The IP Flow Information Export (IPFIX) protocol, also called cflowd, is a tool for
-
monitoring the traffic flowing through devices in the Cisco Catalyst SD-WAN fabric, and
-
exporting information about the traffic to a flow collector.
cflowd version
Cisco Catalyst SD-WAN implements cflowd Version 10, as specified in RFC 7011 and RFC 7012.
Aggregating information
Cisco Catalyst SD-WAN Cflowd performs 1:1 traffic sampling. Information about all the flows is aggregated in the cflowd records. Flows are not sampled.
Devices do not cache any of the records that are exported to a collector.
For a list of elements exported by IPFIX, refer to the information about traffic flow monitoring with Cflowd in the Cisco Catalyst SD-WAN Policies Configuration Guide.
Enabling the collection of traffic flow information
To enable the collection of traffic flow information, you must create data policies that identify the traffic of interest, and then direct that traffic to a Cflowd collector. Refer to the information about traffic flow monitoring with Cflowd in the Cisco Catalyst SD-WAN Policies Configuration Guide.
You can also enable cflowd visibility directly on devices without configuring a data policy, so that you can perform traffic flow monitoring on the traffic coming to the device from all the VPNs in the LAN. You can then monitor the traffic from Cisco SD-WAN Manager or from the device's CLI.