I'm trying to improve network segmentation beyond host, VLAN, and subnet rules by understanding which logical ports and services are actually being used. I can export flow information from my firewall and may also have existing syslog, PCAP, or CSV data, but I haven't worked with NetFlow before. What tools can collect or parse this data and present useful information about traffic, destinations, ports, and possibly applications so I can decide which firewall rules are necessary?
4 Answers
Take a look at ntop or cflowd first. They can turn flow records into useful views of sources, destinations, ports, and traffic volumes. Just keep in mind that flow data is primarily useful for visibility and capacity planning, and the level of detail depends on how your firewall exports it.
If you need visibility into the communicating applications as well as ports, look at microsegmentation products such as Guardicore or Cisco Secure Workload. They are designed to map traffic dependencies and help build policy from observed behavior, rather than requiring you to interpret raw flow records manually.
For security-focused visibility, consider a network-monitoring platform such as Malcolm. It can help analyze captured traffic and expose protocols, ports, and communication patterns, which may be closer to what you need than basic NetFlow dashboards.
Be careful about treating NetFlow as a complete security record. Some environments export nearly every flow, while others use sampling, and flow records generally do not contain payload details. They are good for discovering who talks to whom and on which ports, but packet capture or deeper inspection may be needed to identify the application reliably.

I’m specifically interested in logical ports so I can identify the traffic that is actually present, decide what is relevant, and create more precise firewall rules. Malcolm sounds worth investigating.