cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
933
Views
0
Helpful
0
Replies

Netflow entries with source/dest. ip address 0.0.0.0?

Hi J

 

Have you got any idea, what the entries in the following netflow printouts with the source/destination ip-address 0.0.0.0 mean?  We can see them both on the CE- and PE-Routers and we do not use any tunnels/TE on the appropriate interfaces?

CE-028  àc6500

 netflow activated on Gi1/2 (vrf lite to PE-028)

 

PE-028 à c7600

Netflow activated on Gi2/0/0 (to MPLS-Net)

                                                Gi2/0/3 (vrf lite tp CE-028)

Extractions from printouts:

PE-028#sh mls netflow ip qos

Displaying Netflow entries in Supervisor Earl

DstIP           SrcIP           Prot:SrcPort:DstPort Src i/f         :AdjPtr   

--------------------------------------------------------------------------------

Pkts         Bytes         LastSeen   QoS    PoliceCount  Threshold   Leak     

--------------------------------------------------------------------------------

Drop  Bucket  

---------------

224.0.0.2       192.168.16.190  udp :646    :646     Gi2/0/0          0x0      

299          18538         16:22:20   0xC0   0            0           0        

NO    0       

0.0.0.0         0.0.0.0         0   :0      :0       --               0x0      

110474       9939421       16:22:25   0xC0   0            0           0        

NO    0       

 

 

mrt-028#sh mls netflow ip   

Displaying Netflow entries in Supervisor Earl

DstIP           SrcIP           Prot:SrcPort:DstPort  Src i/f          :AdjPtr

-----------------------------------------------------------------------------

Pkts         Bytes         Age   LastSeen  Attributes

---------------------------------------------------

224.0.0.2       192.168.16.190  udp :646    :646      Gi2/0/0          :0x0        

3            186           12    09:28:16   Multicast

0.0.0.0         0.0.0.0         0   :0      :0        --               :0x0        

250649       20655390      550   09:28:19   L3 – Dynamic

 

 

 

 

 

PE-028#sh ip cache flow

 

-------------------------------------------------------------------------------

MSFC:

IP packet size distribution (4293 total packets):

   1-32   64   96  128  160  192  224  256  288  320  352  384  416  448  480

   .001 .574 .267 .048 .003 .011 .000 .000 .000 .000 .000 .007 .070 .003 .000

 

    512  544  576 1024 1536 2048 2560 3072 3584 4096 4608

   .000 .000 .000 .000 .007 .000 .000 .000 .000 .000 .000

 

IP Flow Switching Cache, 278544 bytes

  1 active, 4095 inactive, 549 added

  26904 ager polls, 0 flow alloc failures

  Active flows timeout in 30 minutes

  Inactive flows timeout in 15 seconds

IP Sub Flow Cache, 33992 bytes

  0 active, 1024 inactive, 0 added, 0 added to flow

  0 alloc failures, 0 force free

  1 chunk, 4 chunks added

  last clearing of statistics never

Protocol         Total    Flows   Packets Bytes  Packets Active(Sec) Idle(Sec)

--------         Flows     /Sec     /Flow  /Pkt     /Sec     /Flow     /Flow

TCP-BGP            101      0.0         1    69      0.0       2.6      15.4

TCP-other          181      0.0        10    62      0.0       5.3      15.1

UDP-NTP             87      0.0         1    76      0.0       0.0      15.4

UDP-other           54      0.0        32   131      0.0     141.8      14.5

ICMP               117      0.0         1    84      0.0       0.0      15.4

IP-other             2      0.0       112   318      0.0     827.3      12.7

Total:             542      0.0         7   105      0.0      19.4      15.2

 

SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts

Gi2/0/3       172.19.225.26   Null          224.0.0.5       59 0000 0000    10

         

-------------------------------------------------------------------------------

PFC:

 

Displaying Hardware entries in Module 1

 SrcIf            SrcIPaddress          DstIPaddress      Pr       SrcP      DstP      Pkts

 Gi2/0/3          172.18.44.69          172.22.36.8       47       0         0         29          

 Gi2/0/3          172.18.45.143         172.22.32.40      tcp      39642     4000      15          

