09-27-2021 01:26 PM - edited 09-27-2021 01:36 PM
Hi,
we are trying to get visibility into traffic at our remote site using netflow on a 9500. This remote site core switch has many VLANs and attaches to many 9300 access switches via trunks. All routing for the site is on the 9500. Traffic from and to the remote site is being captured by our Main campus 6807, so there isn't a need to configure netflow on any interfaces between the remote site and the Main campus.
We are looking to get visibility into traffic at the sight traversing between and within VLANs.
What would be the best way to apply this? On the VLAN interfaces of the Core 9500, or trunks of the 9500 to the access switches or VLANs on the Core and/or access switch or all of the above? I'm assuming that traffic between VLANs would get captured by the VLAN interface netflow config on the 9500. Traffic going to another switch to the same VLAN or a different VLAN would get captured from a trunk netflow config on the 9500 and traffic within a VLAN that will not leave the access switch would be captured by a VLAN netflow config on the access switch VLAN?
Another question I had.....is there a need to configure netflow on both the ingress and egress on the VLAN interface or trunk interface? If I config ingress only on each interface, won't I catch traffic in both directions as the traffic will ingress on another VLAN interface or trunk interface? What advantage would I have be configuring ingress and egress on the same interface?
I know this is a lot, but would appreciate any insight.
Thank you, Pat
09-27-2021 03:14 PM
better visibility i go with Layer3 SVI of VLAN, but new netflow on Cat 9500 do support Layer2
09-28-2021 06:34 AM
Thx BB - do you config ingress and egress on VLAN interfaces or just in one direction? And why?
Also, if I configure only on VLAN interfaces I would miss intra-VLAN flows, correct? For L2 traffic within the VLAN I would need to configure netflow on the trunks to the access switches?
Thank you, Pat
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide