55-2
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 55 Configuring NetFlow-lite
About NetFlow Packet Sampling
About NetFlow Packet Sampling
The Netflow-lite feature is based on ingress packet sampling at a monitoring point that can be an
interface on the switch. By exporting NetFlow sampled packets, it provides visibility into traffic that is
switched through the device. The rate at which input packets are sampled is configurable and a wide
range of sampling rates are supported. The sampled packets can be exported with Netflow V9 or IPFIX
format.
Feature Interaction
Feature interactions exists on three levels:

System-wide Restrictions

WCCP output redirect is not supported when NetFlow-lite is configured on any interface.
Configuring NetFlow-lite monitor on any interface causes Layer 3 Deny ACLs to not generate ICMP
unreachable packets.
Enabling Netflow-lite monitoring reduces the available TCAM usage and packet forwarding
bandwidth.

Interface-level Restrictions

NetFlow-lite monitoring and ingress QoS policy cannot coexist on the same interface. QoS policy
takes precedence over NetFlow-lite monitoring.
NetFlow-lite monitoring and the WCCP Exclude feature cannot coexist on the same interface.
NetFlow-lite and SPAN cannot coexist on the same interface. NetFlow-lite takes precedence over
SPAN.

Monitor-level Restrictions

Port channel with an aggregate bandwidth exceeding 20 Gigabit support the highest sampling rate
of 1 in 64; those with an aggregate bandwidth exceeding 40 Gigabit support 1 in 128.
When running PIM bidirectional mode, NetFlow-lite monitoring for multicast packets does not
work when the RP or DF and any of the receivers are on the same VLAN.
Configuring NetFlow Packet Sampling
To configure the NetFlow-lite feature, complete the tasks in these sections:
Configuring Information about the External Collector, page 55-3
Configuring Sampling Parameters, page 55-4
Activating Sampling on an Interface or VLAN, page 55-5