MetricSplit › Guides

How to send NetFlow or IPFIX to a flow collector

Most routers and firewalls can send a record of every conversation they forward to a flow collector: who talked to which service, how much, through which interface. The two formats that carry enough detail are NetFlow v9 and IPFIX (the open standard that grew out of v9). This page is what every setup needs, whatever the vendor; each vendor's page has the steps.

What every setup needs

1. The collector's address and port

Flow records travel over UDP to one address and port, for example 192.0.2.10, UDP 2055. Port 2055 is the usual NetFlow port; IPFIX's registered port is 4739. Use the one your collector listens on.

2. A firewall rule, and the address after NAT

Allow UDP from each router or firewall out to the collector. If the export leaves through NAT, the collector sees the address after NAT: that's the one to register with the collector.

3. NetFlow v9 or IPFIX

Choose IPFIX where the device offers it, otherwise NetFlow v9. NetFlow v5 has a fixed, short list of fields and no room for application names.

4. The fields that matter

Source and destination address and port, protocol, bytes and packets, start and end time, and the input and output interface: without the interfaces, a collector can't tell download from upload or which circuit carried the traffic.

5. Templates and template refresh

NetFlow v9 and IPFIX send the layout of their records (a template) separately from the records. A collector can read records only after it has the template, so devices resend templates every few minutes or every few records. A shorter interval means a faster recovery after a restart.

6. Sampling

Some devices report 1 packet in N to save work. The collector then has to multiply the counts back up, so it needs the rate: either the device sends it (a sampler table), or you tell the collector. Unsampled exports avoid the question.

7. Application ID

Many devices can add an application ID to each record, and a table of application names. That is what lets traffic be classified by application (for example business, neutral or non-business) instead of only by address and port.

Vendor guides

VendorFormatWith MetricSplit
Cisco Catalyst SD-WANIPFIX (cflowd)Supported
Fortinet FortiGateNetFlow v9Rolling out
Palo Alto NetworksNetFlow v9Rolling out
Juniper SRXIPFIXRolling out
Cisco Meraki MXNetFlow v9Rolling out
MikroTikIPFIX or NetFlow v9Rolling out
Cisco IOS XE (Flexible NetFlow)IPFIX or NetFlow v9Ask us

Supported: proven end to end. Rolling out: support being added and proven now. Anything else: ask us.

What MetricSplit does with flow records

MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence. Your data is stored in India; a full security pack is available on request.

Book a free assessment