cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
225
Views
0
Helpful
4
Replies

NTA Direction

hs08
Spotlight
Spotlight

Hello,

If i execute command show flow monitor NTA-Mon cache format table i got this record.

From below picture how we can determine for every record the traffic is ingress or egress?

For example for record one, is the 10.103.248.66 download or upload to host 10.100.63.27?

hs08_0-1719283566133.png

 

1 Accepted Solution

Accepted Solutions
4 Replies 4

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello @hs08 ,

the table says that 10.103.248.66 is the source address and 10.100.63.27 and it is seen on interface SVI Vlan 905.

What IP address is on interface Vlan 905 ?

probably looking at the table the subnet 10.103.248.0 is where Vlan 905 is.

You can also check the routing table for the destination address, if the next hop to the destination is not out of Vlan 905 you can consider the traffic as inbound received on SVI Vlan 905 to be routed to some other interface.

Hope to help

Giuseppe

 

Hello @Giuseppe Larosa 

Subnet 10.103.0.0/16 is remote subnet on branch, our local subnet is 10.100.0.0/16. Interface g0/1/1 is member of VLAN 905 and connected to the branch over WAN connection. Interface g0/1/0 is member of VLAN 602 which connected to the core switch.

 

hs08_1-1719286084046.png

 

Hello @hs08 ,

what I can suggest you is to use two different flow monitor one to be used in ingress direction and one in egress direction.

This will solve your issue because you will see a table for each flow monitor.

Hope to help

Giuseppe

hs08_0-1719283566133.png

Review Cisco Networking for a $25 gift card