What this configuration is
This is the NetStream configuration of an edge Huawei NE (VRP8) exporting NetFlow v9 to EdgeWarden, for IPv4 and IPv6. The generic step-by-step guide is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden. Here the focus is on what each line does. The same configuration in IPFIX is in Huawei NE NetStream IPFIX configuration explained line by line.
The addresses were replaced with documentation addresses: collector 192.0.2.10, export source 198.51.100.1. Replace them with your own before pasting.
| Item | Guide | This configuration | Effect |
|---|---|---|---|
| Format | IPFIX | NetFlow v9 | EdgeWarden receives both on the same port 2055 |
| Active timeout | 60 s | 1 minute | Same interval, written in minutes |
| Sampling | 1:1000 | 1:500 | More accuracy, roughly twice the flows |
Announced rate (option sampler) | Yes | No | The rate must be entered by hand in EdgeWarden |
| Extras | None | sequence-number fixed and application-label | Change nothing for EdgeWarden |
Board
slot 10
ip netstream sampler to slot self
ipv6 netstream sampler to slot self
quitslot 10: enters the view of the board in slot 10, where the sampled interfaces are.ip netstream sampler to slot self: distributed mode. The board itself builds and exports the IPv4 flows. Without this line the board generates no flows.ipv6 netstream sampler to slot self: the same for IPv6. Both can coexist as long as they use the same mode, as here.- Repeat on every slot with a sampled interface. For an Eth-Trunk with members on more than one board, configure every member's slot.
IPv4 export
Format and fields
ip netstream as-mode 32
ip netstream tcp-flag enable
ip netstream export version 9 origin-as bgp-nexthop ttl
ip netstream export index-switch 32as-mode 32: 4-byte ASN fields. Without it, ASNs above 65535 don't fit the 16-bit field and don't reach EdgeWarden correctly.tcp-flag enable: exports TCP flags, which feed SYN flood detection. Huawei warns that it significantly increases the number of flows.export version 9 origin-as bgp-nexthop ttl: NetFlow v9 format, with the AS that originated the prefix (origin-as, not the neighbor's), the BGP next hop, and the TTL. Withoutttl, EdgeWarden's TTL variation detector has no data.export index-switch 32: exports the 32-bit system ifIndex, the same one SNMP uses. With the 16-bit default, the index doesn't match SNMP and interfaces show up asif:N.
Timeouts and templates
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream export template timeout-rate 1
ip netstream export template option timeout-rate 1
ip netstream export template sequence-number fixed
ip netstream export template option application-labeltimeout active 1: a long flow, such as an attack, is exported every 1 minute. Withoutinterval-second, the value is in minutes; the default Huawei cites is 30 minutes, far too long to detect DDoS. On releases that accept it,timeout active interval-second 60is equivalent.timeout inactive 15: a flow with no packets for 15 s is closed and exported.template timeout-rate 1: resends the data template every minute. After EdgeWarden restarts, v9 flows can only be decoded once the template arrives again; at 1 minute, the wait is short.template option timeout-rate 1: the same for the options template.template sequence-number fixed: changes how template packets count toward the v9 header sequence number. It is meant for collectors that measure loss from the sequence. EdgeWarden doesn't use the sequence number; the line is harmless.template option application-label: sends Huawei's application label table in an options template. From options templates, EdgeWarden only reads the sampling rate and ignores the rest; the line changes nothing for it.
Sampling
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outboundfix-packets 500: samples 1 in every 500 packets, at a fixed interval. This 500 goes into the device record in EdgeWarden.- The same rate in both directions is right: with different rates, one direction would match SNMP and the other wouldn't.
- This is the global rate. A rate configured inside an interface takes precedence over it.
Source and collector
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055export source 198.51.100.1: the source IP of the export packets. This is the IP you register in EdgeWarden, and it counts as one exporter on the license. Use the loopback, with a route to the collector over the data network: the management port doesn't forward this traffic.export host 192.0.2.10 2055: the collector. If it is only reachable through a VRF, addvpn-instance <name>at the end.
IPv6 export
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version 9 origin-as bgp-nexthop ttl
ipv6 netstream export template sequence-number fixed
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1IPv6 has its own commands, and each line above mirrors the IPv4 line of the same name. Three points matter:
ipv6 netstream export index-switch 32is configured separately. Without it, IPv6 flows go out with the 16-bit index.- Source and collector stay IPv4. With the same source in both families, the NE takes one license slot and a single device record in EdgeWarden.
- The rate is the same as IPv4 (500): EdgeWarden applies one rate per exporter.
