Home > Networking Tips > Wide Area Networks > How the NetFlow protocol monitors your WAN
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WIDE AREA NETWORKS

How the NetFlow protocol monitors your WAN


Tom Lancaster
01.03.2008
Rating: -4.56- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


NetFlow technology is a method of switching that collects an extraordinary amount of information about the traffic passing through routers, switches and other network devices. This information has myriad uses -- from monitoring users and applications to trending and network planning. You can also do traffic engineering with it. It is even detailed enough to use for accounting and billing. Most important for some is that the information can be extremely useful for diagnosing those difficult, intermittent performance problems, and it can help you sort out DDoS/worm issues where traditional tools are overwhelmed with tons of traffic going in all directions.

To be clear, what we're talking about here is the NetFlow protocol that's used to transfer the information about your network traffic from the network devices to a server that collects and stores the data. The server is called a "NetFlow collector." Although some other network hardware manufacturers are supporting this technology in various forms, and others are offering competing technology -- like sFlow, which uses sampling -- the current Cisco NetFlow protocol format is the ninth version.
More on NetFlow
NetFlow network monitoring tools go with the 'flow'

Combining NetFlow analysis with security information management systems

Mining NetFlow 

Going beyond the flow: Giving network engineers the tools to think, act globally 

NetFlow was invented by Cisco years ago and has been proprietary for a while, but recently it's become an IETF "standard." Here's a link to the IETF's working group for Flow Information Export (IPFIX). And there's more interesting reading in this IETF informational RFC.

Opening this standard has done two big things:

It lets non-Cisco devices send data to your NetFlow collector. Riverbed's WAN optimization appliances are an example of this. They are typically placed at the edge of the WAN, an ideal position in the network to gather critical data about WAN utilization because they see the packets before and after they're optimized. These devices can export the data in a NetFlow format.

It also lets management software vendors directly access a much more detailed source of information than the old SNMP/ mini-RMON.

Implementing NetFlow

If you're considering implementing NetFlow, here are a few things to keep in mind:

NetFlow has a reputation for increasing CPU utilization on your network devices. Cisco's performance testing seems to indicate that newer hardware can accommodate this load pretty well, but you will still want to check it out before you turn on the feature. Some symptoms of high CPU utilization are very large jitter and increased delay. Services running on the device may also be affected.

Another thing to keep in mind is the amount of data you're going to be sending across the network. Depending on how much traffic you have and how you configure it, the traffic can be substantial. For example, you may not want to send NetFlow data from a datacenter switch to a NetFlow collector on the other side of a small WAN circuit. Also bear in mind that the flows from aggregating large numbers of devices can add up.

About the author:
Tom Lancaster, CCIE# 8829 CNX# 1105, is a consultant with 15 years of experience in the networking industry. He is co-author of several books on networking, most recently CCSP: Secure PIX and Secure VPN Study Guide, published by Sybex.

Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wide Area Networks
WAN optimization: A market update
Remote Desktop troubleshooting
Network design: Five ways to lower your costs
Remote office backup, archiving and disaster recovery for networking pros
Troubleshooting WAN performance issues
Cisco CCIP MPLS certification: Introduction
Distribution of labels -- Cisco CCIP MPLS certification: Lesson 3
Label imposition -- Cisco CCIP MPLS certification: Lesson 4
Configuring MPLS -- Cisco CCIP MPLS certification: Lesson 5
Configuring MPLS and VRF -- Cisco CCIP MPLS certification: Lesson 6

Network Monitoring
Measure wireless network performance using testing tool iPerf
Why wireless network cards show activity when no one uses the computer
WildPackets' packet analysis tool helps newspaper fix network problems
Networking data visualization not just for pointy-headed bosses
What network security threat does a QM FSM error pose in IPsec VPNs?
Juniper updates Network and Security Manager to manage full portfolio
Network management software vendors readying IPv6
DNS management becoming critical to businesses but poorly understood
SolarWinds adds enterprise scalability to its network monitoring tool
Network forensics appliance gets storage boost and 10 GbE support
Network Monitoring Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
10-high-day busy period  (SearchNetworking.com)
ACK  (SearchNetworking.com)
baseboard management controller  (SearchNetworking.com)
call failure rate  (SearchNetworking.com)
jam  (SearchNetworking.com)
Jini  (SearchNetworking.com)
maximum segment size  (SearchNetworking.com)
maximum transmission unit  (SearchNetworking.com)
netstat  (SearchNetworking.com)
network tracking tool  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts