A flow is identified as a unidirectional stream of packets between a given source and destinationboth defined by a network-layer IP address and transport-layer source and destination port numbers. Specifically, a flow is identified as the combination of the following seven key fields:
"Source IP address
"Destination IP address
"Source port number
"Destination port number
"Layer 3 protocol type
"ToS byte
"Input logical interface (ifIndex)
These seven key fields define a unique flow. If a flow has one different field than another flow, then it is considered a new flow. A flow contains other accounting fields (such as the AS number in the NetFlow export Version 5 flow format) that depend on the version record format that you configure for export. Flows are processed in a NetFlow cache.
NetFlow Infrastructure
NetFlow management applications:
"Collect, store and perform data volume reduction on exported NetFlow data
"Provide a scalable and distributed NetFlow data collection and consolidation architecture
"Provide network monitoring, analysis, and troubleshooting tools
NetFlow Collectors
Cisco NetFlow collector provides fast, scalable, and economical data collection from multiple NetFlow Export-enabled devices. The Cisco collector consumes flow datagrams from multiple NetFlow Export-enabled devices and performs data volume reduction through selective filtering and aggregation, performs bi-directional flow analysis and flow de-duplication. The Cisco Network Analysis Module (NAM) can collect NetFlow data within Cisco devices and provides a comprehensive reporting and traffic analysis solution. Other third party traffic analysis, billing, security, and monitoring applications are available for NetFlow. For a complete list of Cisco partners go to the NetFlow partner web page.
NetFlow MIB and Top Talkers:
http://www.cisco.com/en/US/customer/products/sw/iosswrel/ps1838/products_feature_guide09186a0080259533.html