I have my Catalyst 6509 configured for Netflow and I'm testing out NetFlow Traffic Analyzer as a product we might be interested in buying but I can't get the info I'm needing to show this is a viable purchase.
Here is my question. I have been given a Source Port and the NAT hide behind address (Using fake NAT for security) and I'm needing to gather information on this connection. Here is a screen shot of the exact info as it comes to me. I need to be able to provide either a MAC address or the real address of the PC.
IP Address Timestamp
----------------------------------------
192.168.1.1 2010-02-18.19:38:05-0000 SrcPort:TCP/13717
MalwareType:Torpig