LogLogic Cisco NetFlow Log Configuration Guide

Size: px
Start display at page:

Download "LogLogic Cisco NetFlow Log Configuration Guide"

Transcription

1 LogLogic Cisco NetFlow Log Configuration Guide Document Release: March 2012 Part Number: LL ELS This manual supports LogLogic Cisco NetFlow Version 2.0, and LogLogic Software Release 5.1 and later until replaced by a new edition.

2 2012 LogLogic, Inc. Proprietary Information Trademarks This document contains proprietary and confidential information of LogLogic, Inc. and its licensors. In accordance with the license, this document may not be copied, disclosed, modified, transmitted, or translated except as permitted in writing by LogLogic, Inc. LogLogic and the LogLogic logo are trademarks or registered trademarks of LogLogic, Inc. in the United States and/or foreign countries. All other company or product names are trademarks or registered trademarks of their respective owners. Notice The information contained in this document is subject to change at any time without notice. All warranties with respect to the software and accompanying documentation are set our exclusively in the Software License Agreement or in the Product Purchase Agreement that covers the documentation. LogLogic, Inc. 110 Rose Orchard Way, Suite 200 San Jose, CA Tel: Fax: U.S. Toll Free:

3 Contents Preface About This Guide Technical Support Documentation Support Conventions Chapter 1 Configuring LogLogic s Cisco NetFlow Log Collection Introduction to Cisco NetFlow Prerequisites Enabling a Cisco Device to Send NetFlow Data Enabling the LogLogic Appliance to Capture Data Adding a Cisco NetFlow Device Verifying the Configuration Chapter 2 How LogLogic Supports Cisco NetFlow How LogLogic Captures Cisco NetFlow Log Data LogLogic Real-Time Reports Chapter 3 Troubleshooting and FAQ Recommended Sampling Rate Troubleshooting Problems Retrieving Log Files Using Configured Collector Frequently Asked Questions How does the LogLogic Appliance obtain the data from the Cisco NetFlow stream? What access permissions are required? How do I know what version and port NetFlow is sending on? Appendix A Event Reference LogLogic Support for Cisco NetFlow Events Appendix B Field Descriptions Cisco NetFlow Log Configuration Guide 3

4 4 Cisco NetFlow Log Configuration Guide

5 Preface About This Guide The LogLogic Appliance-based solution lets you capture and manage log data from all types of log sources in your enterprise. The LogLogic support for Cisco NetFlow enables LogLogic Appliances to capture logs from Cisco devices exporting NetFlow data. Once the logs are captured and parsed, you can generate reports and create alerts on Cisco NetFlow operations. For more information on creating reports and alerts, see the LogLogic User Guide and LogLogic Online Help. Technical Support LogLogic is committed to the success of our customers and to ensuring our products improve customers' ability to maintain secure, reliable networks. Although LogLogic products are easy to use and maintain, occasional assistance might be necessary. LogLogic provides timely and comprehensive customer support and technical assistance from highly knowledgeable, experienced engineers who can help you maximize the performance of your LogLogic Appliances. To reach LogLogic Customer Support: Telephone: Toll Free, US LOGS (5647) Toll Telephone: Toll Free, Canada LOGS (5647) Toll Telephone: Toll Free, Mexico LOGS (5647) Toll Telephone: Toll Free, United Kingdom Toll Telephone: Toll Free, Mainland Europe Toll Telephone: Toll Free, Japan IDC Toll Not Available Telephone: Toll Free, Japan KDD Toll Not Available Telephone: Toll Free, Brazil Toll Not Available [email protected] You can also visit the LogLogic Support website at: When contacting Customer Support, be prepared to provide: Your name, address, phone number, and fax number Your company name and company address Your machine type and release version A description of the problem and the content of pertinent error messages (if any) Cisco NetFlow Log Configuration Guide 5

6 Documentation Support Your feedback on LogLogic documentation is important to us. Send to if you have questions or comments. Your comments will be reviewed and addressed by the LogLogic technical writing team. In your message, please indicate the software name and version you are using, as well as the title and document date of your documentation. Conventions LogLogic documentation uses the following conventions to highlight code and command-line elements: A monospace font is used for programming elements (such as code fragments, objects, methods, parameters, and HTML tags) and system elements (such as filenames, directories, paths, and URLs). A monospace bold font is used to distinguish system prompts or screen output from user responses, as in this example: username: system home directory: home\app A monospace italic font is used for placeholders, which are general names that you replace with names specific to your site, as in this example: LogLogic_home_directory\upgrade\ Straight brackets signal options in command-line syntax. For example: ls [-AabCcdFfgiLlmnopqRrstux1] [-X attr] [path...] 6 Cisco NetFlow Log Configuration Guide

7 Chapter 1 Configuring LogLogic s Cisco NetFlow Log Collection This chapter describes configuration steps involved to enable a LogLogic Appliance to capture Cisco NetFlow logs. The configuration steps assume that you have a functioning LogLogic Appliance that can be configured to capture Cisco NetFlow log data. Introduction to Cisco NetFlow Prerequisites Enabling a Cisco Device to Send NetFlow Data Enabling the LogLogic Appliance to Capture Data Verifying the Configuration Introduction to Cisco NetFlow Cisco NetFlow provides IP application services, plus valuable information about network users and applications, peak usage times, and traffic routing. Prerequisites Prior to configuring Cisco NetFlow and the LogLogic Appliance, ensure that you meet the following prerequisites: Cisco networking device with a NetFlow-enabled IOS. (Cisco 2900, 3500, 3660, and 3750 do not support NetFlow.) See Cisco NetFlow Technical Overview here. LogLogic Appliance running v5.1 or later with the Cisco NetFlow Log Source Package Administrator access on the LogLogic Appliance Enabling a Cisco Device to Send NetFlow Data To configure a Cisco Device to send NetFlow data you will need to use the ip flow-export command through the Cisco s CLI. The following example shows the commands to configure the NetFlow version, IP, and port. Router# configure terminal Router(config)# ip flow-export version 9 Router(config)# ip flow-export destination For more details on configuring Cisco NetFlow options, please refer to Cisco documentation. Cisco NetFlow Log Configuration Guide 7

8 Enabling the LogLogic Appliance to Capture Data The following sections describe how to configure the LogLogic Appliance to capture Cisco NetFlow log data. Note: When configuring the NetFlow device be sure that you have enabled the proper UDP port in the LogLogic Appliance Access Control list, if Access Control is enabled. Adding a Cisco NetFlow Device The LogLogic Appliance captures Cisco NetFlow logs using the NetFlow Collector. You must configure the Cisco NetFlow device with the correct version and port to make the logs available for searching. To add Cisco NetFlow as a new device: 1. Log in to the LogLogic Appliance. 2. From the navigation menu, select Management > Devices. The Devices tab appears. 3. Click Add New. The Add Device tab appears. 4. Type in the following information for the device: Name Name for the Cisco NetFlow device Description (optional) Description of the Cisco NetFlow device Device Type Select Cisco NetFlow from the drop-down menu Host IP IP address of the Cisco NetFlow appliance Enable Data Collection Select the Yes radio button Refresh Device Name through DNS Lookups (optional) Select this checkbox to enable the Name field to be automatically updated. The name is obtained using a reverse DNS lookup on the configured refresh interval. The DNS name overrides any manual name you assign. Cisco NetFlow Collector Configuration Incoming Port The port of the Appliance where the NetFlow data for this log source is directed. The port is chosen from a menu that offers port numbers 2055, 9555, and Although NetFlow devices can usually be configured to any port number, this collector restricts to these three choices so as to work with the LogLogic LMI Access Control facility. Note that if Access Control is used, any ports used by NetFlow must be configured in the Administration > Firewall Settings configuration page. Raw Data Forwarding Host (optional) IP address of the destination host. Raw Data Forwarding Port (optional) NetFlow port to forward to. Note: The Raw Data Forwarding feature is used to forward raw NetFlow data to any 3rd party NetFlow receiver in parallel to NetFlow collection on the LogLogic Appliance. This feature is global and applies to all NetFlow data received on the configured Incoming Port. Note: If collecting from Multiple NetFlow sources you only need to add the first source. All other sources usig the same configured NetFlow port will be auto-identified. If collecting from multiple NetFlow ports then one source must be manually configured for each port used. 8 Cisco NetFlow Log Configuration Guide