Edge interface
interface Eth-Trunk2.1004
vlan-type dot1q 1004
description Transito-1
ipv6 enable
ip address 203.0.113.250 255.255.255.252
ipv6 address 2001:DB8:6200::1A96/126
statistic enable
ip netstream inbound
ip netstream outbound
ipv6 netstream inbound
ipv6 netstream outbound
quitvlan-type dot1q 1004: subinterface on VLAN 1004 of Eth-Trunk2. NetStream must be on the subinterface: enabled only on the main interface, it doesn't collect subinterface traffic.description Transito-1: the name EdgeWarden reads over SNMP and shows on the Interfaces screen.ipv6 enable: turns IPv6 on for the subinterface, required before the IPv6 address andipv6 netstream.statistic enable: turns on traffic statistics for the subinterface. Without it, the subinterface counters may stay at zero, and the Fluxo × SNMP nas interfaces (flow vs. SNMP on interfaces) panel has no SNMP side to compare.ip netstream inboundandoutbound: sample the IPv4 traffic entering and leaving the subinterface. Attacks against your network arrive inbound; outbound carries traffic going to the internet, including attacks leaving customers.ipv6 netstream inboundandoutbound: the same for IPv6. Without these lines, IPv6 goes unseen.
Enable inbound and outbound only on edge interfaces (transit, IXP, CDN). If customer interfaces also have NetStream in both directions, the same packet is sampled twice, on the ingress of one interface and the egress of the other, and traffic shows up doubled in the totals.
What is missing: announcing the rate
This configuration has no option sampler, so the NE doesn't tell the collector its sampling rate. EdgeWarden uses the rate from the device record, and the Amostragem (sampling) column shows manual. It works, as long as the record says 500. To have the NE announce the rate and EdgeWarden show detectado (detected), add:
ip netstream export template option sampler
ipv6 netstream export template option sampler
commitWith the announcement, a rate changed on the router takes effect in EdgeWarden without touching the device record.
Device record in EdgeWarden
- Under Configurações → Rede → Dispositivos (Settings → Network → Devices), add the NE with Endereço IP (IP address)
198.51.100.1(theexport source), Taxa de Amostragem de Flow (flow sampling rate)500, and the SNMP settings. - Without
option sampler, the Amostragem column shows manual; with it, detectado with 1:500 once the options template arrives (within 1 minute, givenoption timeout-rate 1). - Follow the guide's verification on the router and in EdgeWarden to validate the export and the rate.
Anyone who can reach 2055/UDP can inject forged flows and poison detection. Restrict the port to your routers' IPs.
Full configuration
To paste in one go. Replace the addresses, slot, and interface with your own, paste in system-view, and run commit at the end. The two option sampler lines are already included.
system-view
slot 10
ip netstream sampler to slot self
ipv6 netstream sampler to slot self
quit
ip netstream as-mode 32
ip netstream timeout active 1
ip netstream timeout inactive 15
ip netstream tcp-flag enable
ip netstream export version 9 origin-as bgp-nexthop ttl
ip netstream export template sequence-number fixed
ip netstream export index-switch 32
ip netstream export template timeout-rate 1
ip netstream sampler fix-packets 500 inbound
ip netstream sampler fix-packets 500 outbound
ip netstream export source 198.51.100.1
ip netstream export host 192.0.2.10 2055
ip netstream export template option timeout-rate 1
ip netstream export template option application-label
ip netstream export template option sampler
ipv6 netstream as-mode 32
ipv6 netstream timeout active 1
ipv6 netstream timeout inactive 15
ipv6 netstream tcp-flag enable
ipv6 netstream export version 9 origin-as bgp-nexthop ttl
ipv6 netstream export template sequence-number fixed
ipv6 netstream export index-switch 32
ipv6 netstream export template timeout-rate 1
ipv6 netstream sampler fix-packets 500 inbound
ipv6 netstream sampler fix-packets 500 outbound
ipv6 netstream export source 198.51.100.1
ipv6 netstream export host 192.0.2.10 2055
ipv6 netstream export template option timeout-rate 1
ipv6 netstream export template option sampler
interface Eth-Trunk2.1004
vlan-type dot1q 1004
description Transito-1
ipv6 enable
ip address 203.0.113.250 255.255.255.252
ipv6 address 2001:DB8:6200::1A96/126
statistic enable
ip netstream inbound
ip netstream outbound
ipv6 netstream inbound
ipv6 netstream outbound
quit
commitNext steps
To switch to IPFIX, see Huawei NE NetStream IPFIX configuration explained line by line. The full step-by-step guide, with verification on the NE and common pitfalls, is How to export NetStream as IPFIX or NetFlow v9 from a Huawei NE40E/NE8000 to EdgeWarden. If flows don't show up, work through the checklist No flows showing up in EdgeWarden?.