Cisco :: 6500 Shows Less Traffic For NetFlow Export?

Mar 7, 2012

I am using a Thrid party NetFlow tool, Enabled NetFlow on the Cisco 6500 as per recommendations and getting only half amout of traffic passing thorugh the interfaces. I have verified with 3 different NetFlow based tools, everything showing the same value. Is there any bug in my Cisco 6500.

View 2 Replies


ADVERTISEMENT

Cisco Switching/Routing :: NetFlow / 6500 / Export Packets Were Dropped Due To No Fib?

Mar 13, 2012

I have a problem with the 6500 not exporting netflow data. They are not exported due to no fib.I have read somewhere that this has something to do with VRF. VRF are running on the router.ip flow ingress has been applied to desired ip int.Is there anything I could do to make it export netflow data?
 
VSS-core-XXX-rs1#sh ip flow export
Flow export v5 is enabled for main cache
  Export source and destination details :
  VRF ID : Default
    Source(1)       xxx.xxx.83.253 (Unknown)

[code]....

View 7 Replies View Related

Cisco LAN :: 2651XM / Traffic-export Only Shows Outgoing?

Oct 12, 2012

cisco 2651XM router with WIC1 adsl card and NM-16ESW switch
IOS:  c2600-ipbasek9-mz.124-23.bin
 
I use the following config to export traffic from the adsl card to a fasterthernet port so I can look at the adsl traffic in wireshark on a pc:router(config)#ip traffic-export profile my_rite router(conf-rite)#int FastEthernet 0/0 router(conf-rite)#bidirectional router(conf-rite)#mac-address abcd.efgh.ijkl (mac address of PC) router(conf-rite)#exit router(config)#int dialer0 router(config-if)#ip traffic-export apply my_rite this config works and I can see stuff going on in wireshark but it's only one way. This config only shows traffic going out from my adsl card, but no incoming. There is defintely traffic going both ways because everything about my adsl connection is working perfectly. I've tried using a different fastethernet port, even tried exporting to a different pc but all I see is outgoing ie: source is my public ip address but never as destination . I have bidirectional in the config but it still only shows outgoing. I even tried a different IOS (c2600-adventerprisek9-mz.124-15.T8.bin) but still it doesn't show incoming traffic. Could it be my ISP in some way hiding incoming traffic from view?

View 3 Replies View Related

Cisco Firewall :: Flow Export From ASA5505 To Netflow Collector

Mar 21, 2013

I have three ASA5505, two firewalls connected to central VPN hub. the central inside network is 192.168.0.0/24,Network A is 192.168.1.0/24,Network B is 192.168.2.0/24,In one of this site (central), I have server with NetFlow collector.,I will collect the traffic information from all ASA at the my one serverCan I configure source IP address (or source interface - inside) for NetFlow packet, originate from ASA? (for example from site A)If it is not possible I think, I can rewrite my access lists and permit udp traffic from outside interface to server IP like this:access-list VPNACL permit udp host <Outside IP site A> host <Inside IP the Server> eq 9996,But I do not understand, what port I must be use in access list on Central site ASA. ,access-list VPNACL_A permit udp host <Inside IP the Server> host <Outside IP site A>  eq 9996 ? or, in this place, must be source port in the udp netflow packet?

View 2 Replies View Related

Cisco Switching/Routing :: How To Enable Netflow Export On ASR1001

Nov 3, 2011

To enable netflow export on ASR1001, do i need the firewall feaure license or not ?Docs are not really clear, NBAR requires FW license, but i am unsure about Netflow?

View 1 Replies View Related

Cisco Switching/Routing :: Different Netflow Export Profiles On Cat 6513 With Sup720

Aug 28, 2012

Is it possible to have one netflow export profile (may not be the right word...) to send all the flow information to one collector and another profile to only send traffic to and from centain IP addresses to another collector? If it is possible on the hardware and software, any quick sample config?
 
