05-13-2014 04:29 AM - edited 03-04-2019 10:58 PM
Hi All,
I have a Site A and Site B.
Connected over the Internet via a VPN. I basically want to use Netflow to see the conversations going across the link and then use a program to pull the data in nice to read detail (which I already have).
My question is - do I poll the Outside Interface, or the Lan Interface of the router? Is there a rule set to follow when using Netflow?
Thanks
05-13-2014 06:59 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
Neither.
Normally, what you do is have Netflow send its stats somewhere, i.e. to a Netflow collector. Then you query the collector for the stats you're interested in.
Buried in the MIBs, I'm guessing there would also be a way to "poll" the Netflow table, but again, Netflow will send you its stats.
05-13-2014 07:24 AM
Do I not need to add the netflow commands at all to any interface? Is the following enough ?
ip flow-export version 5
ip flow-export destination x.x.x.x 2055
05-13-2014 08:28 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
You also need to "activate" it, per interface.
Overview found here: http://www.cisco.com/c/en/us/td/docs/ios/netflow/configuration/guide/12_2sr/nf_12_2sr_book/get_start_cfg_nflow.html
NB: note "how" can vary per IOS version.
PS:
Access to Netflow MIB described here: http://www.cisco.com/c/en/us/td/docs/ios/netflow/configuration/guide/12_2sr/nf_12_2sr_book/cfg_snmp_mib_mon_nf.html
05-14-2014 04:55 AM
Do you guys have any experience of using Netflow if there is a Riverbed Steelhead at each end of the site?
I'm thinking if I pull stats from the Interface, all it's going to see is the conversation between Site A Riverbed and Site B Riverbed and not the actual real conversations taking place.
05-14-2014 05:15 AM
Hi,
this is the default Riverbed tunnel mode.
But the Riverbeds are capable to work in transparent mode, keeping the source/destination IP addresses and ports withing the packet header unchanged.
And it should be also possible to get NetFlow from Riverbeds directly, I guess.
Best regards,
Milan
05-13-2014 01:36 PM
Hi,
basically:
You are collecting NetFlow data on some interface(s) and sending it from a router to a Collector.
So no polling involved at all.
Cisco recommends running NetFlow both on your LAN and WAN interfaces in both incoming and outgoing directions.
If you are interested in your WAN traffic only, configuring NetFlow on the WAN interface (both directions) should be enough though.
In your case I suppose you are running some tunnel through the Internet?
So in that case configuring NetFlow on the tunnel interface would be sufficient, I guess?
See http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/netflow/configuration/12-2sx/nf-12-2sx-book/cfg-nf-gre-tun.html#GUID-D9295EA7-596E-4990-8A21-5C3A0840058C
for details.
Best regards,
Milan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide