Determining which network devices to monitor

When planning your Flow Monitor deployment, it is important to understand which network devices are likely to provide you the information you want. In identifying those devices, questions about the data flowing through an individual device, its location in respect to other network devices and the types of addresses (internal/external) available to that device are all of importance.

Are you interested in monitoring the internet gateway routers connecting to your ISP for application level traffic analysis, performing forensics and diagnostics on a core router of a public facing network, or monitoring your WAN core in order to plan for additional capacity? The answers to these and similar questions about the purpose of your monitoring will provide you with some indication as to which devices in your network are of most interest as potential sources for Flow Monitor.

Once a potential Flow Monitor source has been identified, you should consider the location of the device with respect to other networking devices, particularly those devices that perform network address translation (NAT). Depending on where the source is located relative to the device performing NAT, traffic to and from an internal (private) IP addresses are reported differently in the exported NetFlow data.

Other conditions that may also change the nature of the data reported by Flow Monitor include:

See Also

Preparing network devices

Manually configuring devices to export flow data to Flow Monitor

Configuring sFlow enabled devices to export flow data to Flow Monitor

About Flexible NetFlow

About Network Based Application Recognition (NBAR)

About CBQoS

Viewing potential Flow Monitor sources

Using Flow Monitor to Configure Cisco NetFlow Devices