#sh ver
Cisco IOS Software, s72033_rp Software (s72033_rp-ADVIPSERVICESK9_WAN-M), Version 12.2(33)SXH4,
 
#sho module 7
Mod Ports Card Type                              Model              Serial No.
--- ----- -------------------------------------- ------------------ -----------
  7    2  Supervisor Engine 720 (Active)         WS-SUP720-3B       SAL1115LJBR
 
Mod MAC addresses                       Hw    Fw           Sw           Status
--- ---------------------------------- ------ ------------ ------------ -------
  7  0017.9444.9814 to 0017.9444.9817   5.3   8.4(2)       12.2(33)SXH4 Ok
 
Mod  Sub-Module                  Model              Serial       Hw     Status
---- --------------------------- ------------------ ----------- ------- -------
  7  Policy Feature Card 3       WS-F6K-PFC3B       SAL1115L2NH  2.3    Ok
7  MSFC3 Daughterboard         WS-SUP720          SAL1115LH7W  2.6    Ok

Mod  Online Diag Status
---- -------------------
  7  Pass

View 2 Replies View Related

Cisco LAN :: 2811 / Traffic-export Capturing Only Inbound Traffic?

Mar 19, 2013

We have a Cisco 2811 running ITP IOS.  On that router we run the SMPP service.  A client on the network connects to this service, and we need to capture the traffic for debug.
 
I've tried traffic-export, but I cannot see any outbound traffic.I'm guessing that this is due to the fact that the outbound SMPP traffic is not transit traffic as it is generated by the router itself.
 
Is there any way to capture the outbound traffic?

View 4 Replies View Related

Cisco :: 7206 MPLS To Export Netflow From Its MPLS

Jul 11, 2012

I have P router (7206VXR) and I need to export netflow from its MPLS interfaces to the netflow software.

View 2 Replies View Related

Cisco WAN :: 2811 - IP Traffic-Export Mode Capture

Apr 25, 2011

We are trying to sniff traffic in one of our routers 2811 IOS 12.4(3f) capturing data into the flash memory and tftp later to one of our servers. We had followed the command procedure as it is indicate in Router IP Traffic Export Packet Capture Enhancements doc but it seems that the mode capture option is not alllowed in my router. My question is Why? I had read the doc and the hardware and software should support this feature.
 
ROM: System Bootstrap, Version 12.4(1r) [hqluong 1r], RELEASE SOFTWARE (fc1)
 
yourname uptime is 2 weeks, 4 days, 22 hours, 14 minutesSystem returned to ROM by power-onSystem image file is "flash:c2800nm-ipbase-mz.124-3f.bin"
 
Cisco 2811 (revision 53.51) with 251904K/10240K bytes of memory.Processor board ID FCZ104174196 FastEthernet interfacesDRAM configuration is 64 bits wide with parity enabled.239K bytes of non-volatile configuration memory.62720K bytes of ATA CompactFlash (Read/Write)

View 4 Replies View Related

Cisco WAN :: 6500 How To Turn Off NetFlow

Apr 22, 2013

I see these errors on my 6500 router which acts as my server farm and has hundreds of servers connecting to it. I have just taken over these routers from another guy and think the errors may have been there for quiet awhile.  I have another router which doen't seem to have these errors. Can you tell me how to turn off netflow? Will it cause any problems to my server farm? Is there a risk to the router if I disable something?
 
I ask this cause the server guys are having problems with certain servers. I am not sure if they are because of this or not. I really would like to clear the logs. [code]

View 4 Replies View Related

Cisco WAN :: 6500 - Netflow With VRFLite

Sep 4, 2011

We have a Cisco 6500 running the following image;
 
Cisco IOS Software, s72033_rp Software (s72033_rp-IPSERVICES_WAN-M), Version 12.2(33)SXH4, RELEASE SOFTWARE (fc1)
 
We are attempting to configure Netflow and export to a colloector. We have the following configuration applied to the device, we can ping from within the vrf to the destination of the flow collector
 
ip flow-cache timeout active 1
ip flow ingress layer2-switched vlan 1,800-801,803,821-823,861-862,871,900,998,1100-1107,1121,1200,1221,1301-1302,1321-1322
mls netflow interface
mls flow ip interface-full
ip flow-export version 5(code)

 however we do not receive the flows on the collector. We can see the flow for both hardware and software but cannot see them at the collowctor.

