Fluke Computer Accessories Ip route-cache flow infer-fields, Mls netflow, Mls nde sender version

Page 80

User’s Guide – version 3.5

NetFlow Tracker

Enabling NetFlow Export on a 4000 Series Switch

The 4000 and 4500 series switches require a Supervisor IV with a NetFlow Services daughter card (WS-F4531), or a Supervisor V, and IOS version 12.1(19)EW or above to support NetFlow. First configure the device as for an IOS device above, omitting the command ip route-cache flow on each interface, and then issue the following:

ip route-cache flow infer-fields

This ensures routing information is included in the flows.

Enabling NDE on a Native IOS Device

The following commands are required in addition to the commands required to configure an IOS device above to get NetFlow information on route-switched traffic from a Catalyst 6000 or above; they are not required for a Catalyst 4000 series.

mls netflow

This enables NetFlow on the supervisor.

mls nde sender version 5

or

mls nde sender version 7

This sets the export version. Due to several IOS bugs, the export version you must use on the supervisor is dependent on your hardware configuration and IOS version:

Distributed Forwarding Cards and 12.1(13)E03, 12.1(18.1)E, 12.2(13.6)S, 12.2(15.1)S, 12.2(17a)SX or above: use version 5. Note that this configuration will cause the Performance Counters to report missed flows that are not actually missed; this is the result of an IOS bug fixed in the SXF strains.

Distributed Forwarding Cards and older than 12.1(13)E03, 12.1(18.1)E, 12.2(13.6)S, 12.2(15.1)S or 12.2(17a)SX: this configuration will cause serious problems, so please contact Fluke Networks if your device matches this description.

No Distributed Forwarding Cards and 12.0(24)S, 12.2(18)S, 12.3(1) or above: use version 5 and configure the MSFC to export version 9 as described above.

No Distributed Forwarding Cards and 12.1(13)E03, 12.1(18.1)E, 12.2(13.6)S, 12.2(15.1)S, 12.2(17a)SX or above: use version 5.

Anything else: use version 7. Note that version 7 may not include AS or subnet mask information.

mls aging long 64

This breaks up long-lived flows into (roughly) one-minute segments.

mls aging normal 32

This ensures that flows that have finished are exported in a timely manner.

80

Image 80
Contents NetFlow Tracker Contents LONG-TERM Reports Appendix 2 CSV File Format Software License Agreement Grant of Licence and Payment of FeesCopyright Customer Remedies Confidential Information and Security User’s Guide version NetFlow Tracker Definitions Support Services Support ChargesUndertakings by You Supplier’s UndertakingsTermination Limitation of Liability and indemnityIntellectual Property Rights Confidential Information and Security MiscellaneousResponse Times Exceptions to Support ServicesSupport Hours What is NetFlow? What is NetFlow Tracker?Features and Benefits IntroductionUser’s Guide version NetFlow Tracker Installation Pre-installation ChecksMinimum System Requirements Operating System SupportInstallation on Microsoft Windows Installation on Linux Post-installation Tasks Set up Snmp community strings Set up web front-end securityConfigure your routers and switches Add listener portsUsing NetFlow Tracker Device traffic meters InterfacesWorking with Charts Changing the displayed chartChart legend Per-AS dataView a standard chart as a pie chart View a standard chart as a tabular reportZooming Zooming outAlter the filter applied to a standard chart Export a chart to another applicationPrint the chart Open the chart in a new windowWorking with Pie Charts Working with Tabular ReportsSort a tabular report Examine a single rowSession Reports Report TemplatesAddress Reports QoS Reports Network ReportsCreating Filtered Reports Interface ReportsTraffic Identification Reports Other ReportsReport template Sample sizeSource data Start timeTime zone Source deviceInterface Out interfaceProtocol Source portDest port Src/dest portDiffServ Traffic classSource AS Dest ASLong-term Reports Devices and InterfacesPer-device and Per-interface Long-term Reports Filter EditorUser’s Guide version NetFlow Tracker Reports Report Format Parameters Report URL FormatGeneral Form 0023 00240025 0026Chart PieNumber TrueFeatures Sections128 256Time Range Parameters Millis HourDay WeekTime range will extend for this number of units Calendar-based advancedDay1-day2/time1-time2 HHmmApplying a time-of-day mask to the time range 110 105100 113115 120140 125285 300Minute DailyFilter Parameters Port1-port2 NameAddr1-addr2 Port/name Port/numberPort1-port2/name Port1-port2/numberPrec TosPrec%20tos CodeAddr/mask MaskUsername PasswordSecurity Parameters Null Management Portal Access Control ParametersSecret VPN Out VPN Chart scrollbar Chart selection headersFilter Editor button, if applicable Refresh and Resolve All buttons, if applicablePerformance Tuning Database Server SettingsDisk Speed Query SizeConfiguration Guide Snmp SettingsLicensing Listener PortsDevice List Device SettingsDevice Settings Sampled Data Scaling Security Settings VPNsManagement Portal Settings Http//proxy/tracker1/report1Http//tracker1/report.jsp?portalsecret=secret&aclif= Http//proxy/tracker1/report.jsp?portalacl=Using Apache as a Portal Server RewriteEngine OnRewriteRule /tracker1/.*$ http//1.2.3.4/$1 P,L,QSA ProxyPassReverse /tracker1/ http//1.2.3.4Real-time Reports Report SettingsGeneral Settings Saved Filters Scheduled ReportsLong-term Reports Executive Reports Span class=repdesctextTest/span Sub-reports Nelements=5 and chartWidth=400Content User’s Guide version NetFlow Tracker DiffServ Names Hostname Resolution SettingsIP Application Names Subnet Names Database SettingsAS Names Backup Performance Counters Memory SettingsArchiving NetFlow Data Received Traffic DescribedIgnored Flows Unprocessed FlowsetsAbout No In InterfaceAppendix 1 Device Configuration Enabling Netflow Export on an IOS DeviceIp cef Ip flow-export destination addressIp flow-cache timeout active Ip flow-cache timeout inactiveShow ip flow export Show ip cache flow Show ip cache verbose flowIp route-cache flow infer-fields Mls netflowMls nde sender version Mls aging longUser’s Guide version NetFlow Tracker Set mls bridged-flow-statistics enable vlanlist Set mls nde enableSet system name name Set mls nde addressFlow-sampler-map allflows mode random one-out-of 1 exit Enabling Flow Detail Records on a Packeteer DeviceEnabling NetFlow on an Enterasys Device Chart CSV format Pie chart CSV formatAppendix 2 CSV File Format Tabular report CSV formatChart XML format Pie chart XML formatAppendix 3 XML Format Tabular report XML formatAppendix 4 Third Party Software Components JspSmartUpload Quartz