56-2
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 56 Configuring NetFlow
About NetFlow Statistics Collection
About NetFlow Statistics Collection
A network flow is defined as a unidirectional stream of packets between a given source and destination
—both defined by a network-layer IP address and transport-layer port number. Specifically, a flow is
identified as the combination of the following fields: source IP address, destination IP address, source
port number, destination port number, protocol type, type of service, and input interface.
NetFlow Statistics is a global traffic monitoring feature that allows flow-level monitoring of all
IPv4-routed traffic through the switch using NetFlow Data Export (NDE). Collected statistics can be
exported to an external device (NetFlow Collector/Analyzer) for further processing. Network planners
can selectively enable NetFlow Statistics (and NDE) on a per-device basis to gain traffic performance,
control, or accounting benefits in specific network locations.
NetFlow exports flow information in UDP datagrams in one of two formats. The version 1 format was
the initial released version, and version 5 is a later enhancement to add Border Gateway Protocol (BGP)
autonomous system (AS) information and flow sequence numbers. In version 1 and version 5 format, the
datagram consists of a header and one or more flow records. The first field of the header contains the
version number of the export datagram.
This section contains the following subsections:
Information Derived from Hardware, page 56-3
Information Derived from Software, page 56-4
Assigning the Input and Output Interface and AS Numbers, page 56-4
Feature Interaction of NetFlow Statistics with UBRL and Microflow Policing, page 56-5
VLAN Statistics, page 56-5

NDE Versions

The Catalyst 4500 series switch supports NDE versions 1 and 5 for the captured statistics. NetFlow
aggregation requires NDE version 8.
Depending on the current flow mask, some fields in the flow records might not have values. Unsu pported
fields contain a zero (0).
The following tables describe the supported fields for NDE version 5:
Table 56-1—Version 5 header format
Table 56-2—Version 5 flow record format
Table 56-1 NDE Version 5 Header Format
Bytes Content Description
0–1 version NetFlow export format version number
2–3 count Number of flows exported in this packet (1–30)
4–7 SysUptime Current time in milliseconds since the switch booted
8–11 unix_secs Current seconds since 0000 UTC 1970
12–15 unix_nsecs Residual nanoseconds since 0000 UTC 1970
16–19 flow_sequence Sequence counter of total flows seen
20–21 engine_type Type of flow switching engine
21–23 engine_id Slot number of the flow switching engine