NetFlow and sFlow Configuration Guide on Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

NetFlow and sFlow Configuration Guide on Cisco 8000 Series Routers, Cisco IOS XR Releases

Key attributes in IP and MPLS packets for NetFlow

Want to summarize with AI?

Log in

Lists the key attributes in IP and MPLS packets that NetFlow monitors.


NetFlow monitors key attributes in IP and MPLS packets to provide detailed visibility into network traffic for analysis and troubleshooting.

NetFlow supports IPv4, IPv6, MPLS, BGP, SRv6, and GTP-U flow types, enabling monitoring of a wide range of packet information. The key attributes in IP and MPLS packets that NetFlow monitors include:

  • Source and destination IP addresses

  • Source and destination port numbers

  • Layer 3 protocol type

  • Type of service (ToS) byte

  • Input and output interface numbers

  • MPLS labels

  • BGP next hop

  • SRv6 segment identifiers

  • GTP-U tunnel identifiers

These attributes allow NetFlow to provide detailed visibility into network traffic for analysis and troubleshooting.


IP traffic monitors

A IP traffic monitor is a network analysis tool that

  • collects detailed traffic data for both IPv4 and IPv6 networks

  • captures key attributes such as source and destination addresses, protocol types, and bandwidth usage, and

  • enables identification of network trends, detection of security threats, and optimization of network performance

Key IP traffic attributes monitored include:

  • Source and destination IP addresses

  • Source and destination MAC addresses

  • Source and destination ports for TCP and UDP

  • Differentiated Services Code Point (DSCP)

  • Layer 3 protocol

  • Type of Service (ToS) byte

  • Traffic receiving interface

  • Complete IPv4 header fields, including IP-ID and TTL

  • Counts for packets and bytes

  • Full spectrum of IPv6 header fields, including flow label and option header

  • Flow timestamps

Attributes and functions of IP traffic monitors

Describes the main functions and monitored attributes of NetFlow IP traffic monitors for IPv4 and IPv6 networks.

NetFlow IP traffic monitors provide the following capabilities:

  • Collect detailed traffic data for both IPv4 and IPv6 networks

  • Capture key attributes such as source and destination addresses, protocol types, and bandwidth usage

  • Enable identification of network trends, detection of security threats, and optimization of network performance

Key IP traffic attributes monitored include:

  • Source and destination IP addresses

  • Source and destination MAC addresses

  • Source and destination ports for TCP and UDP

  • Differentiated Services Code Point (DSCP)

  • Layer 3 protocol

  • Type of Service (ToS) byte

  • Traffic receiving interface

  • Complete IPv4 header fields, including IP-ID and TTL

  • Counts for packets and bytes

  • Full spectrum of IPv6 header fields, including flow label and option header

  • Flow timestamps


MPLS traffic monitoring

A MPLS traffic monitoring solution is a network visibility tool that

  • uses NetFlow to collect detailed traffic data for MPLS traffic

  • enables identification of anomalies and detection of cyber threats, and

  • supports rapid response to potential security incidents.

MPLS traffic monitoring attributes and benefits

Describes how MPLS traffic monitoring solutions use NetFlow to provide visibility into MPLS traffic, identify anomalies, detect cyber threats, and support rapid response to security incidents.

Key attributes monitored by MPLS traffic monitoring solutions include:

  • MPLS labels


BGP traffic monitoring

A BGP traffic monitoring solution is a network analysis tool that

  • uses NetFlow to capture and analyze BGP packets in the network,

  • provides detailed information on the frequency, direction, and content of BGP traffic, and

  • enables identification of potential security threats and monitoring of BGP router behavior.

BGP traffic monitoring attributes and analysis

Describes how NetFlow monitors BGP traffic and identifies key BGP traffic attributes for network analysis.

BGP (Border Gateway Protocol) is a routing protocol that network routers use to exchange routing information and establish optimal data paths across networks. Monitoring BGP communication with NetFlow provides valuable insights into network performance and helps ensure effective routing strategies.

Key BGP traffic attributes monitored include:

  • Next-hop address

  • Source autonomous system (AS) number

  • Destination autonomous system (AS) number

  • Source prefix mask

  • Destination prefix mask

  • BGP next hop

  • BGP Policy Accounting traffic index


SRv6 traffic monitoring

A SRv6 traffic monitoring is a network feature that

  • enables the collection of information elements specific to SRv6 traffic flow in the core

  • using IPFIX is supported only on P-nodes; decapsulation nodes are not supported, and

  • helps users understand when and how to apply the feature.

Restriction and limitation

Describes the SRv6 traffic monitoring feature, its support for performance monitoring of SRv6-based core networks using IPFIX, and key restrictions.

  • SRv6 traffic monitoring using IPFIX is supported only on P-nodes; decapsulation nodes are not supported.