L3 · management · draft

NetFlow / IPFIX

IP Flow Information Export (IPFIX) and NetFlow

An exporter meters conversations and sends templated records to a collector — traffic metadata, not a full packet capture.

Presenter modeEmbed this figure

IntroductionRFC 7011 · INTERNET STANDARD · September 2013IPFIX Message FormatRFC 7011 · INTERNET STANDARD · September 2013Linkage with the Information ModelRFC 7011 · INTERNET STANDARD · September 2013IntroductionRFC 3954 · INFORMATIONAL · October 2004

Why it exists

Operators need conversation-level visibility — who talked to whom, how much, over which ports — without storing every packet. IntroductionRFC 7011 · INTERNET STANDARD · September 2013

NetFlow began as Cisco technology. IPFIX standardizes the export framing and Information Element model so collectors can speak one IETF protocol. IntroductionRFC 3954 · INFORMATIONAL · October 2004

Templates must arrive before data makes sense

IPFIX and NetFlow v9 carry Template Sets that define field layout. A collector that receives Data Sets without a matching template cannot decode them.

The exporter sends a Template Set describing Information Elements and lengths. The Observation Domain and Template ID bind later Data Sets to this layout. Exporter. Collector.

ExporterCollectorLearn field layout
  • Link
  • Blocking
  • Packet in flight
  • Discarded
  • Emphasis
Select a device to read its state. Arrow keys walk the topology.
Text equivalent of this diagram
Devices and links at this step
ElementKindState
Exporterrouter
Collectorcloud
ExporterCollectorlinkup
1 / 3

The exporter sends a Template Set describing Information Elements and lengths. The Observation Domain and Template ID bind later Data Sets to this layout.

What changed

  • Template Set: Exporter → Collector
  • Learn field layout

How it works

An Observation Point meters packets into Flow Records keyed by configured fields. An Exporter packages Templates and Data Sets toward a Collector. IPFIX Message FormatRFC 7011 · INTERNET STANDARD · September 2013

Template Sets define the ordered list of Information Elements. Data Sets carry values packed to that layout under a Template ID and Observation Domain. Template Record FormatRFC 7011 · INTERNET STANDARD · September 2013

NetFlow Version 9 (RFC 3954, informational) uses a similar template concept; IPFIX (RFC 7011) is the IETF standards-track successor with refined semantics. Export Packet FormatRFC 3954 · INFORMATIONAL · October 2004

Sampling and aggregation are metering choices. They change what numbers mean; they are not optional cosmetics for the collector. Cisco IOS XE — Flexible NetFlow Configuration Guide §Flexible NetFlow — Sampling

On the wire

Constructed examples, encoded from the field table below them — not captured traffic.

Version 10 message from Observation Domain 1. Template and Data Sets would follow.

UDP or SCTP/TCP
IPFIX may use UDP, SCTP, or TCP. Common collector ports include 4739. UDP loses templates silently. RFC 7011
IPFIX Message Header
Fixed header before Template Sets and Data Sets. RFC 7011

Configure it

Flow record, exporter, and monitor toward a collector with template refresh.

Cisco IOS-XE 17.12 · Catalyst 9300, ISR 4451draft

  1. flow record FNF-REC
     match ipv4 source address
     match ipv4 destination address
     match transport source-port
     match transport destination-port
     match ipv4 protocol
     collect counter bytes long
     collect counter packets long
     collect timestamp absolute first
     collect timestamp absolute last

    Flow key (match) plus counters (collect). The exporter builds Template Sets from this layout before Data Sets are useful to the collector.

    Common mistake: Changing the record layout without forcing template refresh — collectors keep stale Template IDs.

    RFC 7011 §3.4.1

  2. flow exporter FNF-EXP
     destination 198.51.100.10
     transport udp 4739
     template data timeout 300
     option interface-table timeout 300

    UDP export toward the collector. Template timeout republishes layouts so late or restarted collectors can decode Data Sets.

    Common mistake: Exporting to an unreachable collector while assuming interface counters prove flow export health.

    RFC 7011 §8.4

  3. flow monitor FNF-MON
     record FNF-REC
     exporter FNF-EXP
     cache timeout active 60
    interface GigabitEthernet1/0/1
     ip flow monitor FNF-MON input

    Bind the monitor to an observation point. Sampling (if added) must be documented for collector scale math.

    Cisco IOS XE — Flexible NetFlow Configuration Guide §Configuring Flexible NetFlow

Verify

show flow exporter FNF-EXP statistics
Templates and records sent; no sustained destination unreachable.
show flow monitor FNF-MON cache format table
Active flows matching the configured key.

Caveats

  • Marked draft: Flexible NetFlow syntax varies by platform and release; treat as teaching shape, not copy-paste production.
  • Collector sampling scale must match any sampler applied on the exporter.

When it breaks

Symptom first, because that is what you have when it happens.

  1. Collector shows undecoded or discarded records.

    Narrow it down

    1. Confirm Template Sets arrive for that Observation Domain and Template ID.
    2. Check firewall rules that might allow data but block templates on another port/session.

    Cause

    Data Sets arrived without a usable matching template.

    Fix

    Ensure template export and refresh; clear stale collector caches after exporter change.

    Template Record FormatRFC 7011 · INTERNET STANDARD · September 2013
  2. Bandwidth graphs are systematically low or high versus interface counters.

