02-16-2011 04:53 AM - edited 03-04-2019 11:26 AM
Hi following the order of operation in IOS,
as you can see Netflow ingress is taken before Decryption
and Netflow egress is taken after Encryption.
So we have the problem that Netflow-records which are exported (created on ingress or egress netflow on a encrypted link) we only get the information about the IP-addresses (because GET-VPN preserves the IP-header) but not about the L4-Protocols. Every traffic is shown a ESP, which is clear if we have a look onto the order of IOS operations.
Is there any (hidden) way to influence these oder of operations, se we would be able to get netflow-records with the correct L4-Ports ?
Thx
Hubert
02-16-2011 05:36 AM
Hi, Configuring flexible Netflow may help using the output-features command. See below
http://www.cisco.com/en/US/docs/ios/fnetflow/configuration/guide/cfg_de_fnflow_exprts.html
02-16-2011 05:43 AM
Hi thats deninitifely not what solves our problem, the Netflow-records just show us ESP!
Hubert
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide