NetFlow Cisco
! global ip flow-export version 9 ip flow-export destination <XORMON_IP> 2055 ip flow-cache timeout active 1 ip flow-cache timeout inactive 15 ! on every interface you want to measure interface GigabitEthernet0/1 ip route-cache flowOn later 12.4/15.x releases,
ip route-cache flow is replaced by:
interface GigabitEthernet0/1 ip flow ingress ip flow egressVerify with:
show ip flow export show ip cache flow
flow record XORMON-RECORD match ipv4 protocol match ipv4 source address match ipv4 destination address match transport source-port match transport destination-port match interface input collect interface output collect counter bytes long collect counter packets long collect timestamp sys-uptime first collect timestamp sys-uptime last flow exporter XORMON-EXPORTER destination <XORMON_IP> transport udp 2055 export-protocol netflow-v9 source Loopback0 flow monitor XORMON-MONITOR record XORMON-RECORD exporter XORMON-EXPORTER cache timeout active 60 cache timeout inactive 15 ! on the interface interface GigabitEthernet1/0/1 ip flow monitor XORMON-MONITOR input ip flow monitor XORMON-MONITOR outputVerify with:
show flow monitor XORMON-MONITOR cache show flow exporter XORMON-EXPORTER statisticsNX-OS uses the same
flow record / flow exporter / flow monitor triad, with slightly different field syntax — ask if you need the Nexus-specific variant.
ip flow-export destination <XORMON_IP> 2055(the existing
ip flow-export destination <old_collector_ip> <port> line stays untouched)
flow monitor can reference multiple exporters, so add a new exporter and attach it to the existing monitor (no need to touch interface config):
flow exporter XORMON-EXPORTER destination <XORMON_IP> transport udp 2055 export-protocol netflow-v9 source Loopback0 flow monitor <EXISTING-MONITOR> exporter XORMON-EXPORTERIf the platform only allows one exporter per monitor (some older 9300/9500 code trains restrict this), the alternative is a second flow monitor with the same
flow record and a second exporter, applied to the same interfaces in addition to the existing one (ip flow monitor <NEW-MONITOR> input/output).
tcpdump -ni any udp port 2055Make sure the firewall allows inbound UDP/2055 from the switch.