Observations on Cisco sampled NetFlow

  • Authors:
  • Baek-Young Choi;Supratik Bhattacharyya

  • Affiliations:
  • University of Missouri, Kansas City;Sprint Advanced Technology Laboratory

  • Venue:
  • ACM SIGMETRICS Performance Evaluation Review - Special issue on the First ACM SIGMETRICS Workshop on Large Scale Network Inference (LSNI 2005)
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Traffic monitoring is an important first step for network management and traffic engineering. With high-speed Internet backbone links, efficient and effective packet sampling is not only desirable, but also increasingly becoming a necessity. The Sampled NetFlow [10] is Cisco router's traffic measurement functionality with static packet sampling for high speed links. Since the utility of sampling depends on the accuracy and economy of measurement, it is important to understand sampling error and measurement overhead. In this paper, we first discuss fundamental limitations of sampling techniques used in the Sampled NetFlow. We assess the accuracy of the Sampled NetFlow by comparing its output with complete packet traces [8] from an operational router. We also show the overheads involved in the Sampled NetFlow. We find that Sampled NetFlow performs correctly without incurring dramatic overhead during our experiments. However, a care should be taken in its use, since the overhead is linearly proportional to the number of flow records.