|
Features
StealthWatch
Xe for sFlow® provides the following features to
cost-effectively optimize security and network operations
across the enterprise:
Leverages
existing investment in sFlow technology
StealthWatch Xe for sFlow gathers network traffic information
from sFlow-capable routers and switches. Most Foundry,
Extreme, and HP Procurve network devices are already
equipped to export sFlow traffic samples, the network
engineer need only enable and utilize this powerful
technology. No hardware, sensor technology, inline device,
or software agent is required.
Stops
threats at the network's edge
StealthWatch
Xe for sFlow monitors traffic from the very edge of
the network. When technologies from vendors such as
Foundry Networks are employed, each access layer router
and switch, down to the individual host, can send sFlow
samples that detail the behavior of the hosts within
the network. Thousands of switchports can be monitored
by a single StealthWatch sFlow collector allowing for
deep, access level visibility.
Provides
real-time traffic analysis for billing, bandwidth accounting,
and network performance troubleshooting
sFlow
analysis allows for extremely fine-grained traffic reporting
and accounting. Where SNMP polling falls short, sFlow
excels. StealthWatch utilizes sFlow to its fullest extent,
proving top talkers, services, and conversations in
both a real-time and historic basis for each sFlow enabled
router and switch interface active on the network. StealthWatch
Xe for sFlow enables traffic accounting, historical
trending, and troubleshooting capabilities not found
in any other flow-based technology available today.
Works
in extremely high-speed environments
Since StealthWatch Xe relies on sFlow-capable routers
and switches to generate traffic flow information, it
does not have to perform both traffic collection and
behavioral analysis at the same time. The result is
extremely rapid detection and response for networks
operating at speeds up to 10Gb.
Layer
7 Visibility
sFlow
traffic samples include a small subset of packet payload
data. In many cases enough information is provided within
the sFlow sample to allow for limited layer-7 visibility
without the need for a SPAN, mirror port, or tap. Such
advanced StealthWatch capabilities such as OS Fingerprinting
are made available by sFlow traffic sampling technology.
|