 Gi2/0/0          192.168.16.190        224.0.0.2         udp      646       646       180         

 --               0.0.0.0               0.0.0.0           0        0         0         426163      

 Gi2/0/3          172.18.45.143         172.22.36.40      tcp      48121     4000      2           

 Gi2/0/3          172.19.225.26         224.0.0.5         89       0         0         11          

 Gi2/0/3          172.18.44.68          172.22.36.7       47       0         0         27          

 Gi2/0/3          172.18.45.141         172.22.36.40      tcp      48678     4000      6           

 Gi2/0/3          172.18.46.253         172.22.36.36      icmp     0         0         1    

 

 

CE-028#sh ip cache flow

 

-------------------------------------------------------------------------------

 

Displaying software-switched flow entries on the MSFC in Module 5:

 

IP packet size distribution (4487 total packets):

   1-32   64   96  128  160  192  224  256  288  320  352  384  416  448  480

   .003 .396 .316 .129 .006 .033 .000 .000 .001 .001 .000 .032 .046 .004 .001

 

    512  544  576 1024 1536 2048 2560 3072 3584 4096 4608

   .006 .000 .000 .002 .016 .000 .000 .000 .000 .000 .000

 

IP Flow Switching Cache, 278544 bytes

  4 active, 4092 inactive, 351 added

  11059 ager polls, 0 flow alloc failures

  Active flows timeout in 30 minutes

  Inactive flows timeout in 15 seconds

IP Sub Flow Cache, 33992 bytes

  0 active, 1024 inactive, 0 added, 0 added to flow

  0 alloc failures, 0 force free

  1 chunk, 4 chunks added

  last clearing of statistics never

Protocol         Total    Flows   Packets Bytes  Packets Active(Sec) Idle(Sec)

--------         Flows     /Sec     /Flow  /Pkt     /Sec     /Flow     /Flow

TCP-other           31      0.0        93    60      0.0      15.3      10.1

UDP-NTP             43      0.0         1    76      0.0       0.0      15.4

UDP-other          126      0.0         5   301      0.0       1.1      15.5

ICMP               142      0.0         1    84      0.0       0.0      15.4

IP-other             5      0.0       135   270      0.0    1012.4       4.4

Total:             347      0.0        12   129      0.0      16.3      14.8

         

SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts

Gi1/2         172.22.32.55    Local         172.19.248.69   06 FF18 0016    68

Gi1/2         172.22.32.36    Local         172.19.248.69   11 EE79 00A1     1

Gi1/2         172.19.225.25   Null          224.0.0.5       59 0000 0000     3

Gi1/2         172.22.36.36    Local         172.19.248.69   11 E0E3 00A1     9

 

-------------------------------------------------------------------------------

 

Displaying hardware-switched flow entries in the DFC Module 1:

 SrcIf            SrcIPaddress     DstIf            DstIPaddress    Pr SrcP DstP  Pkts

 

 --               0.0.0.0          ---              0.0.0.0         00 0000 0000   405K

 Gi1/2            172.22.32.55     ---              172.19.248.69   06 FF18 0016     0

 Gi1/2            172.19.225.25    ---              224.0.0.5       59 0000 0000    48

 Gi1/2            172.22.32.7      Vl980            172.18.44.68    2F 0000 0000    12

 Gi1/2            172.22.32.8      Vl980            172.18.44.69    2F 0000 0000    10

 Gi1/2            172.22.36.8      Vl980            172.18.44.69    2F 0000 0000    10

 Gi1/2            172.22.32.36     Vl980            172.18.44.35    01 0008 0000     1

 Gi1/2            172.22.36.36     Vl980            172.18.46.22    11 E0E4 00A1    10

 Gi1/2            172.22.36.7      Vl980            172.18.44.68    2F 0000 0000     9

 Gi1/2            172.22.32.36     Vl980            172.18.46.23    11 EE79 00A1     1

 Gi1/2            172.22.32.36     Vl980            172.18.46.6     11 EE79 00A1     1

 Gi1/2            172.22.32.36     Vl980            172.18.44.68    11 EE79 00A1     1

 Gi1/2            172.22.32.36     Vl980            172.18.46.253   11 EE79 00A1     1

0 Replies 0