Network Traffic

Enabling Netflow Agent

Genian ZTNA can monitor network traffic by utilizing the Netflow Agent function of a sensor. This flow information of connected devices provides enhanced Network Observability which is a crucial component for enforcing ZTNA policies. Once enabled, the Netflow Agent will log flows of all traffic flowing through the sensor. Information logged in flows includes but is not limited to:

  • Source IP Address
  • Destination IP Address
  • Protocol (UDP/TCP)
  • Source Port
  • Destination Port
  • Application
  • Geolocation Data
  • User (which user the flows are associated with)
  • Number of Packets
  • Number of Bytes
  • Flow Start (date/time)
  • Flow End (date/time)

Note

In order to see flows utilizing the Netflow Agent, traffic from an endpoint must be flowing through a network sensor. To route traffic through a sensor, following the instructions below to deploy a cloud gateway and ZTNA client.

Managing Nodes in the Cloud

Controlling Access to Cloud Resources

To enable the Netflow Agent on the network sensor:

  1. Go to System > Sensor in the top panel
  2. Click on Edit Sensor Settings for the tap_1 sensor interface
  3. Scroll down to Traffic Monitoring section and toggle Netflow Agent to On
  4. Click Update at the bottom of the page

To test and validate that flow data is being collected and logged:

  1. Go to Log > Flow in the top panel
  2. Flows should be populated for any traffic routing through the network sensor

Note

Only flows for connected ZTNA clients will be logged.

To view connected ZTNA clients:

  1. Go to System > Site in the top panel
  2. Under the ZTNA - Client column, click on the (*) link to view connected clients
  3. Flows from these clients should be visible in the flow logs

To view summary information for flow data:

  1. Go to Dashboard in the top panel
  2. Click on Flow Data tab in Dashboard
  3. View various widgets including Top Traffic by Source IP, Destination IP, User, etc.