11-Telemetry Configuration Guide

HomeSupportSwitchesS9820 SeriesConfigure & DeployConfiguration GuidesH3C S9820-8C Switch Configuration Guides-Release 6715-6W10011-Telemetry Configuration Guide
04-Flow group configuration
Title Size Download
04-Flow group configuration 62.89 KB

Configuring flow groups

About flow groups

A flow group allows you to identify flows based on flow generation rules. The device extracts traffic characteristics (for example, 5-tuples in the packet header) and generates flow entries according to the header fields specified in a flow generation rule.

A flow group can use an ACL to limit the traffic for which flow entries are generated. A flow entry is aged out if no matching packets are received before the aging timer expires.

Figure 1 Flow entry generation

 

The flow entries generated by a flow group can be used by other features. A flow group can be in one of the following modes:

·     Simple MOD mode—Used by MOD. This mode has a higher burden on the CPU but saves hardware resources.

·     Elephant/mice flow mode—Used by the elephant and mice flows distinguishing feature (see ACL and QoS Configuration Guide).

Restrictions and guidelines: Flow group configuration

A flow group can reference only one IPv4 ACL. An ACL referenced by a flow group supports only the 5-tuple (source IP address, destination IP address, source port number, destination port number, and protocol) and DSCP priority match items.

Because a flow can belong to only one flow group, make sure the same flow is not assigned to more than one flow group when specifying ACLs. For information about ACLs, see ACL and QoS Configuration Guide.

To delete an applied flow group, first remove the application and then delete the flow group.

Only one flow group can be applied.

Procedure

About this task

The device provides the following system-defined flow group for you to use:

·     IP flow group (system-defined-ip)—Generates flow entries based on the IP 5-tuple.

Restrictions and guidelines

A system-defined flow group does not reference an ACL and cannot be modified.

A system-defined flow group can be applied only in elephant/mice flow mode.

Procedure

1.     Enter system view.

system-view

2.     Create a flow group and enter its view.

telemetry flow-group group-id [ name group-name ] mode simple-mod

3.     Specify an ACL.

if-match acl { acl-number | name acl-name }

By default, no ACL is specified.

4.     Configure the header fields used for generating flow entries.

template { destination-ip | destination-port | protocol | source-ip | source-port } *

By default, no header fields are used for generating flow entries.

5.     Return to system view.

quit

6.     (Optional.) Set the aging time for flow entries.

telemetry flow-group aging-time [ msec ] aging-time

The default setting is 10 milliseconds for the elephant/mice flow mode and 15 minutes for other modes.

7.     (Optional.) Set the maximum rate of packets sent to the CPU to limit the flow entry generation rate.

telemetry flow-group rate-limit pps

By default, the rate of packets sent to the CPU is not limited.

8.     (Optional.) Set the maximum number of flow entries generated.

telemetry flow-group max-entry max-entries

By default, the number of flow entries is not limited.

9.     Apply the flow group.

telemetry apply flow-group { group-id | name group-name | system-defined ip mode mice-elephant-flow }

By default, no flow group is applied.

Display and maintenance commands for flow group

Execute display commands in any view.

 

Task

Command

Display the configuration and application status of flow groups.

display telemetry flow-group [ group-id | name group-name | system-defined ip ] [ slot slot-number ]

Display flow entries.

display telemetry flow-group flow-table [ [ group-id | name group-name ] | mod | mice-elephant-flow ] [ destination-ip { dst-ipv4 | dst-ipv6 } | destination-port dst-port | protocol protocol | source-ip { src-ipv4 | src-ipv6 } | source-port src-port ] * { slot slot-number }

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网