MetricSplit › Guides › Cisco Catalyst SD‑WAN

How to send flow data from Cisco Catalyst SD‑WAN to a collector (cflowd and IPFIX)

Catalyst SD‑WAN routers can export a record of every conversation they forward (addresses, ports, application, bytes) to a flow collector. Cisco calls this cflowd; the records travel as IPFIX over UDP. You set it up once, centrally, in SD‑WAN Manager, and it reaches every router you choose. This guide works for any IPFIX collector; where MetricSplit is mentioned, that's what we do with it.

Before you start

1. Create a cflowd template (where the records go)

In SD‑WAN Manager, under Configuration › Policies › Centralized Policy › Custom Options › Cflowd, add a cflowd template. Menu names differ by release (newer releases may use policy groups).

2. Turn it on with a data policy (which traffic is reported)

In the same centralized policy, add a traffic data policy with a sequence that matches the traffic to report (usually all of it), action Accept, with Cflowd enabled.

3. Check the records are leaving the router

On a router's command line (Cisco's commands):

show sdwan app-fwd cflowd collector     # the collector is listed
show sdwan app-fwd cflowd statistics    # export counters are increasing
show sdwan app-fwd cflowd flows         # active flows

4. Check they're arriving at the collector

On a Linux collector, a short packet capture shows whether anything arrives at all:

sudo tcpdump -ni any udp port 2055 -c 20

Seeing packets from your routers' public addresses means the path is open; the collector then needs each router's templates (sent within the template refresh time) before it can read the records. In MetricSplit, each router then appears in Settings, where you name it, put it in a site and enter its circuit speeds.

What the records contain

What Catalyst SD‑WAN routers send us, per flow:

FieldUsed for
Source and destination IPv4 address and port, protocol, TCP flagswho talked to which service
Bytes and packets (sampled, scaled back up)how much traffic
Flow start and end timewhen, down to the 5-minute reading
Ingress and egress interface (with the interface-name table)which circuit and direction
Application ID (with the application-name table)which application
DSCP marking, VPN IDtraffic class and segment

No packet contents. IPv6 flows:

Troubleshooting

What MetricSplit does with flow records

MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence.

Book a free assessment

Other vendors: How to send NetFlow or IPFIX to a flow collector