Deploy the ExtraHop EFC 1292v NetFlow Sensor
This guide explains how to deploy the EFC 1292v NetFlow sensor virtual appliance.
The EFC 1292v is designed to connect to Reveal(x) 360 and Reveal(x) Enterprise and collect NetFlow records from your network. Packet analysis is not available.
Prerequisites
Your environment must meet the following requirements to deploy an EFC 1292v sensor:
- Access to a virtual sensor (ExtraHop 1100v) on Linux KVM or VMware
- An EFC 1292v product key
Deployment overview
Collecting NetFlow records requires the following configuration setup.
- Deploy an ExtraHop sensor instance in Linux KVM or VMware. For more information, see Deploy an ExtraHop sensor on Linux KVM or Deploy the ExtraHop sensor with VMware.
- Configure interfaces.
- Configure NetFlow settings on the ExtraHop system.
Configure interfaces
- Log in to the Administration settings on the ExtraHop system through https://<extrahop-hostname-or-IP-address>/admin.
- In the Network Settings section, click Connectivity.
- In the Interfaces section, click the name of the interface you want to configure.
- On the Network Settings for Interface <interface number> page, from the Interface Mode drop-down, select Management + Flow Target.
-
Disable all remaining interfaces, since the sensor cannot process NetFlow and
wire data simultaneously:
- In the Interfaces section, click the name of the interface you want to configure.
- From the Interface Mode drop-down, select Disabled.
- Repeat until all additional interfaces are disabled.
- Click Save.
Configure NetFlow settings
You must configure port and network settings on the ExtraHop system before you can collect NetFlow records. Flow networks cannot be configured on Reveal(x) Enterprise systems. The ExtraHop system supports the following flow technologies: Cisco NetFlow v5/v9 and IPFIX.
You must log in as a user with System and Access Administration privileges to complete the following steps.
Add approved networks
- Log in to the Administration settings on the ExtraHop system through https://<extrahop-hostname-or-IP-address>/admin.
- In the Network Settings section, click NetFlow.
- In the Approved Networks section, click Add Approved Network.
- From the Flow Type drop-down menu, select NetFlow.
- For IP address, type the IPv4 or IPv6 address.
- For Network ID, type a name to identify this approved network.
- Click Save.
Discover NetFlow devices
You can configure the ExtraHop system to discover NetFlow devices by adding a range of IP addresses.
- With NetFlow, devices that represent the gateways exporting records are automatically discovered. You can configure the ExtraHop system to discover devices that are representing the IP addresses observed in NetFlow records by adding a range of IP addresses.
- Exercise caution when specifying CIDR notation. A /24 subnet prefix might result in 255 new devices discovered by the ExtraHop system. A wide /16 subnet prefix might result in 65,535 new devices discovered, which might exceed your device limit.
- If an IP address is removed from the Device Discovery settings, the IP address will persist in the ExtraHop system as a remote L3 device as long as there are existing active flows for that IP address or until the capture is restarted. After a restart, the device is listed as an inactive remote L3 device.
Next steps
You can add another IP address or range of IP addresses by repeating steps 3-4.
Thank you for your feedback. Can we contact you to ask follow up questions?