07-01-2016 07:18 AM - edited 03-05-2019 04:20 AM
Hi J
Have you got any idea, what the entries in the following netflow printouts with the source/destination ip-address 0.0.0.0 mean? We can see them both on the CE- and PE-Routers and we do not use any tunnels/TE on the appropriate interfaces?
CE-028 àc6500
netflow activated on Gi1/2 (vrf lite to PE-028)
PE-028 à c7600
Netflow activated on Gi2/0/0 (to MPLS-Net)
Gi2/0/3 (vrf lite tp CE-028)
Extractions from printouts:
PE-028#sh mls netflow ip qos
Displaying Netflow entries in Supervisor Earl
DstIP SrcIP Prot:SrcPort:DstPort Src i/f :AdjPtr
--------------------------------------------------------------------------------
Pkts Bytes LastSeen QoS PoliceCount Threshold Leak
--------------------------------------------------------------------------------
Drop Bucket
---------------
224.0.0.2 192.168.16.190 udp :646 :646 Gi2/0/0 0x0
299 18538 16:22:20 0xC0 0 0 0
NO 0
0.0.0.0 0.0.0.0 0 :0 :0 -- 0x0
110474 9939421 16:22:25 0xC0 0 0 0
NO 0
mrt-028#sh mls netflow ip
Displaying Netflow entries in Supervisor Earl
DstIP SrcIP Prot:SrcPort:DstPort Src i/f :AdjPtr
-----------------------------------------------------------------------------
Pkts Bytes Age LastSeen Attributes
---------------------------------------------------
224.0.0.2 192.168.16.190 udp :646 :646 Gi2/0/0 :0x0
3 186 12 09:28:16 Multicast
0.0.0.0 0.0.0.0 0 :0 :0 -- :0x0
250649 20655390 550 09:28:19 L3 – Dynamic
PE-028#sh ip cache flow
-------------------------------------------------------------------------------
MSFC:
IP packet size distribution (4293 total packets):
1-32 64 96 128 160 192 224 256 288 320 352 384 416 448 480
.001 .574 .267 .048 .003 .011 .000 .000 .000 .000 .000 .007 .070 .003 .000
512 544 576 1024 1536 2048 2560 3072 3584 4096 4608
.000 .000 .000 .000 .007 .000 .000 .000 .000 .000 .000
IP Flow Switching Cache, 278544 bytes
1 active, 4095 inactive, 549 added
26904 ager polls, 0 flow alloc failures
Active flows timeout in 30 minutes
Inactive flows timeout in 15 seconds
IP Sub Flow Cache, 33992 bytes
0 active, 1024 inactive, 0 added, 0 added to flow
0 alloc failures, 0 force free
1 chunk, 4 chunks added
last clearing of statistics never
Protocol Total Flows Packets Bytes Packets Active(Sec) Idle(Sec)
-------- Flows /Sec /Flow /Pkt /Sec /Flow /Flow
TCP-BGP 101 0.0 1 69 0.0 2.6 15.4
TCP-other 181 0.0 10 62 0.0 5.3 15.1
UDP-NTP 87 0.0 1 76 0.0 0.0 15.4
UDP-other 54 0.0 32 131 0.0 141.8 14.5
ICMP 117 0.0 1 84 0.0 0.0 15.4
IP-other 2 0.0 112 318 0.0 827.3 12.7
Total: 542 0.0 7 105 0.0 19.4 15.2
SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts
Gi2/0/3 172.19.225.26 Null 224.0.0.5 59 0000 0000 10
-------------------------------------------------------------------------------
PFC:
Displaying Hardware entries in Module 1
SrcIf SrcIPaddress DstIPaddress Pr SrcP DstP Pkts
Gi2/0/3 172.18.44.69 172.22.36.8 47 0 0 29
Gi2/0/3 172.18.45.143 172.22.32.40 tcp 39642 4000 15
Gi2/0/0 192.168.16.190 224.0.0.2 udp 646 646 180
-- 0.0.0.0 0.0.0.0 0 0 0 426163
Gi2/0/3 172.18.45.143 172.22.36.40 tcp 48121 4000 2
Gi2/0/3 172.19.225.26 224.0.0.5 89 0 0 11
Gi2/0/3 172.18.44.68 172.22.36.7 47 0 0 27
Gi2/0/3 172.18.45.141 172.22.36.40 tcp 48678 4000 6
Gi2/0/3 172.18.46.253 172.22.36.36 icmp 0 0 1
CE-028#sh ip cache flow
-------------------------------------------------------------------------------
Displaying software-switched flow entries on the MSFC in Module 5:
IP packet size distribution (4487 total packets):
1-32 64 96 128 160 192 224 256 288 320 352 384 416 448 480
.003 .396 .316 .129 .006 .033 .000 .000 .001 .001 .000 .032 .046 .004 .001
512 544 576 1024 1536 2048 2560 3072 3584 4096 4608
.006 .000 .000 .002 .016 .000 .000 .000 .000 .000 .000
IP Flow Switching Cache, 278544 bytes
4 active, 4092 inactive, 351 added
11059 ager polls, 0 flow alloc failures
Active flows timeout in 30 minutes
Inactive flows timeout in 15 seconds
IP Sub Flow Cache, 33992 bytes
0 active, 1024 inactive, 0 added, 0 added to flow
0 alloc failures, 0 force free
1 chunk, 4 chunks added
last clearing of statistics never
Protocol Total Flows Packets Bytes Packets Active(Sec) Idle(Sec)
-------- Flows /Sec /Flow /Pkt /Sec /Flow /Flow
TCP-other 31 0.0 93 60 0.0 15.3 10.1
UDP-NTP 43 0.0 1 76 0.0 0.0 15.4
UDP-other 126 0.0 5 301 0.0 1.1 15.5
ICMP 142 0.0 1 84 0.0 0.0 15.4
IP-other 5 0.0 135 270 0.0 1012.4 4.4
Total: 347 0.0 12 129 0.0 16.3 14.8
SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts
Gi1/2 172.22.32.55 Local 172.19.248.69 06 FF18 0016 68
Gi1/2 172.22.32.36 Local 172.19.248.69 11 EE79 00A1 1
Gi1/2 172.19.225.25 Null 224.0.0.5 59 0000 0000 3
Gi1/2 172.22.36.36 Local 172.19.248.69 11 E0E3 00A1 9
-------------------------------------------------------------------------------
Displaying hardware-switched flow entries in the DFC Module 1:
SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts
-- 0.0.0.0 --- 0.0.0.0 00 0000 0000 405K
Gi1/2 172.22.32.55 --- 172.19.248.69 06 FF18 0016 0
Gi1/2 172.19.225.25 --- 224.0.0.5 59 0000 0000 48
Gi1/2 172.22.32.7 Vl980 172.18.44.68 2F 0000 0000 12
Gi1/2 172.22.32.8 Vl980 172.18.44.69 2F 0000 0000 10
Gi1/2 172.22.36.8 Vl980 172.18.44.69 2F 0000 0000 10
Gi1/2 172.22.32.36 Vl980 172.18.44.35 01 0008 0000 1
Gi1/2 172.22.36.36 Vl980 172.18.46.22 11 E0E4 00A1 10
Gi1/2 172.22.36.7 Vl980 172.18.44.68 2F 0000 0000 9
Gi1/2 172.22.32.36 Vl980 172.18.46.23 11 EE79 00A1 1
Gi1/2 172.22.32.36 Vl980 172.18.46.6 11 EE79 00A1 1
Gi1/2 172.22.32.36 Vl980 172.18.44.68 11 EE79 00A1 1
Gi1/2 172.22.32.36 Vl980 172.18.46.253 11 EE79 00A1 1
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide