MetricSplit › Guides › Cisco Meraki MX

How to send NetFlow from a Cisco Meraki MX to a flow collector

Meraki MX appliances export NetFlow from the Meraki Dashboard, per network or template.

What it sends

NetFlow v9 (Meraki: all MX and Z-series), for traffic the MX routes or NATs; traffic switched within one VLAN isn't exported. Addresses, ports, protocol, incoming byte and packet counters, and an SNMP ingress or egress interface index. One collector per network.

Steps

  1. In the Meraki Dashboard: Network-wide › Configure › General, under Reporting.
  2. Set NetFlow traffic reporting to enabled, NetFlow collector IP to 192.0.2.10 and NetFlow collector port to 2055, and save.
  3. Active timeout: nothing to set. Meraki doesn't offer one; it sends an update for a long-running flow as often as every 3 seconds (Meraki's documentation). MetricSplit works in 5-minute readings, so this needs no change.
  4. Let UDP from the MX's public address out to the collector, and send us that address.

Check it's working

A packet capture on the collector (tcpdump -ni any udp port 2055) shows whether records arrive.

Vendor documentation

What MetricSplit does with flow records

MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence.

Book a free assessment

All vendors