9 5. Click Add. Figure 1 Adding a Device to the LogLogic Appliance 6. Verify that your new device appears in the Devices tab and that Enabled is set to Yes. Figure 2 Cisco NetFlow Device Added to LogLogic Appliance Device List When the logs arrive from the specified Cisco NetFlow appliance, the LogLogic Appliance uses the device you just added if the hostname or IP match. Cisco NetFlow Log Configuration Guide 9

10 Verifying the Configuration The section describes how to verify that the configuration changes made to Cisco NetFlow and the LogLogic Appliance are applied correctly. To verify the configuration: 1. Log in to the LogLogic Appliance. 2. From the navigation menu, select Dashboards > Log Source Status. The Log Source Status tab appears. 3. Locate the IP address for each Cisco NetFlow device. If the device name (Cisco NetFlow) appears in the list of devices, then the configuration is correct. If the device does not appear in the Log Source Status tab, run the show ip flow export command from the CLI of the Cisco device. Confirm that one of the destinations is the LogLogic Appliance and has the correct Port number and Version. Figure 3 LogLogic Log Source Status 10 Cisco NetFlow Log Configuration Guide

11 Chapter 2 How LogLogic Supports Cisco NetFlow This chapter describes LogLogic s support for Cisco NetFlow. The LogLogic Appliance enables you to capture log data to monitor Cisco NetFlow events. How LogLogic Captures Cisco NetFlow Log Data LogLogic Real-Time Reports How LogLogic Captures Cisco NetFlow Log Data A collector is required to listen for the log data from the Cisco NetFlow device as the data is transmitted in binary format. The Cisco NetFlow Collector collects the log data from the Cisco NetFlow device in real time and sends database logs to the LogLogic Appliance. Figure 4 shows how Cisco NetFlow logs are captured and forwarded to the LogLogic Appliance for further processing. Figure 4 Cisco NetFlow with LogLogic Components and Processes for Real-Time Collection Once the data is captured, you can search it and generate reports. For more information on searching and creating reports, see the LogLogic User Guide and LogLogic Online Help. Cisco NetFlow Log Configuration Guide 11

12 LogLogic Real-Time Reports LogLogic provides pre-configured Real-Time Reports for Cisco NetFlow log data. The following Real-Time Reports are available: Application Usage Displays application usage seen across all traffic User Browsing Statics Displays site destination statistics by user Top Users Displays top traffic users To access LMI 5 Real-Time Reports: 1. In the top navigation pane, click Reports. 2. Click Flow Activity. The following Real-Time Reports are available: Application Usage User Browsing Statics Top Users 3. Click Operational. The following Real-Time Reports are available: All Unparsed Events You can create custom reports from the existing Real-Time Report templates. For more information, see the LogLogic User Guide and LogLogic Online Help. 12 Cisco NetFlow Log Configuration Guide

13 Chapter 3 Troubleshooting and FAQ This chapter contains troubleshooting information regarding the configuration and/or use of log collection for Cisco NetFlow. It also contains Frequently Asked Questions (FAQ), providing quick answers to common questions. Recommended Sampling Rate Troubleshooting Frequently Asked Questions Recommended Sampling Rate The maximum recommended rate for receiving NetFlow data is 500 flows per second. If you are receiving at a higher rate then this, it is recommended to implement a sampling rate on the Cisco device to limit the amount of flows being sent. Below is a sample configuration. Router(config)# ip cef Router(config)# flow-sampler-map my-map Router(config-sampler)# mode random one-out-of 100 Router(config)# interface GigabitEthernet0/0 Router(config-if)# no ip route-cache flow Router(config-if)# ip route-cache cef Router(config-if)# flow-sampler my-map This configuration will send 1 out of every 100 NetFlow messages to the LogLogic Appliance. Set the appropriate ratio based on the real-life flow data, but do not exceed 500 flows per second. Troubleshooting Problems Retrieving Log Files Using Configured Collector If you are having general problems retrieving log files using your configured collector, you can run an Index Search against as follows: 1. In the navigation menu, click Search > Index Search. 2. Specify LogLogic Appliance as the Device Type and choose the appropriate Source Device. 3. Click the text box and hit Enter. Click Yes to retrieve all messages from the Cisco NetFlow devices. Cisco NetFlow Log Configuration Guide 13

14 Frequently Asked Questions How does the LogLogic Appliance obtain the data from the Cisco NetFlow stream? LogLogic s Cisco NetFlow Collector runs on the LogLogic Appliance and listens on the specified port for the binary NetFlow stream from a Cisco NetFlow-enabled device. What access permissions are required? To configure a Cisco device to send a NetFlow stream, the user must have the proper permissions to make configuration changes to the Cisco device. How do I know what version and port NetFlow is sending on? Log into the Cisco device and run the show ip flow export command. The following is an example output: Flow export v5 is enabled for main cache Export source and destination details : VRF ID : Default Destination(1) (9995) Version 5 flow records flows exported in udp datagrams 0 flows failed due to lack of export packet 24 export packets were sent up to process level 0 export packets were dropped due to no fib 0 export packets were dropped due to adjacency issues 0 export packets were dropped due to fragmentation failures 0 export packets were dropped due to encapsulation fixup failures 14 Cisco NetFlow Log Configuration Guide

15 Appendix A Event Reference This appendix lists the LogLogic-supported Cisco NetFlow events. The Cisco NetFlow event table identifies events that can be analyzed through LogLogic reports. All sample log messages were captured by LogLogic s file pull functionality. LogLogic Support for Cisco NetFlow Events The following list describes the contents of each of the columns in the table below. Version Refers to the log format version Agile Reports/Search Defines if the Cisco NetFlow event is available through the LogLogic Agile Report Engine or through the search capabilities. If the event is available through the Agile Report Engine, then you can use LogLogic s Real-Time Reports and Summary Reports to analyze and display the captured log data. Otherwise, all other supported events that are captured by the LogLogic Appliance can be viewed by performing a search for the log data. Title/Comments Not Applicable (N/A) Event Category Event classification (e.g., IN/OUT) Report Appears in LogLogic-preformatted reports that the event appears in Sample Log Message Sample Cisco NetFlow log messages. Cisco NetFlow Log Configuration Guide 15

16 Table 1 Cisco NetFlow Events Version Agile Reports /Search Event Category Report Appears in Sample Log Message 1 5 Agile IN Application Usage, User Browsing Statics, Top Users 2 9 Agile IN Application Usage, User Browsing Statics, Top Users 3 9 Agile OUT Application Usage, User Browsing Statics, Top Users 4 5 Agile OUT Application Usage, User Browsing Statics, Top Users <189>[NetFlow] version="5",sysuptime=" ",unixsecs=" t16:37:04",unixnsecs=" ",flowSequence="33398",engineType="0",engineId="0",samplingInterval= "0",IN_BYTES="",IN_PKTS="",FLOWS="",PROTOCOL="1",TCP_FLAGS="16",L4_S RC_PORT="0",IPV4_SRC_ADDR=" ",INPUT_SNMP="1",L4_DST_PORT ="771",IPV4_DST_ADDR=" ",OUTPUT_SNMP="0",SRC_AS="0",DST_A S="0",MUL_DST_PKTS="",MUL_DST_BYTES="",LAST_SWITCHED=" ", FIRST_SWITCHED=" ",OUT_BYTES="",OUT_PKTS="",MIN_PKT_LNGT H="",MAX_PKT_LNGTH="",IPV6_SRC_ADDR="",IPV6_DST_ADDR="",SAMPLING _INTERVAL="",SAMPLING_ALGORITHM="",FLOW_ACTIVE_TIMEOUT="",FLOW_ INACTIVE_TIMEOUT="",TOTAL_BYTES_EXP="224",TOTAL_PKTS_EXP="1",TOT AL_FLOWS_EXP="",SRC_VLAN="",DST_VLAN="",IF_NAME="",IF_DESC="",DST_ MASK="24",IPV4_NEXT_HOP=" ",SRC_MASK="8",SRC_TOS="192" <189>[NetFlow] version="9",sysuptime=" ",unixsecs=" t16:38:19",packetseque nce="192",sourceid="0",in_bytes="229",in_pkts="1",flows="",protocol="1 7",TCP_FLAGS="16",L4_SRC_PORT="138",IPV4_SRC_ADDR=" ",INPU T_SNMP="1",L4_DST_PORT="138",IPV4_DST_ADDR=" ",OUTPUT_ SNMP="0",SRC_AS="",DST_AS="",MUL_DST_PKTS="",MUL_DST_BYTES="",LAS T_SWITCHED=" ",FIRST_SWITCHED=" ",OUT_BYTES="",OU T_PKTS="",MIN_PKT_LNGTH="",MAX_PKT_LNGTH="",IPV6_SRC_ADDR="",IPV6 _DST_ADDR="",SAMPLING_INTERVAL="",SAMPLING_ALGORITHM="",FLOW_A CTIVE_TIMEOUT="",FLOW_INACTIVE_TIMEOUT="",TOTAL_BYTES_EXP="",TOT AL_PKTS_EXP="",TOTAL_FLOWS_EXP="",SRC_VLAN="",DST_VLAN="",IF_NAM E="",IF_DESC="",DIRECTION="ingress",DST_MASK="0",FLOW_SAMPLER_ID="0",IPV4_NEXT_HOP=" ",SRC_MASK="0",SRC_TOS="0",UNKNOWN_51="0" <189>[NetFlow] version="9",sysuptime=" ",unixsecs=" t16:38:19",packetseque nce="192",sourceid="0",in_bytes="229",in_pkts="1",flows="",protocol="1 7",TCP_FLAGS="16",L4_SRC_PORT="138",IPV4_SRC_ADDR=" ",IN PUT_SNMP="1",L4_DST_PORT="138",IPV4_DST_ADDR=" ",OUTPUT_ SNMP="0",SRC_AS="",DST_AS="",MUL_DST_PKTS="",MUL_DST_BYTES="",LAS T_SWITCHED=" ",FIRST_SWITCHED=" ",OUT_BYTES="",OU T_PKTS="",MIN_PKT_LNGTH="",MAX_PKT_LNGTH="",IPV6_SRC_ADDR="",IPV6 _DST_ADDR="",SAMPLING_INTERVAL="",SAMPLING_ALGORITHM="",FLOW_A CTIVE_TIMEOUT="",FLOW_INACTIVE_TIMEOUT="",TOTAL_BYTES_EXP="",TOT AL_PKTS_EXP="",TOTAL_FLOWS_EXP="",SRC_VLAN="",DST_VLAN="",IF_NAM E="",IF_DESC="",DIRECTION="ingress",DST_MASK="0",FLOW_SAMPLER_ID="0",IPV4_NEXT_HOP=" ",SRC_MASK="0",SRC_TOS="0",UNKNOWN_51="0" <189>[NetFlow] version="5",sysuptime=" ",unixsecs=" t16:37:04",unixnsecs=" ",flowSequence="33398",engineType="0",engineId="0",samplingInterval= "0",IN_BYTES="",IN_PKTS="",FLOWS="",PROTOCOL="1",TCP_FLAGS="16",L4_S RC_PORT="0",IPV4_SRC_ADDR=" ",INPUT_SNMP="1",L4_DST_PORT ="771",IPV4_DST_ADDR=" ",OUTPUT_SNMP="0",SRC_AS="0",DST_A S="0",MUL_DST_PKTS="",MUL_DST_BYTES="",LAST_SWITCHED=" ", FIRST_SWITCHED=" ",OUT_BYTES="",OUT_PKTS="",MIN_PKT_LNGT H="",MAX_PKT_LNGTH="",IPV6_SRC_ADDR="",IPV6_DST_ADDR="",SAMPLING _INTERVAL="",SAMPLING_ALGORITHM="",FLOW_ACTIVE_TIMEOUT="",FLOW_ INACTIVE_TIMEOUT="",TOTAL_BYTES_EXP="224",TOTAL_PKTS_EXP="1",TOT AL_FLOWS_EXP="",SRC_VLAN="",DST_VLAN="",IF_NAME="",IF_DESC="",DST_ MASK="24",IPV4_NEXT_HOP=" ",SRC_MASK="8",SRC_TOS="192" 16 Cisco NetFlow Log Configuration Guide

17 Appendix B Field Descriptions This appendix lists the field descriptions for the LogLogic-supported Cisco NetFlow events, examples of which appear in Appendix A above. Table 2 Filed Descriptions for Cisco NetFlow v5.0 Netflow v5 Fields Description version The version of NetFlow records exported in this packet; for Version 9, this value is 0x0009 sysuptime SysUptime Time in milliseconds since this device was first booted unixsecs UnixSecs Seconds since 0000 Coordinated Universal Time (UTC) 1970 unixnsecs Residual nanoseconds since 0000 UTC 1970 flowsequence Sequence counter of total flows seen enginetype Type of flow-switching engine engineid Slot number of the flow-switching engine samplinginterval First two bits hold the sampling mode; remaining 14 bits hold value of sampling interval IN_BYTES Incoming counter with length N x 8 bits for number of bytes associated with an IP Flow IN_PKTS Incoming counter with length N x 8 bits for the number of packets associated with an IP Flow FLOWS Number of flows that were aggregated PROTOCOL IP protocol byte TCP_FLAGS Cumulative of all the TCP flags seen for this flow L4_SRC_PORT TCP/UDP source port number ie : FTP, Telnet, or equivalent IPV4_SRC_ADDR IPv4 source address INPUT_SNMP Input interface index; L4_DST_PORT TCP/UDP destination port number ie: FTP, Telnet, or equivalent IPV4_DST_ADDR IPv4 destination address OUTPUT_SNMP Output interface index; SRC_AS Source BGP autonomous system number DST_AS Destination BGP autonomous system number MUL_DST_PKTS IP multicast outgoing packet counter with length N x 8 bits for packets associated with the IP Flow MUL_DST_BYTES IP multicast outgoing byte counter with length N x 8 bits for bytes associated with the IP Flow LAST_SWITCHED System uptime at which the last packet of this flow was switched FIRST_SWITCHED System uptime at which the first packet of this flow was switched OUT_BYTES Outgoing counter with length N x 8 bits for the number of bytes associated with an IP Flow OUT_PKTS Outgoing counter with length N x 8 bits for the number of packets associated with an IP Flow MIN_PKT_LNGTH Minimum IP packet length on incoming packets of the flow MAX_PKT_LNGTH Maximum IP packet length on incoming packets of the flow IPV6_SRC_ADDR IPv6 Source Address IPV6_DST_ADDR IPv6 Destination Address SAMPLING_INTERVAL When using sampled NetFlow, the rate at which packets are sampled ie: a value of 100 indicates that one of every 100 packets is sampled SAMPLING_ALGORITHM The type of algorithm used for sampled NetFlow: 0x01 Deterministic Sampling,0x02 Random Sampling Cisco NetFlow Log Configuration Guide 17

18 Netflow v5 Fields Table 2 Filed Descriptions for Cisco NetFlow v5.0 Description FLOW_ACTIVE_TIMEOUT Timeout value (in seconds) for active flow entries in the NetFlow cache FLOW_INACTIVE_TIMEOUT Timeout value (in seconds) for inactive flow entries in the NetFlow cache TOTAL_BYTES_EXP Counter with length N x 8 bits for bytes for the number of bytes exported by the Observation Domain TOTAL_PKTS_EXP Counter with length N x 8 bits for packets for the number of bytes exported by the Observation Domain TOTAL_FLOWS_EXP Counter with length N x 8 bits for flows for the number of bytes exported by the Observation Domain SRC_VLAN Virtual LAN identifier associated with ingress interface DST_VLAN Virtual LAN identifier associated with egress interface IF_NAME Name of the interface IF_DESC Full interface name ie: "'FastEthernet 1/0" DST_MASK Destination address prefix mask bits IPV4_NEXT_HOP Next Hop SRC_MASK Source address prefix mask bits SRC_TOS Source IP type of service (ToS) Table 3 Filed Descriptions for Cisco NetFlow v9.0 Netflow v9 Fields Description version The version of NetFlow records exported in this packet; for Version 9, this value is 0x0009 sysuptime SysUptime Time in milliseconds since this device was first booted unixsecs UnixSecs Seconds since 0000 Coordinated Universal Time (UTC) 1970 packetsequence Incremental sequence counter of all export packets sent by this export device; this value is cumulative, and it can be used to identify whether any export packets have been missed sourceid The Source ID field is a 32-bit value that is used to guarantee uniqueness for all flows exported from a particular device. IN_BYTES Incoming counter with length N x 8 bits for number of bytes associated with an IP Flow IN_PKTS Incoming counter with length N x 8 bits for the number of packets associated with an IP Flow FLOWS Number of flows that were aggregated PROTOCOL IP protocol byte TCP_FLAGS Cumulative of all the TCP flags seen for this flow L4_SRC_PORT TCP/UDP source port number ie : FTP, Telnet, or equivalent IPV4_SRC_ADDR IPv4 source address INPUT_SNMP Input interface index; L4_DST_PORT TCP/UDP destination port number ie: FTP, Telnet, or equivalent IPV4_DST_ADDR IPv4 destination address OUTPUT_SNMP Output interface index; SRC_AS Source BGP autonomous system number DST_AS Destination BGP autonomous system number MUL_DST_PKTS IP multicast outgoing packet counter with length N x 8 bits for packets associated with the IP Flow MUL_DST_BYTES IP multicast outgoing byte counter with length N x 8 bits for bytes associated with the IP Flow 18 Cisco NetFlow Log Configuration Guide

19 Netflow v9 Fields Description LAST_SWITCHED System uptime at which the last packet of this flow was switched FIRST_SWITCHED System uptime at which the first packet of this flow was switched OUT_BYTES Outgoing counter with length N x 8 bits for the number of bytes associated with an IP Flow OUT_PKTS Outgoing counter with length N x 8 bits for the number of packets associated with an IP Flow MIN_PKT_LNGTH Minimum IP packet length on incoming packets of the flow MAX_PKT_LNGTH Maximum IP packet length on incoming packets of the flow IPV6_SRC_ADDR IPv6 Source Address IPV6_DST_ADDR IPv6 Destination Address SAMPLING_INTERVAL When using sampled NetFlow, the rate at which packets are sampled ie: a value of 100 indicates that one of every 100 packets is sampled SAMPLING_ALGORITHM The type of algorithm used for sampled NetFlow: 0x01 Deterministic Sampling,0x02 Random Sampling FLOW_ACTIVE_TIMEOUT Timeout value (in seconds) for active flow entries in the NetFlow cache FLOW_INACTIVE_TIMEOUT Timeout value (in seconds) for inactive flow entries in the NetFlow cache TOTAL_BYTES_EXP Counter with length N x 8 bits for bytes for the number of bytes exported by the Observation Domain TOTAL_PKTS_EXP Counter with length N x 8 bits for packets for the number of bytes exported by the Observation Domain TOTAL_FLOWS_EXP Counter with length N x 8 bits for flows for the number of bytes exported by the Observation Domain SRC_VLAN Virtual LAN identifier associated with ingress interface DST_VLAN Virtual LAN identifier associated with egress interface IF_NAME Name of the Interface IF_DESC Full interface name ie: "'FastEthernet 1/0" DIRECTION Flow direction: 0 - ingress flow, 1 - egress flow DST_MASK Destination address prefix mask bits FLOW_SAMPLER_ID The Sampling Algo Flow ID IPV4_NEXT_HOP Next Hop SRC_MASK Source address prefix mask bits SRC_TOS Source IP type of service (ToS) UNKNOWN_51 Unknown Cisco NetFlow Log Configuration Guide 19

20 20 Cisco NetFlow Log Configuration Guide

LogLogic Cisco NetFlow Log Configuration Guide

LogLogic Cisco NetFlow Log Configuration Guide LogLogic Cisco NetFlow Log Configuration Guide Document Release: September 2011 Part Number: LL600068-00ELS090000 This manual supports LogLogic Cisco NetFlow Version 1.0, and LogLogic Software Release

More information

LogLogic Cisco IPS Log Configuration Guide

LogLogic Cisco IPS Log Configuration Guide LogLogic Cisco IPS Log Configuration Guide Document Release: March 2011 Part Number: LL600072-00ELS090000 This manual supports LogLogic Cisco IPS Release 1.0 and later, and LogLogic Software Release 4.9.1

More information

LogLogic Trend Micro OfficeScan Log Configuration Guide

LogLogic Trend Micro OfficeScan Log Configuration Guide LogLogic Trend Micro OfficeScan Log Configuration Guide Document Release: September 2011 Part Number: LL600065-00ELS090000 This manual supports LogLogic Trend Micro OfficeScan Release 1.0 and later, and

More information

LogLogic General Database Collector for Microsoft SQL Server Log Configuration Guide

LogLogic General Database Collector for Microsoft SQL Server Log Configuration Guide LogLogic General Database Collector for Microsoft SQL Server Log Configuration Guide Document Release: Septembere 2011 Part Number: LL600066-00ELS100000 This manual supports LogLogic General Database Collector

More information

Juniper Secure Access SSL VPN Log Configuration Guide

Juniper Secure Access SSL VPN Log Configuration Guide Juniper Secure Access SSL VPN Log Configuration Guide Document Release: March 2012 Part Number: LL600049-00ELS01000000 This manual supports LogLogic Juniper Secure Access SSL VPN Release 1.0 and later,

More information

LogLogic Symantec Endpoint Protection Log Configuration Guide

LogLogic Symantec Endpoint Protection Log Configuration Guide LogLogic Symantec Endpoint Protection Log Configuration Guide Document Release: September 2011 Part Number: LL60005-00ELS100001 This manual supports LogLogic Symantec Endpoint Protection Release 1.0 and

More information

LogLogic Microsoft Dynamic Host Configuration Protocol (DHCP) Log Configuration Guide

LogLogic Microsoft Dynamic Host Configuration Protocol (DHCP) Log Configuration Guide LogLogic Microsoft Dynamic Host Configuration Protocol (DHCP) Log Configuration Guide Document Release: September 2011 Part Number: LL600026-00ELS090000 This manual supports LogLogic Microsoft DHCP Release

More information

LogLogic Blue Coat ProxySG Syslog Log Configuration Guide

LogLogic Blue Coat ProxySG Syslog Log Configuration Guide LogLogic Blue Coat ProxySG Syslog Log Configuration Guide Document Release: September 2011 Part Number: LL600070-00ELS100000 This manual supports LogLogic Blue Coat ProxySG Release 1.0 and later, and LogLogic

More information

Cisco IOS NetFlow Version 9 Flow-Record Format

Cisco IOS NetFlow Version 9 Flow-Record Format Cisco IOS NetFlow Version 9 Flow-Record Format Last updated: February 007 Overview Cisco IOS NetFlow services provide network administrators with access to information concerning IP flows within their

More information

LogLogic Microsoft Domain Name System (DNS) Log Configuration Guide

LogLogic Microsoft Domain Name System (DNS) Log Configuration Guide LogLogic Microsoft Domain Name System (DNS) Log Configuration Guide Document Release: September 2011 Part Number: LL600027-00ELS090000 This manual supports LogLogic Microsoft DNS Release 1.0 and later,

More information

LogLogic Juniper Networks Intrusion Detection and Prevention (IDP) Log Configuration Guide

LogLogic Juniper Networks Intrusion Detection and Prevention (IDP) Log Configuration Guide LogLogic Juniper Networks Intrusion Detection and Prevention (IDP) Log Configuration Guide Document Release: September 2011 Part Number: LL600015-00ELS090000 This manual supports LogLogic Juniper Networks

More information

Cisco IOS NetFlow Version 9 Flow-Record Format

Cisco IOS NetFlow Version 9 Flow-Record Format White Paper Cisco IOS NetFlow Version 9 Flow-Record Format Last updated: May 0 Overview Cisco IOS NetFlow services provide network administrators with access to information concerning IP flows within their

More information

Appendix A Remote Network Monitoring

Appendix A Remote Network Monitoring Appendix A Remote Network Monitoring This appendix describes the remote monitoring features available on HP products: Remote Monitoring (RMON) statistics All HP products support RMON statistics on the

More information

LogLogic Microsoft Internet Information Services (IIS) Log Configuration Guide

LogLogic Microsoft Internet Information Services (IIS) Log Configuration Guide LogLogic Microsoft Internet Information Services (IIS) Log Configuration Guide Document Release: September 2011 Part Number: LL60001-00ELS090000 This manual supports LogLogic Microsoft IIS Release 1.0

More information

LogLogic Check Point Management Station Log Configuration Guide

LogLogic Check Point Management Station Log Configuration Guide LogLogic Check Point Management Station Log Configuration Guide Document Release: September 2011 Part Number: LL600013-00ELS090000 This manual supports LogLogic Check Point Management Station Release 2.0

More information

NetFlow Aggregation. Feature Overview. Aggregation Cache Schemes

NetFlow Aggregation. Feature Overview. Aggregation Cache Schemes NetFlow Aggregation This document describes the Cisco IOS NetFlow Aggregation feature, which allows Cisco NetFlow users to summarize NetFlow export data on an IOS router before the data is exported to

More information

EMIST Network Traffic Digesting (NTD) Tool Manual (Version I)

EMIST Network Traffic Digesting (NTD) Tool Manual (Version I) EMIST Network Traffic Digesting (NTD) Tool Manual (Version I) J. Wang, D.J. Miller and G. Kesidis CSE & EE Depts, Penn State EMIST NTD Tool Manual (Version I) Page 1 of 7 Table of Contents 1. Overview...

More information

LogLogic Microsoft SQL Server Log Configuration Guide

LogLogic Microsoft SQL Server Log Configuration Guide LogLogic Microsoft SQL Server Log Configuration Guide Document Release: March 2012 Part Number: LL600028-00ELS090002 This manual supports LogLogic Microsoft SQL Server Release 2.0 and later, and LogLogic

More information

SonicOS 5.8: NetFlow Reporting

SonicOS 5.8: NetFlow Reporting SonicOS 5.8: NetFlow Reporting Document Scope Rapid growth of IP networks has created interest in new business applications and services. These new services have resulted in increases in demand for network

More information

Configuring NetFlow Data Export (NDE)

Configuring NetFlow Data Export (NDE) 49 CHAPTER Prerequisites for NDE, page 49-1 Restrictions for NDE, page 49-1 Information about NDE, page 49-2 Default Settings for NDE, page 49-11 How to Configure NDE, page 49-11 Note For complete syntax

More information

LogLogic Apache Web Server Log Configuration Guide

LogLogic Apache Web Server Log Configuration Guide LogLogic Apache Web Server Log Configuration Guide Document Release: September 2011 Part Number: LL60009-00ELS090001 This manual supports LogLogic Apache Web Server Release 1.0 and later, and LogLogic

More information

Microsoft Active Directory (AD) Service Log Configuration Guide

Microsoft Active Directory (AD) Service Log Configuration Guide Microsoft Active Directory (AD) Service Log Configuration Guide Document Release: October 2011 Part Number: LL600011-00ELS090000 This manual supports LogLogic Microsoft AD Service Release 1.0 and above,

More information

NetFlow v9 Export Format

NetFlow v9 Export Format NetFlow v9 Export Format With this release, NetFlow can export data in NetFlow v9 (version 9) export format. This format is flexible and extensible, which provides the versatility needed to support new

More information

LogLogic IBM i5/os Collector Guide

LogLogic IBM i5/os Collector Guide LogLogic IBM i5/os Collector Guide Software Release: 1.0 Document Release: December 2010 Part Number: LL600020-00EI5010001 This manual supports LogLogic IBM i5/os Collector Release 1.0 and later, and LogLogic

More information

Configuring SNMP and using the NetFlow MIB to Monitor NetFlow Data

Configuring SNMP and using the NetFlow MIB to Monitor NetFlow Data Configuring SNMP and using the NetFlow MIB to Monitor NetFlow Data NetFlow is a technology that provides highly granular per-flow statistics on traffic in a Cisco router. The NetFlow MIB feature provides

More information

http://www.cisco.com/en/us/products//hw/switches/ps4324/index.html http://www.cisco.com/en/us/products/ps6350/index.html

http://www.cisco.com/en/us/products//hw/switches/ps4324/index.html http://www.cisco.com/en/us/products/ps6350/index.html CHAPTER 54 Supervisor Engine 6-E and Catalyst 4900M chassis do not support Netflow; it is only supported on Supervisor Engine IV, Supervisor Engine V, Supervisor Engine V-10GE, or WS-F4531. This chapter

More information

NetFlow Auditor Manual Getting Started

NetFlow Auditor Manual Getting Started NetFlow Auditor Manual Getting Started Setting up NetFlow Check if your Routers or Switches Supports NetFlow. Almost all Cisco devices support NetFlow since its introduction in the 11.1 train of Cisco

