8.3.3.3 Lab - Collecting and Analyzing NetFlow Data PDF
8.3.3.3 Lab - Collecting and Analyzing NetFlow Data PDF
Topology
Addressing Table
Device
R1
Interface
IP Address
Default Gateway
G0/0
192.168.1.1/24
N/A
S0/0/0 (DCE)
192.168.12.1/30
N/A
G0/0
192.168.2.1/24
N/A
S0/0/0
192.168.12.2/30
N/A
S0/0/1 (DCE)
192.168.23.1/30
N/A
G0/0
192.168.3.1/24
N/A
S0/0/1
192.168.23.2/30
N/A
PC-A
NIC
192.168.1.3
192.168.1.1
PC-B
NIC
192.168.2.3
192.168.2.1
PC-C
NIC
192.168.3.3
192.168.3.1
R2
R3
Objectives
Part 1: Build the Network and Configure Basic Device Settings
Part 2: Configure NetFlow on a Router
Part 3: Analyze NetFlow Using the CLI
Part 4: Explore NetFlow Collector and Analyzer Software
Background / Scenario
NetFlow is a Cisco IOS technology that provides statistics on packets flowing through a Cisco router or
multilayer switch. NetFlow enables network and security monitoring, network planning, traffic analysis, and IP
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 1 of 7
Required Resources
3 Routers (Cisco 1941 with Cisco IOS Release 15.2(4)M3 universal image or comparable)
3 PCs (Windows 7, Vista, or XP with terminal emulation program, such as Tera Term)
Console cables to configure the Cisco IOS devices via the console ports
d. Assign cisco as the console and vty passwords and enable login.
e. Encrypt the plain text passwords.
f.
j.
Configure OSPF using Process ID 1 and advertise all networks. Ethernet interfaces should be passive.
k.
Create a local database on R3 with the username admin and password cisco with the privilege level at
15.
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 2 of 7
On R3, enable the HTTP service and authenticate HTTP users by using the local database.
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 3 of 7
From PC-A, browse to R3 using the 192.168.3.1 IP address. Login as admin with the password cisco.
Keep the browser open after you have logged into R3.
Note: Make sure the pop-up blocker is disabled on your browser.
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 4 of 7
SrcIPaddress
112
DstIf
0.2
SrcIf
Se0/0/0
Se0/0/1
SrcIPaddress
192.168.12.1
192.168.23.2
DstIf
Null
Null
50
DstIPaddress
146
12.5
DstIPaddress
224.0.0.5
224.0.0.5
Pr SrcP DstP
59 0000 0000
59 0000 0000
Pkts
43
40
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 5 of 7
Total
Flows
2
2
Flows
/Sec
0.0
0.0
Packets Bytes
/Flow /Pkt
193
79
193
79
SrcIf
Se0/0/0
SrcIPaddress
192.168.12.1
DstIf
Null
DstIPaddress
224.0.0.5
Pr SrcP DstP
59 0000 0000
Pkts
35
SrcIf
Se0/0/1
SrcIPaddress
192.168.23.2
DstIf
Null
DstIPaddress
224.0.0.5
Pr SrcP DstP
59 0000 0000
Pkts
33
Reflection
1. What is the purpose of NetFlow collector software?
3. What are the seven critical fields used by the original NetFlow to distinguish flows?
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 6 of 7
Ethernet Interface #1
Ethernet Interface #2
Serial Interface #1
Serial Interface #2
1800
1900
2801
2811
2900
Note: To find out how the router is configured, look at the interfaces to identify the type of router and how many
interfaces the router has. There is no way to effectively list all the combinations of configurations for each router
class. This table includes identifiers for the possible combinations of Ethernet and Serial interfaces in the device.
The table does not include any other type of interface, even though a specific router may contain one. An
example of this might be an ISDN BRI interface. The string in parenthesis is the legal abbreviation that can be
used in Cisco IOS commands to represent the interface.
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 7 of 7