Hi List,

I have a very confusing and doubting question on NetFlow can you people help
me in clearing this:-


I have a cisco router with multiple interfaces in particular 4 interfaces
out of which 3 are WAN Interfaces having different connectivity speed and
connected from different ISP/Carrier providers for failover and
differentiated traffic for e.g high bandwidth applications are allowed to
pass through high bandwidth links only. Now i have to monitor the link
utilization & traffic distribution of all these 3 WAN Interfaces only. As
per now i have configured the ingress and egress both for only one
particular WAN link which is 2 MBPS line. I am running nfSen as NetFlow
collector and analyzer but the average traffic rate which nfSen is reporting
for that link is above 2 mbps which is obviously not possible. Also i know
the interface number of that WAN Interface like serial 0/1/0 using which i
can filter out the in & out in nfSen i believe (I don't know do i need the
SNMP or egress/ingress ifindex to filter out the in & out using nfSen, as
per nfSen docs we can filter out based on interface number like giving the
filter as in if 1(interface serial number) or out if 1).

Now the probable solutions to this as suggested by some people can be:-

(1) If exporting NetFlow v5, enable ingress on all the interfaces and export
NetFlow from the WAN Interface which you are monitoring to netflow
collector's ip & port, Will we get the total traffic for that particular WAN
Interface this way and i can filter it out based on the interface no (as
suggested by nfSen docs) or ingress/egress ifindex value in the exported
records as suggested by Adam. (Are interface no. and ingress/egress ifindex
are same things, if not how i can see the ingress/egress ifindex in the flow
records). According to Michael and Adam this way it should work and i should
be able to get the total traffic on that particular WAN Interface. But
according to David it will not work if the Router has more than two
interfaces.

(2) According to Michael enable NetFlow v9 ingress and egress both on that
particular WAN Interface only and export it to the collector port and i
should be able to get the total traffic for that particular interface both
in and out which i can filter out later in nfSen or NetFlow Analyzer using
the filters in it.

Am i right guys ? But with which approach i should go ahead now. Can you
people help me in this. Thanks a lot to all.


-- 
Thanks
Manish Kumar
http://in.linkedin.com/in/manishkumar85
------------------------------------------------------------------------------
The demand for IT networking professionals continues to grow, and the
demand for specialized networking skills is growing even more rapidly.
Take a complimentary Learning@Ciosco Self-Assessment and learn 
about Cisco certifications, training, and career opportunities. 
http://p.sf.net/sfu/cisco-dev2dev
_______________________________________________
Nfsen-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfsen-discuss

Reply via email to