Cisco NetFlow Agent Detection

Info Nessus Network Monitor Plugin ID 3159

Synopsis

The remote host is running a Cisco NetFlow Agent.

Description

The remote host is running a Cisco NetFlow Agent. NetFlow is a UDP protocol which sends sniffed traffic from a Cisco device to a Cisco collector device. By using NetFlow, companies do not need to deploy 'taps' or utilize span (or mirror) ports. Instead, the NetFlow agent bundles the sniffed traffic into a UDP packet and forwards to the collector.

Solution

As the NetFlow traffic is passed in plaintext, ensure that NetFlow traffic does not traverse any untrusted networks.

Plugin Details

Severity: Info

ID: 3159

File Name: 3159.prm

Family: Generic

Published: 2005/08/10

Modified: 2015/06/01

Risk Information

Risk Factor: Info