{"id":11889,"date":"2019-01-30T11:08:21","date_gmt":"2019-01-30T13:08:21","guid":{"rendered":"https:\/\/made4it.com.br\/configuracion-de-netflow-en-enrutadores-de-juniper\/"},"modified":"2023-03-09T14:57:04","modified_gmt":"2023-03-09T17:57:04","slug":"configuracion-de-netflow-en-enrutadores-de-juniper","status":"publish","type":"post","link":"https:\/\/made4it.com.br\/es\/configuracion-de-netflow-en-enrutadores-de-juniper\/","title":{"rendered":"Configuraci\u00f3n de Netflow en routers Juniper"},"content":{"rendered":"\n<p>Hola<\/p>\n\n<p>Hoy vamos a desglosar c\u00f3mo configurar su router Juniper para exportar Netflow (jFlow). Al final del art\u00edculo est\u00e1 la configuraci\u00f3n utilizando IPFIX (Netflow v10).<\/p>\n\n<p>Esta es la topolog\u00eda de la red y la informaci\u00f3n del servidor Netflow<\/p>\n\n<figure class=\"wp-block-image\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"362\" src=\"https:\/\/www.made4it.com.br\/wp-content\/uploads\/2019\/01\/netflow-1024x362.png\" alt=\"\" class=\"wp-image-708\" srcset=\"https:\/\/made4it.com.br\/wp-content\/uploads\/2019\/01\/netflow-1024x362.png 1024w, https:\/\/made4it.com.br\/wp-content\/uploads\/2019\/01\/netflow-300x106.png 300w, https:\/\/made4it.com.br\/wp-content\/uploads\/2019\/01\/netflow-768x272.png 768w, https:\/\/made4it.com.br\/wp-content\/uploads\/2019\/01\/netflow.png 1066w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Topolog\u00eda e informaci\u00f3n de Netflow<\/figcaption><\/figure>\n\n<p>Estos son los pasos necesarios para configurar un router Juniper para exportar Netflow v5<\/p>\n\n<ol class=\"wp-block-list\"><li>Configurar el servidor NTP<\/li><li>Configuraci\u00f3n de opciones de reenv\u00edo con frecuencia de muestreo<\/li><li>Configure el Host que recibir\u00e1 los Flujos procedentes del Router<\/li><li>Configurar la interfaz para activar Netflow en la interfaz<\/li><\/ol>\n\n<p>Vamos con la configuraci\u00f3n paso a paso<\/p>\n\n<ol class=\"wp-block-list\"><li>Configurar el servidor NTP<\/li><\/ol>\n\n<p>Es importante configurar un Servidor NTP ya que los datos de Flows utilizan timestamp de acuerdo a la hora del router, si el router est\u00e1 con un servidor horario diferente los datos no estar\u00e1n de acuerdo a la hora, generando un desajuste de informaci\u00f3n.<br\/><br\/>Es importante que configures al menos 2 servidores NTP y tambi\u00e9n la zona horaria de tu router.<\/p>\n\n<pre class=\"wp-block-preformatted\">## Utilizaci\u00f3n de los servidores del a.ntp.br y b.ntp.br<br\/>set system ntp server 200.160.0.8<br\/>set system ntp server 200.189.40.8<br\/><br\/>## Configurar la zona horaria<br\/>set system time-zone America\/Sao_Paulo<br\/><br\/>## Forma predeterminada de ver la configuraci\u00f3n de Juniper<br\/>guilherme@vMX-BGP&gt; show configuration system<br\/>sistema {  <br\/>  zona horaria Am\u00e9rica\/Sao_Paulo;<br\/><br\/><br\/>  ntp {<br\/>  servidor 200.160.0.8;<br\/>  servidor 200.189.40.8;<br\/>  }<br\/>}<\/pre>\n\n<p>2. Configuraci\u00f3n de opciones de reenv\u00edo con frecuencia de muestreo<\/p>\n\n<p>La tasa de muestreo para evitar sobrecargar la CPU de su motor de enrutamiento, crea una muestra del tr\u00e1fico y la exporta, para que el sistema Netflow pueda recibir los datos y aplicar un factor de multiplicaci\u00f3n para convertir los datos en n\u00fameros reales.<br\/><br\/>Para configurar utilice los comandos. El valor ideal de la tasa es en funci\u00f3n de la cantidad de tr\u00e1fico que utiliza, un consejo es importante es utilizar valores superiores a 200 y el an\u00e1lisis de la CPU de su router.