NetFlow / IPFIX
Use detailed flow relationships for capacity, application and source-destination analysis.
Identify traffic whose source or destination conflicts with monitored network boundaries.
Separate unexpected external addresses by source and destination role, then compare volume, packet rate and associated subnet context.
Begin with the global condition, narrow the scope by direction and subnet, identify the responsible source and destination relationship, and compare the result with historical behavior before taking action.
This module uses the same inventory and telemetry model as realtime analytics, security controls, historical reporting and BGP operations.
Use detailed flow relationships for capacity, application and source-destination analysis.
Maintain scalable traffic and PPS visibility across high-speed, high-port-count environments.
Add focused packet-copy visibility for critical services, VLANs and investigation points.
Source-address validation requires more than a single packet counter. Flowtrion uses traffic direction, expected prefixes, interface context and flow behavior to help operators identify addresses appearing where they should not.
Flow records provide source and destination prefixes, ingress and egress information, protocol, rate and timing. Expected customer, infrastructure and transit prefix definitions create the policy context required for a useful spoofing investigation.
The module highlights unexpected source ranges, direction conflicts and rapid changes in source diversity. Results should be verified against routing asymmetry, NAT, anycast and exporter configuration before an enforcement action is taken.
Maintain an accurate prefix and interface inventory. Review uRPF mode, multihoming, NAT boundaries and asymmetric paths so the detection policy reflects the real network topology.
Spoofing indicators can be correlated with anomaly, DDoS, DNS and BGP views before ACL, RTBH or FlowSpec actions are considered.