
74-10
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 74 Configuring Flexible NetFlow
Non-VSS Environment
Note
Flow monitor matching on ingress 802.1Q VLAN Id as the key field cannot be attached on a
VNET trunk port target.
10.
Only permanent and normal flow cache types are supported.
11.
Supervisor Engine 8-E, Supervisor Engine 7-E, Supervisor Engine 7L-E, and Catalyst 4500X do not
support:
–
predefined records like traditional routers (
record netflow ipv4 original-input
)
–
flow based sampler.
12.
On VLAN interfaces, when you use the
interface
option with the
Cos
,
Tos
,
TTL
or
Packet length
options, the system displays inaccurate results for the interface input field.
13.
The configuration of the flow exporter does not support the option
output features.
14.
Flow aging in flow cache is controlled through active and in-active timer configuration. The
minimum for active and in-active aging timers is 5 seconds. The timers must be in units of 5 seconds.
Note
Flows in the hardware table are deleted after 5 seconds of in-activity irrespective of the active
or in-active timer configuration values. This allows you to create new hardware flows quickly.
15.
First and Last-seen flow timestamp accuracy is within 3 seconds.
16.
2048 Flow monitors and records are supported.
When TTL is configured as a flow field, the following values are reported for a given packet TTL
value.
lists the packet TTL and reported values.
17.
Cisco TrustSec (CTS) fields are supported. These fields use Netflow collector to monitor and
troubleshoot the CTS network, and to segregate traffic based on source group tag (SGT) values.
–
When configuring the source group tag (
collect flow cts source group-tag
), note the following:
The system copies the packets to software before it retrieves the CTS field. A large number of
flows mean that a large number of packets are copied to the software, possibly affecting CPU
performance.
The maximum number of (unique) hosts allowed in the switch (IP addresses) is 12,000.
In case of burst packets, the software may not be able to retrieve the CTS field because the
software queue is throttled.
–
When configuring the destination group tag (
collect flow cts destination group-tag
), note that
this CTS field value is collected only if you have already configured an IP-to-SGT mapping.
–
When configuring switch-derived source group tags (
collect flow cts switch derived-sgt
), note
that the switch derives this value locally.
–
When configuring CTS fields on Supervisor Engine 8-E, note that CTS fields are not supported
on wireless interfaces (WLAN) and SSID.
Table 74-4
TTL Map: TTL Configured
Packet TT Value
Reported Value
0
0
1
1
Содержание Catalyst 4500 Series
Страница 2: ......
Страница 4: ......
Страница 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...