Specifications
May 18, 2011 Page 1 of 21
Configuring NetFlow
ThisdocumentdescribestheNetFlowfeatureanditsconfigurationonEnterasys
®
N‐Series,
S‐Series,K‐Series,andX‐Seriesmodularswitches.
What Is NetFlow?
NetFlowisaflow‐baseddatacollectionprotocolthatprovidesinformationaboutthepacketflows
beingsentoveranetwork.NetFlowcollectsdatabyidentifyingunidirectionalIPpacketflows
betweenasinglesourceIPaddress/portandasingledestinationIPaddress/port,usingthesame
Layer3protocolandvaluesfoundin
afixedsetofIPpacketfieldsforeachflow.NetFlowcollects
identifiedflowsandexportsthemtoaNetFlowcollector.UptofourNetFlowcollectorscanbe
configuredonasupporteddevice.ANetFlowmanagementapplicationretrievesthedatafromthe
collectorforanalysisandreportgeneration.
Why Would I Use It in My Network?
Standardsystemfeedbackissimplynotgranularenoughtoprovideforsuchnetwork
requirementsasplanning,userorapplicationmonitoring,securityanalysis,anddatamining.For
example,becauseofitsabilitytoid entifyandcapturenetworkflows,NetFlow:
•Providesameanstoprofileallflowsonyournetworkoveraperiod
oftime.Anetworkprofile
providesthegranularityofinsightintoyournetworknecessaryforsuchsecurenetwork
functionalityasestablishingroleswithpolicyandapplyingQoStopolicy.
•ProvidesameansofisolatingthesourceofDoSattacksallowingyoutoqu icklyrespondwith
apolicy,ACL,QoSchange,or
allofthesetodefeattheattack.
•Canidentifythecauseofanintermittentlysluggishnetwork.Knowingthecauseallowsyouto
determinewhetheritisanunexpected,butlegitimate,networkusagethatmightbe
For information about... Refer to page...
What Is NetFlow? 1
Why Would I Use It in My Network? 1
How Can I Implement NetFlow? 2
Understanding Flows 4
Configuring NetFlow on the Enterasys S-Series, N-Series, and K-Series
Modules
6
Configuring NetFlow on the X-Series Router 11
Terms and Definitions 14
NetFlow Version 5 Record Format 14
NetFlow Version 9 Templates 15