NetFlow and sFlow Configuration Guide on Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

NetFlow and sFlow Configuration Guide on Cisco 8000 Series Routers, Cisco IOS XR Releases

NetFlow Guidelines and Limitations

Want to summarize with AI?

Log in

Describes this topic.


Objective and scope.

General

  • NetFlow is supported in the ingress direction for all routers.

  • NetFlow supports export format Version 9 and IPFIX.

  • The configuration of the sampler rate as 1 out of 1 is supported.

  • You can configure only one active sampler per system.

  • Netflow does not cache for MPLS decap and GRE decap nodes when these are configured on sub-interfaces; cache support is available only on main interfaces.

  • Netflow record collection is not supported on SRv6 decap node.

  • Ingress L2 netflow or IPFIX is not supported.

  • Egress NetFlow and Internet Protocol Flow Information Export (IPFIX) are not supported.

  • The full Packet Capture (FPC) feature is not supported.

  • Destination-based NetFlow accounting is not supported.

  • NetFlow filtering using ACL is not supported.

  • The Post-QoS Data Monitoring feature is not supported on Q100 ASIC-based line cards.

  • Netflow exporter packet does not support TCP.

  • A source interface or source address must be configured to enable the exporter. If you do not configure a source interface, the exporter remains in a disabled state. If both a source interface and a source address are configured, the source address takes precedence.

  • A valid record type such as IPv4, IPv6, or MPLS must be configured for every flow monitor map

  • NetFlow is not supported on Bridge Virtual Interface (BVI).

  • The data and flow records for GRE transit traffic do not have the output interface, source, and destination prefix lengths fields set.

  • We do not recommend using the management interface to export the NetFlow packets.

  • The output interface field is not updated in data and flow records when the traffic is routed through ACL-based forwarding (ABF).

  • If IPFIX 315 is enabled on a line card, then all the ports on that line card should have IPFIX315 configured.

  • Enable the IPFIX 315 configuration on a sub interface explicitly if the traffic for that sub interface is required to be exported.

  • The incoming and outgoing interface information will point to sub-interface if routed via sub-interface.

  • For IPFIX 315, the outgoing interface information may not be correct incase of packets that are multicasted or broadcasted on multiple ports.

  • On a dual RP centralized system, IPFIX 315 or sFlow has to be enabled on both RP's respectively. Otherwise, the system displays an error message during configuration.

  • On edge nodes, only ingress direction is supported.

  • The MPLS record types, such as mpls ipv4-fields, mpls ipv6-fields, and mpls ipv4-ipv6-fields, are only supported.

  • At the edge node on MPLS or SR-MPLS core with Penultimate Hop Popping (PHP) or Ultimate Hop Popping (UHP) disabled, the packets that are sampled should contain the MPLS label to fetch the BGP attributes.

Starting from Cisco IOS XR Software Release 24.2.1, Guidelines for BGP Attributes - MPLS Record Types on Cisco 8010 Series Routers

  • NetFlow can be configured only in the ingress direction.

  • Netflow v9, IPFIX, and IPFIX 315 support a maximum of two sampler maps.

  • A source interface must always be configured. If you do not configure a source interface, the exporter will remain in a disabled state.

  • Only export format Version 9 is supported.

  • A valid record map name must always be configured for every flow monitor map.

  • NetFlow on sub-interface routed via BVI is not supported.

  • Destination-based Netflow accounting is not supported, only IPv4, IPv6 and MPLS record types are supported under monitor-map.

  • Output interface field is not updated in data and flow records when the traffic is routed through ACL based forwarding (ABF).

  • Output interface field is not updated in data and flow records for the multicast traffic.

  • Output interface, source and destination prefix lengths fields are not set in data and flow records for GRE transit traffic.

  • In-line modification of NetFlow configuration is not supported.

  • For Netflow IPFIX315, configure the command.

  • If IPFIX315 is enabled on a line card then all the ports on that line card should have IPFIX315 configured.

  • For hw-module profile qos hqos-enable , NetFlow does not give the output interface for cases like L2 bridging, xconnect, IPFIX, and so on.

  • L4 header port numbers are supported only for TCP and UDP.

  • NetFlow does not give the output interface for traffic terminating on GRE tunnel.

Netflow Specific Guidelines and Limitations:

  • NetFlow can be configured only in the ingress direction.

  • Supports up to 4 sampling Rates (or Intervals) per ethernet line card; there is no such limit for enhanced ethernet line card.

  • Up to 4k interfaces/sub-interfaces can be configured with flow monitor per system (4K system limitation).

  • Supports up to 8 flow exporters per flow monitor.

  • Supports up to 1 million flow entries per line card.

  • Supports up to 50,000 flows per second with line card CPU usage up to 50% per ethernet line card.

  • Supports up to 100,000 flows per second with line card CPU usage up to 50% per enhanced ethernet line cardd.

  • Netflow scale is increased to 200,000pps on enhanced ethernet line cards.

  • Supports exporting packet rates up to 50,000 flows per second (100,000 flows per second on enhanced ethernet line cards) with line card CPU usage up to 50%.

  • A source interface must always be configured. If you do not configure a source interface, the exporter will remain in a disabled state.

  • When the netflow configuration for VPNv4 or VPNv6 is applied in label allocation mode (either per prefix or per CE) then the IPv4 or IPv6 netflow do not capture the BGP attributes such as BGP nh, BGP AS numbers and prefix lengths; these attributes values are set to zero.

  • Under VPNv4 and VPNv6 label allocation mode per vrf, BGP attributes, source and destination lengths are captured but AS numbers are not captured.

  • Netflow is not supported on BNG subscriber.

  • Only export format Version 9 and IPFIX is supported.

  • A valid record map name must always be configured for every flow monitor map.

  • NetFlow is not supported on Bridge Virtual Interface (BVI).

  • NetFlow is not supported on sub-interfaces.

  • NetFlow on sub-interface routed via BVI is not supported.

  • Destination-based Netflow accounting is not supported, only IPv4, IPv6 and MPLS record types are supported under monitor-map.

  • Output interface field is not updated in data and flow records when the traffic is routed through ACL based forwarding (ABF).

  • Output interface field is not updated in data and flow records for the multicast traffic.

  • Output interface, source and destination prefix lengths fields are not set in data and flow records for GRE transit traffic.

  • L4 header port numbers are supported only for TCP and UDP.

  • In-line modification of the flow attribute record of NetFlow configuration is not supported.

  • NetFlow does not give the output interface for traffic terminating on GRE tunnel.

  • If full packet capture is disabled, then NetFlow captures only IPv4 and IPv6 packets. To enable packet flow for IPv4, IPv6, and L2VPN psuedo wire packets, enable the hw-module profile netflow fpc-enable location command.

Flow Filter Specific Guidelines and Limitations

  • NetFlow flow filter is supported on physical interface, physical subinterface, bundle interface, and bundle subinterface.

  • NetFlow flow filter is not supported on satellite access interface, ICL interface and clusters.

  • Flow filter for MPLS traffic netflow is not supported

IPFIX Specific Guidelines and Limitations

  • If IPFIX315 is enabled on a line card then all the ports on that line card should have IPFIX315 configured.

  • For hw-module profile qos hqos-enable , NetFlow does not give the output interface for cases like L2 bridging, xconnect, IPFIX, and so on.

  • IPFIX does not support variable-length information element in the IPFIX template

  • IPFIX does not support Stream Control Transmission Protocol (SCTP) as the transport protocol