FORMACIÓN IP
CAPACITACIÓN INTEGRAL EN NETWORKING
ENCORE 4.0 NETWORK ASSURANCE
CCNP 350-401
NETWORK
ASSURANCE
4.3 NETFLOW
CCNP ENCORE 350 - 401
NETFLOW
▸ Provee estadísticas de los paquetes que pasan a través de
un router.
▸ Se utiliza en aplicaciones de monitoreo, planes de
capacidad , análisis de seguridad y accounting.
CCNP ENCORE 350 - 401
CONFIGURACION NETFLOW
enable
con gure terminal
ip ow-export destination [ip address]
ip ow-export version 9
!
interface [interface]
ip ow ingress
ip ow egress
end
fl
fl
fl
fl
fi
CCNP ENCORE 350 - 401
PASOS DE CONFIGURACION FLEXNETFLOW
▸ Crear un ow record
▸ Con gurar un ow exporter
▸ Crear un ow monitor
▸ Aplicar un ow monitor a una interface
▸ Veri car localmente con
show ow monitor FLOW1 cache
fi
fi
fl
fl
fl
fl
fl
CCNP ENCORE 350 - 401
CONFIGURACION NETFLOW RECORD
enable
ow record NETFLOW1
match ipv4 tos
match ipv4 protocol
match ipv4 source address
match ipv4 destination address
match transport source-port
match transport destination-port
match interface output
match ow direction
collect routing source as
collect routing destination as
collect routing next-hop address ipv6
collect ipv4 source mask
collect ipv4 destination mask
collect transport tcp ags
collect interface input
collect counter bytes
collect counter packets
collect timestamp sys-uptime rst
collect timestamp sys-uptime last
fl
fl
fl
fi
CCNP ENCORE 350 - 401
CONFIGURACIÓN
ow exporter NETFLOW1
destination [Link]
transport udp 9996
ow monitor NETFLOW1
record NETFLOW1
exporter NETFLOW1
Interface [interface]
ip ow monitor NETFLOW1 output
ip ow monitor NETFLOW1 input
fl
fl
fl
fl
CCNP ENCORE 350 - 401
VALIDACIÓN
Show ow monitor NETFLOW1 cache
Show ow monitor NETFLOW1 statistics
fl
fl
CCNP ENCORE 350 - 401
NETFLOW