the "redirect" and "append" filters. In this post, we'll look at some of the more common ones. Most people who have been around IOS for a while...
Introductions and IOS Output Filters
First off, let me introduce myself and the blog. I'll be guest blogging for the month of May. I'm a network engineer for a mid-sized company in Colorado. I've been in IT for about 15 years, with about 10 years devoted to network...