I have setup netflow on two cisco devices, one cisco6506 with sup720 and one cisco7604 with sup720.
software on cisco6506 sup720: 122-33.SXI
software on cisco7604 sup720:122-33.SRC2
NetFlow Traffic Analyzer version: 3.5 SP1
Between these units i have a single fiber cable, running layer3 bewteen them. Each of the devices has several layer3 interface, where some of them are to other locations. And I want to netflow monitor all traffic over this link.
I also have a redundant setup, but this is not importan know.
In a test setup, I have added only these two devices, and added the physical and the logical (vlan) interface to the NPM. In the NTA I have added only the logical interface in this case vlan1107.
My Cisco netflow configuration on both units looks like this:
mls netflow interface
mls flow ip interface-full
ip flow ingress layer2-switched vlan 1107 (I know, this is only if you want layer2 traffic, and in this case i am running layer3 )
mls nde sender
mls nde interface (default at cisco, NOT shown in configuration)
ip flow-export source Loopback1
ip flow-export version 5
ip flow-export destination 10.73.23.20 2055
mls aging long 64
mls aging normal 64
ip flow ingress
ip route-cache flow (default at cisco6500, NOT shown in configuration)
I get these error mesages:
NetFlow Receiver Service [xxxxxx] is receiving a NetFlow data stream from an unmanaged interface on x.x.x.x. The NetFlow data stream will be discarded. Please follow the link x.x.x.x or use the Orion System Manager to add Interface '#64' in order to process this NetFlow data stream.
And because of this error messages, my netflow traffic is discarded. The only traffic I see, are Management traffic wich are going directly to the interface.
In my cisco netflow table, I can see all my traffic.
I'am getting the error messages from all my layer3 interfaces. And I have double check that these SNMP IF indexs really exist on my router :)
show snmp mib ifmib ifindex
I can see that several others here om thwack, have simular problems, but I haven't found the solution yet. Maybe I haven't search well enourgh???
I can make the error-messages to disappear in two ways:
1: Add all my logical interfaces to my NTA!!! But can this truly be wright??
2: I can enable: "Monitoring of flows from unmanaged interfaces" in the NTA!!! But what is the consequence of this??
Is there a third way?
Or is it because I am doing something wrong (proberly)!!!!