Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

netflow question for IPv6 traffic

Hi,

    I tried to setup to my 3640 to export ipv6 traffic.  I used continuious "ping ipv6"  from one window xp system to remote window xp sytem via my network.  From the ping ipv6 are ok, I can get the ping echo back all the time. but, from the netflow-export collector (tool) and wirshark I didn't see any records for IPV6. I did see some records for IPv4 from wireshark andnetflow-export collector (tool).

Not sure does this caused by my configuration problem, or the image or the harware not support? anyone can help will be appreciate.

  I checked Cisco Feature Navigator, my SW version c3640-js-mz.124-23.bin which shall support NetFlow and  Netflow for IPv6 Unicast traffic.

     the following is my show ver, show run information and show ip cache flow information.

     Thanks

Li Miaw

lmiaw@netsocket.com

O1#show ver

Cisco IOS Software, 3600 Software (C3640-JS-M), Version 12.4(23), RELEASE SOFTWARE (fc1)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2008 by Cisco Systems, Inc.

Compiled Sat 08-Nov-08 23:43 by prod_rel_team

ROM: System Bootstrap, Version 11.1(20)AA2, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1)

O1 uptime is 1 hour, 2 minutes

System returned to ROM by reload

System image file is "flash:c3640-js-mz.124-23.bin"

Cisco 3640 (R4700) processor (revision 0x00) with 123904K/7168K bytes of memory.

Processor board ID 26857169

R4700 CPU at 100MHz, Implementation 33, Rev 1.0

2 Ethernet interfaces

2 FastEthernet interfaces

DRAM configuration is 64 bits wide with parity disabled.

125K bytes of NVRAM.

32768K bytes of processor board System flash (Read/Write)

Configuration register is 0x2102

====   show run  ====

O1#

O1#

O1#

O1#show run

Building configuration...

Current configuration : 2342 bytes

!

version 12.4

service timestamps debug uptime

service timestamps log uptime

no service password-encryption

!

hostname O1

!

boot-start-marker

boot system flash c3640-js-mz.124-23.bin

boot-end-marker

!

enable password cisco

!

no aaa new-model

!

!

ip cef

no ip domain lookup

!

!

ipv6 unicast-routing

ipv6 cef

mpls traffic-eng tunnels

!

!

!

!

!

!

!

!

!

!

!

!

username admin password 0 adminn

!

!

!

!

!

interface Loopback0

ip address 10.22.1.1 255.255.255.255

!

interface Tunnel0

no ip address

ipv6 address FE80::202:B3FF:FEA6:F151 link-local

tunnel source 3.0.0.1

tunnel destination 1.0.0.1

tunnel mode ipv6ip

!

interface FastEthernet1/0

ip address 10.12.4.22 255.255.255.252

ip route-cache flow

duplex auto

speed auto

ipv6 address 192:168:1:1:10:12:4:16/126

ipv6 enable

ipv6 flow ingress

ipv6 flow egress

ipv6 ospf 10 area 0.0.0.0

mpls ip

mpls traffic-eng tunnels

ip rsvp bandwidth 1024 1024

!

interface FastEthernet1/1

ip address 10.12.4.14 255.255.255.252

ip route-cache flow

duplex auto

speed auto

ipv6 address 192:168:1:1:10:12:4:E/126

ipv6 enable

ipv6 flow ingress

ipv6 flow egress

ipv6 ospf 10 area 0.0.0.0

!

interface Ethernet2/0

description connect to CE2 f1/0

ip address 3.0.0.1 255.0.0.0

ip route-cache flow

half-duplex

ipv6 address 192:168:1:1:3::1/120

ipv6 enable

ipv6 flow ingress

ipv6 flow egress

ipv6 ospf 10 area 0.0.0.0

!

interface Ethernet2/1

no ip address

ip route-cache flow

shutdown

half-duplex

ipv6 enable

!

router ospf 1

mpls traffic-eng router-id Loopback0

mpls traffic-eng area 0

log-adjacency-changes

network 0.0.0.0 255.255.255.255 area 0

!

no ip http server

ip forward-protocol nd

ip flow-export source FastEthernet1/0

ip flow-export version 9

ip flow-export destination 1.0.0.10 9995

!

