Huawei NE NetStream IPFIX configuration explained line by line

An edge Huawei NE NetStream configuration in IPFIX, IPv4 and IPv6, announcing its rate to the collector, explained block by block, plus the migration from v9.

What this configuration is

This is the NetStream configuration of an edge Huawei NE (VRP8) exporting IPFIX to EdgeWarden, for IPv4 and IPv6. It starts from the NetFlow v9 configuration explained in Huawei NE NetStream v9 configuration explained line by line and changes only what IPFIX calls for. The generic step-by-step guide is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden.

The addresses are documentation addresses: collector 192.0.2.10, export source 198.51.100.1. Replace them with your own before pasting.

LineIn v9In IPFIXWhy
export version9ipfixThis is the format change, for IPv4 and IPv6
template sequence-number fixedYesNoIn IPFIX, the sequence counts only data records (RFC 7011)
template option samplerMissingYesThe NE announces its rate and EdgeWarden shows detectado (detected)
template option application-labelYesNoEdgeWarden doesn't use that options template

Why IPFIX

IPFIX is the IETF standard (RFC 7011) derived from NetFlow v9. On this NE, both carry the same fields: IPv6, origin ASN, BGP next hop, TTL, TCP flags, and the 32-bit ifIndex. EdgeWarden reads both the same way, on the same port 2055. Prefer IPFIX if the other routers at your edge already export IPFIX or if another tool receiving the flows requires the standard. To compare the formats, see NetFlow v5, v9, IPFIX, or sFlow: which one to export.

Board

VRP8: distributed mode on slot 10
slot 10
 ip netstream sampler to slot self
 ipv6 netstream sampler to slot self
 quit

Same as v9: the board in slot 10 builds and exports the IPv4 and IPv6 flows. Repeat on every slot with a sampled interface, including the slots of all members of an Eth-Trunk.

IPv4 export

VRP8: IPv4 NetStream in IPFIX
ip netstream as-mode 32
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream tcp-flag enable
ip netstream export version ipfix origin-as bgp-nexthop ttl
ip netstream export index-switch 32
ip netstream export template timeout-rate 1
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outbound
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055
ip netstream export template option timeout-rate 1
ip netstream export template option sampler
  • export version ipfix origin-as bgp-nexthop ttl: the only line that changes the format. The extra fields are the same as in v9: the AS that originated the prefix, the BGP next hop, and the TTL (without it, the TTL variation detector has no data).
  • export template option sampler: the new line. The NE sends, in an options template, the sampling rate of each interface and direction. EdgeWarden reads that rate and shows detectado in the Amostragem (sampling) column; a rate changed on the router takes effect without touching the device record.
  • template timeout-rate 1 and template option timeout-rate 1: resend the data and options templates every minute. After EdgeWarden restarts, flows can only be decoded once the template arrives again.
  • timeout active 1 (in minutes, equal to 60 s) and timeout inactive 15 (in seconds): a long flow is exported every minute; a flow idle for 15 s is closed and exported.
  • as-mode 32, tcp-flag enable, and export index-switch 32: 4-byte ASNs, TCP flags for SYN flood detection, and the 32-bit ifIndex, the same one SNMP uses.
  • sampler fix-packets 500: 1 in every 500 packets, in both directions.
  • export source and export host: the source you register in EdgeWarden and the collector on port 2055.

IPv6 export

VRP8: IPv6 NetStream in IPFIX
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version ipfix origin-as bgp-nexthop ttl
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1
ipv6 netstream export template option sampler

The mirror of IPv4. The IPv6 export version and option sampler are configured separately: without them, IPv6 stays in v9 or without an announced rate. Source and collector stay IPv4, with the same source as IPv4, so the NE takes one license slot and a single device record.

Edge interface

VRP8: transit subinterface
interface Eth-Trunk2.1004
 vlan-type dot1q 1004
 description Transito-1
 ipv6 enable
 ip address 203.0.113.250 255.255.255.252
 ipv6 address 2001:DB8:6200::1A96/126
 statistic enable
 ip netstream inbound
 ip netstream outbound
 ipv6 netstream inbound
 ipv6 netstream outbound
 quit

The interface doesn't change with the format. NetStream sits on the subinterface where transit arrives; statistic enable keeps the subinterface counters that EdgeWarden compares with the flows; the description is the name shown on the Interfaces screen.

Enable inbound and outbound only on edge interfaces (transit, IXP, CDN). If customer interfaces also have NetStream in both directions, the same packet is sampled twice and traffic shows up doubled in the totals.

Migrating an NE that already exports v9

To move the v9 configuration to IPFIX, only the global part changes; boards and interfaces stay as they are.

VRP8: from v9 to IPFIX
system-view
ip netstream export version ipfix origin-as bgp-nexthop ttl
ipv6 netstream export version ipfix origin-as bgp-nexthop ttl
undo ip netstream export template sequence-number fixed
undo ipv6 netstream export template sequence-number fixed
undo ip netstream export template option application-label
ip netstream export template option sampler
ipv6 netstream export template option sampler
commit
display current-configuration | include netstream export version
 ip netstream export version ipfix origin-as bgp-nexthop ttl
 ipv6 netstream export version ipfix origin-as bgp-nexthop ttl
  • The display at the end confirms that no export version 9 line is left.
  • Nothing changes in EdgeWarden: same source IP, same port, same device record.
  • Right after commit, there may be up to 1 minute without decoded flows, until the first IPFIX template arrives.

Device record in EdgeWarden

  1. Under Configurações → Rede → Dispositivos (Settings → Network → Devices), add the NE with Endereço IP (IP address) 198.51.100.1 (the export source), Taxa de Amostragem de Flow (flow sampling rate) 500, and the SNMP settings.
  2. Within 1 minute of flows starting to arrive, the Amostragem column shows detectado with 1:500. If you see cadastro: 1:N (ignorado), update the record to the announced value.
  3. Follow the guide's verification on the router and in EdgeWarden to validate the export and the rate.

Anyone who can reach 2055/UDP can inject forged flows and poison detection. Restrict the port to your routers' IPs.

Full configuration

To paste in one go on an NE without NetStream. Replace the addresses, slot, and interface with your own.

VRP8: full IPFIX configuration
system-view
slot 10
 ip netstream sampler to slot self
 ipv6 netstream sampler to slot self
 quit
ip netstream as-mode 32
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream tcp-flag enable
ip netstream export version ipfix origin-as bgp-nexthop ttl
ip netstream export index-switch 32
ip netstream export template timeout-rate 1
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outbound
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055
ip netstream export template option timeout-rate 1
ip netstream export template option sampler
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version ipfix origin-as bgp-nexthop ttl
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1
ipv6 netstream export template option sampler
interface Eth-Trunk2.1004
 vlan-type dot1q 1004
 description Transito-1
 ipv6 enable
 ip address 203.0.113.250 255.255.255.252
 ipv6 address 2001:DB8:6200::1A96/126
 statistic enable
 ip netstream inbound
 ip netstream outbound
 ipv6 netstream inbound
 ipv6 netstream outbound
 quit
commit

Next steps

The line-by-line explanation of each command is in Huawei NE NetStream v9 configuration explained line by line. The full step-by-step guide, with verification on the NE and common pitfalls, is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden. If flows don't show up, work through the checklist No flows showing up in EdgeWarden?.

Related articles

All articles

Want to see these flows in EdgeWarden?

Create your account in the Customer area and generate the demo license: 7 days with every Enterprise feature, on your own server. Then follow the installation guide to bring up the collector.