1¡¢IPFIXÍÆ¼öµÄ»ù±¾¹¦ÄÜÅäÖÃÄ£°å

²ÉÑù»ù±¾ÅäÖãº

ip flow-export destination 192.168.217.76 1111           //Ö¸¶¨netflow·þÎñÆ÷ip£¬±ØÅä

ip flow-export destination ipv6 2222::2222 2222          //Ö¸¶¨netflow·þÎñÆ÷ipv6µØÖ·£¬Ó¦ÓÃÓÚipv6²ÉÑùʱ£¬Ñ¡Åä

ip flow-export source loopback 0                              //Ö¸¶¨½»»»»úµÄͨÐÅip

ip flow-export version 10                                          //Ö¸¶¨ipfixÁ÷µÄ°æ±¾£¬Í¨³£ÊÇv9£¬v10£¬±ØÅä

ip flow-export template refresh-rate 200                    //Ö¸¶¨Ä£°åË¢ÐÂʱ¼ä£¬Ñ¡Åä

ip flow-export template timeout-rate 60                     //Ö¸¶¨Ä£°å³¬Ê±Ê±¼ä£¬Ñ¡Åä

ip flow-cache entries 580000                                     //Ö¸¶¨Á÷»º´æ£¬Ñ¡Åä

ip flow-cache timeout active 1                                   //Ö¸¶¨»îÔ¾Á÷µÄ³¬Ê±Ê±¼ä£¬Ñ¡Åä

ip flow-cache timeout inactive 10                              //Ö¸¶¨·Ç»îÔ¾Á÷µÄ³¬Ê±Ê±¼ä£¬Ñ¡Åä

ip flow-top-talkers                                                   //Ö¸¶¨°´ÕÕ±¨ÎÄÊý¶àÉÙÀ´×öÁ÷ÅÅÁУ¬ÏÔʾǰ50µÄÁ÷£¬Ñ¡Åä

Ruijie(config-flow-top-talkers)# top 50

Ruijie(config-flow-top-talkers)# sort-by packets

 

ÔÚÈ«¾Ö²ÉÑùµÄ»ù±¾ÅäÖÃÍê³Éºó£¬»¹ÐèÒª½øÐнӿÚÏà¹ØµÄ²ÉÑùÅäÖ㬸ù¾ÝÐèÇóµÄ²»Í¬£¬Í¨³£·ÖÒÔÏÂÁ½ÖÖ³£¼ûµÄ²ÉÑùģʽ£º

1£©Êä³öÁ÷ÐÅÏ¢µÄ½Ó¿ÚÀàÐÍΪÎïÀí¿ÚµÄ¶þ¡¢Èý²ã½»»»Á÷²ÉÑùÅäÖÃ

Ruijie# config terminal

Ruijie(config)# ip flow-export interface-type port       //Êä³öÁ÷ÐÅÏ¢½Ó¿ÚÀàÐÍΪÎïÀí¿Ú

Ruijie(config)#ip flow layer2-switched enable            //¶þ²ãÁ÷Ò²²É¼¯£¬Ä¬ÈÏÖ»²ÉÑùÈý²ãÁ÷

Ruijie(config)# interface gigabitEthernet 1/1

Ruijie(config-if)# ip flow ingress                              //½Ó¿Ú1/1 ²Î¼ÓÊäÈë²ÉÑù

Ruijie(config)# interface gigabitEthernet 1/2

Ruijie(config-if)# ip flow ingress                               //½Ó¿Ú1/2 ²Î¼ÓÊäÈë²ÉÑù

 

2£©Êä³öÁ÷ÐÅÏ¢µÄ½Ó¿ÚÀàÐÍΪVLAN ²¢ÇÒÔÚVLAN ³ÉÔ±¿ÚÉÏÅäÖòÉÑù

ʾÀý£ºÖ»Í³¼ÆÈý²ãÁ÷£¬gigabitEthernet 4/2-3£¨trunk¿Ú£© ͬʱÊôÓÚVLAN 10ºÍVLAN20£¬Ö»¶Ô´Ó4/2 ½Ó¿Ú³ö£¬²¢ÇÒÊä³öΪSVI20 µÄ±¨ÎĽøÐÐ1£º1 ²ÉÑù£¬ÆäËü²»²ÉÑù£¬Åä

