* IETF has proposed standardizing flow export
IPFIX eases network-flow reporting
By Ben Erwin
Flow-based technologies, increasingly popular for characterizing network traffic, are invaluable to setting QoS policies, deploying applications and engaging in capacity planning. However, network managers have lacked a standard format in which to export traffic flows.
The IETF is standardizing flow export under proposed RFC 3917 – IP Flow Information Export (IPFIX). RFC 3917 has been submitted to the IETF for final approval this year. Using Cisco IOS NetFlow Version 9 as its foundation, the IPFIX standard defines unique traffic flows using the following flow keys: source IP address, destination IP address, source port, destination port, Layer 3 protocol type, type-of-service byte and input logical interface.
The combination of keys in each exported flow record lets reporting applications collect and report on traffic traversing the network. In addition, other flow keys, such as source and destination autonomous system number, TCP flags and next-hop routing addresses, let network managers gain an even deeper understanding of how applications and users are behaving on the network.
The IPFIX standard also focuses on the extensibility of flow export as networks evolve. Network managers will be able to export whichever fields seem appropriate from an IPFIX-compliant device when troubleshooting network issues or engineering their networks for future growth or expansion.
For more on IP Flow Information Export, please click here.




