Wanguard 6.2 User Guide
Appendix 2 – Configuring NetFlow Data Export
The following commands break up flows into shorter segments: 1 minute for active traffic and 30 seconds
for inactive traffic. Flow Sensor drops flows older than 5 minutes!
router(config)# ip flow-cache timeout active 1
router(config)# ip flow-cache timeout inactive 30
In enable mode you can see current NetFlow configuration and state.
router# show ip flow export
router# show ip cache flow
router# show ip cache verbose flow
Configuring NDE on a CatOS Device
In privileged mode on the Supervisor Engine enable NDE:
switch> (enable) set mls nde <ip_address> 2000
Use the IP address of the server running the Flow Sensor and the configured listening port. UDP port 2000 is
used only as an example.
switch> (enable) set mls nde version 5
The following command is required to set up flow mask to full flows.
switch> (enable) set mls flow full
The following commands break up flows into shorter segments: ~1 minute for active flows and ~ 30 seconds
for inactive flows. Flow Sensor drops flows older than 5 minutes!
switch> (enable) set mls agingtime long 8
switch> (enable) set mls agingtime 4
If you want to account all traffic within the specified VLANs rather than inter VLAN traffic use CatOS 7.2 or
higher and issue the following command:
switch> (enable) set mls bridged-flow-statistics enable
Enable NDE:
switch> (enable) set mls nde enable
To see current NetFlow configuration and state issue the following commands:
switch> (enable) show mls nde
switch> (enable) show mls debug
Configuring NDE on a Native IOS Device
To configure NDE use the same commands as for the IOS device. In the enable mode on the Supervisor
Engine, issue the following to set up the NetFlow export version 5.
- 106 -
Summary of Contents for wanguard 6.2
Page 1: ......