ÖÃÈçÏ£º

Ruijie# config terminal

Ruijie# ip flow-export interface-type vlan            //Êä³öÁ÷ÐÅÏ¢½Ó¿ÚÀàÐÍΪvlan¿Ú£¬±ØÅä

Ruijie(config)# interface gigabitEthernet 4/2

Ruijie(config-if)# ip flow egress         //½Ó¿Ú4/2 ²Î¼ÓÊä³ö²ÉÑù

Ruijie(config-if)# exit

Ruijie(config)# interface vlan 20

Ruijie(config-if)# ip flow egress       //ʹÄÜSVI µÄÊä³öÁ÷ͳ¼Æ,²ÉÑùÂÊΪ1 ±È1

Ruijie(config-if)# exit

¶ÔSVI³ÉÔ±¿Ú²ÉÑù£¬ÒªÇóSVI¼°³ÉÔ±ÎïÀí¿Ú¶¼ÐèÒªÅäÖòÉÑùʹÄÜ¡£

 

 

2¡¢IPFIX¹ÊÕϵij£¹æÅŲ鷽·¨

1£©²½Öè1£¬Ê¹ÓÃshow version¡¢show version slots²é¿´NMM¿¨ÊÇ·ñÕý³£Ê¶±ð£¬È·ÈÏÓ²¼þ¿ÉÒÔÕý³£¹¤×÷£¬NMM¿¨¶Ô²ÛλûÓÐÌØ±ðÒªÇó¡£

Êä³öÐÅÏ¢ÏÔʾÈçÏ£º

Slot-9 : M8600-NMM

    Cpu 0:

    Hardware version : 1.20

    Software version : RGOS 10.4(2b3) Release(100306)

    BOOT version     : 10.4(2b3) Release(95683)

    CTRL version     : 10.4(2b3) Release(100306)

    Cpu 1:

    Hardware version : 1.20

    Software version : RGOS 10.4(2b3) Release(100306)

    BOOT version     : 10.4(2b3) Release(95683)

    CTRL version     : 10.4(2b3) Release(100306)

Ruijie#sh version slo

  Dev Slot Port Configured Module            Online Module                User Status  Software Status

  --- ---- ---- ---------------------------- ---------------------------- ------------ ---------------

  1   1    0    none                         none                         none         none          

  1   2    2    M8600-08XFP                  M8600-08XFP                  installed    ok            

  1   3    0    none                         none                         none         none                    

  1   4    0    M8600-NMM                    M8600-NMM                    installed    ok                   

  1   M1   0    N/A                          M8614-CM II                  N/A          master        

 

2£©²½Öè2¼ì²éÅäÖÃÊÇ·ñÕýÈ·£¬IPFIXµÄ»ù±¾ÅäÖÿÉÒԲο¼ÉÏÃæµÄÍÆ¼öʾÀý¡£

 

3£©²½Öè3  show IPFIXÏà¹Ø²ÎÊý£¬ÅжÏIPFIXÊÇ·ñÕý³£¹¤×÷

IPFIX»ù±¾ÅäÖÃÍê±Ïºó£¬ÐèÒª¼ì²éIPFIXÊÇ·ñÒѾ­Õý³£¹¤×÷£¬Ö÷Òª¼ì²éFlowÊÇ·ñÒѾ­½¨Á¢£¬ÒÔ¼°Á÷µÄÊä³öÇé¿ö¡£Ö÷Òª¿´active,Èç¹ûactive ²»Îª0 ±íʾµ±Ç°ipfix ÒѾ­¿ªÊ¼¹¤×÷

½¨Òé²é¿´Íê±Ïºó£¬Ö´ÐÐclear ip flow cacheÇå³ýÁ÷¼Ç¼£¬ÖØÐÂÖ´ÐÐshow ip flow cache²é¿´ÊÇ·ñÓÐеÄÁ÷Éú³É¡£

Router# show ip flow cache

IP Flow Switching Cache, 4456448 bytes

3 active, 65533 inactive, 820628747 added

0 flow alloc failures

Exporting flows to 1.1.15.1 (2057)

820563238 flows exported in 34485239 udp datagrams, 0 failed

Last clearing of statistics 00:00:03

 

Protocol   Total     Flows  Packets  Bytes  Packets Active(Sec) Idle(Sec)

--------   Flows     /Sec   /Flow     /Pkt   /Sec    /Flow         /Flow

TCP-BGP       71      0.0     1         49      0.0     2.5           15.8

UDP-other    17      0.0     1         328     0.0     0.0           15.7

ICMP       18966     6.7     10         28     72.9    0.1            22.9

Total:     19054     6.7     10         28     72.9    0.1            22.9

 

SrcIf         SrcIPAddress DstIf          DstIPAddress Pr TOS Flgs Pkts

Port Msk AS                  Port Msk AS  NextHop                B/Pk Active

Et1/1         52.52.52.1    Fd4/0         42.42.42.1    01  55  10    3748

0000 /8  50                   0000 /8  40 202.120.130.2          28    17.8

Et1/2         52.52.52.1    Fd4/0         42.42.42.1    01  CC  10    3568

0000 /8  50                   0000 /8  40 202.120.130.2          28    17.8

Et1/2         10.1.3.2       Fd4/0        42.42.42.1     01 C0  10    1124

0000 /0 0                    0000 /8 40   202.120.130.2         28    17.8

......

bytes£º»ù±¾Á÷¼Ç¼±íÕ¼ÓõÄÄÚ´æ´óС¡£

active£ºµ±Ç°ÕýÔÚʹÓõÄÁ÷¼Ç¼±íÏî¸öÊý¡£1¸öÁ÷¶ÔÓ¦1¸öÁ÷¼Ç¼±íÏî¡£

inactive£ºÅäÖõĻù±¾Á÷¼Ç¼±íÖÐÓжàÉÙÁ÷¼Ç¼±íÏîδ·ÖÅäʹÓá£

added£ºÔڴ˴μǼÆÚ¼ä£¬¹²´´½¨Á˶àÉÙ¸öÁ÷¼Ç¼±íÏî¡££¨¿ª»úÒ»Ö±µ½2µÄ32·½ºó¹éÁ㣩

flow alloc failures£ºÁ÷±íÏî·ÖÅäʧ°Ü¼ÆÊý¡£

Exporting flows to£ºIPFIX»ù±¾Á÷¼Ç¼±¨ÎÄÊä³öÄ¿µÄIP£¨UDP¶Ë¿ÚºÅ£©¡£

flow exported in udp datagram£º¹²ÓжàÉÙ¸öÁ÷¼Ç¼±íÏîͨ¹ý¶àÉÙ¸öUDP±¨ÎÄÊä³ö¡£

failed£ºIPFIX±¨ÎÄÊä³öµÄʧ°Ü¼ÆÊý¡£

Last clearing of statistics£º´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsÆð£¬¹ýÁ˶೤ʱ¼ä£¬¸ñʽΪHH:MM:SS£¬³¬¹ý24Сʱ£¬»¹ÒªÔö¼ÓÌìÊýÏÔʾ£ºDD days HH:MM:SS¡£

protocol£º³£ÓõÄIPЭÒéÓë¶Ë¿ÚºÅ¡£

Total Flows£º´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsºó£¬ÊôÓÚprotocolÀàÐ͵ÄÁ÷¼Ç¼±íÏî¸öÊý¡£

Flows/Sec£º´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsºó£¬ÊôÓÚprotocolÀàÐÍµÄÆ½¾ùÿÃë´´½¨µÄÁ÷¼Ç¼±íÏîÊý£¬ÎªTotal Flows / Last clearing of statistics

