?
Solved

Cisco Netflow

Posted on 2013-12-07
2
Medium Priority
?
439 Views
Last Modified: 2013-12-22
Does anyone have experience setting up Cisco Netflow cards to capture data flow to export to an external workstation?
I need help understanding what's the best cache settings/overall config to ensure least amount of bandwidth used exporting from netflow card to external workstation.

I also don't want to add a ton of extra utilization on my switches.

I've got a redundant Catalyst 4507R, WS-X4515 Supervisor Engine's both with Netflow cards installed.
Basically right now I've only got the cards installed.  

The Cisco guides aren't clear if the cache settings are important for exporting the data to a external workstation for analyzing, or what best practices/recommended settings to use.

The configuration doesn't look to complicated I just want to make sure I don't add a ton of extra load on the switch while capturing data or while exporting it.
If anyone has implemented Netflow and has some best practices/recommended settings that you can share I'd greatly appreciate it.

Thanks,
Corey Amonette
corey.amonette@ktpo.com
0
Comment
Question by:ktpoitm
2 Comments
 
LVL 29

Expert Comment

by:Jan Springer
ID: 39706110
Netflow is very easy implement and should cause no problems with the device.

Unless you are doing sampling, your configuration should be relatively simple.
0
 
LVL 32

Accepted Solution

by:
harbor235 earned 1000 total points
ID: 39708376
Cache settings are important if you are interested in attack mitigation activities for real-time traffic analysis. Netflow Caching allows for real time analysis of collected flows directly on the 4500. Otherwise your collector Netflow data  is typically 15 minutes behind which is a long time if you are being attacked.

Sampled netflow is just that, you sample the traffic (each flow is not collected) to get an idea of that traffic that is flowing through your device, the longer you sample the more accurate your collection will become. Obviously, if you are able to attain flow records for every packet that comes in/out of your network you have better visibility. You will have to tweak your config to see what is the best mix of 4500 resources and traffic visibility.

Things to consider:

Do you have ample disk space to collect this information? depending on the amount of data sampled/collected from your location this can become allot of data.

Have a data retention policy for flow record data, 3 months?

What software are you going to use for your collector? freeware, COTS?

Netflow does not impose a heavy tax on resources for most routers/L3 switches. That being said you have dedicated netflow cards so there should be no additional resources consumed on the switch/route processor.

Manage which interfaces you turn netflow on, only enable the interfaces your interested in for netflow e.g if your interested in the data coming into your network only enable netflow on the external interface

Consider routing netflow data over a management network

harbor2356 :-}
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Suggested Courses
Course of the Month7 days, 19 hours left to enroll

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question