Showing posts with label netflow. Show all posts
Showing posts with label netflow. Show all posts

Wednesday, March 23, 2011

SolarWinds Orion Part 3 - Netflow

Basic interface monitoring on SNMP probably only get you some bandwidth utilization rate. But it won't give further insights and break-down on the network applications, like which is the most talkative applications? Which node generate the most traffic? To gain deeper insights, you have to enable netflow monitoring on the routers and use a netflow management console (e.g. Solarwinds Netflow module known as "Netflow Traffic Analyzer") to view the reports.

To enable netflow on the managed node:
!
Choose a netflow version (either 5 or 9) depending on your netflow console support. Solarwinds supports both versions
(config)# ip flow-export version 9
!
Send the netflow traffic to your netflow server's IP address and designated port no. VRF is optional but we use it for Out-of-band monitoring(config)# ip flow-export destination 10.10.10.10 1055 vrf vrf-name
!
Choose an interface that should report to the netflow server(config)# ip flow-export source interface-name
!
On the interfaces that you want to monitor. Add these commands at the interface level.(config-if)# ip flow ingress
(config-if)# ip flow egress

The above example is to monitor all traffic entering and leaving the interface. If you wish to monitor a specific flow, you can replace the above with Cisco Flexible Netflow (click on example). For Juniper J-flow configuration, refer to this example.



Login to your netflow server console and you should see netflow messages saying that new netflow information are being recieved and added automatically. If it doesn't, you have to ensure that the node and interfaces have been added to the Orion core. Leave it running for some time and you should start seeing detailed graphs.

Monday, March 8, 2010

Cisco Flexible Netflow

Cisco NetFlow is a IP traffic monitoring protocol used in Cisco IOS devices - mainly used for bandwidth monitoring and other reporting purposes, such as billings. A simple netflow configuration may look like this

1) To create flow export to a server:
ip flow-export destination {hostname|ip_address} {port no.}

2) Apply on interface:
interface {interface} {interface_number}
ip route-cache flow

As you can see, almost every traffic will be exported out. What if you want to monitor only a specific flow? Cisco now introduces Flexible Netflow, which export v9 and v5 (from Cisco 12.4(22)T). A simple configuration may now look like this:

(define the specific flow that you are interested in)
flow record app-traffic-analysis
description This flow record tracks TCP application usage
match transport tcp destination-port
match transport tcp source-port
match ipv4 destination address
match ipv4 source address
collect counter bytes
collect counter packets

(export to a netflow analyzer)
flow exporter export-to-server
destination 172.16.1.1
flow monitor my-flow-monitor
record app-traffic-analysis
exporter export-to-server

(apply on an interface)
interface Ethernet 1/0
ip flow monitor my-flow-monitor input

Of course, you would also need netflow analyzer software to process these collected data. There are several on the Internet that you can try out, including this free version ManageEngine Netflow Analyzer that supports up to 2 interfaces.

References:
  1. Getting Started with Configuring Cisco IOS Flexible NetFlow
  2. Cisco IOS Flexible NetFlow Technology Q&A

Sunday, August 30, 2009

Bandwidth Measurement using Cisco Netflow

Netflow is great and handy to measure the amount of resources used in a typical Cisco network. Netflow comes with 3 versions: v1, v5 and v9. The most common version is v5. Recently, I have to justify for the amount of bandwidth upgrade for our Internet access - with a breakdown of the Internet application usage e.g. http, ftp, p2p etc. I configured the Internet router to keep pumping netflow data to a Netflow collector. I used an eval copy of PRTG network monitor (http://www.paessler.com/prtg)

The setup is amazingly simple:
On the router,
interface [WAN]
ip route-cache flow
ip flow-export version 5 peer-as
ip flow-export destination [Server IP] [UDP port]


Make sure that the Netflow collector is also configured with the matching server IP address and UDP port number. Few days later, I presented this chart to get my boss to agree on the bandwidth upgrade.