Cisco Configuration Guide,Cisco SD-WAN Controllers Release 20.8.x Release 4.2

PDF

Cisco Configuration Guide,Cisco SD-WAN Controllers Release 20.8.x Release 4.2

NetFlow Version 9

Want to summarize with AI?

Log in

Overview

NetFlow Version 9 Short Desc

NetFlow Version 9 is a template-based approach that provides flexibility in the record format. It enables enhancements to NetFlow services without concurrently altering the basic flow-record format.


NetFlow Options Template

The NetFlow Options Template serves as a distinctive template record designed to communicate the format of data associated with the NetFlow operation. Instead of sharing details about IP flows, these options serve the purpose of providing metadata pertaining to the NetFlow process itself. There are distinct options templates: the sampler options template and the interface options template. The NetFlow process exports these two tables. Furthermore, the NetFlow process also exports the VRF (Virtual Routing and Forwarding) table.


Sampler Table

The Sampler Table and Interface Option Templates play a significant role in organizing information.

The Sampler Options Template consists of a sampler table, while the Interface Option Templates consists of an interface table. Enabling these options for the sampler and interface tables simplifies the process for the collector to determine data flow information.

The sampler table offers insights into active samplers. Its primary purpose is to aid the collector in estimating the sampling rate for individual data flows. The sampler table provides the following information for each sampler:

Element ID Field Name Value

48

SamplerID

This ID is assigned to the sampler. It is used by the collector to retrieve information about the sampler for a data flow record.

49

SamplerMode

This field indicates the mode in which the sampling has been performed.

50

SamplerRandomInterval

This field indicates the rate at which the sampling is performed.

84

SamplerName

This field indicates the name of the sampler.


Interface Table

The interface table, contains data about interfaces that are monitored for data flow. With this data, the collector derives the interface names linked to the data flow. The interface table contains the following information:

Field Name Value

ingressInterface

This field indicates the SNMP index assigned to the interface. By matching this value to the Ingress interface in the data flow record, the collector is able to retrieve the name of the interface.

interfaceDescription

This field indicates the name of the interface.


VRF Table

The VRF table Another chapter wrapper consists mapping of VRF IDs to the VRF names. Using this information, the collectorAnother chapter nested topic determines the name of the Same chapter parent topic required VRF.

The VRF table is Another chapter parent topic exported at intervals specified by the optional timeout keyword that can be Another chapter wrapper configured manually. The default value is Same chapter nested topic 1800 seconds.

The VRF table consists of the following information:

Field Name Value

ingressVRFID

The identifier of the VRF with the name in the VRF-Name field.

VRF-Name

The VRF name has the VRFID value ingressVRFID. The value "default" indicates that the interface is not assigned explicitly to a VRF.

The data records contain ingressVRFID as an extra field in each record. The values of these fields are used to lookup the VRF Table to find the VRF names. A value of 0 in these fields indicates that the VRF is unknown.


Configure NetFlow Version 9

Let's consider the following topology to configure NetFlow.

To monitor traffic, you must configure one or more and associate it to a Flow Monitor and enable NetFlow on the interface either in egress or ingress direction. Optionally, you can configure a to set the sampling rate for flow samples.

Procedure

1.

First, let's gather the required details to enable NetFlow on a router:

  • The IP address of the source : 2001:db8::0003

  • The IP address of the NetFlow Collector (Destination address): 2001:db8::0002

  • Interface of the router where we will enable Netflow: HundredGigE 0/0/0/24

  • NetFlow version used to transport the data to the collector: version 9

2.

Configure a Flow Exporter using the command to specify where and how the packets should be exported.

Router# configure
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table configure the port To monitor traffic
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exitRouter# configure configure the port To monitor traffic
Router(config)# flow exporter-map Expo1 
Router(config-fem)# source-address 2001:db8::0003
Router(config-fem)# destination 2001:db8::0002
Router(config-fem)# transport udp 1024
Router(config-fem)# version v9
Router(config-fem-ver)# options interface-table options interface-table options interface-table
Router(config-fem-ver)# commit
Router(config-fem-ver)# root
Router(config)#exit

Verify the Flow Exporter configuration using the command.


Router#show flow exporter-map Expo1
Flow Exporter Map : Expo1
-------------------------------------------------
Id                  : 1
Packet-Length       : 1468
DestinationIpAddr   : 2001:db8::2
VRFName             : default
SourceIfName        : 
SourceIpAddr        : 2001:db8::3
DSCP                : 0
TransportProtocol   : UDP
TransportDestPort   : 1024
Do Not Fragment     : Not Enabled

Export Version: 9
  Common Template Timeout : 1800 seconds
  Options Template Timeout : 1800 seconds
  Data Template Timeout : 1800 seconds
  Interface-Table Export Timeout : 1800 seconds
  Sampler-Table Export Timeout : 0 seconds
  VRF-Table Export Timeout : 0 seconds
3.

Create a Flow Monitor using the command to define the type of traffic to be monitored. You can include one or more exporter maps in the monitor map. A single flow monitor map can support up to eight exporters.

The record type specifies the type of packets that are sampled as the packets pass through the router. MPLS, IPv4, and IPv6 packet sampling is supported.


