Understanding Netflow and how to use it
Introduced by Cisco back in 1996, Netflow is a protocol that's used to help analyze network traffic. Netflow has three main components: flow exporter, flow collector, and analyzer. An advantage of using Netflow is that it captures the packet flow, including information about the source and destination IP and port number. As OPNsense's official documentation claims, it is the only open source solution that integrates all this in a web GUI. In other words, with OPNsense, you don't need another application to collect and analyze network flows. The exception is when you have OPNsense as a firewall in a large network with a lot of traffic – here, you will need an external analyzer with a dedicated database engine.
Important Note
OPNsense's embedded Netflow analyzer has a local cache with a 100 MB limit (wispy for larger networks). Therefore, in large or high-throughput networks, it is highly recommended to use an...