NetFlow Cisco

XorMon's NetFlow collector requires NetFlow version 9 — v5 and IPFIX are not parsed.

  • UDP, destination port 2055 by default (configurable on the collector side)
  • Destination: the XorMon server's IP address
Catalyst 2960/3560/3750, IOS 12.2–15.x:
! global
ip flow-export version 9
ip flow-export destination <XORMON_IP> 2055
ip flow-cache timeout active 1
ip flow-cache timeout inactive 15

! on every interface you want to measure
interface GigabitEthernet0/1
 ip route-cache flow
On later 12.4/15.x releases, ip route-cache flow is replaced by:
interface GigabitEthernet0/1
 ip flow ingress
 ip flow egress
Verify with:
show ip flow export
show ip cache flow
Catalyst 9000, ISR 4000, IOS-XE 16.x+:
flow record XORMON-RECORD
 match ipv4 protocol
 match ipv4 source address
 match ipv4 destination address
 match transport source-port
 match transport destination-port
 match interface input
 collect interface output
 collect counter bytes long
 collect counter packets long
 collect timestamp sys-uptime first
 collect timestamp sys-uptime last

flow exporter XORMON-EXPORTER
 destination <XORMON_IP>
 transport udp 2055
 export-protocol netflow-v9
 source Loopback0

flow monitor XORMON-MONITOR
 record XORMON-RECORD
 exporter XORMON-EXPORTER
 cache timeout active 60
 cache timeout inactive 15

! on the interface
interface GigabitEthernet1/0/1
 ip flow monitor XORMON-MONITOR input
 ip flow monitor XORMON-MONITOR output
Verify with:
show flow monitor XORMON-MONITOR cache
show flow exporter XORMON-EXPORTER statistics
NX-OS uses the same flow record / flow exporter / flow monitor triad, with slightly different field syntax — ask if you need the Nexus-specific variant.
Classic NetFlow — a router can export to multiple destinations at once; just add a second line, nothing else changes:
ip flow-export destination <XORMON_IP> 2055
(the existing ip flow-export destination <old_collector_ip> <port> line stays untouched)

Flexible NetFlow — a single flow monitor can reference multiple exporters, so add a new exporter and attach it to the existing monitor (no need to touch interface config):
flow exporter XORMON-EXPORTER
 destination <XORMON_IP>
 transport udp 2055
 export-protocol netflow-v9
 source Loopback0

flow monitor <EXISTING-MONITOR>
 exporter XORMON-EXPORTER
If the platform only allows one exporter per monitor (some older 9300/9500 code trains restrict this), the alternative is a second flow monitor with the same flow record and a second exporter, applied to the same interfaces in addition to the existing one (ip flow monitor <NEW-MONITOR> input/output).

Quick check on the XorMon server side

tcpdump -ni any udp port 2055
Make sure the firewall allows inbound UDP/2055 from the switch.