NetFlow Server location in the network depends on the network topology. The amount of NetFlow data exported from network devices is in direct correlation to the amount of traffic passing through that device (exporter). Studies show that the NetFlow traffic is 0.5% to 2% of total traffic, therefore NetFlow Server should not be “too far” from the exporter.

More important parameters are the availability and security of the NetFlow Server. NetFlow Server is usually connected to the central network node or close to it, because the most of the traffic passes through this node. In the case of an exporter or link fail, it is important to have NetFlow Server still available so you can analyze the traffic.

 

 

For security reasons, it is recommended that you set a separate VLAN for the NetFlow Server and raise a firewall on the server for its protection.