Huawei NE NetStream v9 configuration explained line by line

A real NetStream configuration in NetFlow v9 on an edge Huawei NE, IPv4 and IPv6, explained block by block: board, fields, timeouts, sampling, and interface.

What this configuration is

This is the NetStream configuration of an edge Huawei NE (VRP8) exporting NetFlow v9 to EdgeWarden, for IPv4 and IPv6. The generic step-by-step guide is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden. Here the focus is on what each line does. The same configuration in IPFIX is in Huawei NE NetStream IPFIX configuration explained line by line.

The addresses were replaced with documentation addresses: collector 192.0.2.10, export source 198.51.100.1. Replace them with your own before pasting.

ItemGuideThis configurationEffect
FormatIPFIXNetFlow v9EdgeWarden receives both on the same port 2055
Active timeout60 s1 minuteSame interval, written in minutes
Sampling1:10001:500More accuracy, roughly twice the flows
Announced rate (option sampler)YesNoThe rate must be entered by hand in EdgeWarden
ExtrasNonesequence-number fixed and application-labelChange nothing for EdgeWarden

Board

VRP8: distributed mode on slot 10
slot 10
 ip netstream sampler to slot self
 ipv6 netstream sampler to slot self
 quit
  • slot 10: enters the view of the board in slot 10, where the sampled interfaces are.
  • ip netstream sampler to slot self: distributed mode. The board itself builds and exports the IPv4 flows. Without this line the board generates no flows.
  • ipv6 netstream sampler to slot self: the same for IPv6. Both can coexist as long as they use the same mode, as here.
  • Repeat on every slot with a sampled interface. For an Eth-Trunk with members on more than one board, configure every member's slot.

IPv4 export

Format and fields

VRP8: NetFlow v9 and exported fields
ip netstream as-mode 32
ip netstream tcp-flag enable
ip netstream export version 9 origin-as bgp-nexthop ttl
ip netstream export index-switch 32
  • as-mode 32: 4-byte ASN fields. Without it, ASNs above 65535 don't fit the 16-bit field and don't reach EdgeWarden correctly.
  • tcp-flag enable: exports TCP flags, which feed SYN flood detection. Huawei warns that it significantly increases the number of flows.
  • export version 9 origin-as bgp-nexthop ttl: NetFlow v9 format, with the AS that originated the prefix (origin-as, not the neighbor's), the BGP next hop, and the TTL. Without ttl, EdgeWarden's TTL variation detector has no data.
  • export index-switch 32: exports the 32-bit system ifIndex, the same one SNMP uses. With the 16-bit default, the index doesn't match SNMP and interfaces show up as if:N.

Timeouts and templates

VRP8: timeouts and templates
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream export template timeout-rate 1
ip netstream export template option timeout-rate 1
ip netstream export template sequence-number fixed
ip netstream export template option application-label
  • timeout active 1: a long flow, such as an attack, is exported every 1 minute. Without interval-second, the value is in minutes; the default Huawei cites is 30 minutes, far too long to detect DDoS. On releases that accept it, timeout active interval-second 60 is equivalent.
  • timeout inactive 15: a flow with no packets for 15 s is closed and exported.
  • template timeout-rate 1: resends the data template every minute. After EdgeWarden restarts, v9 flows can only be decoded once the template arrives again; at 1 minute, the wait is short.
  • template option timeout-rate 1: the same for the options template.
  • template sequence-number fixed: changes how template packets count toward the v9 header sequence number. It is meant for collectors that measure loss from the sequence. EdgeWarden doesn't use the sequence number; the line is harmless.
  • template option application-label: sends Huawei's application label table in an options template. From options templates, EdgeWarden only reads the sampling rate and ignores the rest; the line changes nothing for it.

Sampling

VRP8: 1:500 sampling in both directions
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outbound
  • fix-packets 500: samples 1 in every 500 packets, at a fixed interval. This 500 goes into the device record in EdgeWarden.
  • The same rate in both directions is right: with different rates, one direction would match SNMP and the other wouldn't.
  • This is the global rate. A rate configured inside an interface takes precedence over it.

Source and collector

VRP8: source and collector
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055
  • export source 198.51.100.1: the source IP of the export packets. This is the IP you register in EdgeWarden, and it counts as one exporter on the license. Use the loopback, with a route to the collector over the data network: the management port doesn't forward this traffic.
  • export host 192.0.2.10 2055: the collector. If it is only reachable through a VRF, add vpn-instance <name> at the end.

