Solved

Cisco Netflow: not supported on my device

Posted on 2014-02-10
4
803 Views
Last Modified: 2014-02-25
I am fairly new to Cisco and was wanting to use Netflow on our network to diagnose network issues.

We currently have Cisco Catalyst 2960 switches, which do not support Netflow.

If we purchase one Cisco switch that does support Netflow, will we then be able to track network traffic across all of our switches? or do all of our switches need to support Netflow?
0
Comment
Question by:AVIVOL
  • 2
4 Comments
 
LVL 12

Expert Comment

by:Infamus
Comment Utility
What information do you want out of netflow?

Wan traffic or LAN traffic? or All of them?

How is your network setup?  Are access switches connected to the core switches?
0
 

Author Comment

by:AVIVOL
Comment Utility
What information do you want out of netflow?

We are experiencing an issue currently where someone/something is causing the link between two office to use its maximum bandwidth, we would like to find the cause of this traffic. We'd like to trace traffic volume (or top n traffic volume) back to specific users/ports out on the floor/rack.

Also we would like to get a better understanding of what general traffic is on our network. (where it is coming from, where it is going, what type of traffic it is etc.)

Wan traffic or LAN traffic? or All of them?

Both.

How is your network setup?  Are access switches connected to the core switches?

Yes, all access switches are connected to the core switches.
Core switches are: Cisco 2960s
Access switches are: Cisco 2960
0
 
LVL 7

Accepted Solution

by:
unfragmented earned 500 total points
Comment Utility
I'd say a much cheaper way to do this as a one-off is with a span port (supported on the 2960) on the switch connected to a decent PC running wireshark or similar.  If you really want "netflow" then you can probably buy a software netflow probe to put on the PC, that will export "netflow" data for your netflow collector to work with.

Otherwise you will be spending $$$ on netflow capable switches (in the Cisco camp, think 3850 or 3750X with NF module as a minimum).

To answer your question, one netflow switch as one of your cores would do the job, as that will intercept all traffic between offices.  Netflow will show you source and destination IP which you can trace to a port, even if the port is on an access switch.
0
 
LVL 12

Expert Comment

by:Infamus
Comment Utility
You can purchase a layer 3 switch that supports the netflow and monitor the interface which connects to another site. Then you can use netflow software to see the traffic.

You can also span the interface and use wireshard as unfragmented mentioned.
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
installed old nagios.... 13 89
Network Upgrade 4 54
Routing multiple VLAN's on a LAN 4 50
Cisco stacked switches monitoring 4 59
The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now