- Cisco Nexus Data Broker Overview
- Deploying Cisco Nexus Data Broker
- Managing TLS Certificate, KeyStore, and TrustStore Files
- Logging in and Managing Cisco Nexus Data Broker
- Configuring Cisco Nexus 9000 Series Switches
- Managing Devices
- Configuring Ports and Devices
- Filtering Flows
- Managing Roles and Resources
- Managing Flows
- Troubleshooting
- Managing Slices
- Administrative Tasks
Filtering Flows
This chapter contains the following sections:
- About Cisco Nexus Data Broker Networks
- About Forwarding Path Options
- About Filters and Connections
- Adding a Filter
- Editing a Filter
- Deleting a Filter
- Adding a Connection
- Modifying a Connection
- Cloning a Connection
- Removing a Connection
About Cisco Nexus Data Broker Networks
A Cisco Nexus Data Broker network consists of one or more Cisco Nexus 3000, 3100, or 3500 Series switches and Cisco Nexus 9000 Series switches with Cisco Plug-in for OpenFlow and for NX-API dedicated for connecting multiple spanned ports and network taps from the production network infrastructure. Cisco Nexus Data Broker programs the switches using the OpenFlow protocol. Cisco Nexus Data Broker filters the packets that travel the network and delivers them to a pool of connected monitoring devices.
About Forwarding Path Options
Cisco Nexus Data Broker supports the following forwarding path options:
-
Multipoint-to-Multipoint—With the Multipoint-to-Multipoint (MP2MP) forwarding path option, both the ingress edge port where SPAN or TAP traffic is coming into the monitor network and the egress delivery ports are defined. Cisco Nexus Data Broker uses the delivery ports to direct traffic from those ingress ports to one or more devices.
-
Any-to-Multipoint—With the Any-to-Multipoint (A2MP) forwarding path option, the ingress edge port of the monitor network is not known, but the egress delivery ports are defined. Cisco Nexus Data Broker automatically calculates a loop-free forwarding path from the root node to all other nodes using the Single Source Shortest Path (SSSP) algorithm.
About Filters and Connections
Filters
In Cisco Nexus Data Broker, you can use a filter to define the Layer 2 (L2), Layer 3 (L3), and Layer 4 (L4) criteria used to filter traffic. Traffic that matches the criteria in the filter is routed to the delivery ports and from there to the attached monitor devices.
Connections
You can use connections to associate filters to configured monitor devices. You can configure connections with or without a source. Connections with a source node and port use the Multipoint-to-Multipoint forwarding path option. Connections without a source port on a node use the loop-free Any-to-Multipoint forwarding path option.
When a rule is configured with the Deny option, the ingress edge ports may or may not be defined. Cisco nexus Data Broker drops traffic on the specified ingress edge port(s) or on all nodes if no ingress edge ports are defined.
Each rule has a priority that can be configured. Connections with a higher priority are given precedence over those with a lower priority.
Connections can be created and saved without installing them. After they are saved, installation can be toggled on and off in the Cisco nexus Data Broker GUI.
![]() Note | After the connections are installed or uninstalled using the Toggle functionality in Cisco Nexus Data Broker, the device should not be rebooted for 120 secs. Otherwise the configured parameters by Cisco Nexus Data Broker are not saved and you might see a inconsistency between Cisco Nexus Data Broker and the device. |
Default Filter
Cisco Nexus Data Broker is pre-installed with a default filter to match all traffic. The default filter is created using pre-defined Ethernet types as the match selection. The name of the default filter is default-match-all. This filter is available out-of-the-box when Cisco Nexus Data Broker starts up from scratch.
Adding a Filter
Editing a Filter
You must add a filter before you can edit it.
![]() Note | You cannot change the filter Name in the Edit Filter dialog box. |
| Step 1 | On the Configure Filters tab, click the Edit button next to the Name of the filter that you want to edit. | ||||||||||||||
| Step 2 | In the
Edit
Filter dialog box, edit the following fields:
| ||||||||||||||
| Step 3 | In the
Layer
2 section of the
Edit
Filter dialog box, edit the following fields:
| ||||||||||||||
| Step 4 | In the
Layer
3 section of the
Edit
Filter dialog box, edit the following fields:
|
Deleting a Filter
You can delete a filter that has associated rules, resulting in removal of all the rules at the same time.
| Step 1 | On the Configure Filters tab, check the check box next to filter or filters that you want to delete, and then click Remove Filters. When filters have rules associated with them, this information is displayed in the Remove Filters dialog box. |
| Step 2 | In the Remove Filters dialog box, click Remove Filters. |
Adding a Connection
| Step 1 | On the Connection Setup tab, click New Connection. | ||||||||||||||||||
| Step 2 | In the
New
Connection dialog box, you can add the
Connection Name and the
Priority of the connection in the
Connection Details
area:
| ||||||||||||||||||
| Step 3 | In the
Allow
Matching Traffic area, modify the following fields:
| ||||||||||||||||||
| Step 4 | In the
Drop
Matching Trafficarea, complete the following fields:
| ||||||||||||||||||
| Step 5 | In the
Source
Ports (Optional)area, complete the following fields:
| ||||||||||||||||||
| Step 6 | Do one of the following: |
Modifying a Connection
You must add a connection before you can modify it.
| Step 1 | On the Connection Setup tab, click the Edit button next to the Name of the connection that you want to modify. | ||||||||||||||||||
| Step 2 | In the
Modify
Connection dialog box, you can modify the
Connection Name and the
Priority of the connection in the
Connection Details
area:
| ||||||||||||||||||
| Step 3 | In the
Allow
Matching Traffic area, modify the following fields:
| ||||||||||||||||||
| Step 4 | In the
Drop
Matching Trafficarea, complete the following fields:
| ||||||||||||||||||
| Step 5 | In the
Source
Ports (Optional)area, complete the following fields:
| ||||||||||||||||||
| Step 6 | Click Submit or Close. |
Cloning a Connection
You must add a connection before you can modify it.
| Step 1 | On the Connection Setup tab, click the Clone next to the Name of the connection that you want to clone. | ||||||||||||||||||
| Step 2 | In the
Clone
Connection dialog box, you can modify the
Connection Name and the
Priority of the connection in the
Connection Details
area:
| ||||||||||||||||||
| Step 3 | In the
Allow
Matching Traffic area, modify the following fields:
| ||||||||||||||||||
| Step 4 | In the
Drop
Matching Traffic area, complete the following fields:
| ||||||||||||||||||
| Step 5 | In the
Source
Ports (Optional) area, complete the following fields:
| ||||||||||||||||||
| Step 6 | Do one of the following: |

Feedback