Solved

Cisco Netflow on Sub-Interfaces

Posted on 2014-07-22
5
656 Views
Last Modified: 2014-07-24
Hello Experts,

I never really understood if its necessary to configure netflow on sub-interfaces or just on the physical interface. For example, our WAN circuit is physically connected to Gi 0/0. We have sub-interface of Gi0/0/2928. Both interfaces are currently configured as follows:

interface GigabitEthernet0/0
 no ip address
 load-interval 30
 duplex full
 speed 10

interface GigabitEthernet0/0.2938
 description BT MPLS CID SHI/CU-SHI/BT NP432 (supplier 2013-04655-k01)
 encapsulation dot1Q 2938
 ip address 10.1.243.38 255.255.255.252
 no ip unreachables
 ip flow ingress
 ip flow egress
 ip virtual-reassembly in
 no cdp enable
 service-policy output Shape-Ethernet-QoS
end

As you can see, netflow is configured on the sub-interface but we don't have it configured on our physical interface. Should we have it configured on both?

Regards

Carlton
0
Comment
Question by:cpatte7372
  • 2
  • 2
5 Comments
 
LVL 22

Accepted Solution

by:
Jody Lemoine earned 500 total points
ID: 40212884
Enabling Netflow on the physical interface will capture everything going through it and its sub-interfaces. Enabling it only on the sub-interface will capture only what traverses the sub-interface. If you have only one sub-interface for 802.11q processing, then it makes no difference which one you have it on, but enabling it on both will create double entries for the same flows.
0
 
LVL 22

Expert Comment

by:eeRoot
ID: 40213104
Are there any other sub interfaces that you want to monitor?  And do you want to monitor the L3 traffic that is going through the physical interface such as routing protocols and link status packets?
0
 

Author Comment

by:cpatte7372
ID: 40216485
Hi Jody, thats great.

eeRoot, there are no other sub-interfaces I want to monitor.

Cheers
0
 
LVL 22

Expert Comment

by:Jody Lemoine
ID: 40216596
Glad I could help. Is there anything else that needs clarification or are you good with the answers provided?
0
 

Author Closing Comment

by:cpatte7372
ID: 40216725
Cheers
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
VPN protocal 18 66
Cisco ACS mixed versions 8 53
Can't access DMZ from internal network 7 44
NSD FAIL 2 25
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now