Escolar Documentos
Profissional Documentos
Cultura Documentos
Analysis - 9.3.3
Set Up the Routers
Date:
25-Oct-2016
25-Oct-2016
3/6
Table of Contents
25-Oct-2016
5/6
12 - IPV4_DST_ADDR
14 - OUTPUT_SNMP
Follow these steps:
1. Back up the current router configuration.
2. Configure NetFlow export for each interface individually:
a. Set the flow export version.
b. Set the flow source IP address. Cisco recommends that you configure a loopback
source interface. The IP addresses of non-loopbacked interfaces can change.
c. Set the flow destination IP address and set the destination port to 9995. If you are
using a custom value for the harvester listening port, use that value as the destination
port. The port values must match or the Harvester does not receive flow data.
d. Set the flow expiration timeout to 1 minute.
3. Enable flow for each interface.
NetFlow v5 or v5-compatible flow:
Monitoring multiple interfaces on a router: Use either all ingress or all egress. Use the
same option for all of the interfaces. Ingress and egress values may vary slightly due to
routers dropping packets and changing ToS values as traffic travels between
interfaces.
Monitoring a single known interface on a router: Use ingress and egress. This option
results in fewer total flows from the router to the Harvester and puts less load on the
network and the Harvester.
NetFlow v9 or v9-compatible flow:
The Harvester identifies and deduplicates multiple flows on a single router, so you can use
ingress and egress on multiple interfaces. You may find it most efficient to use this option
for two or three interfaces. You have the option to enable ingress and egress across all
interfaces, but this configuration may put an unnecessary burden on the Harvester.
4. Configure SNMP index persistence on each router that supports this feature.
More information:
NetFlow Version 9 Flow-Record Format (http://www.cisco.com/en/US/technologies/tk648
/tk362/technologies_white_paper09186a00800a3db9.html)
25-Oct-2016
6/6