Cannot config "ip flow-top-talkers" on 7606-S
We have a router 7606-S is running IOS 12.2 (33r) SRD2 and Internet BGP protocol.
I tried to enable Flow Top Talkers on it to check Top 10 flow talkers.
1.configure interface:
Router(config-if)#ip flow ingress
2.configure
Router(config)#ip flow-top-talkers
but it shows:
Router((config)#ip flow-top-talkers
^
% Invalid input detected at '^' marker.
Router(config)#ip flow-?
flow-aggregation flow-cache flow-capture flow-egress flow-export
I then tried command
Router#show ip flow top-talkers
% Top talkers not configured
Can anyone advice if anything I miss please?
Thanks in advance.
Does your switch have a network services module installed?
Note Flexible NetFlow is supported only on the Catalyst 3750-X and 3560-X switch running the IP base or IP services feature set and equipped with the network services module. It is not supported on switches running the NPE or the LAN base image.
Similar Messages
-
So I stumbled upon the ip flow-top-talkers feature and attempted to configure it on a 3560-X running 12.2(58)SE2. It allowed me to configure this:
ip flow-top-talkers
top 5
sort-by bytes
cache-timeout 60000
Then on the interface I am interested in:
interface GigabitEthernet0/21
ip flow ingress
Which results is (drum roll please....)
Switch#show ip flow top
% Cache is empty
No joy. So I checked the config guide for unsupported commands, these are not listed.
Then I thought maybe it had to be on a layer 3 interface (g0/21 is layer 2) so I did "ip flow ingress" on an SVI, same results.
So then I checked feature navigatore for "Flexible Netflow - Top N Talkers Support". 12.2SE is not listed, but 15.0(2)SE is.
Questions:
- Is the existence of the commands in 12.2(58)SE just an oversight? Functionality seems to almost be there, just not quite.
- Does neflow need to be enabled on a layer 3 interface or will it work on layer 2 (assuming platform support of course)
Thanks,
-JeffDoes your switch have a network services module installed?
Note Flexible NetFlow is supported only on the Catalyst 3750-X and 3560-X switch running the IP base or IP services feature set and equipped with the network services module. It is not supported on switches running the NPE or the LAN base image. -
Cisco2821 - ip flow top talkers = cache is empty
Hi Everyone,
I've been fighting an issue with a 2821 router for some time now. I'm trying to pull the top talkers from an interface, however the cache is empty. I verified the configuration with a known working 2821 and the output for the interfaces are the same. Any help would be greatly appreciated!
NON-WORKING:::
interface GigabitEthernet0/0
description P2P Comcast NLAN to ENET
ip address 10.103.2.6 255.255.255.0
ip flow ingress
ip flow egress
duplex full
speed 100
interface GigabitEthernet0/1
description connect to JDR_3560_2
ip address 10.200.12.1 255.255.255.0
duplex auto
speed auto
interface Serial0/1/0
no ip address
shutdown
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0
no ip http server
no ip http secure-server
ip flow-cache timeout active 1
ip flow-export source GigabitEthernet0/0
ip flow-export version 5
ip flow-export destination 10.100.1.58 2055
ip flow-top-talkers
top 25
sort-by bytes
logging 10.100.1.17
logging 10.100.1.119
WORKING CONFIG:
interface GigabitEthernet0/0
description Comcast MetroEthernet CID: 54.VLXP.006454.CPLC
ip address 10.103.2.5 255.255.255.0
ip flow ingress
ip flow egress
ip pim sparse-dense-mode
ip igmp query-interval 125
duplex full
speed 100
service-policy output WAN-EDGE
ip flow-cache timeout active 1
ip flow-export source GigabitEthernet0/0
ip flow-export version 5
ip flow-export destination 10.100.6.111 2055
ip flow-export destination 10.100.1.58 2055
ip flow-top-talkers
top 30
sort-by bytes
ip mroute 0.0.0.0 0.0.0.0 10.103.2.240
logging 10.100.1.17
logging 10.100.1.40
logging 10.100.1.119Hi,
I'm not a Netflow expert by let's try; config seems to be correct, could you post the output of
sh ip flow export
sh ip flow top-talker
sh ver
enrico -
what happened to this command in the new IOS 15.1(1) with flexflow;
sh ip flow top-talkers...
Thanks,
SinanHi Maicon,
Under "ip flow-top-talkers", you need to configure "sort-by" as it's required to run top-talkers command.