Packets/Flow£º´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsºó£¬ÊôÓÚprotocolÀàÐÍµÄÆ½¾ùÿ¸öÁ÷¼Ç¼±íÏîµÄ±¨ÎÄÊý¡£

Bytes/Pkt£º´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsºó£¬ÊôÓÚprotocolÀàÐÍµÄÆ½¾ùÿ¸ö±¨ÎĵÄ×Ö½ÚÊý¡£

Packets/Sec£º´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsºó£¬ÊôÓÚprotocolÀàÐÍµÄÆ½¾ùÿÃ뱨ÎÄÊý¡£

Active(Sec)/Flow£ºÆ½¾ùÿ¸öÁ÷µÄ»îԾʱ¼ä¡£´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsºó£¬ÊôÓÚprotocolÀàÐ͵ÄÒÑÀÏ»¯µÄ»ù±¾Á÷¼Ç¼±íÏîÖУ¬Ã¿¸öÁ÷µÄ×îºóÒ»¸ö±¨ÎÄÓëµÚÒ»¸ö±¨ÎĵÄʱ¼ä²îµÄºÍ£¬³ýÒÔTotal Flows¡£

Idle(sec)/Flow£ºÆ½¾ùÿ¸öÁ÷µÄ·Ç»îԾʱ¼ä¡£´ÓÉÏÒ»´ÎÖ´ÐÐclear ip flow statsºó£¬»ù±¾Á÷¼Ç¼±íÏîÖУ¬ÊôÓÚprotocolÀàÐ͵Äÿ¸öÁ÷µÄ×îºóÒ»¸ö±¨ÎÄʱ¼äÓëÊÕµ½¡°show ip flow cache¡±ÇëÇóµÄʱ¼ä²îµÄºÍ£¬³ýÒÔTotal Flows¡£

 

show ip flow export

        29689 flows exported in 23307 udp datagrams

        0 flows failed to export

        0 messages failed to export

¿´¿´Á÷µÄÊä³öÐÅÏ¢£¬×¢Òâ¿´ÓÐûÓÐÁ÷Êä³ö£¬¶àÉÙ¸ö±¨ÎÄÊä³ö£¬Êä³öÓÐûÓÐʧ°Ü£¿Í¬Ê±×¢Ò⣺

Exporting flows to 203.193.155.208 (9996)

         Exporting using source IP address 192.168.196.44

         Version 10 flow records

Êä³öµÄÄ¿µÄµØÖ·£¬Êä³öµÄÔ­µØÖ·£¬Êä³ö¸ñʽµÄversionÊÇ·ñºÍÔ¤ÆÚÏà·û£¿ÈçÊä³öʧ°ÜÇë¼ì²éµ½NetFlow·þÎñÆ÷ͨѶÊÇ·ñÕý³£¡£Êä³öʧ°Ü»¹°üÀ¨ÈçÏ¿ÉÄÜ£º

1.IPFIXûÓÐÆôÓá£

2.IPFIX ûÓÐÅäÖÃÊä³öÄ¿µÄµØÖ·¡£

3.IPFIXûÓÐÅäÖÃÊä³öÔ­µØÖ·¡£

 

4£©²½Öè4 IPFIX×½°üÈ·ÈÏ

IPFIXĿǰ֧³Ö×î¶àÊä³öÁ÷µ½2̨·þÎñÆ÷£¬ÎÒÃÇ¿ÉÒÔ½«Ä³PCÉèÖÃΪÁ÷Êä³ö·þÎñÆ÷£¬²¢ÔÚPCÉÏʹÓÃWireshark½øÐÐ×½°üÈ·ÈÏÁ÷ÐÅÏ¢ÊÇ·ñÒѾ­ÕýÈ·Êä³ö¡£

Á÷×½°ü½ØÍ¼ÈçÏ£º

 

