07-11-2008 04:32 AM
We have a Cisco 6504 switch with sup720 supervisor engine, running native IOS. NetFlow was enabled on the device. We find that the analyzer software reports traffic much lower than the actual traffic passing through the switch whereas other Cisco6504 switches (same model and similar configuration) works fine. The only difference is that the flow export is through a VRF configured on the device. So the command we have for exporting flows is as follows:
ip flow-export destination xx.xx.xx.xx 9996 vrf NAME1
If the VRF command is removed, no flows at all reach the analyzer software. Is there any limitation on NetFlow because of the presence of VRF on the device. Or is there any other possible reason on why the traffic is reported different on the analyzer software.
The following is the NetFlow related commands on the device:
snmp-server ifindex persist
ip flow-cache timeout active 1
ip flow-cache timeout inactive 15
ip flow-export source Vlan200
ip flow-export version 5
ip flow-export destination xx.xx.xx.xx 9996 vrf NAME1
mls nde sender version 7
mls flow ip interface-full
mls netflow interface
mls aging long 64
mls aging normal 32
ip flow ingress layer2-switched vlan 101-105,200-240,300-340,500-540
ip flow export layer2-switched vlan 101-105,200-240,300-340,500-540
Regards,
Don
07-17-2008 08:24 AM
Here is the URL for the configuration for the netflow which will help you :
http://www.cisco.com/en/US/docs/ios/fnetflow/configuration/guide/get_start_cfg_fnflow.html
http://www.cisco.com/en/US/docs/ios/12_0s/feature/guide/12s_mdnf.html
10-27-2008 06:17 AM
'ip flow-export destination
If you 'debug ip flow export' you will see that the first flow packet works correctly, with a correct source address (this is the RP first flow as the hardware is programmed). All additional flow export packets will be sent with a source address of 0.0.0.0, which will never work (these are the mls NDE exported flows).
According to Cisco, this is not yet a supported feature. Moving the flow export to the global routing table may work, but you may not receive all flows from all VRFs.
Track bug id CSCsh99774 for more info...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide