MetricSplit › Guides
How to send NetFlow or IPFIX to a flow collector
Most routers and firewalls can send a record of every conversation they forward to a flow collector: who talked to which service, how much, through which interface. The two formats that carry enough detail are NetFlow v9 and IPFIX (the open standard that grew out of v9). This page is what every setup needs, whatever the vendor; each vendor's page has the steps.
What every setup needs
1. The collector's address and port
Flow records travel over UDP to one address and port, for example 192.0.2.10, UDP 2055. Port 2055 is the usual NetFlow port; IPFIX's registered port is 4739. Use the one your collector listens on.
2. A firewall rule, and the address after NAT
Allow UDP from each router or firewall out to the collector. If the export leaves through NAT, the collector sees the address after NAT: that's the one to register with the collector.
3. NetFlow v9 or IPFIX
Choose IPFIX where the device offers it, otherwise NetFlow v9. NetFlow v5 has a fixed, short list of fields and no room for application names.
4. The fields that matter
Source and destination address and port, protocol, bytes and packets, start and end time, and the input and output interface: without the interfaces, a collector can't tell download from upload or which circuit carried the traffic.
5. Templates and template refresh
NetFlow v9 and IPFIX send the layout of their records (a template) separately from the records. A collector can read records only after it has the template, so devices resend templates every few minutes or every few records. A shorter interval means a faster recovery after a restart.
6. Sampling
Some devices report 1 packet in N to save work. The collector then has to multiply the counts back up, so it needs the rate: either the device sends it (a sampler table), or you tell the collector. Unsampled exports avoid the question.
7. Application ID
Many devices can add an application ID to each record, and a table of application names. That is what lets traffic be classified by application (for example business, neutral or non-business) instead of only by address and port.
Vendor guides
| Vendor | Format | With MetricSplit |
|---|---|---|
| Cisco Catalyst SD-WAN | IPFIX (cflowd) | Supported |
| Fortinet FortiGate | NetFlow v9 | Rolling out |
| Palo Alto Networks | NetFlow v9 | Rolling out |
| Juniper SRX | IPFIX | Rolling out |
| Cisco Meraki MX | NetFlow v9 | Rolling out |
| MikroTik | IPFIX or NetFlow v9 | Rolling out |
| Cisco IOS XE (Flexible NetFlow) | IPFIX or NetFlow v9 | Ask us |
Supported: proven end to end. Rolling out: support being added and proven now. Anything else: ask us.
What MetricSplit does with flow records
MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence. Your data is stored in India; a full security pack is available on request.