!

!

snmp-server community public RO

snmp-server ifindex persist

snmp-server enable traps snmp linkdown linkup

snmp-server enable traps tty

snmp-server host 10.12.2.2 version 2c public  snmp

ipv6 router ospf 10

router-id 10.22.1.1

log-adjacency-changes

!

ipv6 flow-export source FastEthernet1/0

ipv6 flow-export destination 1.0.0.10 9995

!

!

!

control-plane

!

!

!

!

!

!

!

dial-peer cor custom

!

!

!

!

line con 0

exec-timeout 0 0

privilege level 15

logging synchronous

stopbits 1

line aux 0

line vty 0 4

privilege level 15

password cisco

logging synchronous

no login

!

!

end

O1#

===show ip cache flow ====

O1#

O1#show ip cache flow

IP packet size distribution (50022 total packets):

   1-32   64   96  128  160  192  224  256  288  320  352  384  416  448  480

   .000 .871 .124 .003 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000

    512  544  576 1024 1536 2048 2560 3072 3584 4096 4608

   .000 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000

IP Flow Switching Cache, 278544 bytes

  8 active, 4088 inactive, 1457 added

  21851 ager polls, 0 flow alloc failures

  Active flows timeout in 30 minutes

  Inactive flows timeout in 15 seconds

IP Sub Flow Cache, 21640 bytes

  8 active, 1016 inactive, 1455 added, 1455 added to flow

  0 alloc failures, 0 force free

  1 chunk, 1 chunk added

  last clearing of statistics never

Protocol         Total    Flows   Packets Bytes  Packets Active(Sec) Idle(Sec)

--------         Flows     /Sec     /Flow  /Pkt     /Sec     /Flow     /Flow

TCP-Telnet         210      0.0       207    41      9.0       3.4       3.0

TCP-other          117      0.0         1    52      0.0       3.0      15.5

UDP-other         1119      0.2         5    71      1.2       0.0      15.4

ICMP                 1      0.0         2    56      0.0       0.2      15.3

IPv6INIP             2      0.0         5    93      0.0       2.1      15.8

Total:            1449      0.3        34    45     10.3       0.8      13.6

SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts

Fa1/1         10.12.2.2       Local         10.22.1.1       06 C778 0017    46

Fa1/1         10.12.2.2       Local         10.22.1.1       11 810A 00A1     2

Fa1/0         10.22.3.1       Local         10.22.1.1       06 4A9E 0286     2

Fa1/1         10.12.2.2       Local         10.22.1.1       11 5588 00A1    13

Fa1/1         10.12.2.2       Local         10.22.1.1       11 66F7 00A1     1

Fa1/1         10.12.2.2       Local         10.22.1.1       11 271E 00A1     1

Fa1/1         10.12.2.2       Local         10.22.1.1       11 7B7F 00A1     3

Fa1/1         10.12.2.2       Local         10.22.1.1       11 7D98 00A1    17

Everyone's tags (2)
1 REPLY
Bronze

netflow question for IPv6 traffic

Hi,

Can you try with flexible NetFlow export? My blog has some info on how to create a NetFlow record which includes IPv6 conversations:

https://blogs.manageengine.com/netflowanalyzer/2011/04/13/ipv6-and-netflow-netflow-analyzer-ipv6-data-reporting

For flexible NetFlow configuration guide, check the below link:

http://www.cisco.com/en/US/docs/ios/fnetflow/configuration/guide/fnetflow_overview_ps6441_TSD_Products_Configuration_Guide_Chapter.html

Regards,

Don Thomas Jacob

www.netflowanalyzer.com

NOTE: Please rate posts and close questions if you have got your answer.

Regards, Don Thomas Jacob http://www.solarwinds.com/netflow-traffic-analyzer.aspx Head Geek @ SolarWinds NOTE: Please rate and close questions if you found any of the answers helpful.
738
Views
0
Helpful
1
Replies