Cisco C3KX-SM-10G= Datenblatt Seite 6

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 14
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 5
© 2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 6 of 14
Figure 1. Service Module Functional Block Diagram and Interaction with Switch
From what has been discussed so far, it is clear that the service module ASIC monitors packets traversing the
uplink ports. The analyzed traffic includes CPU traffic directed to or coming from uplinks. Additionally, it includes
downstream traffic received on the uplink ports that would be dropped by the switch, for example, because of an
access-control list (ACL) deny statement.
The service module ASIC does not analyze the following traffic categories:
Locally switched traffic incoming and exiting downlink ports
Traffic originated or terminated into the switch CPU that is going to or received from downlink ports
Upstream traffic directed to uplink ports that is dropped by the switch, for example, because of an ACL deny
statement
Ethernet management port (FastEthernet0) ingress and egress traffic
As the Flexible NetFlow engine is outside the switch ASIC logic, both the destination interface information for
downstream traffic and the source interface for upstream traffic are not available. The service module CPU hence
plays an important role in handling Layer 2 and Layer 3 cache received by the switch CPU every 20 seconds and
computing input/output interface fields for each flow. The interface value is based on destination/source MAC
address for switched traffic and IP destination/source address for routed traffic. In this perspective it is mandatory
that these fields be configured in the flow record.
Flexible NetFlow Fields in the Access Layer
Flexible NetFlow implemented by the service module at FCS time contains the standard Layer 2, Layer 3, and
Layer 4 fields and input/output physical interface information.
Of these, the following are particularly relevant for the access layer, as they carry information useful to identify the
end-user device and its traffic: MAC address, class of service (CoS), virtual LAN (VLAN), and input/output
interface.
Seitenansicht 5
1 2 3 4 5 6 7 8 9 10 11 12 13 14

Kommentare zu diesen Handbüchern

Keine Kommentare