VMWare Netflow Collector

VMWare Netflow Collector

Lumu Virtual Appliance is capable of processing Netflow traffic in VMware, with the purpose of identifying malicious activity originating or remaining within virtual machines, allowing effective processing of lateral movement in said instances.

For more information about the benefits of Netflow monitoring, consult Netflow Collector Documentation.

Prerequisites

  • vSphere 6.5 +
  • Lumu Defender Subscription
  • Lumu Virtual Appliance

Netflow configuration in vSphere

The following sections go over the configurations required to activate Netflow collection in vSphere. 

Activate Netflow protocol 

Enable the Netflow protocol on the virtual switches you want to monitor. To do so, select DSwitch from the left-side menu and go to the Configure tab. Then, select Netflow under the Settings menu. 


Inside the Netflow configuration menu, configure the following parameters only, other values can remain as default:

  • Collector IP address: IP Address of the Lumu Virtual Appliance.
  • Collector Port: Service port where the Lumu Virtual Appliance will receive information (default UDP 2055).

Once settings are applied, the dashboard should look as follows:

Activate data transfer to the collector

After enabling the Netflow protocol, it is necessary to configure the virtual switches to generate the flows so they can be processed by the collector. To do this, you must edit the Manage Distributed Ports. Right click DSwitch, then select Distributed Port Group > Manage Distributed Port Groups.

Subsequently, monitoring must be activated on the DSwitches as shown in the following example.

Collector activation in the Lumu Portal

Notes The Lumu VA only supports a single Netflow/IPFIX Collector. If multiple collectors are required, it is necessary to create multiple VAs. 
To add a VA Collector, go to the Lumu Portal and navigate to the Collectors > Virtual Appliance menu, click on the VA in which you want to add the collector to, then click on Add Collector.

Then, provide the following information:

  1. Name: a name for your VA Collector.
  2. Type: Netflow/IPFIX. This is the type of metadata you want this VA collector to process.
Once you are finished, it will look as follows.

Lastly, execute the command lva-collectors-refresh on the Lumu Virtual Appliance and enter the following data as required by the wizard.

  • Device type: [1] Netflow/IPFIX
  • Are flows bidirectional?: [3] no
  • Install Filebeat: y
  • Listen netflow port: 2055

As a result, you should visualize traffic in the Lumu Portal.