L3 · management · draft
NetFlow / IPFIX
IP Flow Information Export (IPFIX) and NetFlow
An exporter meters conversations and sends templated records to a collector — traffic metadata, not a full packet capture.
Presenter modeEmbed this figure
Why it exists
Operators need conversation-level visibility — who talked to whom, how much, over which ports — without storing every packet. IntroductionRFC 7011 · INTERNET STANDARD · September 2013
NetFlow began as Cisco technology. IPFIX standardizes the export framing and Information Element model so collectors can speak one IETF protocol. IntroductionRFC 3954 · INFORMATIONAL · October 2004
Templates must arrive before data makes sense
IPFIX and NetFlow v9 carry Template Sets that define field layout. A collector that receives Data Sets without a matching template cannot decode them.
The exporter sends a Template Set describing Information Elements and lengths. The Observation Domain and Template ID bind later Data Sets to this layout. Exporter. Collector.
- Link
- Blocking
- Packet in flight
- Discarded
- Emphasis
Text equivalent of this diagram
| Element | Kind | State |
|---|---|---|
| Exporter | router | — |
| Collector | cloud | — |
| Exporter — Collector | link | up |
The exporter sends a Template Set describing Information Elements and lengths. The Observation Domain and Template ID bind later Data Sets to this layout.
What changed
- Template Set: Exporter → Collector
- Learn field layout
How it works
An Observation Point meters packets into Flow Records keyed by configured fields. An Exporter packages Templates and Data Sets toward a Collector. IPFIX Message FormatRFC 7011 · INTERNET STANDARD · September 2013
Template Sets define the ordered list of Information Elements. Data Sets carry values packed to that layout under a Template ID and Observation Domain. Template Record FormatRFC 7011 · INTERNET STANDARD · September 2013
NetFlow Version 9 (RFC 3954, informational) uses a similar template concept; IPFIX (RFC 7011) is the IETF standards-track successor with refined semantics. Export Packet FormatRFC 3954 · INFORMATIONAL · October 2004
Sampling and aggregation are metering choices. They change what numbers mean; they are not optional cosmetics for the collector. Cisco IOS XE — Flexible NetFlow Configuration Guide §Flexible NetFlow — Sampling
On the wire
Constructed examples, encoded from the field table below them — not captured traffic.
- UDP or SCTP/TCP
- IPFIX may use UDP, SCTP, or TCP. Common collector ports include 4739. UDP loses templates silently. RFC 7011
- IPFIX Message Header
- Fixed header before Template Sets and Data Sets. RFC 7011
Configure it
flow record FNF-REC match ipv4 source address match ipv4 destination address match transport source-port match transport destination-port match ipv4 protocol collect counter bytes long collect counter packets long collect timestamp absolute first collect timestamp absolute lastFlow key (match) plus counters (collect). The exporter builds Template Sets from this layout before Data Sets are useful to the collector.
Common mistake: Changing the record layout without forcing template refresh — collectors keep stale Template IDs.
RFC 7011 §3.4.1
flow exporter FNF-EXP destination 198.51.100.10 transport udp 4739 template data timeout 300 option interface-table timeout 300UDP export toward the collector. Template timeout republishes layouts so late or restarted collectors can decode Data Sets.
Common mistake: Exporting to an unreachable collector while assuming interface counters prove flow export health.
RFC 7011 §8.4
flow monitor FNF-MON record FNF-REC exporter FNF-EXP cache timeout active 60 interface GigabitEthernet1/0/1 ip flow monitor FNF-MON inputBind the monitor to an observation point. Sampling (if added) must be documented for collector scale math.
Cisco IOS XE — Flexible NetFlow Configuration Guide §Configuring Flexible NetFlow
Verify
show flow exporter FNF-EXP statistics- Templates and records sent; no sustained destination unreachable.
show flow monitor FNF-MON cache format table- Active flows matching the configured key.
Caveats
- Marked draft: Flexible NetFlow syntax varies by platform and release; treat as teaching shape, not copy-paste production.
- Collector sampling scale must match any sampler applied on the exporter.
When it breaks
Symptom first, because that is what you have when it happens.
Collector shows undecoded or discarded records.
Narrow it down
- Confirm Template Sets arrive for that Observation Domain and Template ID.
- Check firewall rules that might allow data but block templates on another port/session.
Cause
Data Sets arrived without a usable matching template.
Fix
Ensure template export and refresh; clear stale collector caches after exporter change.
Template Record FormatRFC 7011 · INTERNET STANDARD · September 2013Bandwidth graphs are systematically low or high versus interface counters.