<\/p>\n\n<pre class=\"wp-block-preformatted\">## Aplicando el valor de la Tasa a 500<br\/>set forwarding-options sampling input rate 500<br\/><br\/>## Juniper display form without display-set<br\/>opciones de reenv\u00edo {<br\/>  muestreo {<br\/>  entrada {<br\/>  tipo 500;<br\/>  }<br\/><\/pre>\n\n<p>3. Configure el Host que recibir\u00e1 los Flujos procedentes del Router<\/p>\n\n<p>Para configurar su router para exportar Netflow es necesario informar en qu\u00e9 direcci\u00f3n IP el servidor recibir\u00e1 los flujos y en qu\u00e9 puerto UDP recibir\u00e1 ese tr\u00e1fico.<br\/><br\/>Para ello, utilice los comandos:<\/p>\n\n<pre class=\"wp-block-preformatted\">## Exportando a IP 192.168.210.47 en puerto 2055 y usando netflow versi\u00f3n 5<br\/>set forwarding-options sampling family inet output flow-server 192.168.210.47 port 2055<br\/>  set forwarding-options sampling family inet output flow-server 192.168.210.47 version 5<br\/><br\/>## Mostrar visualizaci\u00f3n sin configurar<br\/>guilherme@vMX-BGP&gt; show configuration forwarding-options<br\/>  muestreo {<br\/>  familia inet {<br\/>  salida {<br\/>  flow-server 192.168.210.47 {<br\/>  puerto 2055;<br\/>  versi\u00f3n 5;<br\/>  }<br\/>  }<br\/>  }<br\/>  }<br\/><\/pre>\n\n<p>4. Configurar la interfaz para activar Netflow en la interfaz<\/p>\n\n<p>Despu\u00e9s de configurar la frecuencia de muestreo y el servidor de flujo, es necesario activar Netflow en la interfaz donde se generar\u00e1n los datos. Recordando que es necesario configurar el comando dentro de cada unidad.<br\/><br\/>Para ello, configure las interfaces dentro de cada unidad con el siguiente comando:<\/p>\n\n<pre class=\"wp-block-preformatted\">### Aplicar el comando de entrada de muestreo<br\/>  set interfaces ge-0\/0\/1 unit 0 family inet sampling input<br\/><\/pre>\n\n<p>La configuraci\u00f3n completa es la siguiente:<\/p>\n\n<pre class=\"wp-block-preformatted\">guilherme@vMX-BGP&gt; show configuration | display set<br\/>  set system time-zone America\/Sao_Paulo<br\/>  set system ntp server 200.160.0.8<br\/>  set system ntp server 200.189.40.8<br\/> <br\/>set interfaces ge-0\/0\/0 description \"Hablar con Netflow<br\/>  set interfaces ge-0\/0\/0 unit 0 family inet address 192.168.210.49\/24<br\/> <br\/>set interfaces ge-0\/0\/1 description \"INTERFAZ WAN - TR\u00c1NSITO IP<br\/>  set interfaces ge-0\/0\/1 unit 0 family inet sampling input<br\/>  set interfaces ge-0\/0\/1 unit 0 family inet address 200.200.200.1\/30<br\/> <br\/>set forwarding-options sampling input rate 500<br\/>  set forwarding-options sampling family inet output flow-server 192.168.210.47 port 2055<br\/>  set forwarding-options sampling family inet output flow-server 192.168.210.47 version 5<br\/><br\/><br\/>## Juniper show form<br\/>guilherme@vMX-BGP&gt; mostrar configuraci\u00f3n<br\/>  \u00daltima confirmaci\u00f3n: 2019-01-30 13:30:01 BRST por guilherme<br\/>  versi\u00f3n 17.1R2.7;<br\/>  sistema {<br\/>  host-name vMX-BGP;<br\/>  zona horaria Am\u00e9rica\/Sao_Paulo;<br\/>  ntp {<br\/>  servidor 200.160.0.8;<br\/>  servidor 200.189.40.8;<br\/>  }<br\/>  }<br\/>  interfaces {<br\/>  ge-0\/0\/0 {<br\/>  descripci\u00f3n \"Hablar con Netflow\";<br\/>  unidad 0 {<br\/>  familia inet {<br\/>  direcci\u00f3n 192.168.210.49\/24;<br\/>  }<br\/>  }<br\/>  }<br\/>  ge-0\/0\/1 {<br\/>  descripci\u00f3n \"INTERFAZ WAN - TR\u00c1NSITO IP\";<br\/>  unidad 0 {<br\/>  familia inet {<br\/>  muestreo {<br\/>  entrada;<br\/>  }<br\/>  direcci\u00f3n 200.200.200.1\/30;<br\/>  }<br\/>  }<br\/>  }<br\/>  }<br\/>  opciones de reenv\u00edo {<br\/>  muestreo {<br\/>  entrada {<br\/>  tipo 500;<br\/>  }<br\/>  familia inet {<br\/>  salida {<br\/>  flow-server 192.168.210.47 {<br\/>  puerto 2055;<br\/>  versi\u00f3n 5;<br\/>  }<br\/>  }<br\/>  }<br\/>  }<br\/>  }<br\/><\/pre>\n\n<p>Para hacerlo a\u00fan m\u00e1s f\u00e1cil tenemos el v\u00eddeo que demuestra la configuraci\u00f3n de cada comando aplicado en este tutorial<\/p>\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"Configura\u00e7\u00e3o de Netflow - Jflow em Roteadores Juniper\" width=\"800\" height=\"450\" src=\"https:\/\/www.youtube.com\/embed\/VIWQZISAbqM?