Flow data sources

The Flow Gateway can be configured to receive traffic flow information from devices using NetFlow (versions 1, 5, 7 and 9), SteelFlow Net, IPFIX, sFlow (versions 2, 4 and 5), and Packeteer (versions 1 and 2). You can specify one or more ports in a comma-separated list for each type of flow data, up to a combined total of 50 ports.

You can also exclude data sources. Flow Gateway ignores data sent to it from addresses listed in the Excluded Sources box. For example, it drops NetFlow data sent to it from a router whose address is listed in the Excluded Sources box.

Specifying data sources to process

  1. Go to the Configuration > General Settings page and scroll to the Data Sources section.

  2. Select the data type and enter the port number or numbers on which the Flow Gateway is to receive it. The Flow Gateway does not require flow data to use particular ports. However, you must identify the port that the sending device is configured to send to. Each port can receive only one type of flow data.

  3. Click Configure Now at the bottom of the page to apply the settings.

When the Flow Gateway is configured to use the Aux and Management interfaces on separate networks, use the "Allow on interface" option to control which interface is to receive traffic flow data.

The number of sources that you can configure to send flow data to the Flow Gateway depends on the amount of data each is sending. The total from all sources combined must not exceed the capacity of the Flow Gateway. Refer to your license agreement or the Overview page for the flow capacity of your Flow Gateway.

Specifying data sources to exclude

  1. Go to the Configuration > General Settings page and scroll to the Data Sources section.

  2. In the Excluded Sources box, specify the data sources to be excluded. These can be specified as:

    • Address or range of addresses in CIDR format (for a single device, use the /32 single host CIDR mask)

    • Comma-separated list of CIDR blocks

  1. Click Configure Now at the bottom of the page to apply the settings.

Data from sources specified in the Excluded Sources box cannot be forwarded to other devices.

Additional data filtering

In addition to excluding all flow data from a specified flow data source, you can drop incoming flow data based on its IP address, protocol, and/or port. This excludes the specified flow data regardless of which device is sending it. The excluded flow data does not count toward the license limit.

This type in raw data filtering requires creating a filter specification in an XML file and loading it into the Flow Gateway using the command line interface. Instructions are provided in Knowledge Base article S28800, "Incoming Flow Filtering on a Alluvio Flow Gateway," which is available on the Riverbed Support site.

Collecting statistics for flow data sources

Flow Gateway can store additional statistics about flow exporters at various resolutions, which can provide details about bandwidth flow data consumption on the network and which devices are contributing to flow license usage on the appliance. This feature is disabled by default. To enable, 

  1. Go to the Configuration > General Settings page and scroll to the Data Sources section.

  2. Select the Enable detailed Flow Source statistics collection and analytics checkbox.

  1. Click Configure Now at the bottom of the page to apply the settings.

Detailed flow source statistics are accessed from the Home page:

  • Top 10 Flow Sources section
  • Riverbed/Non-Riverbed Flow Sources table – includes additional columns for total flows and flow peaks. Also, the IP  address column includes links to the flow source report for the listed IP addresses. The flow source report is also available from Reports > Flow Source.

Flow Gateway configuration

Flow source report

Start

How-to list