I have been experimenting with Netflows on my 7206 router as a replacement to switch-level MRTG monitoring.
A few things have come up.
My 7206 has 3 FE interfaces, one is the BGP Uplink to provider, the other two are internal, subnetted with my own IPs, etc.,.
So I configured the Netflows on the Uplink interface only.
interface FastEthernet 0/0 ip route-cache flow
Then in the main config added:
ip flow-export
I'm using flowtools and flowviewer on FreeBSD to do the analysis.
Everything works, but when I analyze the flows, I only see inbound traffic - i.e. my IP's are the destination, never the source (same thing is true when I just do sh ip cache flow on the router itself). Why am I not seeing outbound traffic?
Also, since I have never used netflows, I am curious if there is a performance hit when using it. Does it use up memory. If I dont clear the flow cache routinely, the sh ip cache flow cmd returns a ton of data, is that using up memory? If so, how can you force it clear out?
My 7206 is NPE-200 with 128Mb RAM, and it only pushes around 5-7Mbps.
Thanks John