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" allowfullscreen><\/iframe>\n<\/div><figcaption>Configuraci\u00f3n de Netflow en Juniper<\/figcaption><\/figure>\n\n<p>Como extra publicaremos la configuraci\u00f3n IPFIX para algunos tipos de routers<\/p>\n\n<h4 class=\"wp-block-heading\">Juniper MX204<\/h4>\n\n<p>Configuraci\u00f3n para routers como el MX204, puede utilizar IPFIX (Netflow v10). Para configurar el MX204, utilice los comandos cambiando las IP del servidor de flujo y de la direcci\u00f3n de origen.<\/p>\n\n<pre class=\"wp-block-preformatted\">  set services flow-monitoring version-ipfix template MADE4FLOW flow-active-timeout 60<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW flow-inactive-timeout 15<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW template-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW option-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW ipv4-template<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 flow-active-timeout 60<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 flow-inactive-timeout 15<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 template-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 option-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 ipv6-template<br\/>  set chassis fpc 0 sampling-instance MADE4FLOW<br\/>  set chassis fpc 0 inline-services flow-table-size ipv4-flow-table-size 10<br\/>  set chassis fpc 0 inline-services flow-table-size ipv6-flow-table-size 5<br\/>  set forwarding-options sampling instance MADE4FLOW input rate 1000<br\/>  set forwarding-options sampling instance MADE4FLOW input run-length 0<br\/>  set forwarding-options sampling instance MADE4FLOW input max-packets-per-second 10000<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-inactive-timeout 15<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-active-timeout 60<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-server 10.1.1.1 port 2055<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-server 10.1.1.1 autonomous-system-type origin<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-server 10.1.1.1 version-ipfix template MADE4FLOW<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output inline-jflow source-address 10.1.1.2<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-inactive-timeout 15<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-active-timeout 60<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-server 10.1.1.1 port 2055<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-server 10.1.1.1 autonomous-system-type origin<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-server 10.1.1.1 version-ipfix template MADE4FLOW-v6<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output inline-jflow source-address 10.1.1.2<br\/><br\/>### En cada interfaz y cada unidad a\u00f1ada los comandos<br\/>  set interfaces xe-2\/0\/0 unit 151 family inet sampling input<br\/>  set interfaces xe-2\/0\/0 unit 151 family inet6 sampling input<br\/><\/pre>\n\n<hr class=\"wp-block-separator\"\/>\n\n<h4 class=\"wp-block-heading\">Juniper MX104<\/h4>\n\n<p>Para configurar el Juniper MX104 utilice los siguientes comandos. Recuerde que MX104 s\u00f3lo admite la exportaci\u00f3n a un servidor Netflow con IPFIX.