Cisco TrustSec Fields in Flexible NetFlow
The Flexible NetFlow Export of Cisco TrustSec Fields feature supports the Cisco TrustSec fields in the Flexible NetFlow (FNF) flow record and helps to monitor, troubleshoot, and identify non-standard behavior for Cisco TrustSec deployments.
Note |
Flexible netflow records and recording of Cisco TrustSec fields in the IP packets only work on IPv4 packets. IPv6 packets do not support capture of Cisco TrustSec fields. |
The Cisco TrustSec fields, source security group tag (SGT) and destination security group tag (DGT) in the Flexible NetFlow (FNF) flow records help administrators correlate the flow with identity information. It enables network engineers to gain a detailed understanding of the customer use of the network and application resources. This information can then be used to efficiently plan and allocate access and application resources and to detect and resolve potential security and policy violations.
The Cisco TrustSec fields are supported for ingress FNF and for unicast and multicast traffic.
The following table presents Netflow v9 enterprise specific field types for Cisco TrustSec that are used in the FNF templates for the Cisco TrustSec source and destination source group tags.
ID |
Description |
---|---|
CTS_SRC_GROUP_TAG |
Cisco Trusted Security Source Group Tag |
CTS_DST_GROUP_TAG |
Cisco Trusted Security Destination Group Tag |
The Cisco TrustSec fields are configured in addition to the existing match fields under the FNF flow record. The following configurations are used to add the Cisco TrustSec flow objects to the FNF flow record as non-key fields and to configure the source and destination security group tags for the packet.
The collect flow cts {source | destination} group-tag command is configured under flow record to specify the Cisco TrustSec fields as non-key fields. The values in non-key fields are added to flows to provide additional information about the traffic in the flows.
The flow record is then configured under flow monitor and the flow monitor is applied to the interface. To export the FNF data, a flow exporter needs to be configured and then added under the flow monitor.