So, have you asked yourself, should I upgrade to Flexible NetFlow? And if you have, has the next question been, why?
- NBAR – provides deeper packet inspection to identify applications such as Skype, Webex, etc. Without NBAR, NetFlow will display these apps via the port they use (e.g. port 80 or 443, etc.).
- Packet capture – we have played with this a bit, but it isn’t ready for prime time because the pre filtering is almost nonexistent. Basically, the router can be configured to send actual packets inside NetFlow udp datagrams. It is very cool, but you can’t specify what you want yet. In short, you can ask for all TCP or UDP. You basically can’t turn it on if the router is seeing serious traffic. It will be perfected over time.
- Syslogs – We are seeing this from the Cisco ASA already in the form of NetFlow Security Event Logging (aka NSEL). These messages tell us what access list entry denied a flow.
- Accounting – You can setup a Permanent cache to export bytes for a particular subnet. This is really useful if the volume of NetFlow is too great for any NetFlow collector. Less details means less flows, however, the total byte count is still highly accurate.
- Sampling – this is useful for large enterprises and especially service providers. It allows admins to get a great idea of traffic patterns by looking at samples of the data. Sampling is necessary when flow exports are excessive.
- Layer 2 details – details on layer 2 can be exported (e.g. MAC addresses, VLAN IDs, etc.).
- IPv6 support – this will be important some day.
- Unlimited Exports – can export to more than 2 collectors. FnF can send details to an unlimited amount of collectors.
- Option Templates – although you can do this in NetFlow v9, FnF is taking it to another level. You can export the interface names (e.g. ifName, ifAlias, ifDesc, etc.) using NetFlow and no longer rely on SNMP.
- FnF is paving the way for the future of NetFlow and is a big part of IPFIX (the proposed NetFlow standard).
We also posted this blog on Cisco NetFlow v5 vs. NetFlow v9. You might find it useful as well. We are seeing companies kick out some amazing details with IPFIX (e.g. latency, URLs, etc.). FnF is definitely the future of NetFlow. Our next release of Scrutinizer NetFlow Analyzer allows you to filter and report on all things FnF.
Hope this answers your questions on if and why to use Flexible NetFlow.