[c-nsp] netflow with source-mac address?

Gert Doering gert at greenie.muc.de
Sat Mar 30 08:13:57 EDT 2013


Hi,

On Sat, Mar 30, 2013 at 11:52:59AM +0000, Phil Mayers wrote:
> http://www.cisco.com/en/US/prod/collateral/iosswrel/ps8802/ps11821/ps11846/product_bulletin_c25-717747_ps708_Products_Bulletin.html
> 
> ...talks about 15.1(SY) on the sup2T and says:
> 
> """NetFlow (TNF) Export L2 MAC and Port Information for IPv4
> This feature gives you a way to find out the NetFlow information for 
> destination and source MAC address along with the port LTL. This is 
> useful when a bot on the network is spoofing the IP address. We will be 
> able to track this down with the MAC address using NetFlow."""

This is extremely cool.

I'm somewhat disappointed by the "for IPv4" bit, though.

gert

-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert at greenie.muc.de
fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 305 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/cisco-nsp/attachments/20130330/6a82ef8f/attachment.sig>


More information about the cisco-nsp mailing list