I was able to get Netflow to pull from our distribution switch. Which is a Cisco 6506-E in VSS configuration. Then that ties into a Cisco Core VSS block which is 6504-E. We have a lot of Layer 2 and Layer 3 links coming to the Distribution switch.
So I have the following commands on the distribution switch.
flow record ipv4
match ipv4 protocol
match ipv4 source address
match ipv4 destination address
match transport source-port
match transport destination-port
match interface input
collect interface output
collect counter bytes
collect counter packets
!
!
flow exporter NetFlow-to-Orion
destination 172.18.2.107
source Loopback0
transport udp 2055
export-protocol netflow-v5
!
flow platform cache timeout fast
!
flow monitor NetFlow-Monitor
description Original Netflow Captures
record ipv4
exporter NetFlow-to-Orion
cache timeout inactive 10
cache timeout active 5
!
flow hardware export threshold 70 linecard 90
So I have all the layer 3 port channel and vlan interfaces configured with
ip flow monitor NetFlow-Monitor input
ip flow monitor NetFlow-Monitor output
I get netflow data, but I want to make sure this would be good enough to get accurate netflow data for our environment. Example, we got a layer 3 switch on 8th floor going to the distribution switch. The switch on 8th floor isn't setup for netflow since its a 3750v2 and I do not believe that switch supports netflow, but the link on the distribution switch that points back to that switch is. So will that be good enough to capture data for that area on 8th floor? does netflow have to capture from both sides or is gathering data from the distribution side good enough?
appreciate the help!