### Flexible Netflow on the Cisco 4500 Switch

Netflow is the very basic need which is required when troubleshooting Network slowness problems. Unfortunately Cisco 4500 switch does not have General/Traditional Netflow which we configure on Cisco Routers and Cisco 6500 switches etc. Cisco 4500 only supports Flexible Netflow which is basically Netflow V9. In this post I will guide you to configure Flexible Netflow in Cisco 4500 switch.

There are 4 steps to configure Flexible Netflow in Cisco 4500 switch:

• Create a flow record

• Create a flow exporter

• Create a flow monitor

• Apply the monitor to an interface

### Step 1 : Create Flow record :

The flow record defines the fields that will be used to group traffic into unique flows. In my example, I used the following configuration:

flow record IPV4-FLOW-RECORD
match ipv4 tos
match ipv4 protocol
match transport source-port
match transport destination-port
collect interface input
collect interface output
collect counter bytes long
collect counter packets long

### Step 2 : Create Flow Export :

In flow exporter we configure the IP of netflow analyser tool which will receive Netflow data. By default, Cisco will send data to UDP Port 9995 but you can configure this port to any number. I have also configured Source Interface which is reachable from Netflow analyser server.

flow exporter Netflow_analyser
destination 192.168.0.245
source Loopback0
transport udp 9995

### Step 3 : Create Flow Monitor :

The flow monitor is where you link records and exporters together :
flow monitor IPV4-FLOW
description Used for Monitoring IPv4 Traffic
record IPV4-FLOW-RECORD
exporter Netflow_analyser

Now its time to apply this to Interface where we want to enable Netflow.

### Step 4 : Apply The Configuration :

First we will apply it to SVI vlan port :
4500(config)#vlan config 2  -----> This is Vlan number
4500(config-vlan-config)#ip flow monitor IPV4-FLOW input

Similarly we will apply to L3 port :
interface GigabitEthernet 0/1
ip flow monitor IPV4-FLOW input

### Show Commands to check Flexible Netflow is configured correctly :

4500#show flow ?
exporter   Flow Exporter information
interface  Flow interface information
internal   Show the flow fields
monitor    Flow Monitor information
record     Show Flow Record configuration

You can check different parameters and configuration by using "show flow " command.

Thanks for reading my short post regarding Flexible Netflow on Cisco 4500 Switch.

### SuperPuTTY for EVE-NG

To use SuperPuTTY as default client for telnet in Eve-NG for multi tab console When we click on Router or Switch in EVE-NG by default console open in CMD. Here I posting a method to use SuperPutty with EVE-NG so that you can use TAB function of SuperPutty. You need to edit registry  Enable handling of telnet://hostname:port/ URLs on the command line. With this feature, you can now set SuperPuTTY as the default handler for Telnet URLs  If you run the Registry Editor (Start->Run->regedit.exe) and set the value in: HKEY_CLASSES_ROOT\telnet\shell\open\command to be: "\path\to\SuperPutty.exe" (with the full pathname of your SuperPuTTY executable) In my case it like this : C:\Program Files (x86)\SuperPuTTY\SuperPutty.exe %1 Second most important thing : Select "Only allow single instance of SuperPutty to run" in SuperPutty options (Tools > Options) And in GUI options , select Tab Text : "Dynamic" And Fin

### NAT Cloud in EVE-NG

NAT Cloud in EVE-NG I want to share with you how to create a NAT cloud in the EVE-NG community edition. Essentially, this is a virtual network with a DHCP server, which will allow NAT connections over the management interface of the EVE-NG VM for Internet access. Interface, DHCP Server and NAT First of all, we need to create a network which can be used in the topology. I’ll be using the predefined pnet9 interface (Cloud 9 network) for this, but any other interface will do. 1 2 3 ip address add 192.168.255.1 / 24 dev pnet9 echo 1 > / proc / sys / net / ipv4 / ip_forward iptables - t nat - A POSTROUTING - o pnet0 - s 192.168.255.0 / 24 - j MASQUERADE This will assign an IP address to the device, enable IP forwarding in the kernel and establish an iptables rule to NAT the traffic to the pnet0 interface, which has the management IP address assigned. Technically, the pnet devices are bridges, but for the sake of this note this does no

### copy IOS from FTP server for cisco switch upgrade

These are the commands to copy IOS from FTP to Flash: Filezilla SERVER : copy ftp://username:password@ftp-server-ip/IOS-name.bin flash: Example : copy  ftp://cisco:cisco@192.168.1.1/c2960x-universalk9-mz.152-4.E6.bin  flash: SolarWinds SFTP & SCP Server (When we need to copy IOS to Flash using Secured channel like SCP or SFTP: copy scp://<User>:<Password>@<Server-IP>/<File-name> flash0://<File-Name>

### Radius and Tacacs server for Authentication

Radius and Tacacs server for Authentication When we study for certification regarding Cisco, we encounter topic like Radius or Tacacs Server many times. You all know what are these and when to use them. But will it be beneficial to setup Radius or Tacacs authentication in real production network ? Suppose you have 20 - 30 devices and there are three network administrator handling those devices in your company. One day you get a news that one of the network engineer is leaving an organization. To comply with company's security policy, you need to delete his/her Login credentials from all 20 - 30 devices. It hardly takes 20 - 30 Min to do that. No problem ! All is well till now. Now imagine a different scenario in which you are working in even bigger organization which has around 2000 devices and has large network team around 15 - 20 Network admins. Each one of them has different access permissions on the network devices and some of them only have access permissions to limite

### Network Engineer should Learn Python

Network Engineer should Learn Python Suppose you are a Network Administrator or Engineer in a company which has 20 - 30 Network devices like Cisco , Juniper or some other vendors devices. How would you manage these Devices ? Yes you do Telnet or SSH to these devices and do your configuration etc. This is a happy happy situation. Now lets consider second scenario. Suppose you are handling multi-site company with different offices which are  distributed geographically across country and world too. You have to manage around 1000 different network devices spread around different locations. One day your boss come to you and ask you to change or add new NTP server to these network devices. Aaahhh... Yes he actually means to these 1000 devices!!! Now what will be your first reaction ? How it is possible to Login to each network device and enter the NTP command ? Yes it is possible to just grab your chair and SSH to each and every device manually and put NTP command. What an idiotic an

### Eat that Frog Chapter - 1

Eat That Frog!: 21 Great Ways to Stop Procrastinating and Get More Done in Less Time by Brian Tracy Chapter - 1 - Set the Table Recently, I have started reading the book " EAT THAT FROG " by Brian Tracy. So here I am giving you the summary of the first chapter which I have recently completed. The title of the first chapter is "Set your Table" which means  Clarity of the goal that you set. Clarity is described by the author as the most important part for personal productivity. Why some people are ultra productive and other are very less productive. The reason behind is thst the ultra productive people are well focused on their goals and tasks. A major reason for procrastination to do the work is the cloud and haziness of the goal in front of your eyes. We don't have clarity about the goal. We are not certain about what we have to do and in which order . To over come this habit of procrastination, Brain Tracy has described seven step method as mentioned