View 2 Replies View Related

Cisco :: NetFlow Enabling On 6500 And 4500

May 26, 2011

Configured 6500 and 4500 to send netflow to a stealthwatch NADS.When visited by the stealthwatch engineer found that because i didnt have NDE configaured.i wasnt actually exporting any but the initial data in the flow.Now if i have got this right the command for this is -  mls nde sender version 5

This is confirmed by looking at the following out put -show mls nde.Neither of these command work on my 4500 switch -does this mean that its not outputting  all the data or do i not need to configure NDE or do i need another command ?
 
-4500  Sup V-10GE 10GE
-6500  Supervisor Engine 720 10GE
-or Supervisor Engine 720

View 0 Replies View Related

Cisco :: Configure Netflow Catalyst 6500 With SUP720-10GE

Jun 5, 2012

I tried to configure netflow without success.
 
Setup is the following.
 
Cisco Catalyst 6509 with Sup720-10GE IOS 12.2(33)SHX7. There are around 30 L3 vlans configured on the switch. I'm only interested for the traffic on one L3 vlan which is the connection to wan cloud.
 
I wanna see only the traffic that goes to and come from the wan. On other Catalyst where I have routed interfaces i successfully configured netflow. I read a lot in the forums and documentations but i didn't find the right one.

View 1 Replies View Related

Cisco Switching/Routing :: Configure Egress Netflow In 6500 (VSS) With VS-S720-10G Supervisor?

Jun 9, 2013

I'm trying to configure a egress netflow in a 6500 (VSS) with VS-S720-10G supervisor. I foud some old posts and understood that netflow wasn't supported on 6500 but i found a new document and it seems that netflow is supported in Supervisor Engine 2T:[URL] Does the netflow still not supported in VS-S720-10G? It's weird because the command is supported:
 
#sh run int vlan 4
Building configuration... 
Current configuration : 353 bytes
!
interface Vlan4
ip address X.X.X.X 255.255.0.0

[cod]....

View 1 Replies View Related

Cisco Switching/Routing :: Catalyst 6500 - Netflow Table Utilization Logs

Nov 27, 2011

We are getting log messages like

%EARL-DFC4-4-NF_USAGE: Current Netflow Table Utilization is 95%
%EARL-DFC4-4-NF_USAGE: Current Netflow Table Utilization is 99%
 
What this messages really means and how to get rid of these messages. We are using IOS version 12.2(33)SXJ in Catalyst 6500.

View 3 Replies View Related

Cisco WAN :: 2911 / NetFlow Traffic Not Received

Jan 13, 2012

Recently bring up a new Router connected to  ISP A and the Netflow collector/server is located in different location and they are connected to ISP B. I have enabled snmp and netflow config on my router(2911) but not receiving the netflow packets are not reaching the server for due to some strange reason whereas other packets like ICMP for snmp are reaching the netflow collector.Finally,I created GRE tunnel between the two locations routers and set the route  for the netflow collector/server to the tunnel other end IP. In this way the netflow traffic are reaching successfully to the server.

View 1 Replies View Related

Cisco Firewall :: ASA 5520 Netflow Traffic Delayed To Solarwinds

Dec 5, 2012

I am currently testing Netflow accuracy on my Solarwinds platform. So I have been transferring a large file across an ASA 5520, which is set up to send Netflow data to out Solarwinds server.
 
The problem is that the Netflow data does not show up on Solarwinds for about 2.5 hours. Once it gets there the size is correct, but the time stamp on Solarwinds is 2.5 hours behind when the transfer happened. For routers it is showing up within a few minutes. 
 
ASA is running 8.2(5) and Solarwinds NTA 3.9.0. Firewall and Solarwinds times / timezones are the same.

View 8 Replies View Related

Cisco WAN :: 2901 Txload Shows 255 / 255 Even With No Traffic

Jan 22, 2012

2901 router that I just installed. I replaced a 1760 router with a new 2901 router and all seems to be working but for some reason the txload on interface g0/0 and interface multilink1 show 255/255 even though there is no traffic going over to this router. I have dual routers at this location and at the moment I have all traffic going over to my other router a 2821.
 
reliability 255/255, txload 255/255, rxload 1/255

View 7 Replies View Related

Cisco Switching/Routing :: Configuring Netflow For Layer 2 Switched Traffic On Cat6509

Jul 10, 2012

I want to configure layer 2 switched netflow on my cat 6509 running vss,
 
I have configured the 2 commands below 
   
ip flow ingress layer2-switched vlan 1,2,3
ip flow export layer2-switched vlan 1,2,3
 
However, if I look in the config the export bit isnt there after?
 
