Open Source Monitoring Tools
You can use several open source monitoring tools in conjunction with NetFlow. If your organization is small, or if you do not have the budget for more sophisticated monitoring tools, you can take advantage of any of these open source tools that are freely available. Table 3-1 includes the most commonly used open source monitoring tools.
|
Tool Name |
Website |
|
Caida's Cflowd Analysis Software |
http://www.caida.org/tools/measurement/cflowd |
|
My Netflow Reporting System by Dynamic Networks |
http://www.dynamicnetworks.us/netflow/index.html |
|
OSU Flow-tools |
http://www.splintered.net/sw/flow-tools |
|
Flow Viewer |
http://ensight.eos.nasa.gov/FlowViewer |
|
Flowd |
http://www.mindrot.org/projects/flowd |
|
NetFlow Monitor (NF) |
http://netflow.cesnet.cz |
|
Ntop |
http://ntop.ethereal.com/ntop.html |
|
Panoptis |
http://panoptis.sourceforge.net |
|
Plixer's Scrutinizer |
http://www.plixer.com/products/free-netflow.php |
|
Stager |
http://software.uninett.no/stager |
Most of these tools are designed to run in common *NIX-type operating systems, including Linux, FreeBSD, Mac OS/X, and Solaris. Some of these tools support the storage of data in databases such as MySQL and Oracle. Despite the fact that these open source tools are free, they are extremely useful for collecting NetFlow from routers and storing the raw flows for auditing and forensic purposes. The most commonly used tool is the OSU flow-tool, which is typically used in conjunction with other packages that provide detailed graphs, charts, and on-demand queries. Visit each of the websites listed in Table 3-1 to learn more about which tool is most suitable for your environment.
Continue reading here: Cisco Traffic Anomaly Detectors and Cisco Guard DDoS Mitigation Appliances
Was this article helpful?