cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
250
Views
0
Helpful
5
Replies

Looking for NetFlow Analyzer with Post-NAT Destination IP Reporting

saba53
Level 1
Level 1

Hello,

I am looking for a NetFlow analyzer that can display and report statistics using the Post-NAT Destination IPv4 Address.

For example, I’d like to monitor the download traffic of each individual end host based on their internal LAN IP addresses. However, the NetFlow analyzers I’ve tested so far only show the Destination IP address, which means I can only see my public IP in download traffic reports.

If there is any NetFlow solution that supports reporting by Post-NAT Destination IPv4 Address, please recommend one.

Thank you in advance

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

It depends on the product we are referring here, If you send both inside and outside interface netflow, you can correlate them right(just thought)

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks for your response.

What do you mean by “product”? Are you referring to the NetFlow Analyzer? Could you recommend one suitable for this kind of scenario?

From what device are you looking to extract information? As long as the Neflow data is exported, any NetFlow extractor tool can help you.

 

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

We have both Cisco and MikroTik routers in our network, and we’d like to collect NetFlow data from them. The NetFlow tools we’ve tested so far only display the Destination IP Address, which in our case is the public IP. Because of this, we’re unable to see the internal (end host) IP addresses and their corresponding internet traffic usage.

We need a NetFlow solution that supports reporting based on the Post-NAT Destination IPv4 Address so we can properly monitor traffic per internal host.

Thank you

On a Cisco device, you can use either the inside or outside interface as the source and send Netflow to the destination.

What information do you see?

After NAT, you will not see any information. If you are doing interface NAT, you will see the source as the interface IP. But inside, you can see the source Devices right (or am I thinking wrong here?)

Note: Again, to determine which Cisco Device and IOS code are running, you need to refer to the code.

example NetFlow config for reference :

https://www.balajibandi.com/?p=1383

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help