Michael Leung Formation Lap
HI team


we have requirement to analyzer where our bandwidth heading to , it is better to show out which BGP AS ip address belong to , and what agency own this AS. 

can netflow import a IP address and BGP database like that ? 

Replies (12)

Hi,

Thank you for the response.

Please refer the below link to know more about Netflow & Reports.


Regards,

Suresh.k.v
Michael Leung Formation Lap
sorry , i can't find any info about BGP of netflow on the link . 

i saw some one use it to analyze data flow base on BGP AS number . 

Hi Michael,

Thank you for writing to us. Please let us know the the device model that you are monitoring in NetFlow Analyzer, we will assist you accordingly.

Thanks & Regards,

Aravind Lenin
Technical Support Engg- Netflow Analyzer
Michael Leung Formation Lap
thanks please, 

our monitoring device is Huawei CE6800s 

Hi ,

Thank you for writing to us. Please configure the device as mentioned below:

netstream export ip index-switch 32
netstream timeout ip active 1
netstream timeout ip inactive 15
netstream template ip timeout 1
netstream export ip source Source interfaceIP
netstream export ip host 10.16.70.175 9996
netstream export ip version 9 peer-as bgp-nexthop

netstream record NetFlow ip
 match ip tos
 match ip protocol
 match ip source-address
 match ip destination-address
 match ip source-port
 match ip destination-port
 collect counter packets
 collect counter bytes
 collect interface input
 collect interface output

Under all interfaces:

netstream record NetFlow ip
netstream inbound ip

Once done, please navigate to Settings -> NetFlow -> Storage Settings -> Autonomous -> Select Enable and Save the changes.

You can get the AS information under Inventory -> Click on the Device Name -> Expand the view -> Scroll Down to the Last widget and Click on the Refresh Icon and check.


Thanks & Regards,

Aravind Lenin
Technical Support Engg- Netflow Analyzer

Michael Leung Formation Lap
thank so much 

i was thinking we have to establish a BGP session with our Switch . 

do you think so ? 
Michael Leung Formation Lap
BTW ,

netstream record NetFlow ip

what is this NetFlow ip ? 

is the destination or the source ? 

from the statement of the command line , it needed to be a "STRING".
Hi ,

Thank you for your reply. The Netstream export from the device will have the information of BGP next hop if the BGP is enabled in the device, else you will not have any information on BGP.

The command "netstream record NetFlow ip" is the format of the command where NetFlow is the Record name that we are creating in the device. You do not have to specify any IP address there.

Thanks & Regards,

Aravind Lenin
Technical Support Engg- Netflow Analyzer
Michael Leung Formation Lap
netstream export ip version 9 [ peer-as | original-as ], 

what is different  between option peer-as and  original-as  
Hi ,

Thank you for your reply. Please refer the below link:

Peer-as adds information about the peering AS (immediate upstream and downstream AS) with your NetFlow data.

With origin-as you can see information about the AS from which the traffic originated and where it would be terminated, ie. the absolute origin and destination AS information.

Thanks & Regards,

Aravind Lenin
Technical Support Engg- Netflow Analyzer
Michael Leung Formation Lap
i m not sure now.
 
i follow you suggestion setting on my switch , but netflow analyzer 9  did not receive AS info , so  there were nothing in the "Device->Autonomous System View". 

but i cancel " undo netstream record NetFlow ip" in the switch interface View . 

and add a aggregation as 

netstream aggregation as 
enable
netstream template time-rate 1

then , NetFlow analyzer 9 started to receive AS info. 

what is the different ? 
Hi ,

Thank you for your reply. We are not sure on the Change in the configuration that you did. Please let us know the reason of remove the flow record from the configuration.

Also, If there is no AS information exported by the device, we will not be able to give you any details in the NetFlow Analyzer UI.

Please do the suggested configuration in the device.

If you are not able to view the AS information, please install packet capturing tool like wireshark in the NetFlow Analyzer installed server and do an capture for 5 min.

Send us the capture in pcap format with the device IP to netflowanalyzer-support@manageengine.com, we will check and get back to you.


Thanks & Regards,

Aravind Lenin
Technical Support Engg- Netflow Analyzer