What this configuration is
This is the NetStream configuration of an edge Huawei NE (VRP8) exporting IPFIX to EdgeWarden, for IPv4 and IPv6. It starts from the NetFlow v9 configuration explained in Huawei NE NetStream v9 configuration explained line by line and changes only what IPFIX calls for. The generic step-by-step guide is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden.
The addresses are documentation addresses: collector 192.0.2.10, export source 198.51.100.1. Replace them with your own before pasting.
| Line | In v9 | In IPFIX | Why |
|---|---|---|---|
export version | 9 | ipfix | This is the format change, for IPv4 and IPv6 |
template sequence-number fixed | Yes | No | In IPFIX, the sequence counts only data records (RFC 7011) |
template option sampler | Missing | Yes | The NE announces its rate and EdgeWarden shows detectado (detected) |
template option application-label | Yes | No | EdgeWarden doesn't use that options template |
Why IPFIX
IPFIX is the IETF standard (RFC 7011) derived from NetFlow v9. On this NE, both carry the same fields: IPv6, origin ASN, BGP next hop, TTL, TCP flags, and the 32-bit ifIndex. EdgeWarden reads both the same way, on the same port 2055. Prefer IPFIX if the other routers at your edge already export IPFIX or if another tool receiving the flows requires the standard. To compare the formats, see NetFlow v5, v9, IPFIX, or sFlow: which one to export.
Board
slot 10
ip netstream sampler to slot self
ipv6 netstream sampler to slot self
quitSame as v9: the board in slot 10 builds and exports the IPv4 and IPv6 flows. Repeat on every slot with a sampled interface, including the slots of all members of an Eth-Trunk.
IPv4 export
ip netstream as-mode 32
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream tcp-flag enable
ip netstream export version ipfix origin-as bgp-nexthop ttl
ip netstream export index-switch 32
ip netstream export template timeout-rate 1
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outbound
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055
ip netstream export template option timeout-rate 1
ip netstream export template option samplerexport version ipfix origin-as bgp-nexthop ttl: the only line that changes the format. The extra fields are the same as in v9: the AS that originated the prefix, the BGP next hop, and the TTL (without it, the TTL variation detector has no data).export template option sampler: the new line. The NE sends, in an options template, the sampling rate of each interface and direction. EdgeWarden reads that rate and shows detectado in the Amostragem (sampling) column; a rate changed on the router takes effect without touching the device record.template timeout-rate 1andtemplate option timeout-rate 1: resend the data and options templates every minute. After EdgeWarden restarts, flows can only be decoded once the template arrives again.timeout active 1(in minutes, equal to 60 s) andtimeout inactive 15(in seconds): a long flow is exported every minute; a flow idle for 15 s is closed and exported.as-mode 32,tcp-flag enable, andexport index-switch 32: 4-byte ASNs, TCP flags for SYN flood detection, and the 32-bit ifIndex, the same one SNMP uses.sampler fix-packets 500: 1 in every 500 packets, in both directions.export sourceandexport host: the source you register in EdgeWarden and the collector on port 2055.
IPv6 export
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version ipfix origin-as bgp-nexthop ttl
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1
ipv6 netstream export template option samplerThe mirror of IPv4. The IPv6 export version and option sampler are configured separately: without them, IPv6 stays in v9 or without an announced rate. Source and collector stay IPv4, with the same source as IPv4, so the NE takes one license slot and a single device record.
Edge interface
interface Eth-Trunk2.1004
vlan-type dot1q 1004
description Transito-1
ipv6 enable
ip address 203.0.113.250 255.255.255.252
ipv6 address 2001:DB8:6200::1A96/126
statistic enable
ip netstream inbound
ip netstream outbound
ipv6 netstream inbound
ipv6 netstream outbound
quitThe interface doesn't change with the format. NetStream sits on the subinterface where transit arrives; statistic enable keeps the subinterface counters that EdgeWarden compares with the flows; the description is the name shown on the Interfaces screen.
Enable inbound and outbound only on edge interfaces (transit, IXP, CDN). If customer interfaces also have NetStream in both directions, the same packet is sampled twice and traffic shows up doubled in the totals.
Migrating an NE that already exports v9
To move the v9 configuration to IPFIX, only the global part changes; boards and interfaces stay as they are.
system-view
ip netstream export version ipfix origin-as bgp-nexthop ttl
ipv6 netstream export version ipfix origin-as bgp-nexthop ttl
undo ip netstream export template sequence-number fixed
undo ipv6 netstream export template sequence-number fixed
undo ip netstream export template option application-label
ip netstream export template option sampler
ipv6 netstream export template option sampler
commit
display current-configuration | include netstream export version
ip netstream export version ipfix origin-as bgp-nexthop ttl
ipv6 netstream export version ipfix origin-as bgp-nexthop ttl- The
displayat the end confirms that noexport version 9line is left. - Nothing changes in EdgeWarden: same source IP, same port, same device record.
- Right after
commit, there may be up to 1 minute without decoded flows, until the first IPFIX template arrives.
Device record in EdgeWarden
- Under Configurações → Rede → Dispositivos (Settings → Network → Devices), add the NE with Endereço IP (IP address)
198.51.100.1(theexport source), Taxa de Amostragem de Flow (flow sampling rate)500, and the SNMP settings. - Within 1 minute of flows starting to arrive, the Amostragem column shows detectado with 1:500. If you see
cadastro: 1:N (ignorado), update the record to the announced value. - Follow the guide's verification on the router and in EdgeWarden to validate the export and the rate.
Anyone who can reach 2055/UDP can inject forged flows and poison detection. Restrict the port to your routers' IPs.
Full configuration
To paste in one go on an NE without NetStream. Replace the addresses, slot, and interface with your own.
system-view
slot 10
ip netstream sampler to slot self
ipv6 netstream sampler to slot self
quit
ip netstream as-mode 32
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream tcp-flag enable
ip netstream export version ipfix origin-as bgp-nexthop ttl
ip netstream export index-switch 32
ip netstream export template timeout-rate 1
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outbound
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055
ip netstream export template option timeout-rate 1
ip netstream export template option sampler
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version ipfix origin-as bgp-nexthop ttl
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1
ipv6 netstream export template option sampler
interface Eth-Trunk2.1004
vlan-type dot1q 1004
description Transito-1
ipv6 enable
ip address 203.0.113.250 255.255.255.252
ipv6 address 2001:DB8:6200::1A96/126
statistic enable
ip netstream inbound
ip netstream outbound
ipv6 netstream inbound
ipv6 netstream outbound
quit
commitNext steps
The line-by-line explanation of each command is in Huawei NE NetStream v9 configuration explained line by line. The full step-by-step guide, with verification on the NE and common pitfalls, is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden. If flows don't show up, work through the checklist No flows showing up in EdgeWarden?.