5£©²½Öè5

ÔÚ¾­¹ýÒÔÉϲ½ÖèÅŲéÈÔȻδÄܽâ¾öÎÊÌ⣬Ôò¿ÉÒÔ²¦´ò4008111000»ñȡ֧³Ö£¬ÊÕ¼¯ÒÔÏÂÐÅÏ¢Á¬Í¬Ç°ÃæµÄ²Ù×÷ÐÅϢһͬ·´À¡¸ø¹¤³Ìʦ´¦Àí¡£

Show version

Show version slots

Show ip flow cache£¨¶à´Î£©

Show ip flow interface

Show interface xx

Show interface xx counter

Show ip flow export£¨¶à´Î£©

Show log

IPFIX·þÎñÆ÷×½°ü

 

 

3¡¢IPFIX¹¦ÄÜͬ¶Ë¿Ú¾µÏñ£¨SPAN£©¹²ÓÃʱµÄһЩעÒâµã

1£©ÔÚS8600½»»»»úÉÏSPAN ¼°IPFIX ¹¦Äܶ¼»áÏûºÄ¾µÏñ×ÊÔ´£¬µ±¾µÏñ×ÊÔ´²»×ãʱ£¬»áµ¼ÖÂÅäÖÃʹÄܶ˿ڵÄIPFIX Á÷²ÉÑù¹¦ÄÜʧ°Ü¡£

2£©ÔÚÒ»¸ö¶Ë¿ÚÉÏ£¬¾µÏñºÍ²ÉÑù·½ÏòÏàͬʱ²»ÄÜͬʱÅäÖ㬷½Ïò²»Í¬Ê±¿ÉÒÔͬʱÅäÖã¬ÀýÈ磺Èë¾µÏñ£¨rx£©ºÍÈë²ÉÑù£¨ingress£©²»ÄÜͬʱÅäÖ㬻òÕß³ö¾µÏñ£¨tx£©ºÍ³ö²ÉÑù£¨egress£©Ò²²»ÄÜͬʱÅäÖ㻵«ÊÇÈë¾µÏñºÍ³ö²ÉÑù¿ÉÒÔͬʱÅäÖ㬻òÕßÈë²ÉÑùºÍ³ö¾µÏñ¿ÉÒÔͬʱÅäÖá£

3£©µ±Ò»¿é½»»»¿¨ÅäÖÃÁËÒ»¸ö´ø¾µÏñÊä³öÔ´¿Úʱ£¨source interface xx tx£©£¬²»ÔÊÐíÔڸý»»»¿¨µÄÈκζ˿ÚÉÏÔÙÅäÖÃIPFIX Á÷Êä³ö£¨egress£©Í³¼Æ¹¦ÄÜ¡£

4£©Ò»¸ö½Ó¿ÚÅäÖÃΪ¾µÏñµÄÄ¿µÄ¿Ú£¬¸Ã½Ó¿Ú²»ÄÜÅäÖóö²ÉÑù¡£

 

 

4¡¢IPFIXÅäÖÃegress²ÉÑùʱ±¨The port enable ipfix fail because of hardware´íÎó

ip flow-cache entries 580000

ip flow-cache timeout active 1

ip flow-cache timeout inactive 10

ip flow-export template timeout-rate 1

ip flow-export template refresh-rate 600

ip flow-export version 9

ip flow-export destination 1.1.1.1 9996

monitor session 1 destination interface GigabitEthernet 2/3

monitor session 1 source interface GigabitEthernet 2/1 both

Ruijie(config)#int g2/9

Ruijie(config-if-GigabitEthernet 2/9)#ip flow ingress

Ruijie(config-if-GigabitEthernet 2/9)#ip flow egress

The port enable ipfix fail because of hardware

 

¸Ã¹ÊÕϾÍÊÇÓÉÓÚÏÞÖÆ£º¡°µ±Ò»¿é½»»»¿¨ÅäÖÃÁËÒ»¸ö´ø¾µÏñÊä³öÔ´¿Úʱ£¨source interface xx tx£©£¬²»ÔÊÐíÔڸý»»»¿¨µÄÈκζ˿ÚÉÏÔÙÅäÖÃIPFIX Á÷Êä³öͳ¼Æ¹¦ÄÜ¡±ÒýÆðµÄ¡£GigabitEthernet 2/1 bothÅäÖÃÁËË«Ïò¾µÏñ£¨ÄǾͿ϶¨°üº¬tx£©¡£

