Specifications

Understanding Flows
May 18, 2011 Page 4 of 21
2. Chooseuptofourcollectorsandamanagementapplication,suchasEnterasysSIEMor
NetSightRelease4.1orhigher,bestsuitedforthepurposeforwhichyouarecollectingthe
data.InstalltheapplicationontheNetFlowcollectorserver(s).
3. IdentifythepathsusedbythedatatobecollectedbyNetFlow.
4. Identify
the“chokepoint”interfaceswheretheIPpacketflowsyouwantNetFlowtocapture
aggregate.
5. EnableNetFlowontheidentifiedinterfaces.
6. IdentifyuptofourNetFlowcollectorserversbyconfiguringtheIPaddressforeachcollector.
7. UsethedatareportinggeneratedbytheNetFlowmanagementapplicationtoaddressthe
purposedeterminedin
step1.
Understanding Flows
Theconceptofaflowiscriticaltoundersta ndingNetFlow.AflowisastreamofIPpacketsin
whichthevaluesofafixedsetofIPpacketfieldsisthesameforeachpacketinthestream.Aflow
isidentifiedbyasetofkeyIPpacketfields
foundintheflow.Eachpacketcontainingthesame
valueforallkeyfieldsisconsideredpartofthesameflow,untilflowexpirationoccurs.Ifapacket
isviewedwithanykeyfieldvaluethatisdifferentfromanycurrentflow,anewflowisstarted
baseduponthe
keyfieldvaluesforthatpacket.TheNetFlowprotocolwilltrackaflowuntilan
expirationcriteriahasbeenmet,uptoaconfigurednumberofcurrentflows.
Thedatacapturedforeachflowisdifferent,basedontheNetFlowexportversionformat
supportedbythenetworkdevi ce.Thisdatacan
includesuchitemsaspacketcount,bytecount,
destinationinterfaceindex,startandendtime,andnexthoprouter.SeeNetFlowVersion5Record
Formatonpage 14forNetFlowVersion5templatedatafielddescriptionsandNetFlowVersion9
Templatesonpage 15forNetFlowVersion9templatedatafielddescriptions.
Flow Expiration Criteria
FlowdatarecordsarenotexportedbythenetworkswitchtotheNetFlowcollector(s)until
expirationtakesplace.Therearetwotimersthataffectflowexpiration:theNetFlowactiveand
inactivetimers.
Theactivetimerdeterminesthemaximumamountoftimealonglastingflowwillremainactive
beforeexpiring.When
alonglastingactiveflowexpires,duetotheactivetimerexpiring,another
flowisimmediatelycreatedtocontinuetheongoingflow.Itistheresponsibilityofthe
managementapplicationontheNetFlowcollectortorejointhesemultipleflowsthatmakeupa
singlelogicalflow.Theactivetimeris
configurableintheCLI(seeConfiguringtheActiveFlow
ExportTimeronpage 7).
TheinactivetimerdeterminesthelengthoftimeNetFlowwaitsbeforeexpiringagivenflowonce
thatflowhasstopped.Theinactivetimerisafixedvalueof40secondsandcannotbeconfigured.
RulesforexpiringNetFlowcache
entriesinclude:
•Flowswhichhavebeenidlefor40seconds(fixedvalueinfirmware)areexpiredandremoved
fromthecache.
Longlivedflowsareexpiredandremovedfromthecache.(Flowsarenotallowedtolivemore
than30minutesbydefault;theunderlyingpacketconversationremainsundisturbed).
•Flows
associatedwithaninterfacethathasgonedownarea utomaticallyexpired.