<\/p>\n\n<pre class=\"wp-block-preformatted\">  set services flow-monitoring version-ipfix template MADE4FLOW flow-active-timeout 60<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW flow-inactive-timeout 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW template-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW option-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW ipv4-template<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 flow-active-timeout 60<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 flow-inactive-timeout 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 template-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 option-refresh-rate seconds 30<br\/>  set services flow-monitoring version-ipfix template MADE4FLOW-v6 ipv6-template<br\/>  set forwarding-options sampling instance MADE4FLOW input rate 500<br\/>  set forwarding-options sampling instance MADE4FLOW input run-length 0<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-inactive-timeout 15<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-active-timeout 60<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-server 10.1.1.1 port 2055<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output flow-server 10.1.1.1 version-ipfix template MADE4FLOW<br\/>  set forwarding-options sampling instance MADE4FLOW family inet output inline-jflow source-address 10.1.1.2<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-inactive-timeout 15<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-active-timeout 60<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-server 10.1.1.1 port 2055<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output flow-server 10.1.1.1 version-ipfix template MADE4FLOW-v6<br\/>  set forwarding-options sampling instance MADE4FLOW family inet6 output inline-jflow source-address 10.1.1.2<br\/>  set chassis afeb slot 0 sampling-instance MADE4FLOW<br\/><br\/>  ## En cada interfaz de su router use los comandos<br\/>  set interfaces xe-2\/0\/0 unit 151 family inet sampling input<br\/>  set interfaces xe-2\/0\/0 unit 151 family inet6 sampling input<\/pre>\n\n<p>Si tiene alg\u00fan router no mencionado aqu\u00ed, env\u00ede un correo electr\u00f3nico a: comercial@made4it.com.br y le enviaremos las configuraciones.<br\/><br\/>Espero haber ayudado y hasta la pr\u00f3xima.<br\/><br\/>Un gran abrazo.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hola Hoy vamos a desglosar c\u00f3mo configurar su router Juniper para exportar Netflow (jFlow). Al final del art\u00edculo est\u00e1 la configuraci\u00f3n utilizando IPFIX (Netflow v10). Esta es la topolog\u00eda de la red y la informaci\u00f3n del servidor Netflow Estos son los pasos necesarios para configurar un router Juniper para exportar Netflow v5 Configurar el servidor [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":8415,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"postBodyCss":"","postBodyMargin":[],"postBodyPadding":[],"postBodyBackground":{"backgroundType":"classic","gradient":""},"footnotes":""},"categories":[292,625,307,357],"tags":[700,701,702,366,703,704,705,706,707,626,627],"class_list":["post-11889","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-acerca-de-made4flow","category-flujo-de-red","category-red","category-sin-categoria","tag-como-configurar-netflow-en-juniper","tag-como-configurar-netflow-en-juniper-mx","tag-como-configurar-netflow-en-mx204","tag-flujo-de-red","tag-ipfix-es","tag-ipfix-mx204-es","tag-jflow-es","tag-jflow-juniper-es","tag-netflow-juniper-es","tag-netflow-v5-es","tag-netflow-v9-es"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/posts\/11889","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/comments?post=11889"}],"version-history":[{"count":0,"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/posts\/11889\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/media\/8415"}],"wp:attachment":[{"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/media?parent=11889"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/categories?post=11889"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/made4it.com.br\/es\/wp-json\/wp\/v2\/tags?post=11889"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}