²ÉÓÃÈçϹæ±Ü·½·¨£¬SPANÖÐÖ»ÅäÖÃRX·½ÏòµÄ¾µÏñ£º

monitor session 1 destination interface GigabitEthernet 2/3

monitor session 1 source interface GigabitEthernet 2/1 rx

interface GigabitEthernet 2/9

 ip flow egress

 ip flow ingress

 

 

5¡¢IPFIX¿¨£¬Ôö´ó²ÉÑùÂÊÊÇ·ñ»á¼õÉÙ·¢ÍùnetflowµÄ°üÊýÁ¿»òÕß½µµÍ·¢ËÍÆµÂÊ

²ÉÑùÅäÖÃ

Core-ACTIVE(config)#flow-sampler-map ruijie

Core-ACTIVE(config-sampler)#mode random one-out-of 500   //500:1µÄ²ÉÑùÂÊ

Core-ACTIVE(config-if-TenGigabitEthernet 1/1/1)#flow-sampler ruijie

 

1£©86-IPFIX¹¦ÄÜÕâ¿é£¬Ôö´ó²ÉÑùÂÊÊDz»»á¼õÉÙÍùnetflow Èí¼þµÄ·¢°üµÄÊýÁ¿µÄ£¬Ò²²»»á½µµÍ·¢°üƵÂÊ£»

2£©±ÈÈç86ÉÏÃæÕë¶Ô²ÉÑù¿ÚµÄ±¨ÎÄ£¬ÓÐ10000ÌõÁ÷£¬Ã¿ÌõÁ÷ÓÐ×Ô¼ºµÄͳ¼Æ±¨ÎĽá¹û£¬Èç¹ûÊÇ1:1£¬ÄÇô¾ÍÊÇÒ»ÌõÁ÷ÀïµÄËùÓб¨Îͼ×öͳ¼Æ¼ÆÊý£¬Èç¹ûÊÇ1000:1µÄ²ÉÑùÂÊ£¬ÄÇô¾ÍÊÇÒ»ÌõÁ÷ÀïµÄ±¨ÎÄ×ö1000:1µÄͳ¼Æ¼ÆÊý£¬µ«ÊÇ10000ÌõÁ÷µÄ¼Ç¼¿Ï¶¨¶¼ÊÇҪͳ¼ÆµÄ£¬¶¼ÊÇÒª°Ñ±¨ÎÄ·¢¸ønetflow£¬²»»á¼õÉÙ·¢°üµÄÊýÁ¿¡£

3£©²ÉÑùÂʵĸü¸Ä²»»á½µµÍ86µÄ´¦ÀíÐÔÄÜ£¬Ò²²»»á¼õÉÙÍùnetflowµÄ·¢°üÊýÁ¿£¬Ò²¾ÍÊDz»»á½µµÍ·þÎñÆ÷µÄ´¦ÀíÐÔÄÜ£¬Ö»»áÓ°ÏìÈí¼þ×îÖÕµÄÒ»¸öͳ¼Æ±ÈÀý£¬¼ÆËã±ÈÀý¡£

 

 

6¡¢IPFIX¿¨£¬ÈçºÎ¼õÉÙ·¢ÍùnetflowµÄ±¨ÎÄÊýÁ¿£¬»òÕß½µµÍ·¢ËÍÆµÂÊ

1£©¼õÉÙnetflowµÄ¼à¿ØµÄÉ豸£¬»òÕßÊǼõÉÙS86ÉÏÃæµÄ²ÉÑùµÄ¶Ë¿Ú£»

