Forum Discussion
Anonymous
10 months agoAh, so the netflow is capturing the encrypted/tunnelled traffic instead of the raw traffic. Thus the culprit’s identity is lumped in with all other ipsec traffic making it impossible to know the actual source.
No chance to turn on netflow at some point in the path before or after the ipsec tunnel?
Related Content
- 10 months ago
- 7 months ago
- 10 months ago
- 5 months ago