    Narrow it down

    1. Compare exporter sample interval with collector scale factor.
    2. Confirm whether the platform exports raw sampled or already scaled counts.

    Cause

    Sampling interval mismatched between exporter and collector interpretation.

    Fix

    Align and document the interval; encode it in export metadata when available.

    Cisco IOS XE — Flexible NetFlow Configuration Guide §Flexible NetFlow — Sampling
  3. After a device reload, flow fields look scrambled.

    Narrow it down

    1. Compare Template ID definitions before and after restart.
    2. Flush collector template state for that Observation Domain.

    Cause

    Collector applied a cached template that no longer matches the exporter.

    Fix

    Force template refresh; shorten template lifetime; invalidate on exporter reboot.

    Additional Considerations for Template Management over UDPRFC 7011 · INTERNET STANDARD · September 2013
  4. Too many or too few flow records versus expectation.

    Narrow it down

    1. List the flow key fields on the exporter.
    2. Confirm direction and observation point (ingress vs egress).

    Cause

    Flow keys aggregate differently than the analyst assumed (e.g. missing ToS or VLAN).

    Fix

    Redesign the record key to match the question being asked.

    TerminologyRFC 7011 · INTERNET STANDARD · September 2013
  5. Gaps in collector timelines while interfaces still pass traffic.

    Narrow it down

    1. Check exporter CPU and export drops.
    2. Verify collector reachability and UDP loss on the path.

    Cause

    Export is typically unreliable datagram delivery; overload or path loss drops records silently.

    Fix

    Reduce sampling load, rate-limit export, or use a more reliable transport profile where supported.

    IntroductionRFC 7011 · INTERNET STANDARD · September 2013

Design notes

Flow export is not a packet capture. Payload bytes and most L2 details are absent unless explicitly exported as Information Elements.

Template refresh and Observation Domain identity are operational contracts between exporter and collector — treat them like a schema registry. Additional Considerations for Template Management over UDPRFC 7011 · INTERNET STANDARD · September 2013

Misconceptions

NetFlow/IPFIX stores every packet like a capture.
Exporters meter aggregated flow records. Payload and most header detail are not retained unless explicitly defined as Information Elements. IntroductionRFC 7011 · INTERNET STANDARD · September 2013
Templates are optional metadata.
Without a matching Template Set, Data Set field layout is undefined. Templates are required for correct decode. Template Record FormatRFC 7011 · INTERNET STANDARD · September 2013
NetFlow and IPFIX are identical wire formats.
NetFlow v9 (RFC 3954) and IPFIX (RFC 7011) share the template idea but differ in message details and Information Element registries. Collectors must speak the dialect in use. IntroductionRFC 7011 · INTERNET STANDARD · September 2013

More walkthroughs

Sampling rate must match collector mathdesign-choice

Sampled metering multiplies observed packets by an interval. If the exporter samples 1:1000 but the collector assumes 1:1, dashboards understate traffic by three orders of magnitude.

Only every Nth packet (or a probabilistic draw) updates the meter. Sampling reduces export load at the cost of statistical error on short flows. Observation point. Sampled exporter: Sample 1:1000. Collector.

Observation pointSampled exporterSample interval configuredSample: 1:1000Collector
  • Link
  • Blocking
  • Packet in flight
  • Discarded
  • Emphasis
Select a device to read its state. Arrow keys walk the topology.
Text equivalent of this diagram
Devices and links at this step
ElementKindState
Observation pointzone
Sampled exporterrouterSample: 1:1000
Collectorcloud
Observation pointSampled exporterlinkup
Sampled exporterCollectorlinkup
1 / 3

Only every Nth packet (or a probabilistic draw) updates the meter. Sampling reduces export load at the cost of statistical error on short flows.

What changed

  • Sample interval configured
  • Sampled exporter: Sample → 1:1000

Exporter restart invalidates cached templatesfailure

After a reboot the Observation Domain may reuse Template IDs with a new layout, or the collector still holds stale templates. Data Sets decode incorrectly until templates are refreshed.

Before restart the collector cached Template ID 256 as a 5-tuple layout. After reboot the exporter may redefine ID 256 differently, or delay sending templates. Exporter · reboot: State rebooting. Collector · stale cache.

Exporter · rebootState: rebootingCollector · stale cacheStale template cache
  • Link
  • Blocking
  • Packet in flight
  • Discarded
  • Emphasis
Select a device to read its state. Arrow keys walk the topology.
Text equivalent of this diagram
Devices and links at this step
ElementKindState
Exporter · rebootrouterState: rebooting
Collector · stale cachecloud
Exporter · rebootCollector · stale cachelinkup
1 / 3

Before restart the collector cached Template ID 256 as a 5-tuple layout. After reboot the exporter may redefine ID 256 differently, or delay sending templates.

What changed

  • Stale template cache
  • Exporter · reboot: State → rebooting

Check yourself

  • What must a collector have before it can decode an IPFIX Data Set?
  • What happens if the collector ignores the exporter’s sample interval?
  • Which document is the IETF standards-track IPFIX protocol specification?
  • How does flow export differ from a packet capture?
  • Why can an exporter reboot scramble collector decode?
  • What primarily decides how packets are aggregated into flows?
  • What is RFC 3954’s relationship to IPFIX?
  • Why do operators sample high-speed interfaces?