Académique Documents
Professionnel Documents
Culture Documents
Netflow is a network protocol developed by Cisco for the monitoring and collection of traffic flow data. It is used to
analyze network traffic flow as well as traffic volume in order to learn: where the traffic originated, where it was going
to, as well as the quantity of traffic generated. A Netflow enabled router exports traffic statistics as a Netflow record
that is then gathered by a Netflow collector. A collector can be a form of software or a hardware appliance. This
section will guide through configuring and verifying Cisco Netflow version 5 and 9 and teach you how to retrieve the
data locally.
Netflow offers usage-based network billing, security, network monitoring, denial of the service monitoring abilities,
and network traffic accounting. Netflow offers valuable information about applications and network users, traffic
routing routing and peak usage times. Ciscos Netflow is the leader in IP traffic flow technologies.
Netflow is transparent to an existing network such as application software, end stations and also network devices
such as LAN switches. Netflow performs independently on every internetworking device. By using NDE- Netflow data
export, you can export data to a remote workstation for gathering/processing. Network admins selectively invoke NDE
on a per-subinterface or router basis for the purpose of the traffic performance, accounting or control.
To ensure the proper functionality, remember the following when configuring the device:
To configure Netflow, the first step is required. All other steps are optional :
Command:
Or
Command:
In this step the Netflow information is exported to the network management application. To configure a router to
export Netflow statistics in a Netflow cache to the workstation when the flow expires (times out), make use of the
below command:
Command 1:
Command 2:
In this configuration, you can display and clear Netflow statistics. The Netflow statistic comprises of the IP packet size
distributions, information to the IP flow cache and also flow information such as total flow, protocol and flows per
second. To manage the Netflow statistics make use of the given privileged EXEC mode command:
Verification:
To verify information about aggregation cache, make use of the below command in the EXEC mode:
To confirm the data export, make use of the below command in the EXEC mode:
In the below diagram, Netflow data is exported from a network device. The Netflow data is exported to a centralized
collector analyzer which processes the data and also generates reports.
The traditional Netflow (or Netflow v5) is used widely. It supports AS - autonomous system reporting as well as some
additional fields. These flows are calculated when they come into an interface. Outbound traffic is also reported by
using the inbound flow from another interface. Hence, it advised that netfow v5 is enabled on all device interfaces or
else the outbound utilization of some interfaces will not be captured. Packet formats are fixed and always be same.
The following commands enable Netflow v5 on Fa0/1 and also export it to the machine 10.199.15.103 on port 2055.
Perform the below task to verify the configuration:
Netflow v9:
The basic output of Netflow is the flow record. There are various formats for flow records which have evolved as
Netflow has matured. The most recent evolution of a flow record format is the Netflow version9 format, which is the
basis for the IETF standard (which is template based). The template offers an extensible design to a record format,
and a feature which allows future enhancement to Netflow service without the need for concurrent changes to a basic
format of flow records. By using templates, there are a variety of benefits:
This config enables Netflowv9 on Fa0/1 and exports to 10.199.15.103 on port 2055.
Verify Netflow v9 configuration:
Once Netflow is configured, Netflow packets are sent to a designated collector or server.
Interface <interface>
Ip flow ingress
By analyzing the data offered by Netflow, the network administrator can easily find out things such as destination and
source of the traffic, causes of the congestion and class of service. Netflow is becoming the de-factto industry
standard and is supported by the platforms like Cisco including 3com/HP, Netgear, Huawaei, Ericsson, Alcatel-lucent,
and Juniper. Cisco developed this flow technology which allows bandwidth monitoring of the network. It allows
extremely granular as well as accurate bandwidth monitoring by recording the network traffic to a device cache.