Specifications
Configuring NetFlow on the Enterasys S-Series, N-Series, and K-Series Modules
May 18, 2011 Page 9 of 21
Thedefaultbehaviorisforthetemplatetobesentafter20flowreportpacketsaresent.Sincedata
recordpacketsaresentoutperflow,alongFTPflowmaycausethetemplatetimeouttimerto
expirebeforethemaximumnumberofpacketsaresent.Inanycasearefresh
ofthetemplateis
sentattimeoutexpirationaswell.
Settingtheappropriaterefreshrateforyoursystemmustbedetermined,becausethedefault
settingsofa20flowreportrefreshrateanda30‐minutetimeoutmaynotbeoptimalforyour
environment.Forexample,aswitchprocessinganextremely
slowflowrateof,say,20flowreports
perhalfhour,wouldrefreshthetemplatesonlyeveryhalfhourusingthedefaultsettings,whilea
switchsending300flowreportpacketspersecondwouldrefreshthetemplates15timesper
second.
Enterasysrecommendsthatyouconfigureyoursystemsoit
doesnotrefreshtemplatesmoreoften
thanoncepersecond.
UsethesetnetflowtemplatecommandtosettheNetFlowexporttemplaterefreshrateand
timeoutforthissystem.
UsetheclearnetflowtemplatecommandtoresettheNetFlowexporttemplaterefreshrateand
timeouttothe defaultvalues.
Configuring a NetFlow Port
NetFlowrecordsareonlycollectedonportsthatareenabledforNetFlow.
UsethesetnetflowportenablecommandtoenableNetFlowonthespecifiedports.
Useeitherthesetnetflowportdisablecommandortheclearnetflowportcommandtodisable
NetFlowonthespecifiedports.
Usetheclearnetflowport
commandtosettheporttothedefaultvalueofdisabled.
Configuring the NetFlow Cache
EnablingtheNetFlowCachegloballyenablesNetFlowonallmodulesforthissystem.When
NetFlowrecognizesanewflowontheingressport,itcreatesaNetFlowrecordforthatflow. The
NetFlowrecordresidesintheNetFlowcacheforthatportuntilanexpirationeventistriggeredfor
thatflow,
atwhichtimeitissentalongwithotherexpiredflowsinanexportpackettothe
NetFlowcollectorforprocessing.
UsethesetnetflowcacheenablecommandtoenableNetFlowonthissystem.
UsethesetnetflowcachedisablecommandtogloballydisableNetFlowonthissystem.
Usetheclear
netflowcachecomm andtoresettheNetFlowcachetothedefaultvalueofdisabled
forthismodule.
Configuring Optional NetFlow Export Data
TheexportofoptionalsourceanddestinationMACaddressandVLANIDdataisdisabledby
default.Includingtheseexportdataoptionsintheflowrecordmakestherecordlargerandresults
infewerrecordsandexportedpackets.
Ifthemacoptionisenabled,bothincomingsourceanddestinationMACaddresses
areincluded
intheexportdataforthecollector.