Wanguard 6.2 User Guide
Appendix 2 – Configuring NetFlow Data Export
Appendix 2 – Configuring NetFlow Data Export
This appendix is a brief guide to setting up the NetFlow data export (NDE) on Cisco and Juniper routers or
intelligent Cisco Layer 2/Layer 3/Layer 4 switches. If you have problems with the configuration, contact your network
administrator or consultant. For devices that run hybrid mode on a Supervisor Engine (Catalyst 65xx series), it is
recommended to configure IOS NDE on the MSFC card and CatOS NDE on the Supervisor Engine. For more
information about setting up NetFlow on Cisco, please visit
http://www.cisco.com/go/netflow
Configuring NDE on older IOS Devices
In the configuration mode on the router or MSFC, issue the following to start NetFlow Export.
First, enable Cisco Express Forwarding:
router(config)# ip cef
router(config)# ip cef distributed
T
urn on flow accounting for each input interface with the interface command:
interface
ip route-cache flow
For example:
interface FastEthernet0
ip route-cache flow
interface Serial2/1
ip route-cache flow
It is necessary to enable NetFlow on all interfaces through which traffic (you are interested in) will flow. Now,
verify that the router (or switch) is generating flow stats – try command 'show ip cache flow'. Note that for routers
with distributed switching (GSR's, 75XX's) the RP cli will only show flows that made it up to the RP. To see flows on
the individual line cards use the 'attach' or 'if-con' command and issue the 'sh ip ca fl' on each LC.
Enable the exports of these flows with the global commands:
router(config)# ip flow-export version 5
router(config)# ip flow-export destination <ip_address> 2000
router(config)# ip flow-export source FastEthernet0
Use the IP address of the server running the Flow Sensor and the configured listening port. UDP port 2000 is
used as an example. The ‘ip flow-export source’ command is used to set up the source IP address of the exports sent
by the equipment.
If your router uses the BGP protocol, you can configure AS to be included in exports with command:
router(config)# ip flow-export version 5 [peer-as | origin-as]
- 105 -
Summary of Contents for wanguard 6.2
Page 1: ......