Yoong Seong -
"show ip flow top-talkers" output question
Hello all,
I have a question about the "show ip flow top-talkers" command. The top enry for this 1841 router with a T1 connection is always this line:
SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Bytes
Se0/1/0 64.32.253.138 Local 71.16.240.14 32 6EB0 306B 2366K
How do I get more information about this connection? I looked at ip protocol 32 and it says it is the MERIT Internodal Protocol. Also what does the bytes field mean? Is that bytes per second or per "flow"?Hello,
protocol is 0x32 (in hex) = 50 (dec). This protocol is ESP. I assume, this flow is an IPSEC tunnel.
The endpoint is your device (regarding to dest interface = local). The "Bytes" field means number of
bytes in the flow. It is not releated to bytes/sec. Please, feel free to contact me if you need more
information.
Kind regards,
Jan Nejman
Caligare, co.
http://www.caligare.com/ -
Does WCCP skew results of 'ip flow top-talkers'?
I have a router that has been configured to show ip flow top-talker information. I recently added a WAAS to this site that is using WCCP redirection. The 'top-talkers' output on the router still works - but shows source/destination of the router and WAAS device as the talkers for all traffic that has been redirected. I'm not able to see that actual client IPs for that traffic .. and that is the majority of my traffic. Is there any way to still be able to view this traffic as I did before? If I dump netflow to an actual netflow server instead of using top-talkers will that work - or will it display the same thing?
Router configuration:
interface multilink1
ip flow ingress
interface gi0/0
ip flow ingress
ip flow-top-talkers
top 25
sort-by bytes
Now when I do a 'show ip flow top-talkers', here's what I see: 10.10.11.18 is WAAS and 10.10.255.11 is loopback of the router.
SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Bytes
Gi0/0.1 10.10.11.18 Mu1 10.10.255.11 2F 0000 0000 141M
Gi0/0.1 10.10.11.18 Mu1 10.10.255.11 2F 0000 0000 12M
Gi0/0.1 10.10.11.124 Gi0/0.1 10.10.10.53 06 1058 0A26 1801K
Gi0/0.1 10.10.11.54 Gi0/0.1 10.10.10.5 06 0E0C 0A26 882K
Gi0/0.1 10.10.11.107 Gi0/0.1 10.10.10.50 06 043D 05D6 736K
Gi0/0.1 10.10.11.60 Gi0/0.1 10.10.10.5 06 0409 0A26 723K
Gi0/0.1 10.10.11.103 Gi0/0.1 10.10.10.5 06 0407 0A26 713K
Gi0/0.1 10.10.11.120 Gi0/0.1 10.10.10.14 06 0456 05D6 531K
Gi0/0.1 10.10.11.237 Gi0/0.1 10.10.10.27 06 238C 110E 527K
Gi0/0.1 10.10.11.62 Gi0/0.1 10.10.10.53 06 C00E 05D6 463K
Gi0/0.1 10.10.11.125 Gi0/0.1 10.10.10.30 06 12A1 1F90 355K
Gi0/0.1 10.10.11.115 Gi0/0.1 10.10.10.14 06 042C 05D6 336K
Gi0/0.1 10.10.11.137 Gi0/0.1 10.10.10.6 06 04AC 0D3D 244K
Gi0/0.1 10.10.11.154 Gi0/0.1 10.10.10.53 06 0A0D 0A26 216K
Gi0/0.1 10.10.11.66 Gi0/0.1 10.10.10.6 06 C018 05D6 195K
Gi0/0.1 10.10.11.91 Gi0/0.1 10.10.10.5 06 0439 05D6 145K
Gi0/0.1 10.10.11.58 Gi0/0.1 10.10.10.14 06 0458 05D6 134K
Gi0/0.1 10.10.11.127 Gi0/0.1 10.10.10.30 06 0618 1F90 115K
Gi0/0.1 10.10.11.18 Local 10.10.255.11 11 0800 0800 96K
Gi0/0.1 10.10.11.147 Gi0/0.1 10.10.10.14 06 118F 0A26 88K
Gi0/0.1 10.10.11.95 Gi0/0.1 10.10.10.14 06 0C35 0D3D 84K
Gi0/0.1 10.10.11.105 Gi0/0.1 10.10.10.27 06 C98F 01BD 70K
Gi0/0.1 10.10.11.117 Gi0/0.1 10.10.10.53 06 CB1A 0D3D 41K
Gi0/0.1 10.10.11.65 Gi0/0.1 10.10.10.14 06 0EF9 05D6 40K
Gi0/0.1 10.10.11.112 Gi0/0.1 10.10.10.21 06 08D5 0D3D 37K
Thanks!I believe the problem is caused because I have the WAAS appliance in the same subnet as users. I am using the 'egress-method negotiated-return intercept-method wccp' on the WAAS to send the traffic back to the router. This uses GRE, which is causing the cache flow data to show up the way it is.
I will have to move the WAAS to a different subnet and change the return method. -
Hi All,
i would like to enable "ip flow-top-talkers" in 6500 in native mode.
this command is not supported in current version.
is there any alernative command or it won't support.
running ios is s72033-pk9sv-mz.122-18.SXD5.bin
Thanx in advance for the response.
Regards,
RajeshThis command was introduced only from 12.2(25)S and this feature was integrated into 12.3(11)T. So,if you are using any lower version other than this,this command will not work at all.If possible,better download any of the above 2 versions from cisco website and upgrade your IOS.
-
Hi Folks,
I was trying to use the top talkers feature to find the culprits hogging my bandwidth. I am pertty new top talker feature and its implemented on a 6500 with sup720. I have a couple of queries w.r.t this.
* tried to configure the cort by bytes feature got a warning that its not supported on the hardware based model.So is there any way to use sort by bytes on the sup 720?
* The O/P fileds of a show ip flow top-talkers are usually,
SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts( had to use sort by packets due to warning)
Now is this pkts field the number of packets calculated between the cache-timeout value or is it the total seen so far? Will it be the same for sort by bytes too? Total bytes seen for this flow rather than a realtime bytes/sec or bytes/cache time-out value.
If this is the case then its actually not a real time top talker value right? Please help
Thanks,
PrakadeeshThe --command -- sh ip cache flow shows the cache-timeout value only not the collective bytes of data ; if you need the Total bytes seen for this flow you need to use the Crannog netflow Tracker kind of tools or you need to use " ip accounting " and clear the counter manually as and when required !!!
And it its actually a real time top talker value for that specifed cache-timeout value and i found most of the time it shows the correct top-talker many times !!!!!!!!!!!!!!!!!!! -
Netflow top-talkers configuration
Hello
I would like to know the purpose of these configuration commands :
ip flow-top-talkers
top 50
sort-by packets
cache-timeout 2000
match source address 192.1.1.97/32
match destination address 192.1.1.110/32
This is extracted from a documentation from Cisco.
For me there is no sense to configure a top talkers : how do we know that this will be the top talkers ?
Thanks for help
RegardsTop talkers are based on the conversations or flows generating the heaviest traffic on your routing device. A flow refers to traffic from source A to source B through any interface of the router and "heaviest traffic" means volume of traffic generated. They can be sorted based on any one of the following criteria:
1. By the total number of packets in each top talker
2. By the total number of bytes in each top talker
There are further filter options, which can done using "match statements".
For eg, if you simply enable top talkers for 50 and set the sort feature based on packets, the 50 conversations who were sending the most traffic (volume - KB, MB, GB) will be taken and displayed. The displayed conversations will be sorted based on the packet counts in the flow.
If you add an match IP source statement to the above example, then the same as above is done but only flows whose source IP is the same as in the match statement is captured.
If you add a match source and destination IP, then only the top 50 flows between those 2 IP Addresses will be captured and displayed.
Regards,
Don Thomas Jacob
www.netflowanalyzer.com
NOTE: Please rate posts and close questions if you have got the answer. -
May be slightly simple question from a new Mac user: Why can't I quit safari? I cannot quit it from top menu bar neither to do it from dock? All other apps are working normally.
Or you can actived the right button on your magic mouse and click on they icon in the dock. then you select "stop" and it's out of your dock.
Greetings
*update: Sorry, my mistake! I didn't read your message correct! Sorry for the inconvience! -
I cannot "click" on the top inch of any screen when in firefox. This prevents me from signing in and out of certain webpages. If I minimize the screen this does not go away either. This doesn't happen when I am either on my desktop or using IE. I love firefox, but this is frustrating! Help!
Try the Firefox SafeMode to see how it works there. <br />
''A troubleshooting mode, which disables most Add-ons.'' <br />
''(If you're not using it, switch to the Default Theme.)''
* You can open the Firefox 4/5/6/7 SafeMode by holding the '''Shft''' key when you use the Firefox desktop or Start menu shortcut.
* Or use the Help menu item, click on '''Restart with Add-ons Disabled...''' while Firefox is running. <br />
''Don't select anything right now, just use "Continue in SafeMode."''