2£©Ôö´ó86ÉÏÃæµÄÁ÷ÀÏ»¯µÄ»îԾʱ¼ä£¬Óë²»»îԾʱ¼ä£¬ÕâÑù¿ÉÒÔÔö´ó86Á÷Êä³öµÄʱ¼ä£¬Ò²¾ÍÊǽµµÍÁË·¢ËÍµÄÆµÂÊ£¬Ó¦¸Ã¿ÉÒÔ½µµÍnetflowµÄ´¦ÀíÐÔÄÜ

²Î¿¼ÃüÁ

Ruijie(config)#ip flow timeout active 60

Ruijie(config)#ip flow timeout inactive 600

a¡¢Á÷ÀÏ»¯£¬»îÔ¾µÄʱ¼ä²ÎÊý³¢ÊÔµ÷ÕûΪ×î´ó£¬ÏȲâÊÔÕâ¸ö¹¦ÄÜÊÇ·ñÉúЧ£¬¿ÉÒÔ¼õÇánetflow´¦ÀíµÄѹÁ¦£¬ËùÒÔÐèÒª¼«¶ËµÄÊýÖµ£¬Èç¹û¹Û²ìµ½ÓмõÇᣬÄÇôÔÚȥѰÇóÐÔÄÜÓë·¢ËÍʱ¼äµÄÒ»¸öºÏÀíÖµ£¬ÔÚ×öµ÷Õû¡£Õâ¸öµ÷Õû²»»áÓ°Ïì86ÉÏÃæÆäËûµÄ¹¦ÄÜ£¬½¨Òé¼Ç¼µ÷ÕûǰµÄÊýÖµ£¬È»ºó¹Û²ìµ÷Õûºó1hµÄ£¬¼Ç¼ÊýÖµ£¬×ö¶Ô±È¡£

b¡¢µ÷ÕûÁ÷ÀÏ»¯Ê±¼äÊÇÓй¦ÄÜÐÔЧ¹ûµÄ£¬µ«ÊÇÊÇ·ñ¿ÉÒԴﵽʵÖÊÐÔµÄ×÷Ó㬱ÈÈç½µµÍµ½5KppsµÄÐÔÄÜ£¬ÄÇôÐèҪʵ¼ÊÏÖ³¡²âÊÔΪ׼£¬ÒòΪÕâ¸öÊÜÏÞÓÚ¿Í»§Êµ¼ÊÍøÂçÁ÷Á¿µÄÊý¾ÝÄ£ÐÍ

3£©¿ÉÒÔ³¢ÊÔÅäÖÃÁ÷¾ÛºÏģʽ¡£

Ò»¸öÁ÷¾ÛºÏģʽ£¬¾ÍÊÇͨ¹ýÆä¶¨ÒåµÄÌØ¶¨¹Ø¼ü×ֶΣ¬¶ÔÖ÷ģʽµÄÁ÷½øÐÐÖØÐµľۺϲúÉúеÄÁ÷£¬¿ÉÒÔÀí½âΪ½«Ô­À´±ÈÈçÒª·¢Ë͵Ä1000ÌõÁ÷ÐÅÏ¢£¬ÏÖÔÚ¸ù¾ÝËûÃǵÄһЩ²ÎÊý£¬±ÈÈçÔ´ipÏàͬ£¬¿ÉÒÔ×ö¾ÛºÏ£¬Ö»·¢ËÍÒ»ÌõÐÅÏ¢¸ønetflow£¬Õâ·Ý±¨ÎÄÀïÃæ½«ÏêϸЯ´øÏ¸½ÚµÄÁ÷ÐÅÏ¢£¬Ó¦¸Ã¿ÉÒÔ»º½â·¢°üµÄÇ¿¶È£¬µ«ÊǾßÌåµÄЧ¹û»¹ÊÇÒÔÏÖ³¡²âÊÔΪ׼£¬±Ï¾¹ÊÇʵ¼ÊµÄÁ÷Á¿Ä£ÐÍÓкܴóµÄ¹ØÏµ¡£

