Re: Bogon IPs traffic only seen by netflow, confined within a VLANonly
Stef <[email protected]> Tue, 11 Apr 2006 18:31:22 -0500
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <[email protected]> |
Please see $subj - this is how I knew it was confined to one VLAN only - the interface in netflow was the VLAN number Thanks, Stef On 4/11/06, Nyuk Loong Kiw <[email protected]> wrote: > Are all the netflow packets generated by the 4506 switch? Are you using > flowtools for netflow analysis? > > From memory flows generated by cisco devices actually have the > additional interface identifier or something similar in the actual flow > packets itself, if you know which cisco interface is the 'incoming' > interface you should be able to apply a filter to look for all traffics > going through that incoming interface, that should help isolate things. > > > Kiw > <snip>