Description

Using NetFlow or CFlow to monitor traffic but need to determine how to inspect the Netflow or Cflow specific packets

Symptoms

  • CFLOW
  • Sampling packets in the output direction of an interface
  • Sniffer trace taken between SRX / J-Series device and flow server

Solution

Assuming you have captured packets with an external sniffer between the SRX/J-Series device and the flow-server, you can look at the details of the cflow packets with Wireshark by decoding the packets as cflow.  To do this, right click any of the frames for cflow.  Then, select "decode as".  You will be presented with a dialog box, with a transport tab.  Click on the transport tab, and scroll down to select cflow.  Click OK.

At this point, the frames will be decoded as cflow.  You can expand the Cisco Netflow/IPFIX field for further details of the cflow packets.