[nsp] Netflow V8 Prefix statistics not summarizing per subnet ?

cros_m at tsm.es cros_m at tsm.es
Thu Jan 23 15:45:40 EST 2003


Hello:

We are interested in getting statistics of traffic between subnets. We
think Netflow V8  (ip flow-aggregation cache prefix) is one option to get
this information.

CEF was activated before Netflow configuration but we are getting
unexpected results. In the following example one Cisco router (12.1(8a)
3640) is configured with 10.240.0.0/23 in the FastEthernet 0/0 interface.
      C       10.240.0.0/23 is directly connected, FastEthernet0/0
We were expecting that Netflow V8 prefix statistics would summarize all the
traffic coming from Hosts in the FastEthernet 0/0 but we are getting
multiple entries, oen for each host (mask 32).


RouterPrefix File
===============
            SOURCE 10.224.254.51|FORMAT A|AGGREGATION RouterPrefix|PERIOD 5|STARTTIME 1043318240|ENDTIME 1043318540|FLOWS 246|MISSED 0|RECORDS 102
            0.0.0.0|10.240.0.0|0|23|5|0|0|0|8|588|4|740640391|740640577|184
            10.240.0.0|0.0.0.0|23|0|5|10|0|0|804|392709|6|740640246|740640648|275716
            ......
Not Expected ==> 10.240.1.130|0.0.0.0|32|0|5|10|0|0|11198|583468|4|740640378|740640616|135824
Not Expected ==> 10.240.1.133|0.0.0.0|32|0|5|10|0|0|299|33562|1|740640444|740640482|37876
Not Expected ==> 10.240.1.143|0.0.0.0|32|0|5|10|0|0|337|73836|6|740640406|740640649|116392
Not Expected ==> 10.240.1.225|0.0.0.0|32|0|5|10|0|0|566|76095|7|740640257|740640658|494048
            Many Lines with /32 mask.
            ......


Command Printout
==================
This  doesn't happen in other routers (7500). Maybe it has nothing to do.

            router#sh ip cef 10.240.1.130
            10.240.1.130/32, version 58, cached adjacency 10.240.1.130
            0 packets, 0 bytes
23 expected==>   Flow: AS 0, mask 32
              via 10.240.1.130, FastEthernet0/0, 0 dependencies
                next hop 10.240.1.130, FastEthernet0/0
                valid cached adjacency


            router#sh ip cef 10.240.0.0
            10.240.0.0/32, version 1, receive
              Flow: AS 0, mask 23

What do you think ?

* Is it the normal behavior ?
* Is a configuration mistake ? or
* maybe something wrong with the IOS version ?


Thank you in advance.

Regards

      Miguel




More information about the cisco-nsp mailing list