It is running a PFC
 
VS-F6K-PFC3C
 
Should layer 2 switched netflow work in this chassis ? it says on the Cisco site that it works on the below
 
"The command is supported on Supervisor Engine 720 in PFC3B and PFC3BXL mode only and on Supervisor Engine 2 with a PFC2"

View 1 Replies View Related

Cisco Switching/Routing :: Capturing Traffic Flows From 3750 To 6509 Then To Netflow

Aug 6, 2012

I am aware that the 3750 switches are not able to support Netflows, so I have created a SPAN port and spanning traffic from a specific port. I would like to create a seperate VLAN and trunk the traffic from the SPAN port down to the 6509 switch and then capture all the traffic for that VLAN on the 6509.

View 4 Replies View Related

Cisco Switching/Routing :: 3560CG Shows 0 Traffic In Class-map?

Apr 10, 2012

I tried to put QoS in a  WS-C3560CG-8TC-S  version 12.2(55)EX2.It shows 0 traffic in class-map. Here is the config My question is why I can not see the traffic via class-map?it should in the default Q if incorrect mark.I erased the config and config with the autoQoS, shows the same result. 

class-map match-any VoIP  description Voice IP Phone RTPmatch access-group 157
class-map match-any WEB  description Internal Web, SSL Web, DNS query, Pinnaclematch access-group 153
!
policy-map QOSMARK
class VoIP  set dscp ef 
class WEB  set dscp cs3 
class class-default  set dscp default

[code].....

View 3 Replies View Related

Cisco Routers :: WRVS4400N - SNMP Shows Strange Traffic Data

Apr 5, 2011

I am monitoring my WRVS4400N with SNMP and create graphs by MRTG. Problem is that data about traffic are strange, very low. I have 50 MB line but max traffic shown on graphs is about 8000 bits per second. Also the "shape" of graph does not correspond with real traffic.

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Logs All Traffic Shows Up As Router External Address

Nov 10, 2011

I have a cable modem internet connection and my cable modem is connected to an ASA 5505.  The inside interface of the ASA has an IP address of 192.168.2.2 and is connected to a Linksys router's internet port which has an IP address of 192.168.2.1.  The Linksys router then has a local area network of 192.168.1.0 and all my clients are on that network.  Everything is working fine except in my ASA logs all the traffic shows up as the router's external address which is 192.168.2.1.  I would like to see the 192.168.1.x address of the clients in the ASA firewall.  I've tried making some changes to the Linksys router but that hasn't resolved it.  Is there any changes I can make on the ASA to get this to work?  

View 6 Replies View Related

Cisco Switching/Routing :: 4948 - Difference Between Netflow / Netflow-Lite

Mar 13, 2012

Any major difrrence between Netflow v/s Netflow-Lite?
 
I am trying to understand if Cisco 4948E can do the same job as Cisco 4500E or not and difference between Netflow v/s Netflow-Lite will work for me to select correct product.

View 2 Replies View Related

Cisco Switching/Routing :: 6500 / How To Filter IPX Traffic

Feb 23, 2013

We have a lot of IPX traffic flowing through a switched network and we are being asked to filter it from a network standpoint. At one point they were using IPX in their network, but no longer need to, so they still have a lot of machines spewing out IPX traffic. We have removed the IPX routing commands from our distribution switches, (Cisco 6500), but after running a short 10 minute Wireshark capture I'm still getting a good bit of IPX traffic from a lot of different devices.

View 2 Replies View Related

Cisco Switching/Routing :: Does 6500 With SUP-720 Support Nat On Multicast Traffic

Jan 16, 2012

does 6500 with SUP-720 support nat on multicast traffic?
 
i know it support Multicast service reflection based on SXI4 which can facilitate me on destination address nat.
 
but if i need only source nat, does the defualt NAT feature supported on multicast traffic ?

