Netflow enabled interfaces with ifType 1 don't show up in NFA 9.3.3.

Document created by sigju01 Employee on Dec 28, 2015Last modified by sigju01 Employee on Dec 30, 2015
Version 2Show Document
  • View in full screen mode

Problem:

In NFA 9.3.3 you may experience interfaces with netflow commands set on the device not show up in NFA.  This is because the interface is assigned to ifType 1 (other).

 

Environment:

NFA 9.3.3 and later.

 

Cause:

In NFA 9.3.3+ we exclude certain interfaces from showing up in NFA to prevent database bloat.  These interfaces usually do not have the capability of exporting netflow.  However, we have found that some interfaces who are assigned to ifType 1 (other), may export netflow.

The interfaces from which CA Network Flow Analysis will process flow data are configurable based on ifType. There are interface types that typically will not export flow data, and CA NFA ignores these ifTypes:

1

18

37

100

101

102

103

104

134

 

However, you may have a different router configuration, and need to modify the ifTypes on this list.

 

Resolution/Workaround:

 

1. Locate the poller.properties file.

 

     <install_path>\Netflow\bin\poller.properties

 

     Open the file in a text editor.

 

2. The ifTypes that CA NFA will ignore are included on the following line:

 

     ifTypesToIgnore=1,18,37,100,101,102,103,104,134

 

     Edit this list to add or remove ifTypes as necessary. The list must contain integer values, separated by commas, and containing no spaces.

 

3. Save the edited file

 

4. Restart the harvester (CA NFA Harvester) then the poller service (CA NFA Poller) and then the harvester (CA NFA Harvester) again.

Additional Information:

Excluding ifTypes

https://www.iana.org/assignments/ianaiftype-mib/ianaiftype-mib

 

KB Article ID : TEC1841336

Attachments

    Outcomes