Configuring Netflow

Introduction

Netflow is an industry standard for traffic monitoring. Cisco developed this network protocol to collect network traffic patterns and volume.

One host (the Netflow Exporter) sends information about its network flows to a different host (the Netflow Collector).

A network flow is a unidirectional stream of packets that contain the same set of characteristics.

You can configure a Quantum Spark Applicance as an Exporter of NetFlow records for all the traffic that passes through it.

The Netflow Collector is a different external server, and you configure it separately.

Netflow Export configuration is a list of collectors, to which the service sends records:

  • To enable Netflow, configure at minimum one Netflow Collector.

  • To disable Netflow, remove all Netflow Collectors from the Gaia Embedded configuration.

You can configure a maximum of three Netflow Collectors. Gaia Embedded sends the NetFlow records go to all configured Netflow Collectors. If you configure three Netflow Collectors, Gaia Embedded sends each Netflow record three times.

Regardless of which Netflow export format you configure, Gaia Embedded exports values as set of fields.

Notes:

  • The IP addresses and TCP/UDP ports the Netflow reports are the ones, on which the Netflow expects to receive traffic.

    Therefore, for NAT connections, the Netflow reports one of the two directions of the flow with the NATed address.

  • Netflow sends the connection records after the connections terminated.

    If the connections are open for a long time, it can take time for the Netflow to sends the records.

Configuration Procedure for Centrally Managed