More information

How-To Configure NetFlow v5 & v9 on Cisco Routers

How-To Configure NetFlow v5 & v9 on Cisco Routers How-To Configure NetFlow v5 & v9 on Cisco Routers Share: Visibility into the network is an indispensable tool for network administrators. Network visibility can be achieved through daily troubleshooting,

More information

LogLogic Juniper Networks JunOS Log Configuration Guide

LogLogic Juniper Networks JunOS Log Configuration Guide LogLogic Juniper Networks JunOS Log Configuration Guide Document Release: September 2011 Part Number: LL600052-00EL01000000 This manual supports LogLogic s Juniper Networks JunOS Release 1.0 and above,

More information

Configuring a Load-Balancing Scheme

Configuring a Load-Balancing Scheme Configuring a Load-Balancing Scheme Last Updated: October 5, 2011 This module contains information about Cisco Express Forwarding and describes the tasks for configuring a load-balancing scheme for Cisco

More information

Getting Started with Configuring Cisco IOS NetFlow and NetFlow Data Export

Getting Started with Configuring Cisco IOS NetFlow and NetFlow Data Export Getting Started with Configuring Cisco IOS NetFlow and NetFlow Data Export Last Updated: November 28, 2011 This module contains the minimum amount of information about and instructions necessary for configuring

More information

Junos OS. Flow Monitoring Feature Guide for Routing Devices. Release 14.1. Published: 2014-09-27. Copyright 2014, Juniper Networks, Inc.

Junos OS. Flow Monitoring Feature Guide for Routing Devices. Release 14.1. Published: 2014-09-27. Copyright 2014, Juniper Networks, Inc. Junos OS Flow Monitoring Feature Guide for Routing Devices Release 14.1 Published: 2014-09-27 Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net

More information

LogLogic McAfee Firewall Enterprise (Sidewinder) Log Configuration Guide

LogLogic McAfee Firewall Enterprise (Sidewinder) Log Configuration Guide LogLogic McAfee Firewall Enterprise (Sidewinder) Log Configuration Guide Document Release: September 2011 Part Number: LL600046-00ELS900001 This manual supports LogLogic Sidewinder Release 1.2 and later,

More information

LogLogic Blue Coat ProxySG Log Configuration Guide

LogLogic Blue Coat ProxySG Log Configuration Guide LogLogic Blue Coat ProxySG Log Configuration Guide Document Release: September 2011 Part Number: LL600012-00ELS100001 This manual supports LogLogic Blue Coat ProxySG Release 1.0 and later, and LogLogic

More information

Net-flow. PacNOG 6 Nadi, Fiji

Net-flow. PacNOG 6 Nadi, Fiji Net-flow PacNOG 6 Nadi, Fiji Agenda Netflow What it is and how it works Uses and Applications Vendor Configurations/ Implementation Cisco and Juniper Flow-tools Architectural issues Software, tools etc

More information

Configuring NetFlow Secure Event Logging (NSEL)

Configuring NetFlow Secure Event Logging (NSEL) 73 CHAPTER This chapter describes how to configure NSEL, a security logging mechanism that is built on NetFlow Version 9 technology, and how to handle events and syslog messages through NSEL. The chapter

More information

Cisco IOS Flexible NetFlow Technology

Cisco IOS Flexible NetFlow Technology Cisco IOS Flexible NetFlow Technology Last Updated: December 2008 The Challenge: The ability to characterize IP traffic and understand the origin, the traffic destination, the time of day, the application

More information

Netflow Overview. PacNOG 6 Nadi, Fiji

Netflow Overview. PacNOG 6 Nadi, Fiji Netflow Overview PacNOG 6 Nadi, Fiji Agenda Netflow What it is and how it works Uses and Applications Vendor Configurations/ Implementation Cisco and Juniper Flow-tools Architectural issues Software, tools

More information

LogLogic Microsoft Windows Server 2000/2003 Log Configuration Guide

LogLogic Microsoft Windows Server 2000/2003 Log Configuration Guide LogLogic Microsoft Windows Server 2000/2003 Log Configuration Guide Document Release: September 2011 Part Number: LL600029-00ELS090002 This manual supports LogLogic Microsoft Windows Server 2000/2003 Release

More information

Configuring Flexible NetFlow

Configuring Flexible NetFlow CHAPTER 62 Note Flexible NetFlow is only supported on Supervisor Engine 7-E, Supervisor Engine 7L-E, and Catalyst 4500X. Flow is defined as a unique set of key fields attributes, which might include fields

More information

Symantec Event Collector for Cisco NetFlow version 3.7 Quick Reference

Symantec Event Collector for Cisco NetFlow version 3.7 Quick Reference Symantec Event Collector for Cisco NetFlow version 3.7 Quick Reference Symantec Event Collector for Cisco NetFlow Quick Reference The software described in this book is furnished under a license agreement

More information

Integrated Traffic Monitoring

Integrated Traffic Monitoring 61202880L1-29.1F November 2009 Configuration Guide This configuration guide describes integrated traffic monitoring (ITM) and its use on ADTRAN Operating System (AOS) products. Including an overview of

More information

UltraFlow -Cisco Netflow tools-

UltraFlow -Cisco Netflow tools- UltraFlow UltraFlow is an application for collecting and analysing Cisco Netflow data. It is written in Python, wxpython, Matplotlib, SQLite and the Python based Twisted network programming framework.

More information

Flow Monitor for WhatsUp Gold v16.2 User Guide

Flow Monitor for WhatsUp Gold v16.2 User Guide Flow Monitor for WhatsUp Gold v16.2 User Guide Contents Table of Contents Flow Monitor Overview Welcome to WhatsUp Gold Flow Monitor... 1 What is Flow Monitor?... 2 How does Flow Monitor work?... 2 System

More information

Configuring a Load-Balancing Scheme

Configuring a Load-Balancing Scheme Configuring a Load-Balancing Scheme Finding Feature Information Configuring a Load-Balancing Scheme Last Updated: August 15, 2011 This module contains information about Cisco Express Forwarding and describes

More information

Enabling NetFlow on Virtual Switches ESX Server 3.5

Enabling NetFlow on Virtual Switches ESX Server 3.5 Technical Note Enabling NetFlow on Virtual Switches ESX Server 3.5 NetFlow is a general networking tool with multiple uses, including network monitoring and profiling, billing, intrusion detection and

More information

WhatsUpGold. v12.3.1. NetFlow Monitor User Guide

WhatsUpGold. v12.3.1. NetFlow Monitor User Guide WhatsUpGold v12.3.1 NetFlow Monitor User Guide Contents CHAPTER 1 WhatsUp Gold NetFlow Monitor Overview What is NetFlow?... 1 How does NetFlow Monitor work?... 2 Supported versions... 2 System requirements...

