Netflow Configuration Guide, Cisco IOS Release 15S
Total Page:16
File Type:pdf, Size:1020Kb
NetFlow Configuration Guide, Cisco IOS Release 15S Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY. The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California. NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http:// www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) © 2014 Cisco Systems, Inc. All rights reserved. CONTENTS CHAPTER 1 Cisco IOS NetFlow Overview 1 Finding Feature Information 1 Information About Cisco IOS NetFlow 1 The NetFlow Application 1 NetFlow Benefits Monitoring Analysis and Planning Security and Accounting and Billing 2 NetFlow Cisco IOS Packaging Information 3 NetFlow Flows 3 NetFlow Main Cache Operation 4 NetFlow Data Capture 4 NetFlow Export Formats 4 NetFlow Operation Processing Order of NetFlow Features 5 NetFlow Preprocessing Features Filtering and Sampling 5 NetFlow Advanced Features and Services BGP Next Hop Multicast MPLS NetFlow Layer 2 6 NetFlow Postprocessing Features Aggregation Schemes and Export to Multiple Destinations 7 NetFlow MIBs 7 How to Configure Cisco IOS NetFlow 7 Configuration Examples for Cisco IOS NetFlow 8 Where to Go Next 8 Additional References 8 Glossary 10 CHAPTER 2 Getting Started with Configuring Cisco IOS NetFlow and NetFlow Data Export 13 Finding Feature Information 13 Prerequisites for Configuring NetFlow and NetFlow Data Export 14 Restrictions for Configuring NetFlow and NetFlow Data Export 14 NetFlow Data Capture 14 NetFlow Configuration Guide, Cisco IOS Release 15S iii Contents NetFlow Data Export 15 Information About Configuring NetFlow and NetFlow Data Export 15 NetFlow Data Capture 15 NetFlow Flows Key Fields 16 NetFlow Data Export Using the Version 9 Export Format 16 How to Configure NetFlow and NetFlow Data Export 16 Configuring NetFlow and NetFlow Data Export Using the Version 9 Export Format 16 Verifying That NetFlow Is Operational and View NetFlow Statistics 18 Verifying That NetFlow Data Export Is Operational 21 Configuration Examples for Configuring NetFlow and NetFlow Data Export 21 Example Configuring Egress NetFlow Accounting 21 Example Configuring NetFlow Subinterface Support 22 Example Configuring NetFlow Multiple Export Destinations 22 Example Configuring NetFlow and NetFlow Data Export Using the Version 9 Export Format 22 Example Configuring NetFlow for Analyzing PPPoE Session Traffic 23 Additional References 23 Feature Information for Configuring NetFlow and NetFlow Data Export 25 Glossary 27 CHAPTER 3 Configuring NetFlow and NetFlow Data Export 29 Finding Feature Information 29 Prerequisites for Configuring NetFlow and NetFlow Data Export 29 Restrictions for Configuring NetFlow and NetFlow Data Export 30 NetFlow Data Capture 31 NetFlow Data Export 32 Information About Configuring NetFlow and NetFlow Data Export 32 NetFlow Data Capture 32 NetFlow Flows Key Fields 33 NetFlow Cache Management and Data Export 33 NetFlow Export Format Versions 9 8 5 and 1 34 Overview 34 Details 35 NetFlow Export Version Formats 35 NetFlow Export Packet Header Format 36 NetFlow Configuration Guide, Cisco IOS Release 15S iv Contents NetFlow Flow Record and Export Format Content Information 37 NetFlow Data Export Format Selection 41 NetFlow Version 9 Data Export Format 42 NetFlow Version 8 Data Export Format 44 NetFlow Version 5 Data Export Format 45 NetFlow Version 1 Data Export Format 47 Egress NetFlow Accounting Benefits NetFlow Accounting Simplified 48 NetFlow Subinterface Support Benefits Fine-Tuning Your Data Collection 49 NetFlow Multiple Export Destinations Benefits 49 NetFlow on a Distributed VIP Interface 50 How