View 1 Replies View Related

Cisco Switching/Routing :: 6500 - Route-map Not Used / ACL Not Matching Traffic

Jan 12, 2012

I'm performing tests with following desired scenario: We have several remote offices, connected to our HQ via MPLS. In these remote offices, we have several vlan's. Each vlan has it's own ip-range. The MPLS cloud is routed, so we cannot switch our HQ vlan's to the remote offices. In this case, the client pc is in a guest vlan which allows him internet access. The uplink for this internet access is hosted in our HQ datacenter.
 
basic scheme:
client pc --> MPLS cloud (managed by ISP) --> 6500 switch LAN --> Checkpoint Firewall --> 6500 switch DMZ --> ASA Firewall
 
My test scheme:
Client pc is in a subnet A (guest vlan range office).
We receive this traffic on our first LAN 6500.

[Code].....

View 29 Replies View Related

Cisco Firewall :: ASA 5520 - Memory Shows 94% And CPU Shows 85%

Oct 15, 2012

I Have asa 5520 with the  code 8.0, the mem shows 94% and the CPU shows 85%

View 5 Replies View Related

Cisco Switching/Routing :: Catalyst 6500 - Cannot See Return Traffic On SPAN Session?

Jan 31, 2012

On a Catalyst 6500, we configured a SPAN session with VLAN 300 as a source. We configured the session bi-directional ("both" keyword). We connect a sniffer on the SPAN destination port.
 
Strangely enough, we only see the traffic from the VRF to the firewall, but not the reverse traffic ! What can be the problem ?

View 2 Replies View Related

Cisco Switching/Routing :: 6500 Sup VS-S720-10G Traffic Forwarding In Active And Hot State

Jan 24, 2012

I have catalyst 6500s with two VS-S720-10Gs, one is in Active and one is in Hot state. Both Sup cards have two 10G uplink ports. How does the traffic forwarding works in this case on the uplink ports? Do these uplink ports actively forward traffic or it is only the uplinks ports on Active that forward traffic? I see CDP neighbors on both Active and Hot SUPs uplinks ports - it  indicates that packets are flowing on both cards.
 
I want all uplink ports on both SUPs to actively forward traffic. Does it work? What is the config for this?

View 1 Replies View Related

Cisco Switching/Routing :: 6500 / 3560 - Get L2 Traffic Amount (bit / Byte) Passing Through Switch

May 30, 2012

We want to get L2 traffic amount (bit/byte) passing through a cisco switch (6500/3560 ...) for a specific VLAN. it can be via SNMP or CLI ...How can we do that?
 
note: there is no L3 interface on swtiches.

View 2 Replies View Related

Cisco Switching/Routing :: 6500 / IGMP Snooping - All Mcast Traffic Forwarded To Mrouter Ports?

Mar 22, 2012

I've been looking into IGMP snooping and have read that a L2 switch will forward multicast traffic to all ports connected to an interested receiver AND all mrouter ports. In a L2 'V' topology this results in all multicast traffic routed onto a VLAN being forwarded to the 2nd distribution switch. My question is how should a 6500 Sup720 deal with this unwanted multicast traffic? Both a Local SPAN of the RP and a Netdr capture suggest that this traffic is punted to the RP and ultimately dropped. Is this expected behavior or should the traffic be dropped in H/W?

View 2 Replies View Related

Cisco Firewall :: 6500 - FWSM - Not Passing Traffic Through Firewall

May 3, 2011

We have 2 FWSM modules in each 6500 switches. 1st module is having 04 firewall vlan groups with 18 vlan interfaces in a single context firewall. All are working fine with no issues. Recently we create one more vlan on MFSC and add into the same firewall module. However newly created vlan inside the FW is not able to communicate with outside and also outside users not able to reach newly created subnet. But within the firewall zones (other interfaces) it can communicate. Once we did packet capture we noticed that its hitting firewall outside interface only and when we ping we got TTL expired error. we have default routes to outside and there's no any route inside as new segment is within the firewall (no any hop).
 
I guess there's no limitation on number of vlans that we can assign on one firewall eventhough there is a limitation for number of vlan-group which is 16 max (but we are within that limit).

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved