About Network Integration Features : Enabling flow export
  
Enabling flow export
SteelHeads support NetFlow v5.0 and later, CascadeFlow v9.1 and later, and CascadeFlow-compatible features.
Cloud appliances do not support this feature.
NetFlow export is supported only when Xbridge mode is enabled. NetProfiler 10.20 and later are supported.
Flow export requires these components:
Exporter—When you enable flow export support, the SteelHead exports data about the individual flows that it sees as they traverse the network.
Collector—A server or appliance designed to aggregate data sent to it by the SteelHead and other exporters.
Analyzer—A collection of tools used to analyze the data and provide relevant data summaries and graphs. NetFlow analyzers are available for free or from commercial sources. Analyzers are often provided in conjunction with the collectors.
Before you enable flow export in your network, consider the following:
Flow data typically consumes less than 1 percent of link bandwidth. Take care with low bandwidth links to ensure that flow export doesn’t consume too much bandwidth and thereby impacting application performance.
You can reduce the amount of bandwidth consumption by applying filters that only export the most critical information needed for your reports.
These options are available under Flow Statistics Settings:
Enable Peer Bandwidth and RTT Stats
Continuously collects performance statistics for each peer SteelHead. The Peer Optimization reports display these statistics. The performance statistics of individual peers or an aggregate of all connected peers can be viewed. This statistic collection is disabled by default.
To view the reports, choose Reports > Optimization: Peer Optimization.
Enable WAN Throughput Statistics
Continuously collects detailed application-level statistics for both pass-through and optimized traffic. The Application Visibility and Application Statistics reports display these statistics. This statistic collection is disabled by default.
To view the reports, choose Reports > Networking: Application Statistics or Application Visibility.
Enabling application visibility also improves connection reporting on the Current Connections report. For example, HTTP-SharePoint is displayed as the WebDAV or FPSE protocols and Office 365 appears as MS-Office-365 instead of HTTP.
Enable Top Talkers
Continuously collects statistics for the most active traffic flows. A traffic flow consists of data sent and received from a single source IP address and port number to a single destination IP address and port number over the same protocol.
The most active, heaviest users of WAN bandwidth are called the Top Talkers. A flow collector identifies the top consumers of the available WAN capacity (the top 50 by default) and displays them in the Top Talkers report. Collecting statistics on the Top Talkers provides visibility into WAN traffic without applying an in-path rule to enable a WAN visibility mode.
You can analyze the Top Talkers for accounting, security, troubleshooting, and capacity planning purposes. You can also export the complete list in CSV format.
The collector gathers statistics on the Top Talkers based on the proportion of WAN bandwidth consumed by the top hosts, applications, and host and application pair conversations. The statistics track pass-through or optimized traffic, or both. Data includes TCP or UDP traffic, or both (configurable in the Top Talkers report page).
A NetFlow collector is not required for this feature.
Optionally, select a time period to adjust the collection interval:
24-hour Report Period specifies a five-minute granularity (the default setting).
48-hour Report Period specifies a ten-minute granularity.
The system also uses the time period to collect SNMP Top Talker statistics. For top talkers displayed in the Top Talker report and SNMP Top Talker statistics, the system updates the Top Talker data ranks either every 300 seconds (for a 24- hour reporting period), or 600 seconds (for a 48-hour reporting period).
The system saves a maximum of 300 Top Talker data snapshots, and aggregates these to calculate the top talkers for the 24-hour or 48-hour reporting period.
The system never clears top talker data at the time of polling; however, every 300 or 600 seconds, it replaces the oldest Top Talker data snapshot of the 300 with the new data snapshot.
After you change the reporting period, it takes the system one day to update the Top Talker rankings to reflect the new reporting period. In the interim, the data used to calculate the Top Talkers still includes data snapshots from the original reporting period. This delay applies to Top Talker report queries and SNMP Top Talker statistics.
These options are available under Flow Export Settings:
Enable Flow Export
Enables the SteelHead to export network statistics about the individual flows that it sees as they traverse the network. By default, this setting is disabled.
Enable IPv6
Enables support for IPv6 addresses for flow exports.
Active Flow Timeout
Specifies the amount of time, in seconds, the collector retains the list of active traffic flows. The default value is 60 seconds. You can set the time-out period even if the Top Talkers option is enabled.
Inactive Flow Timeout
Specifies the amount of time, in seconds, the collector retains the list of inactive traffic flows. The default value is 15 seconds.
These options are available under Flow Collectors:
Collector Hostname or IP Address
Specifies the IP address or (in RiOS 9.7 and later) a hostname for the Flow collector.
Port
Specifies the UDP port the Flow collector is listening on. The default value is 2055.
Version
Specifies a version from the drop-down list.
CascadeFlow and CascadeFlow-compatible are enhanced versions of flow export. These versions allow automatic discovery and interface grouping for SteelHeads in a Riverbed NetProfiler or a Flow Gateway and support WAN and optimization reporting.
Packet Source Interface
Selects the interface to use as the source IP address of the flow packets (Primary, Aux, or MIP) from the drop-down list. NetFlow records sent from the SteelHead appear to be sent from the IP address of the selected interface.
LAN Address
Causes the TCP/IP addresses and ports reported for optimized flows to contain the original client and server IP addresses and not those of the SteelHead. The default setting displays the IP addresses of the original client and server without the IP address of the SteelHeads.
This setting is unavailable with NetFlow v9 and later, because the optimized flows are always sent out with both the original client server IP addresses and the IP addresses used by the SteelHead.
Capture Interface/Type
Specifies the traffic type to export to the flow collector. Select one of these types from the drop-down list:
All exports both optimized and nonoptimized traffic.
Optimized exports optimized traffic.
Passthrough exports pass-through traffic.
None disables traffic flow export.
The default is All for LAN and WAN interfaces, for all four collectors. The default for the other interfaces (Primary, rios_lan, and rios_wan) is None. You can’t select a MIP interface.
Enable Filter
(CascadeFlow and NetFlow v9 only) filters flow reports by IP and subnets or IP:ports included in the Filter list. When disabled, reports include all IP addresses and subnets.