Router#configure
Router(config)# flow monitor-map fmm-ipv6
Router(config-fmm)# record ipv6
Router(config-fmm)# cache entries 500000
Router(config-fmm)# cache timeout active 60
Router(config-fmm)# cache timeout inactive 20
Router(config-fmm)# exporter Expo1
outer(config-fmm)# commit
Router(config-fmm)# root
Router(config)#exit

Verify the Flow Monitor configuration using the command.

Router#show flow monitor-map fmm-ipv6

Flow Monitor Map : fmm-ipv6
-------------------------------------------------
Id:                1
RecordMapName:     ipv6
ExportMapName:     Expo1
CacheAgingMode:    Normal
CacheMaxEntries:   500000
CacheActiveTout:   60 seconds
CacheInactiveTout: 20 seconds
CacheUpdateTout:   N/A
CacheRateLimit:    2000
HwCacheExists:     False
HwCacheInactTout:  50

Here are additional examples to record MPLS packets, BGP packets.

In this example, you create a flow monitor map to record the MPLS packets.


Router(config)#flow monitor-map fmm-mpls-ipv6
Router(config-fmm)#record mpls ipv6-fields labels 3
Router(config-fmm)#exporter Expo1
Router(config-fmm)#cache entries 2000000
Router(config-fmm)#cache permanent
Router(config-fmm)#exit

In this example, you create a flow monitor map to record the BGP packets with the permanent cache.


Router(config)# router bgp 50 
Router(config-bgp)# address-family ipv6 unicast
Router(config-bgp-af)# bgp attribute-download
Router(config-bgp-af)#root
Router(config)#flow monitor-map fmm-bgp
Router(config-fmm)#record ipv6 peer-as
Router(config-fmm)#exporter Expo1
Router(config-fmm)#cache entries 2000000
Router(config-fmm)#exit
4.

Configure a Flow Sampler using the command to define the rate at which the packet sampling should be performed at the interface where NetFlow is enabled. Use the same sampler map configuration on the sub-interfaces and physical interfaces under a port.

Router(config)# configure
Router(config)# sampler-map fsm1 
Router(config-sm)# random 1 out-of 262144
Router(config)# exit
Router(config)#commit
Router(config)#exit
Router#

Verify the sampler map configuration using the command.

Router#show sampler-map fsm1

Sampler Map : fsm1
-------------------------------------------------
Id:      1
Mode:    Random (1 out of 262144 Pkts)
Router#
5.

Apply a Flow Monitor Map and a Flow Sampler to a physical interface using the command to enable NetFlow on the router. You can choose to enable IPv4, IPv6, MPLS-aware NetFlow on the interface. Enable NetFlow in the ingress direction to monitor the incoming packets and enable NetFlow in the egress direction to monitor egress traffic.

Note

Consider these points before applying the sampler map:

  • Remove any existing Netflow or sFlow configurations before applying a new Flow sampler on an interface using the no form of the command.

  • Use the same sampler map configuration on the sub-interfaces and physical interfaces under a port.


Router#configure
Router(config)#interface HundredGigE 0/0/0/24
Router(config-if)#flow ipv6 monitor fmm-ipv6 sampler fsm1 ingress 
Router(config-if)#commit
Router(config-if)#root
Router(config)#exit
6.

View the running configuration to verify the configuration that you have configured.


Router# show run

flow exporter-map Expo1
 version v9
  options interface-table
 !
 transport udp 1024
 source-address 2001:db8::3
 destination 2001:db8::2
!         
flow monitor-map fmm-ipv6
 record ipv6
 exporter Expo1
 cache entries 500000
 cache timeout active 60
 cache timeout inactive 20
!         
sampler-map fsm1
 random 1 out-of 262144
!         
       
interface HundredGigE0/0/0/24
 shutdown 
 flow ipv6 monitor fmm-ipv6 sampler fsm1 ingress
!              
end       
      
7.

Verify the flows captured using the command.

In the following example, you can verify the amount of flows added and exported.


Router#show flow monitor fmm-ipv6 cache summary location 0/0/CPU0 
Cache summary for Flow Monitor monitor1:
Cache size: 1000000
Current entries: 295
Flows added: 184409
Flows not added: 0
Ager Polls: 9824
 - Active timeout 183855 
 - Inactive timeout 259
 - Immediate 0
 - TCP FIN flag 0
 - Emergency aged 0
 - Counter wrap aged 0
 - Total 184114
Periodic export:
- Counter wrap 0
- TCP FIN flag 0
Flows exported 184114

This verifies that the data is successfully exported to the collector.

What to do next

You can now analyse the exported data using a NetFlowAnalyser.

Configure MPLS-Aware NetFlow

Let's consider this topology where the PE1 router is configured with MPLS NetFlow, while the traffic flow is from Traffic Generator 2 to Traffic Generator 1.

Procedure

1.

Create a Flow Monitor using the command to define the type of traffic to be monitored.