More information

Configuring a Load-Balancing Scheme

Configuring a Load-Balancing Scheme This module contains information about Cisco Express Forwarding and describes the tasks for configuring a load-balancing scheme for Cisco Express Forwarding traffic. Load-balancing allows you to optimize

More information

Configuring NetFlow Switching

Configuring NetFlow Switching Configuring NetFlow Switching This chapter describes how to configure NetFlow switching. For a complete description of NetFlow commands used in this chapter, refer to the Cisco IOS Switching s chapter

More information

Cisco IOS Flexible NetFlow Command Reference

Cisco IOS Flexible NetFlow Command Reference Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND INFORMATION

More information

Overview of Network Traffic Analysis

Overview of Network Traffic Analysis Overview of Network Traffic Analysis Network Traffic Analysis identifies which users or applications are generating traffic on your network and how much network bandwidth they are consuming. For example,

More information

NetFlow Tracker Overview. Mike McGrath x ccie CTO [email protected]

NetFlow Tracker Overview. Mike McGrath x ccie CTO mike@crannog-software.com NetFlow Tracker Overview Mike McGrath x ccie CTO [email protected] 2006 Copyright Crannog Software www.crannog-software.com 1 Copyright Crannog Software www.crannog-software.com 2 LEVELS OF NETWORK

More information

Configuring NetFlow on Cisco IOS XR Software

Configuring NetFlow on Cisco IOS XR Software Configuring NetFlow on Cisco IOS XR Software A NetFlow flow is a unidirectional sequence of packets that arrive on a single interface ( subinterface), and have the same values f key fields. NetFlow is

More information

NetStream (Integrated) Technology White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date 2012-9-6

NetStream (Integrated) Technology White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date 2012-9-6 (Integrated) Technology White Paper Issue 01 Date 2012-9-6 HUAWEI TECHNOLOGIES CO., LTD. 2012. All rights reserved. No part of this document may be reproduced or transmitted in any form or by any means

More information

NetFlow Subinterface Support

NetFlow Subinterface Support NetFlow Subinterface Support Feature History Release Modification 12.2(14)S This feature was introduced. 12.2(15)T This feature was integrated into Cisco IOS Release 12.2 T. This document describes the

More information

SolarWinds Technical Reference

SolarWinds Technical Reference SolarWinds Technical Reference Configuring Devices for Flow Collection Introduction... 3 Cisco... 3 Cisco Catalyst 3560/3750... 4 Cisco Catalyst 4500... 7 Cisco Catalyst 6500... 9 Cisco Nexus 7000/7010...

More information

Using IPM to Measure Network Performance

Using IPM to Measure Network Performance CHAPTER 3 Using IPM to Measure Network Performance This chapter provides details on using IPM to measure latency, jitter, availability, packet loss, and errors. It includes the following sections: Measuring

More information

Per-Packet Load Balancing

Per-Packet Load Balancing Per-Packet Load Balancing Feature History Release 12.0(19)ST 12.0(21)S 12.0(22)S Modification This feature was introduced on the Cisco 10000 series routers. This feature was introduced on the Cisco 12000

More information

Flow Monitor for WhatsUp Gold v16.1 User Guide

Flow Monitor for WhatsUp Gold v16.1 User Guide Flow Monitor for WhatsUp Gold v16.1 User Guide Contents Table of Contents Flow Monitor Overview Welcome to WhatsUp Gold Flow Monitor... 1 What is Flow Monitor?... 2 How does Flow Monitor work?... 2 System

More information

Integrated Traffic Monitoring

Integrated Traffic Monitoring 61202880L1-29.1E July 2008 Configuration Guide This configuration guide describes integrated traffic monitoring (ITM) and its use on ADTRAN Operating System (AOS) products. Including an overview of the

More information

NetFlow Configuration Guide, Cisco IOS Release 12.4

NetFlow Configuration Guide, Cisco IOS Release 12.4 NetFlow Configuration Guide, Cisco IOS Release 12.4 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

WhatsUpGold. v15.0. Flow Monitor User Guide

WhatsUpGold. v15.0. Flow Monitor User Guide WhatsUpGold v15.0 Flow Monitor User Guide Contents CHAPTER 1 Flow Monitor Overview Welcome to WhatsUp Gold Flow Monitor... 1 What is Flow Monitor?... 2 How does Flow Monitor work?... 2 System requirements...

More information

Configuring NetFlow on Cisco ASR 9000 Series Aggregation Services Router

Configuring NetFlow on Cisco ASR 9000 Series Aggregation Services Router Configuring NetFlow on Cisco ASR 9000 Series Aggregation Services Router This module describes the configuration of NetFlow on the Cisco ASR 9000 Series Aggregation Services Router. A NetFlow flow is a

More information

Introduction to Cisco IOS Flexible NetFlow

Introduction to Cisco IOS Flexible NetFlow Introduction to Cisco IOS Flexible NetFlow Last updated: September 2008 The next-generation in flow technology allowing optimization of the network infrastructure, reducing operation costs, improving capacity

More information

SonicOS 5.8: NetFlow Reporting

SonicOS 5.8: NetFlow Reporting SonicOS 5.8: NetFlow Reporting Document Scope Rapid growth of IP networks has created interest in new business applications and services. These new services have resulted in increases in demand for network

More information

Sampled NetFlow. Feature Overview. Benefits

Sampled NetFlow. Feature Overview. Benefits Sampled NetFlow This feature module describes the Sampled NetFlow feature. It includes information on the benefits of the new feature, supported platforms, supported standards, and the commands necessary

More information

ProSafe Plus Switch Utility

ProSafe Plus Switch Utility ProSafe Plus Switch Utility User Guide 350 East Plumeria Drive San Jose, CA 95134 USA September 2010 202-10524-03 v1.0 ProSafe Plus Switch Utility User Guide 2010 NETGEAR, Inc. All rights reserved. No

More information

Hillstone StoneOS User Manual Hillstone Unified Intelligence Firewall Installation Manual

Hillstone StoneOS User Manual Hillstone Unified Intelligence Firewall Installation Manual Hillstone StoneOS User Manual Hillstone Unified Intelligence Firewall Installation Manual www.hillstonenet.com Preface Conventions Content This document follows the conventions below: CLI Tip: provides

More information

- Multiprotocol Label Switching -

- Multiprotocol Label Switching - 1 - Multiprotocol Label Switching - Multiprotocol Label Switching Multiprotocol Label Switching (MPLS) is a Layer-2 switching technology. MPLS-enabled routers apply numerical labels to packets, and can

More information

SolarWinds Technical Reference

SolarWinds Technical Reference SolarWinds Technical Reference Configuring Devices for Flow Collection Introduction... 3 Cisco... 3 Cisco Catalyst 3560/3750... 4 Cisco Catalyst 4500... 7 Cisco Catalyst 6500... 9 Cisco Nexus 7000/7010...

More information

Enabling and Monitoring NetFlow on Subinterfaces

Enabling and Monitoring NetFlow on Subinterfaces Enabling and Monitoring NetFlow on Subinterfaces This module contains instructions for enabling and monitoring NetFlow on a router subinterface or a Versatile Interface Processor (VIP) controller interface.

More information

NetFlow/IPFIX Various Thoughts

NetFlow/IPFIX Various Thoughts NetFlow/IPFIX Various Thoughts Paul Aitken & Benoit Claise 3 rd NMRG Workshop on NetFlow/IPFIX Usage in Network Management, July 2010 1 B #1 Application Visibility Business Case NetFlow (L3/L4) DPI Application

More information

HP Load Balancing Module

HP Load Balancing Module HP Load Balancing Module Load Balancing Configuration Guide Part number: 5998-2685 Document version: 6PW101-20120217 Legal and notice information Copyright 2012 Hewlett-Packard Development Company, L.P.

More information

SolarWinds Technical Reference

SolarWinds Technical Reference SolarWinds Technical Reference Understanding Cisco ASA NetFlow Cisco Adaptive Security Appliance (ASA) NetFlow Overview... 3 Understanding the Implementation Requirements... 4 Troubleshooting ASA NetFlow...

