I am using 40+ Vyatta and 3 cysco devices to simulate an enterprise network. I was handed LiveNX as a visualization tool that the stakeholders can use to see the flow from the attacker to the victim. This would be awesome IF netflow worked. I get flows but they are disjointed in such a way that I cannot track flows through the routers from the attacker to the target. I can see the flows all the way through the cisco and checkpoint virtual devices.
I see temporary fixes for this back in 2015 and a request for enhancement at that time. However, It has not been added the workaround posted below did not seem to work for me.
I am attempting to modify this for a visual representation for the brass. Hopefully this is something that is coming? But are there any other tweaks that I could try to tie netflow end to end. Hopefully this makes sense?