''To exit the Firefox Safe Mode, just close Firefox and wait a few seconds before using the Firefox shortcut (without the Shft key) to open it again.''
If it is good in the Firefox SafeMode, your problem is probably caused by an extension, and you need to figure out which one. <br />
http://support.mozilla.com/en-US/kb/troubleshooting+extensions+and+themes -
How to config work flow for approval in snp?
Dear Expert,
we want to running TLB for deployment stock orders which are approved by leaders.
please tell us how to config work flow for approval in snp?
thanks so muchHi,
I got to know from DB49 that some workflow is available in GATP, but as far as I know, there is no such possibility in SNP.
Deployment stock transfer kind of data exists in livecache order series, and it's very tough to manipulate it in some way to suit the approval workflow.
As far as I can propose, you would need to do following (big custom development):
1) Create a custom transaction
2) Read Deployment Stock transfer data in accordance with your selection criteria and display it to the relevant user/approver
3) User would accept/reject the Deployment Stock Transfer. This action is possible in a custom transaction.
4) If Deployment Stock transfer is rejected, delete it from livecache
5) Now when you run TLB, only approved Deployment Stock Transfer would be available to be coverted to STOs.
In the above development, you could create logs/reports as you need for audit kind of purpose.
This won't be a very simple development, but it's possible.
May be someone could give you some better alternative.
Thanks - Pawan -
Cannot build a flow graph with the customized options
Dear JMF-Gurus,
we implemented a DataSource for video capturing that is based on the lti-civil API, so that video capturing on Mac OS X should be possible.
When we try to build the flow graph, we get an jmf-error as described in the following log:
# JMF Version 2.1.1e
## Platform: Mac OS X, ppc, 10.4.9
## Java VM: Apple Computer, Inc., 1.5.0_06
## DataSource created: net.sf.fmj.media.protocol.civil.DataSource@a76306
$$ Profile: instantiation: 30 ms
## Processor created: com.sun.media.processor.unknown.Handler@21ec03
## using DataSource: net.sf.fmj.media.protocol.civil.DataSource@a76306
$$ Profile: parsing: 377 ms
## Getting the supported output formats for:
## RGB, 176x144, FrameRate=10.0, 24-bit, Masks=3:2:1, PixelStride=3, LineStride=528
## # of nodes visited: 50
## # of formats supported: 38
$$ Profile: getSupportedOutputFormats: 340 ms
## Building flow graph for: civil:?
## Building Track: 0
## Input: RGB, 176x144, FrameRate=10.0, 24-bit, Masks=3:2:1, PixelStride=3, LineStride=528
## Custom options specified.
## An output format is specified: YUV Video Format: Size = null MaxDataLength = -1 DataType = class [B yuvType = 2 StrideY = -1 StrideUV = -1 OffsetY = -1 OffsetU = -1 OffsetV = -1
## An output content type is specified: RAW
## Here's the completed flow graph:
com.sun.media.parser.RawBufferParser@a075e6
connects to: com.sun.media.codec.video.colorspace.JavaRGBToYUV@9c61d3
format: RGB, 176x144, FrameRate=10.0, 24-bit, Masks=3:2:1, PixelStride=3, LineStride=528
com.sun.media.codec.video.colorspace.JavaRGBToYUV@9c61d3
connects to: com.sun.media.multiplexer.RawBufferMux@da7565
format: YUV Video Format: Size = java.awt.Dimension[width=176,height=144] MaxDataLength = 38016 DataType = class [B yuvType = 2 StrideY = 176 StrideUV = 88 OffsetY = 0 OffsetU = 25344 OffsetV = 31680
$$ Profile: graph building: 113 ms
$$ Profile: realize, post graph building: 9 ms
$$ Profile: instantiation: 0 ms
## Processor created: com.sun.media.processor.unknown.Handler@654dec
## using DataSource: VIC.MonitorCDS@e0c0b6
$$ Profile: parsing: 1 ms
## Getting the supported output formats for:
## YUV Video Format: Size = java.awt.Dimension[width=176,height=144] MaxDataLength = 38016 DataType = class [B yuvType = 2 StrideY = 176 StrideUV = 88 OffsetY = 0 OffsetU = 25344 OffsetV = 31680
## # of nodes visited: 48
## # of formats supported: 37
$$ Profile: getSupportedOutputFormats: 97 ms
## Building flow graph for: null
## Building Track: 0
## Input: YUV Video Format: Size = java.awt.Dimension[width=176,height=144] MaxDataLength = 38016 DataType = class [B yuvType = 2 StrideY = 176 StrideUV = 88 OffsetY = 0 OffsetU = 25344 OffsetV = 31680
