[c-nsp] Netflow for same SVI vlan interface

Ian Cox icox at cisco.com
Mon Mar 27 19:12:09 EST 2006


At 06:58 AM 3/25/2006 -0800, Shahid Shafi wrote:
>  Vl260            10.4.27.7             10.4.26.58        udp      67
>67        0
>
>Folks how is this possible?

The host may have a /24 mask, and the router is forwarding traffic 
between them, rather than it going directly. The host is sending 
traffic to the router, the router is making a forwarding decision to 
send the packet to the host by sending it back out the same interface 
with the appropriate MAC address.


Ian

>Both of these hosts are on the same vlan as 10.4.26.0 has a subnet mask of
>/23 on the SVI. My understanding was I cannot get intra vlan flows unless
>Netflow layer2 stats are enabled on the switch. This is a 6500 switch
>running 12.2.17xxx. Is this normal behaviour?
>
>Thanks,
>Shahid
>_______________________________________________
>cisco-nsp mailing list  cisco-nsp at puck.nether.net
>https://puck.nether.net/mailman/listinfo/cisco-nsp
>archive at http://puck.nether.net/pipermail/cisco-nsp/


More information about the cisco-nsp mailing list