03-24-2009 03:01 AM - edited 03-06-2019 04:46 AM
Hi Experts,
We have NetFlow Analyzer 7 for our internet traffic monitor.
We have BGP and OSPF in all internet devices.
The configuration as like below...
ip flow-export source FastEthernet0/0
ip flow-export version 5 origin-as bgp-nexthop
ip flow-export destination 10.246.x.xx 9996
ip flow-export destination 10.246.x.xx 9996
Regarding #ip flow-export version 5 origin-as bgp-nexthop
If your router uses BGP you can specify that either the origin or peer AS is included in exports - it is not possible to include both.
Now my question is is it possible to enable NetFlow as I have running BGP & OSPF.
Regards,
Naidu.
03-24-2009 03:19 AM
Hello Naidu,
yes it is commonly done.
notice: use origin-as that allows to associate a prefix with the AS that owns it.
Some notes: internal prefixes will be associated to BGP AS number 0 but no other issues
Hope to help
Giuseppe
03-24-2009 04:08 AM
Hi Giuseppe,
Thanks for your quick response.
Can you show me the full command to enable (notice: use origin-as that allows to associate a prefix with the AS that owns it)
Regards,
Naidu.
03-24-2009 04:19 AM
Hello Naidu,
there are other commands that need to be added to the interfaces that you want to monitor:
int type x/y
ip route-cache flow
note: by default netflow classifies traffic inbound the interfaces
so on the wan interfaces you see traffic coming from internet and on lan interfaces on border router you see traffic going to internet.
This is important later to create correct aggregations of traffic data.
about origin-as:
if net 145.145.0.0 comes from AS 7000
you see a BGP path like
1255 4500 3336 7000
if you use peer-as the prefix is associated to AS 1255 that is the AS that has passed you the BGP advertisement and then one you send the traffic to
Origin-as is useful because allows to understand from what AS traffic comes.
Hope to help
Giuseppe
03-25-2009 11:28 PM
Hi Giuseppe,
To install NetFlow Analyser in some device what are the things compatibilites with device we need to consider.
Example I have 4560S, 1850R what things I need to see and consider to install NetFlow.
Regards,
Naidu.
03-26-2009 12:51 AM
Hello Naidu,
netflow analyzer and netflow collector are installed in unix workstations not on network devices
network devices just need to be configured to export info about monitored flows
see
Hardware Requirements
Cisco NetFlow Collector, Release 6.0 has the following hardware requirements:
â¢Minimum: 2 GB RAM, 73 GB disk, dual processor on an entry-level server.
â¢Recommended: 4 to 8 GB RAM, two or more 15K SAS 146 GB or greater disks, dual 3 GHz dual-core (5160) processor entry-level server.
Supported Operating Systems and Platforms
Cisco NetFlow Collector, Release 6.0 supports the following operating systems and platforms:
â¢Solaris 8, Solaris 9, or Solaris 10 on an entry-level server with dual 1 GHz or greater SPARC processors such as a Sun Fire V240.
â¢Red Hat Enterprise Linux 2.1, 3.0, or 4.0 (ES and AS) on an entry-level server, such as an IBM x3550 or x3650 with dual 2.8 GHz or greater Intel Xeon single-core processor or dual 3 GHz dual-core (5160) processors.
to be noted that open source alternatives to netflow collector exist
an example:
Hope to help
Giuseppe
03-26-2009 06:32 AM
Hi Giuseppe,
Sorry for the confusion.
I mean what are the minimal requirements that the device need have to enable the NetFlow commands in that not to installation of NetFlow Analyzer.
Regards,
Naidu.
03-26-2009 07:08 AM
Hello Naidu,
sorry for the misunderstanding
for software based routers no problem.
multilayer switches: actually only C6500 support it.
example C3750 don't support netflow
for c4500:
Supervisor Engine 6-E and LAN Base image do not support Netflow.
see
Hope to help
Giuseppe
03-26-2009 10:31 PM
Hi Giuseppe,
Unfortunately I have the below following devices and those need to create NetFlow for Traffic & Packet analyzer.
Cisco 4507S & 7 numbers 1841R
Will it support for above devices.
Regards,
Naidu.
03-27-2009 01:00 AM
Hello Naidu,
for the C4507 if the supervisor is different from 6-E and you have an image above lan base the answer is yes.
For the 1841 it is supported: it is supported on older 1721 so I think no problem about these software based routers
see also table-7 here:
Hope to help
Giuseppe
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: