MetricSplit › Guides › Cisco IOS XE routers

How to send IPFIX from a Cisco IOS XE router (Flexible NetFlow) to a flow collector

IOS XE routers export with Flexible NetFlow: a flow record (what to match and collect), a flow exporter (where to send it) and a flow monitor applied to interfaces.

What it sends

IPFIX or NetFlow v9, as you choose in the exporter, with exactly the fields your flow record collects. Catalyst SD‑WAN routers run IOS XE too and send the same kind of IPFIX records.

Steps

  1. A flow record: match IPv4 source and destination address, protocol, source and destination port; collect interface input and output, bytes and packets (long counters), and first and last seen. Optionally match application name (needs Cisco's application recognition on the router).
  2. A flow exporter: destination 192.0.2.10, transport udp 2055, export-protocol ipfix, and, if you match application names, option application-table so names arrive with the IDs.
  3. A flow monitor using the record and the exporter, applied to the internet-facing interface in both directions (ip flow monitor NAME input and output).
  4. In the flow monitor, set the active timeout to 60 seconds: cache timeout active 60 (Cisco's default is 1800). Why: MetricSplit works in 5-minute readings, so a long-running flow has to be reported at least every minute to land in the right reading.
  5. Cisco's guide has the full command set and examples for your release.

Check it's working

Cisco's command show flow exporter statistics shows records being sent; show flow monitor NAME cache shows the flows.

Vendor documentation

What MetricSplit does with flow records

MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence.

Book a free assessment

All vendors