Netflow in CS-MARS
Hi all,
NetFlow is also involved in CS-MARS for anomaly detection. Can anyone tell me is there any any difference when NetFlow data used in NFC Engine/CS-MARS.Is there any performance issues result over the Netflow data used in NFC/CS-MARS.
Regards,
Srini
Expert's answerThis Cisco security presentation discusses using Netflow with CS-Mars and indicates that enabling Netflow 5 and exporting data can increase CPU load on the router between 15 and 20 percent and that Netflow traffic may represent between 1 and 1.5 percent of the network traffic being monitored. The Device Configuration Guide for Cisco Security MARS, Release 6.x says that NSEL, which is an adaptation of Netflow 9 can transmit much of the same information in a less CPU-intensive, more secure, and more bandwidth-efficient way. The performance difference between using CS-MARS or the Netflow Collector Engine is going to depend on the hardware and which version(s) of software you are running. |
Product Guides

Post new comment