More information

Configuring NetFlow-lite

Configuring NetFlow-lite CHAPTER 55 Note NetFlow-lite is only supported on Catalyst 4948E Ethernet Switch. This chapter describes how to configure NetFlow-lite on the Catalyst 4948E switch. NetFlow-lite provides traffic monitoring

More information

Network Load Balancing

Network Load Balancing Network Load Balancing Step by Step installation of Network Load Balancing in Windows Server 2008 R2. Prerequisite for NLB Cluster 1. Log on to NODE1 Windows Server 2008 R2 system with a domain account

More information

Virtual Fragmentation Reassembly

Virtual Fragmentation Reassembly Virtual Fragmentation Reassembly Currently, the Cisco IOS Firewall specifically context-based access control (CBAC) and the intrusion detection system (IDS) cannot identify the contents of the IP fragments

More information

Traffic monitoring with sflow and ProCurve Manager Plus

Traffic monitoring with sflow and ProCurve Manager Plus An HP ProCurve Networking Application Note Traffic monitoring with sflow and ProCurve Manager Plus Contents 1. Introduction... 3 2. Prerequisites... 3 3. Network diagram... 3 4. About the sflow protocol...

More information

CHAPTER 1 WhatsUp Flow Monitor Overview. CHAPTER 2 Configuring WhatsUp Flow Monitor. CHAPTER 3 Navigating WhatsUp Flow Monitor

CHAPTER 1 WhatsUp Flow Monitor Overview. CHAPTER 2 Configuring WhatsUp Flow Monitor. CHAPTER 3 Navigating WhatsUp Flow Monitor Contents CHAPTER 1 WhatsUp Flow Monitor Overview What is Flow Monitor?... 1 How does Flow Monitor work?... 2 Supported versions... 2 System requirements... 2 CHAPTER 2 Configuring WhatsUp Flow Monitor

More information

NetFlow Analytics for Splunk

NetFlow Analytics for Splunk NetFlow Analytics for Splunk User Manual Version 3.5.1 September, 2015 Copyright 2012-2015 NetFlow Logic Corporation. All rights reserved. Patents Pending. Contents Introduction... 3 Overview... 3 Installation...

More information

Configuring NetFlow. Information About NetFlow. Send document comments to [email protected]. CHAPTER

Configuring NetFlow. Information About NetFlow. Send document comments to nexus1k-docfeedback@cisco.com. CHAPTER CHAPTER 11 Use this chapter to configure NetFlow to characterize IP traffic based on its source, destination, timing, and application information, to assess network availability and performance. This chapter

More information

LAB II: Securing The Data Path and Routing Infrastructure

LAB II: Securing The Data Path and Routing Infrastructure LAB II: Securing The Data Path and Routing Infrastructure 8. Create Packet Filters a. Create a packet filter which will deny packets that have obviously bogus IP source addresses but permit everything

More information

GLBP - Gateway Load Balancing Protocol

GLBP - Gateway Load Balancing Protocol GLBP - Gateway Load Balancing Protocol Gateway Load Balancing Protocol (GLBP) protects data traffic from a failed router or circuit, like Hot Standby Router Protocol (HSRP) and Virtual Router Redundancy

More information

NetFlow Configuration Guide, Cisco IOS Release 15M&T

NetFlow Configuration Guide, Cisco IOS Release 15M&T Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND INFORMATION

More information

Copyright 2012 Trend Micro Incorporated. All rights reserved.

Copyright 2012 Trend Micro Incorporated. All rights reserved. Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files,

More information

Interworks. Interworks Cloud Platform Installation Guide

Interworks. Interworks Cloud Platform Installation Guide Interworks Interworks Cloud Platform Installation Guide Published: March, 2014 This document contains information proprietary to Interworks and its receipt or possession does not convey any rights to reproduce,

More information

Cisco IOS NetFlow Command Reference

Cisco IOS NetFlow Command Reference July 2011 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND

More information

Lab 4.1.2 Characterizing Network Applications

Lab 4.1.2 Characterizing Network Applications Lab 4.1.2 Characterizing Network Applications Objective Device Designation Device Name Address Subnet Mask Discovery Server Business Services 172.17.1.1 255.255.0.0 R1 FC-CPE-1 Fa0/1 172.17.0.1 Fa0/0 10.0.0.1

More information

SOA Software API Gateway Appliance 7.1.x Administration Guide

SOA Software API Gateway Appliance 7.1.x Administration Guide SOA Software API Gateway Appliance 7.1.x Administration Guide Trademarks SOA Software and the SOA Software logo are either trademarks or registered trademarks of SOA Software, Inc. Other product names,

More information

NetFlow-Lite offers network administrators and engineers the following capabilities:

NetFlow-Lite offers network administrators and engineers the following capabilities: Solution Overview Cisco NetFlow-Lite Introduction As networks become more complex and organizations enable more applications, traffic patterns become more diverse and unpredictable. Organizations require

More information

642 523 Securing Networks with PIX and ASA

642 523 Securing Networks with PIX and ASA 642 523 Securing Networks with PIX and ASA Course Number: 642 523 Length: 1 Day(s) Course Overview This course is part of the training for the Cisco Certified Security Professional and the Cisco Firewall

More information

Application Notes for BT Wholesale/HIPCOM SIP Trunk Service and Avaya IP Office 8.0 Issue 1.0

Application Notes for BT Wholesale/HIPCOM SIP Trunk Service and Avaya IP Office 8.0 Issue 1.0 Avaya Solution & Interoperability Test Lab Application Notes for BT Wholesale/HIPCOM SIP Trunk Service and Avaya IP Office 8.0 Issue 1.0 Abstract These Application Notes describe the procedures for configuring

More information

Configuring Network Address Translation (NAT)

Configuring Network Address Translation (NAT) 8 Configuring Network Address Translation (NAT) Contents Overview...................................................... 8-3 Translating Between an Inside and an Outside Network........... 8-3 Local and

More information

SolarWinds Technical Reference

SolarWinds Technical Reference SolarWinds Technical Reference Enabling NetFlow and NetFlow Data Export (NDE) on Cisco Catalyst Switches Introduction... 3 Requirements... 3 Catalyst 4500 Series... 3 Enabling NetFlow... 3 Configuring

More information

Network Agent Quick Start

Network Agent Quick Start Network Agent Quick Start Topic 50500 Network Agent Quick Start Updated 17-Sep-2013 Applies To: Web Filter, Web Security, Web Security Gateway, and Web Security Gateway Anywhere, v7.7 and 7.8 Websense

More information

Parallels Plesk Control Panel

Parallels Plesk Control Panel Parallels Plesk Control Panel Copyright Notice ISBN: N/A Parallels 660 SW 39 th Street Suite 205 Renton, Washington 98057 USA Phone: +1 (425) 282 6400 Fax: +1 (425) 282 6444 Copyright 1999-2008, Parallels,

More information

Cisco UCS Director Payment Gateway Integration Guide, Release 4.1

Cisco UCS Director Payment Gateway Integration Guide, Release 4.1 First Published: April 16, 2014 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883

More information

Catalyst 6500/6000 Switches NetFlow Configuration and Troubleshooting

Catalyst 6500/6000 Switches NetFlow Configuration and Troubleshooting Catalyst 6500/6000 Switches NetFlow Configuration and Troubleshooting Document ID: 70974 Introduction Prerequisites Requirements Components Used Conventions Background Information Configure Network Diagram

More information

Cisco Configuring Basic MPLS Using OSPF

Cisco Configuring Basic MPLS Using OSPF Table of Contents Configuring Basic MPLS Using OSPF...1 Introduction...1 Mechanism...1 Hardware and Software Versions...2 Network Diagram...2 Configurations...2 Quick Configuration Guide...2 Configuration

More information