cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Popup Hotspot Using ISR 1000 with WiFi/LTE for Teleworkers and Micro Branchesr
459
Views
5
Helpful
4
Replies
Highlighted
Frequent Contributor

Negative impacts by implementing Netflow?

Would there be any considerations in regards to negative impacts by implementing Netflow on production network devices/infrastructure such as memory, CPU, etc? I know only cached data is sent to a collector so I would not think so but seeking some guidance.

4 REPLIES 4
Highlighted
VIP Advisor VIP Advisor
VIP Advisor

Re: Negative impacts by implementing Netflow?

Hi, On modern hardware you would only expect to see a couple of additional % utilisation once netflow is enabled.

 

HTH

Highlighted
Frequent Contributor

Re: Negative impacts by implementing Netflow?

How about switches, routers, ASA, etc.? I read about possible high CPU utilization but even if that were the case, can't you set CPU threshold parameters to make sure Netflow does not hog CPU on the device?
Highlighted
VIP Advisor VIP Advisor
VIP Advisor

Re: Negative impacts by implementing Netflow?

A long time ago (15 years ago) netflow hogging resources used to be considered an issue, nowadays newer hardware shouldn't be a problem, even if hardware is 5 years old. You can define a CPU utilisation threshold, example here.

 

HTH

Highlighted
Frequent Contributor

Re: Negative impacts by implementing Netflow?

Awesome!

What do you think is a good limit to set for the CPU?

Is it best to set cache limits as well?

Basically, if there is a ton of traffic on the network, I would want to reduce any potential for issue as much as possible by configuring certain parameters other than perhaps random  sampling or something.

Also, if you have IPSEC VPNs that use the interface NetFlow in configured on, it should collect that tunnel data as well correct? What if there are multiple tunnels on that interface?

CreatePlease to create content
Content for Community-Ad