74-4
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
 
Chapter 74      Configuring Flexible NetFlow
VSS Environment
For example, when the user tries to configure an exporter destination address using a sixth VRF limit 
is exceeded, the following warning is displayed:
flow exporter e10
        destination 20.1.20.4 vrf blue
%%Warning - Netflow exporter on Cat4k VSS switch cannot exceed a total max of 5 vrfs 
used for destination address
configuration. Flow exporter e10 cannot export in vrf blue.
22. Flow aging in flow cache is controlled through active and in-active timer configuration. The 
minimum for active and in-active aging timers is 5 seconds. The timers must be in units of 5 seconds.
Note Flows in the hardware table are deleted after 5 seconds of in-activity irrespective of the active 
or in-active timer configuration values. This allows you to create new hardware flows quickly.
23. First and Last-seen flow timestamp accuracy is within 3 seconds.
24. 2048 Flow monitors and records are supported.
When TTL is configured as a flow field, the following values are reported for a given packet TTL 
value. Table 74-1 lists the packet TTL and reported values.
25. Cisco TrustSec (CTS) fields are supported. These fields use Netflow collector to monitor and 
troubleshoot the CTS network, and to segregate traffic based on source group tag (SGT) values.
–
When configuring the source group tag (collect flow cts source group-tag), note the following:
The system copies the packets to software before it retrieves the CTS field. A large number of 
flows mean that a large number of packets are copied to the software, possibly affecting CPU 
performance.
The maximum number of (unique) hosts allowed in the switch (IP addresses) is 12,000.
In case of burst packets, the software may not be able to retrieve the CTS field because the 
software queue is throttled.
–
When configuring the destination group tag (collect flow cts destination group-tag), note that 
this CTS field value is collected only if you have already configured an IP-to-SGT mapping.
–
When configuring switch-derived source group tags (collect flow cts switch derived-sgt), note 
that the switch derives this value locally.
–
When configuring CTS fields on Supervisor Engine 8-E, note that CTS fields are not supported 
on wireless interfaces (WLAN) and SSID.
Table 74-1 TTL Map: TTL Configured
Packet TT Value Reported Value
00
11
2-10 10
11-25 25
26-50 50
51-100 100