Narrow it down
- Compare exporter sample interval with collector scale factor.
- Confirm whether the platform exports raw sampled or already scaled counts.
Cause
Sampling interval mismatched between exporter and collector interpretation.
Fix
Align and document the interval; encode it in export metadata when available.
Cisco IOS XE — Flexible NetFlow Configuration Guide §Flexible NetFlow — SamplingAfter a device reload, flow fields look scrambled.
Narrow it down
- Compare Template ID definitions before and after restart.
- Flush collector template state for that Observation Domain.
Cause
Collector applied a cached template that no longer matches the exporter.
Fix
Force template refresh; shorten template lifetime; invalidate on exporter reboot.
Additional Considerations for Template Management over UDPRFC 7011 · INTERNET STANDARD · September 2013Too many or too few flow records versus expectation.
Narrow it down
- List the flow key fields on the exporter.
- Confirm direction and observation point (ingress vs egress).
Cause
Flow keys aggregate differently than the analyst assumed (e.g. missing ToS or VLAN).
Fix
Redesign the record key to match the question being asked.
TerminologyRFC 7011 · INTERNET STANDARD · September 2013Gaps in collector timelines while interfaces still pass traffic.
Narrow it down
- Check exporter CPU and export drops.
- Verify collector reachability and UDP loss on the path.
Cause
Export is typically unreliable datagram delivery; overload or path loss drops records silently.
Fix
Reduce sampling load, rate-limit export, or use a more reliable transport profile where supported.
IntroductionRFC 7011 · INTERNET STANDARD · September 2013
Design notes
Flow export is not a packet capture. Payload bytes and most L2 details are absent unless explicitly exported as Information Elements.
Template refresh and Observation Domain identity are operational contracts between exporter and collector — treat them like a schema registry. Additional Considerations for Template Management over UDPRFC 7011 · INTERNET STANDARD · September 2013
Misconceptions
- “NetFlow/IPFIX stores every packet like a capture.”
- Exporters meter aggregated flow records. Payload and most header detail are not retained unless explicitly defined as Information Elements. IntroductionRFC 7011 · INTERNET STANDARD · September 2013
- “Templates are optional metadata.”
- Without a matching Template Set, Data Set field layout is undefined. Templates are required for correct decode. Template Record FormatRFC 7011 · INTERNET STANDARD · September 2013
- “NetFlow and IPFIX are identical wire formats.”
- NetFlow v9 (RFC 3954) and IPFIX (RFC 7011) share the template idea but differ in message details and Information Element registries. Collectors must speak the dialect in use. IntroductionRFC 7011 · INTERNET STANDARD · September 2013
More walkthroughs
Sampling rate must match collector mathdesign-choice
Sampled metering multiplies observed packets by an interval. If the exporter samples 1:1000 but the collector assumes 1:1, dashboards understate traffic by three orders of magnitude.
Only every Nth packet (or a probabilistic draw) updates the meter. Sampling reduces export load at the cost of statistical error on short flows. Observation point. Sampled exporter: Sample 1:1000. Collector.
- Link
- Blocking
- Packet in flight
- Discarded
- Emphasis
Text equivalent of this diagram
| Element | Kind | State |
|---|---|---|
| Observation point | zone | — |
| Sampled exporter | router | Sample: 1:1000 |
| Collector | cloud | — |
| Observation point — Sampled exporter | link | up |
| Sampled exporter — Collector | link | up |
Only every Nth packet (or a probabilistic draw) updates the meter. Sampling reduces export load at the cost of statistical error on short flows.
What changed
- Sample interval configured
- Sampled exporter: Sample → 1:1000
Exporter restart invalidates cached templatesfailure
After a reboot the Observation Domain may reuse Template IDs with a new layout, or the collector still holds stale templates. Data Sets decode incorrectly until templates are refreshed.
Before restart the collector cached Template ID 256 as a 5-tuple layout. After reboot the exporter may redefine ID 256 differently, or delay sending templates. Exporter · reboot: State rebooting. Collector · stale cache.
- Link
- Blocking
- Packet in flight
- Discarded
- Emphasis
Text equivalent of this diagram
| Element | Kind | State |
|---|---|---|
| Exporter · reboot | router | State: rebooting |
| Collector · stale cache | cloud | — |
| Exporter · reboot — Collector · stale cache | link | up |
Before restart the collector cached Template ID 256 as a 5-tuple layout. After reboot the exporter may redefine ID 256 differently, or delay sending templates.
What changed
- Stale template cache
- Exporter · reboot: State → rebooting