IPv6 export

VRP8: IPv6 NetStream in v9
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version 9 origin-as bgp-nexthop ttl
ipv6 netstream export template sequence-number fixed
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1

IPv6 has its own commands, and each line above mirrors the IPv4 line of the same name. Three points matter:

  • ipv6 netstream export index-switch 32 is configured separately. Without it, IPv6 flows go out with the 16-bit index.
  • Source and collector stay IPv4. With the same source in both families, the NE takes one license slot and a single device record in EdgeWarden.
  • The rate is the same as IPv4 (500): EdgeWarden applies one rate per exporter.

Edge interface

VRP8: transit subinterface
interface Eth-Trunk2.1004
 vlan-type dot1q 1004
 description Transito-1
 ipv6 enable
 ip address 203.0.113.250 255.255.255.252
 ipv6 address 2001:DB8:6200::1A96/126
 statistic enable
 ip netstream inbound
 ip netstream outbound
 ipv6 netstream inbound
 ipv6 netstream outbound
 quit
  • vlan-type dot1q 1004: subinterface on VLAN 1004 of Eth-Trunk2. NetStream must be on the subinterface: enabled only on the main interface, it doesn't collect subinterface traffic.
  • description Transito-1: the name EdgeWarden reads over SNMP and shows on the Interfaces screen.
  • ipv6 enable: turns IPv6 on for the subinterface, required before the IPv6 address and ipv6 netstream.
  • statistic enable: turns on traffic statistics for the subinterface. Without it, the subinterface counters may stay at zero, and the Fluxo × SNMP nas interfaces (flow vs. SNMP on interfaces) panel has no SNMP side to compare.
  • ip netstream inbound and outbound: sample the IPv4 traffic entering and leaving the subinterface. Attacks against your network arrive inbound; outbound carries traffic going to the internet, including attacks leaving customers.
  • ipv6 netstream inbound and outbound: the same for IPv6. Without these lines, IPv6 goes unseen.

Enable inbound and outbound only on edge interfaces (transit, IXP, CDN). If customer interfaces also have NetStream in both directions, the same packet is sampled twice, on the ingress of one interface and the egress of the other, and traffic shows up doubled in the totals.

What is missing: announcing the rate

This configuration has no option sampler, so the NE doesn't tell the collector its sampling rate. EdgeWarden uses the rate from the device record, and the Amostragem (sampling) column shows manual. It works, as long as the record says 500. To have the NE announce the rate and EdgeWarden show detectado (detected), add:

VRP8: sampling rate announcement
ip netstream export template option sampler
ipv6 netstream export template option sampler
commit

With the announcement, a rate changed on the router takes effect in EdgeWarden without touching the device record.

Device record in EdgeWarden

  1. Under Configurações → Rede → Dispositivos (Settings → Network → Devices), add the NE with Endereço IP (IP address) 198.51.100.1 (the export source), Taxa de Amostragem de Flow (flow sampling rate) 500, and the SNMP settings.
  2. Without option sampler, the Amostragem column shows manual; with it, detectado with 1:500 once the options template arrives (within 1 minute, given option timeout-rate 1).
  3. Follow the guide's verification on the router and in EdgeWarden to validate the export and the rate.

Anyone who can reach 2055/UDP can inject forged flows and poison detection. Restrict the port to your routers' IPs.

Full configuration

To paste in one go. Replace the addresses, slot, and interface with your own, paste in system-view, and run commit at the end. The two option sampler lines are already included.

VRP8: full v9 configuration
system-view
slot 10
 ip netstream sampler to slot self
 ipv6 netstream sampler to slot self
 quit
ip netstream as-mode 32
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream tcp-flag enable
ip netstream export version 9 origin-as bgp-nexthop ttl
ip netstream export template sequence-number fixed
ip netstream export index-switch 32
ip netstream export template timeout-rate 1
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outbound
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055
ip netstream export template option timeout-rate 1
ip netstream export template option application-label
ip netstream export template option sampler
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version 9 origin-as bgp-nexthop ttl
ipv6 netstream export template sequence-number fixed
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1
ipv6 netstream export template option sampler
interface Eth-Trunk2.1004
 vlan-type dot1q 1004
 description Transito-1
 ipv6 enable
 ip address 203.0.113.250 255.255.255.252
 ipv6 address 2001:DB8:6200::1A96/126
 statistic enable
 ip netstream inbound
 ip netstream outbound
 ipv6 netstream inbound
 ipv6 netstream outbound
 quit
commit

Next steps

To switch to IPFIX, see Huawei NE NetStream IPFIX configuration explained line by line. The full step-by-step guide, with verification on the NE and common pitfalls, is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden. If flows don't show up, work through the checklist No flows showing up in EdgeWarden?.

Related articles

All articles

Want to see these flows in EdgeWarden?

Create your account in the Customer area and generate the demo license: 7 days with every Enterprise feature, on your own server. Then follow the installation guide to bring up the collector.