²Î¿¼ÃüÁîÈçÏ£º

a¡¢ÏȽ«Ô­À´É豸ÉϹØÓÚÖ÷ģʽµÄÁ÷Êä³öµÄÕâÁ½ÌõÅäÖÃɾ³ý£¬ÆäËûÅäÖñ£Áô

ip flow-export version 9

ip flow-export destination x.x.x.x 9996

b¡¢Ôö¼Ó£¬»ùÓÚԴǰ׺µÄÁ÷¾ÛºÏÅäÖã¬Èç¹û¹Û²ìЧ¹û²»Ã÷ÏÔ£¬¿ÉÒÔÅäÖûùÓÚÄ¿µÄǰ׺µÄÁ÷¾ÛºÏ£¬»òÕ߯äËû²ÎÊý£¬µ«ÊÇÖ»ÄÜÑ¡ÔñÒ»ÖÖ

ip flow-aggregation cache source-prefix

 export version 9

 export destination x.x.x.x 9996

 cache entries 131072

 cache timeout active 50

 cache timeout inactive 500

 enabled      //Ò»¶¨ÒªÇÃenabled

 

 

7¡¢IPFIX½Ó¿Ú²ÉÑùÂʵÄÍÆ¼öÅäÖÃÄ£°å

Ruijie# config terminal

Ruijie(config)# ip flow-export interface-type port

Ruijie(config)# flow-sampler-map one-tenth //ÅäÖÃÒ»¸öone-tenthÃû×ÖµÄsampler-map

Ruijie(config-sampler)# mode random one-out-of 10 //ÅäÖÃÒ»¸öone-tenth µÄsampler-map Ëæ»ú²ÉÑùÂÊΪ10 ±È1

 

Ruijie(config)# interface gigabitEthernet 4/2

Ruijie(config-if)# ip flow egress //ʹÄܽӿÚ4/2 µÄÊä³öÁ÷ͳ¼Æ,²ÉÑùÂÊΪ1 ±È1

Ruijie(config-if)# exit

Ruijie(config)# interface gigabitEthernet 4/3

Ruijie(config-if)# ip flow ingress //ʹÄܽӿÚ4/3 µÄÊäÈëÁ÷ͳ¼Æ,²ÉÑùÂÊΪ1 ±È1

Ruijie(config-if)# exit

Ruijie(config)# interface gigabitEthernet 4/4

Ruijie(config-if)# flow-sampler one-tenth egress //ʹÄܽӿÚ4/4 µÄÊä³öÁ÷ͳ¼Æ,²ÉÑùÂÊΪ10 ±È1

Ruijie(config-if)# ip flow ingress //ʹÄܽӿÚ4/4 µÄÊäÈëÁ÷ͳ¼Æ,²ÉÑùÂÊΪ1 ±È1

Ruijie(config-if)# exit

Ruijie(config)# interface gigabitEthernet 4/5

Ruijie(config-if)# flow-sampler one-tenth egress //ʹÄܽӿÚ4/5 µÄÊä³öÁ÷ͳ¼Æ,²ÉÑùÂÊΪ10 ±È1

Ruijie(config-if)# flow-sampler one-tenth     //ʹÄܽӿÚ4/5 µÄÊäÈëÁ÷ͳ¼Æ,²ÉÑùÂÊΪ10 ±È1£¨Ä¬ÈÏΪÈë²ÉÑù£¬Ã»ÓÐingress²ÎÊý£©

 

 

8¡¢S5750E/P£¬S6000ϵÁн»»»»úÊÇ·ñÖ§³ÖIPFIX

´Ó10.4£¨3b16£©°æ±¾¿ªÊ¼£¬S5750E/P£¬S6000ϵÁн»»»»ú¶¼Ö§³ÖIPFIXµÄÁ÷²ÉÓ㬲»¹ýÐèҪעÒâµÄÊÇ£¬Á÷±íÏîÌõÄ¿ÓÐÏÞ£¬ÊäÈë×î´ó1500Ìõ£¬Êä³ö×î´ó500Ìõ£¬ËùÒÔ²¿ÊðµÄʱºòÐèÆÀ¹ÀÏÂʵ¼ÊÍøÂç»·¾³µÄÁ÷ÊýÁ¿