Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureMedium
A network operations team is implementing a new monitoring solution that requires detailed, real-time visibility into network traffic patterns, application usage, and potential security threats across their enterprise network. They need a protocol that can collect IP flow information, such as source/destination IP, ports, and protocols, from routers and switches without capturing the full packet payload. Which network service should be configured?
- ASNMP
- BIP SLA
- CNetFlow
- DSyslog
Show answer & explanationAnswer & explanation
Correct answer: C. NetFlow
NetFlow is a Cisco-developed technology that collects IP traffic information as it flows through a router or switch. It provides detailed statistics on traffic flows, including source/destination IP addresses, ports, protocols, and byte/packet counts, which is ideal for monitoring traffic patterns and application usage without capturing full packet payloads.
Why the other options are wrong
- A. SNMP (Simple Network Management Protocol) collects device statistics and manages network devices but does not provide detailed IP flow information.
- B. IP SLA (IP Service Level Agreement) actively monitors network performance metrics like jitter and latency, but does not provide passive collection of all IP traffic flows.
- D. Syslog collects system messages and events for logging and troubleshooting, not traffic flow data.
NetFlow
A Cisco feature that collects IP traffic statistics (flow records) as packets pass through a network device, providing insights into traffic patterns, bandwidth usage, and network anomalies.
- Collects flow records, not full packets.
- Includes source/destination IP, ports, protocol, timestamps.
- Used for network monitoring, security analysis, billing.
- Requires a NetFlow collector to analyze data.
Memory trick: Monitoring: Different tools for different views.