Router#configure
Router(config)# fmm-mpls-ipv4-ipv6
Router(config-fmm)# record mpls ipv6-fields labels 3
Router(config-fmm)# cache entries 500000
Router(config-fmm)# cache timeout active 60
Router(config-fmm)# cache timeout inactive 20
Router(config-fmm)# commit
Router(config-fmm)# root
Router(config)#exit

Verify the Flow Monitor configuration using the command.

Router#show flow monitor-map fmm-ipv6

Flow Monitor Map : fmm-ipv6
-------------------------------------------------
Id:                1
RecordMapName:     ipv6
ExportMapName:     Expo1
CacheAgingMode:    Normal
CacheMaxEntries:   500000
CacheActiveTout:   60 seconds
CacheInactiveTout: 20 seconds
CacheUpdateTout:   N/A
CacheRateLimit:    2000
HwCacheExists:     False
HwCacheInactTout:  50
2.

Configure a Flow Sampler using the command to define the rate at which the packet sampling should be performed at the interface where NetFlow is enabled. Use the same sampler map configuration on the sub-interfaces and physical interfaces under a port.

Router(config)# configure
Router(config)# sampler-map fsm1 
Router(config-sm)# random 1 out-of 262144
Router(config)# exit
Router(config)#commit
Router(config)#exit
Router#

Verify the sampler map configuration using the command.

Router#show sampler-map fsm1

Sampler Map : fsm1
-------------------------------------------------
Id:      1
Mode:    Random (1 out of 262144 Pkts)
Router#
3.

Apply a Flow Monitor Map and a Flow Sampler to a physical interface using the command to enable NetFlow on the router.


Router#configure
Router(config)#interface HundredGigE 0/0/0/24
Router(config-if)#flow mpls monitor fmm-mpls-ipv4-ipv6 sampler fsm1 ingress 
Router(config-if)#commit
Router(config-if)#root
Router(config)#exit
4.

Verify the OutputInterface value is 0 in last two rows for captured ingress netflow records on PW-tail end node; the command is executed on the PE1 router:


Router#show flow monitor fmm-mpls-ipv4-ipv6 cache location 0/0/cPU0
Cache summary for Flow Monitor fmm-mpls-ipv4-ipv6:
Cache size:                          10000
Current entries:                        20
Flows added:                            20
Flows not added:                         0
Ager Polls:                             77
  - Active timeout                       0
  - Inactive timeout                     0
  - TCP FIN flag                         0
  - Emergency aged                       0
  - Counter wrap aged                    0
  - Total                                0
Periodic export:
  - Counter wrap                         0
  - TCP FIN flag                         0
Flows exported                           0

LabelType Prefix/Length      Label1-EXP-S     Label2-EXP-S     Label3-EXP-S     Label4-EXP-S     Label5-EXP-S     Label6-EXP-S     InputInterface  OutputInterface ForwardStatus        FirstSwitched   LastSwitched    ByteCount    PacketCount  Dir SamplerID  InputVRFID                        OutputVRFID
  Unknown 0.0.0.0/0                 0-0-0        16001-0-1           -                -                -                -          AT0/1/1/2.1     Gi0/0/0/0       Fwd                  00 00:50:37:458 00 00:50:48:947 69078        1047         Egr 3          default                           default
  Unknown 0.0.0.0/0                 0-0-0        16057-0-1           -                -                -                -          AT0/1/1/2.58    Gi0/0/0/0       Fwd                  00 00:50:37:464 00 00:50:48:953 69078        1047         Egr 3          default                           default
  Unknown 0.0.0.0/0                 0-0-0        16059-0-1           -                -                -                -          AT0/1/1/2.6     Gi0/0/0/0       Fwd                  00 00:50:37:459 00 00:50:48:947 69078        1047         Egr 3          default                           default
  Unknown 0.0.0.0/0                 0-0-0        16022-0-1           -                -                -                -          AT0/1/1/2.26    Gi0/0/0/0       Fwd                  00 00:50:42:339 00 00:50:48:950 39336        596          Egr 3          default                           default
  Unknown 0.0.0.0/0                 0-0-0        16041-0-1           -                -                -                -          Gi0/0/0/0       0               Fwd                  00 00:50:42:340 00 00:50:48:951 39336        596          Ing 1          default                           0
  Unknown 0.0.0.0/0                 0-0-0        16023-0-1           -                -                -                -          Gi0/0/0/0       0               Fwd                  00 00:50:42:339 00 00:50:48:950 39336        596          Ing 1          default    

This verifies that the data is successfully exported to the collector.

What to do next

You can now analyse the exported data using a NetFlowAnalyser.

Modify NetFlow Configuration

You can modify only the following flow attributes that is already applied to an interface for a monitor map, exporter map, or a sampler map.

Note that when you modify the flow attributes, the cache counters are cleared and results in resetting of the counters. As a result there could be flow accounting mismatch.

Table 1. Flow Entities and Flow Attributes that can be altered

Flow Entity

Flow Attribute

Command

Monitor map

cache timeout

  • active

  • inactive

  • update

  • rate-limit

exporter

cache entries

cache permanent

options outphysint | bgstrings

Exporter Map

source <source interface>

destination <destinaiton address>

dscp <dscp_value>

version v9 | ipfix

Sampler Map

sampling interval