Configuring NetFlow
15-2 NetFlow Configuration
•IthasaccumulatedthemaximumnumberofNetFlowrecordsperpacket,whichis30,or
•Ithasaccumulatedfewerthan30NetFlowrecordsandtheactiveflowtimerhasexpired,or
•Theflowexpires(agesoutorisinvalidated).
Version Support
TheEnterasysMatrixDFEfirmwaresupportsNetFlowVersion5and Version9.Formore
informationaboutVersion9dataexportformat,refertoRFC3954,“CiscoSystemsNetFlow
ServicesExportVersion9.”
WhentransmittingNetFlowVersion5reports,theDFEbladeuses“netflowinterface”indexes.
NormallythesewouldbeactualMIB‐
2ifIndexvalues,buttheVersion5recordformatlimitsthe
valuesto2bytes,whichisnotsufficienttohold4byteifIndexes.NetFlowcollectorapplications
thatusethein/outinterfaceindexestogatherSNMPdataabouttheinterface(suchasifName)
musttranslatetheinterfaceindexesusingtheEnterasys
MIBetsysNetflowMIB
(1.3.1.6.1.4.1.5624.1.2.61).
NetFlowVersion9recordsgeneratedbyDFEbladesusetrueMIB‐2ifIndexvaluessincethe
templatemechanismpermitstransmissi on of4byteifIndexes.Version9alsouses8bytepacket
andbytecounters,sotheyarelesslikelytorollover.Checkwithyourcollectorproviderto
determineiftheyprovidethenecessarysupport.
ThecurrentVersion9implementation:
•Doesnotsupportaggregationcaches
•Provides4predefinedtemplates.Theappropriatetemplateisselectedforeachflow
dependingonwhethertheflowisroutedorswitched,andwhetheritisaTCP/UDPpacketor
not.
Version9templatesarere‐
transmittedwhen:
•Thetimeoutisreached.Thedefaultis30minutesbutisuserconfigurableusingtheset
netflowtemplatetimeoutcommand(“setnetflowtemplate”onpage 15‐9).
Templatesaresentfromeverybladewhenthetimeoutisreached.
•Thepacketrefreshrateisreached.Thedefaultisevery20packets,
butisuserconfigurable
usingthesetnetflowtemplaterefresh‐ratecommand(“setnetflowtemplate”onpage 15‐9).
Templatesaresentasaresultoftherefreshratebyeachblade,sinceeachbladehandlesitʹsown
packettransmission.Forflowgenerationandprocessingefficiencyreasons,Enterasys
recommends
thatcustomersconfiguretheirEnterasysMatrixsy stemssothattemplatesarenot
generatedmoreoftenthanoncepersecond,asaminimum.Formoreinformationaboutsetting
therefreshrate,seetheUsagediscussionin“setnetflowtemplate”onpage 15‐9.
Commands
Note: A flow is a unidirectional sequence of packets having a set of common properties, travelling
between between a source and a destination endpoint. A flow is created on the Enterasys Matrix
device when the MAC destination address of a packet is learned on a port and torn down when
either it ages out or it is explicitly torn down by the firmware.
For information about... Refer to page...
show netflow 15-3
set netflow cache 15-4