Specifications

How Can I Implement NetFlow?
May 18, 2011 Page 3 of 21
Figure 1 NetFlow Network Profile Example
TocompleteaNetFlownetworkprofile,enableNetFlowonallportswherepacketflows
aggregate.AtthetopofFigure 1youwillfindanabbreviatedsampleoftheindependentflow
recordsthatarecapturedateachNetFlowenabledport.Theseflowrecordswillberetained
locallyinacacheuntil
aflowexpirationcriteriahasbeenmet.Asshown,whenoneoftheflow
expirationcriteriaismet,NetFlowexportpacketsarethensenttotheNetFlowcollectorserver(s),
whereacollectorandmanagementapplicationhasbeeninstalled.Themanagementapplication
willprocesstherecordsandgenerateusefulreports.Thesereports
provideyouwithaclear
pictureoftheflowsthattraverseyournetwork,baseduponsuchdatapointsassourceand
destinationaddress,startandendtime,application,andpacketpriority.
ThefollowingstepsprovideahighleveloverviewofaNetFlowimplementation:
1. Determinethebusinessornetworkpurposeofthe
informationNetFlowwillprovideyou.
LAN Cloud
Srdf
Ge.1.1
Srd Padd
173.100.21.2
Protocol
TCP
Dstif
Ge.1.5
TOS
0x20
SPrt
4967
DPrt
80
. . .
Srdf
Ge.1.1
Srd Padd
173.100.21.2
Protocol
UDP
Dstif
Ge.1.3
TOS
0xA0
SPrt
6234
DPrt
SIP
. . .
Profile Your Network Using NetFlow
Captured Flows
HTTP Flow
Voice over IP
Dstl Padd
10.0.277.12
Dstl Padd
20.0.100.10
Srdf
Ge.1.1
Srd Padd
173.100.21.2
Protocol
TCP
Dstif
Ge.1.7
TOS
0x00
SPrt
21
DPrt
4623
. . .
Voice over IP
Srdf Padd
20.0.100.50
Enable NetFlow
NetFlow
Collector IP
Address
10.10.0.1
Enable NetFlow
Enable NetFlow
Management
Application
Installed
Independent Flows
Flows captured and cached at ingress port
NetFlow export packets sent to the collector/management
application based upon a flow expiration criteria