## Custom options specified.
## An output format is specified: H263P/RTP, 176x144, FrameRate=10.0
## An output content type is specified: RAW/RTP
XX Failed to realize: com.sun.media.ProcessEngine@8393ef
XX Cannot build a flow graph with the customized options:
XX Unable to transcode format: YUV Video Format: Size = java.awt.Dimension[width=176,height=144] MaxDataLength = 38016 DataType = class [B yuvType = 2 StrideY = 176 StrideUV = 88 OffsetY = 0 OffsetU = 25344 OffsetV = 31680
XX to: H263P/RTP, 176x144, FrameRate=10.0
XX outputting to: RAW/RTP
XX Error: Unable to realize com.sun.media.ProcessEngine@8393ef
## com.sun.media.BasicFilterModule@31477b: input format changed: RGB, 640x480, 24-bit, Masks=3:2:1, PixelStride=3, LineStride=1920
We guess that the problem was first the wrong input format (wrong video-size or wrong framerate) but this has been changed to the correct format.
The flow graph looks like correct, but it doesn't work anyway.
What does the last line in the log means, and are there any information were the problem good be located?How were you even able to accomplish that? In my classpath I have fmj-nojmf.jar, jmf.jar and lti-civil.jar but I keep on getting this in my log.
# JMF Version 2.1.1e
## Platform: Mac OS X, i386, 10.5.4
## Java VM: Apple Inc., 1.5.0_13
## DataSource created: com.sun.media.protocol.javasound.DataSource@f98d58
I can't get it to find the civil datasource in fmj-nojmf.jar. -
How to get Top Talkers on ASA ?
hi Friends,
We ahave ASA 5510 and 5520 @ our office. We are not using any netflow tools in order to get the talk talklers.
As this firewalls are shared firewall (used by different Projects), we are not able to get , which project is using more traffic and which is less.
Can someone help me out in this ?
Regards
Nirav BhattI know this is an old thread, but I'm hoping this will come in handy for anyone doing a search.
All our 5505's and 5510's are on ASA 8.2(5) and didn't get some of the nicer "top 10" features that come with later versions. I always assumed it was due to the ASA version, but I built an ASA recently on 8.2(5) which has ASDM 7.1(2) on it and the pie charts for top talkers is there now.
I'm in the process of updating all our devices to ASDM 7.1(2) and it's given us a lot more visibility of the network. -
ASA5505 - IP FLOW TOP or IP Accounting
How does one find the top user or IP accounting with this ASA5505 v7.22 device?
With 1841 ISR:
sh ip accounting
sh ip flow top
Very lame if they don't have similar commands or capabilities on the ASA series.David,
The version that you are running is very old. The IP accounting Im not sure what it does, but the show IP flow, I am almost 99% sure that it has to do with Netflow, which was introduced on the ASA in version 8.2 and higher.
Just looked for the IP accounting and mostlikely, all that you are asking for is implemented on Netflow, here is more info:
https://supportforums.cisco.com/docs/DOC-6114
You can upgrade to 8.2.1 not having to do much of a change, now that you know that you are running an old version, please do not consider to (mind as well) upgrade to the latest version without reading what it first needs to be done. The upgrade to 8.2.1 should not be much of a change.
Mike Rojas
Maybe you are looking for
-
ADF: Mandatory symbol for ReadOnly input fields
Hi All, I am using JDeveloper 11.1.2 version. I am creating sample login window. In that there is Input Text filed called "old Password" which should be readOnly always [It will display oldPassword value]. When I ran my page in OldPassword field, man
-
There is no tool bar in Foxfire--it doesn't matter if the page is maximized or not as indicated in one article. I changed the default browser in "preferences" on Safari, but it didn't REALLY change it.
-
I have an applet which amongst other things contains a JTable and a JButton. The JTable has a write-to-model-on-focus-lost implemented, so that the last change is written to the model if the table loses focus. The problem I have is that under MSWindo
-
Lens correction in Photoshop or LR?
Does any of the adobe software's have any cylindrical volume anamorphosis correction like DXO or Hemi? I was planning to get a Canon 10-22 or a Tokina fisheye but would want to Have a distortion correction tool on hand.
-
When i enter my new apple id/password to get the free upgrade for Maverick, i get an error msg (100) that states it cannot complete the process because of an issue with iTunes. It's a new macbook pro (last year's model new in box). I changed my app