Cisco NetFlow Agent Detection

info Nessus Network Monitor Plugin ID 3159

Synopsis

The remote host is running a Cisco NetFlow Agent.

Description

The remote host is running a Cisco NetFlow Agent. NetFlow is a UDP protocol which sends sniffed traffic from a Cisco device to a Cisco collector device. By using NetFlow, companies do not need to deploy 'taps' or utilize span (or mirror) ports. Instead, the NetFlow agent bundles the sniffed traffic into a UDP packet and forwards to the collector.

Solution

As the NetFlow traffic is passed in plaintext, ensure that NetFlow traffic does not traverse any untrusted networks.

Plugin Details

Severity: Info

ID: 3159

Family: Generic

Published: 8/10/2005

Updated: 6/1/2015