to Configure NetFlow and NetFlow Data Export 50 Configuring NetFlow 50 Verifying that NetFlow Is Operational and Displaying NetFlow Statistics 51 Configuring NetFlow Data Export Using the Version 9 Export Format 54 Verifying that NetFlow Data Export Is Operational 57 Clearing NetFlow Statistics on the Router 58 Customizing the NetFlow Main Cache Parameters 58 NetFlow Cache Entry Management on a Routing Device 58 NetFlow Cache Size 59 Configuration Examples for Configuring NetFlow and NetFlow Data Export 62 Example Configuring Egress NetFlow Accounting 62 Example Configuring NetFlow Subinterface Support 62 NetFlow Subinterface Support for Ingress (Received) Traffic on a Subinterface 62 NetFlow SubInterface Support for Egress (Transmitted) Traffic on a Subinterface 63 Example Configuring NetFlow Multiple Export Destinations 63 Example Configuring NetFlow Version 5 Data Export 63 Example Configuring NetFlow Version 1 Data Export 64 Additional References 64 Feature Information for Configuring NetFlow and NetFlow Data Export 66 Glossary 67 CHAPTER 4 Configuring NetFlow BGP Next Hop Support for Accounting and Analysis 69 Finding Feature Information 69 Prerequisites for NetFlow BGP Next Hop Support 70 Restrictions for NetFlow BGP Next Hop Support 70 NetFlow Configuration Guide, Cisco IOS Release 15S v Contents Information About NetFlow BGP Next Hop Support 71 NetFlow BGP Next Hop Support Benefits 71 NetFlow BGP Next Hop Support and NetFlow Aggregation 71 How to Configure NetFlow BGP Next Hop Support 71 Configuring NetFlow BGP Next Hop Accounting 71 Troubleshooting Tips 73 Verifying the Configuration 73 Configuration Examples for NetFlow BGP Next Hop Support 75 Example Configuring NetFlow BGP Next Hop Accounting 75 Additional References 76 Feature Information for NetFlow BGP Next Hop Support 77 Glossary 78 CHAPTER 5 Configuring MPLS Egress NetFlow Accounting and Analysis 79 Finding Feature Information 79 Prerequisites for Configuring MPLS Egress NetFlow Accounting 80 Restrictions for Configuring MPLS Egress NetFlow Accounting 80 Information About Configuring MPLS Egress NetFlow Accounting 81 MPLS Egress NetFlow Accounting Benefits Enhanced Network Monitoring and More Accurate Accounting Statistics 81 MPLS VPN Flow Capture with MPLS Egress NetFlow Accounting 81 How to Configure MPLS Egress NetFlow Accounting 82 Configuring MPLS Egress NetFlow Accounting 82 Troubleshooting Tips 83 Verifying MPLS Egress NetFlow Accounting Configuration 83 Configuration Examples for Configuring MPLS Egress NetFlow Accounting 86 Enabling MPLS Egress NetFlow Accounting Example 86 Additional References 87 Feature Information for Configuring MPLS Egress NetFlow Accounting 89 Glossary 89 CHAPTER 6 Configuring SNMP and using the NetFlow MIB to Monitor NetFlow Data 91 Finding Feature Information 91 Prerequisites for Configuring SNMP and the NetFlow MIB to Monitor NetFlow Data 92 Restrictions for Configuring SNMP and the NetFlow MIB to Monitor NetFlow Data 92 NetFlow Configuration Guide, Cisco IOS Release 15S vi Contents Information About Configuring SNMP and the NetFlow MIB to Monitor NetFlow Data 92 NetFlow MIB Feature Benefits 92 NetFlow MIB Overview 93 Terminology Used 93 Using SNMP and MIBs to Extract NetFlow Information 94 Objects That are Used by the NetFlow MIB 94 How to Configure SNMP and use the NetFlow MIB to Monitor NetFlow Data 95 Configuring the Router to use SNMP 95 Configuring Options for the Main Cache 96 Configuring Options for the Main Cache 98 Identifying the Interface Number to use for Enabling NetFlow with SNMP 99 Configuring NetFlow on an Interface 99 Configuring NetFlow on an Interface 101 Configuring