Chapter 1 Overview

What Are NetFlow Services?

Catalyst 5000 series switches can identify flows by looking at a subset of these fields. For example, they can identify flows by source and destination address only.

Note For Catalyst 5000 series switches, the analog to NetFlow services is integrated Multilayer Switching (MLS) management. Included are products, utilities, and partner applications designed to gather flow statistics, export the statistics, and collect and perform data reduction on the exported statistics. MLS management then forwards them to consumer applications for traffic monitoring, planning, and accounting.

NetFlow Services Device and IOS Release Support

You can find the most up-to-date information available to help you determine the compatibility among different Cisco hardware platforms, Cisco IOS software releases, and supported NetFlow data export versions at the following URL:

http://tools.cisco.com/ITDIT/CFN/Dispatch?SearchText=Netflow&act=featSelect&rnFeatId=null

&featStartsWith=&task=TextSearch&altrole=

Note Except for descriptions requiring references to specific router or switch platforms, the remainder of this chapter and the remaining chapters of this guide use the term export device instead of the terms router and switch.

NetFlow Data Export

NetFlow data export makes NetFlow traffic statistics available for purposes of network planning, billing, and so on. An export device configured for NetFlow data export maintains a flow cache used to capture flow-based traffic statistics. Traffic statistics for each active flow are maintained in the cache and are updated when packets within each flow are switched. Periodically, summary traffic statistics for all expired flows are exported from the export device by means of User Datagram Protocol (UDP) datagrams, which CNS NetFlow Collection Engine receives and processes.

How and When Flow Statistics Are Exported

NetFlow data exported from the export device contains NetFlow statistics for the flow cache entries that have expired since the last export. Flow cache entries expire and are flushed from the cache when one of the following conditions occurs:

The transport protocol indicates that the connection is completed (TCP FIN) plus a small delay to allow for the completion of the FIN acknowledgment handshaking.

Traffic inactivity exceeds 15 seconds.

For flows that remain continuously active, flow cache entries currently expire every 30 minutes to ensure periodic reporting of active flows.

NetFlow data export packets are sent to a user-specified destination, such as the workstation running CNS NetFlow Collection Engine, either when the number of recently expired flows reaches a predetermined maximum, or every second-whichever occurs first. For:

Version 1 datagrams, up to 24 flows can be sent in a single UDP datagram of approximately 1200 bytes.

Cisco CNS NetFlow Collection Engine User Guide, Release 5.0.2

1-2

OL-6899-01

 

 

Page 14
Image 14
Cisco Systems OL-6900-01 manual NetFlow Services Device and IOS Release Support, NetFlow Data Export

OL-6900-01 specifications

Cisco Systems OL-6900-01 represents a pivotal advancement in the realm of data center networking. As organizations continue to lean towards digital transformation and cloud-based solutions, the need for robust, scalable, and efficient networking equipment becomes increasingly vital. The OL-6900-01 router is engineered to meet these demands, offering an array of advanced features and technologies that cater to modern network requirements.

One of the standout features of the OL-6900-01 is its high-performance architecture. This router is equipped with a powerful CPU and a sizeable memory footprint, ensuring that it can handle significant amounts of traffic with low latency. This capability is particularly useful for data centers and enterprise environments where the speed of data processing is crucial for operational success.

The OL-6900-01 utilizes Cisco's proprietary software, providing enhanced security features, including robust firewall capabilities and threat detection mechanisms. With security being a paramount concern for organizations today, this router incorporates advanced encryption protocols and access control measures, ensuring that data remains secure in transit and at rest.

Additionally, the OL-6900-01 supports advanced routing protocols, including OSPF, BGP, and EIGRP. This versatility allows for optimal network performance as it can dynamically adjust routing paths based on network conditions, ensuring reliable connectivity and efficient resource utilization. The support for IPv6 also ensures that organizations can future-proof their networks as they transition to this next-generation protocol.

Another important characteristic of the OL-6900-01 is its scalability. Designed to accommodate growing network demands, this router supports modular expansion. Organizations can easily upgrade their systems with additional interfaces and services, ensuring that the OL-6900-01 can grow alongside their needs without requiring a complete infrastructure overhaul.

In terms of connectivity, the OL-6900-01 features multiple interfaces, including Gigabit Ethernet and 10 Gigabit SFP+ ports, providing flexibility in network design and facilitating seamless integration into existing infrastructure. Its high availability features ensure minimal downtime, making it ideal for mission-critical applications.

Overall, Cisco Systems OL-6900-01 stands out as a robust and versatile networking solution, combining performance, security, and scalability to meet the dynamic needs of modern enterprises. With its comprehensive feature set and advanced technologies, it positions itself as a valuable asset for organizations aiming for operational excellence in a digitally-driven landscape.