cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2209
Views
0
Helpful
2
Replies

Netflow Stats for Selected Prefixes

jmujica
Level 1
Level 1

Hi.

I'm wondering if I can enable netflow on an interface and capture just the flows for specific prefixes. The problem is that I have netflow enable on a couple of OC-3 interfaces and my netflow collector is getting a lot of stats and is getting full with just a couple of hours of stats. I would like to capture stats for at least 3 weeks for those specific prefixes.

I can enable netflow on the access layer but the problem is that the prefixes are spread all over the place and the OC3 links are the exit point.

Any idea on how to gather those statistics.... without overloading the NFC Server... :)

TIA,

-Jose

2 Replies 2

m.singer
Level 4
Level 4

The Netflow collector would use a particular port on which the exported data from the routers will be collected. Try putting an access-list or some other kind of filtering that would block the unwanted Prefixes from reaching the Netflow collector. Identify the port used by the Netflow collector and filter the unwanted prefixes from reaching the Netflow collector.

yjdabear
VIP Alumni
VIP Alumni

One approach may be to get a commercial or freeware NetFlow analysis/reporting tool that imports the NFC data into its own database periodically, say every 15 mins, so you don't have to worry about data storage on the NFC anymore. The tool can possibly report on specific prefixes too.

Another is to replace NFC completely with a third-party collection that can filter by prefixes.

BTW, NetFlow version 8 seems to support both dst-prefix and src-prefix aggregation.