In Figure 1, departments 1 and 2 connect to the Internet through SwitchA. Network administrators want to monitor communication between departments and the Internet, and perform accounting based on the department.
To monitor communication between the departments and the Internet, the network administrator needs to:
The configuration roadmap is as follows:
# Configure IP addresses for interfaces on SwitchA.
<HUAWEI> system-view [HUAWEI] sysname SwitchA [SwitchA] vlan batch 100 200 300 400 [SwitchA] interface vlanif 100 [SwitchA-Vlanif100] ip address 10.1.1.1 24 [SwitchA-Vlanif100] quit [SwitchA] interface vlanif 200 [SwitchA-Vlanif200] ip address 10.1.2.1 24 [SwitchA-Vlanif200] quit [SwitchA] interface vlanif 300 [SwitchA-Vlanif300] ip address 10.1.3.1 24 [SwitchA-Vlanif300] quit [SwitchA] interface vlanif 400 [SwitchA-Vlanif400] ip address 10.1.4.1 24 [SwitchA-Vlanif400] quit [SwitchA] interface gigabitethernet 0/0/1 [SwitchA-GigabitEthernet0/0/1] port link-type hybrid [SwitchA-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [SwitchA-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [SwitchA-GigabitEthernet0/0/1] quit [SwitchA] interface gigabitethernet 0/0/2 [SwitchA-GigabitEthernet0/0/2] port link-type hybrid [SwitchA-GigabitEthernet0/0/2] port hybrid pvid vlan 200 [SwitchA-GigabitEthernet0/0/2] port hybrid untagged vlan 200 [SwitchA-GigabitEthernet0/0/2] quit [SwitchA] interface gigabitethernet 0/0/3 [SwitchA-GigabitEthernet0/0/3] port link-type hybrid [SwitchA-GigabitEthernet0/0/3] port hybrid pvid vlan 300 [SwitchA-GigabitEthernet0/0/3] port hybrid untagged vlan 300 [SwitchA-GigabitEthernet0/0/3] quit [SwitchA] interface gigabitethernet 0/0/4 [SwitchA-GigabitEthernet0/0/4] port link-type hybrid [SwitchA-GigabitEthernet0/0/4] port hybrid pvid vlan 400 [SwitchA-GigabitEthernet0/0/4] port hybrid untagged vlan 400 [SwitchA-GigabitEthernet0/0/4] quit
# Configure NetStream sampling on GE0/0/1, set the sampling ratio to 1200.
[SwitchA] interface gigabitethernet 0/0/1 [SwitchA-GigabitEthernet0/0/1] ip netstream sampler fix-packets 1200 inbound [SwitchA-GigabitEthernet0/0/1] ip netstream sampler fix-packets 1200 outbound [SwitchA-GigabitEthernet0/0/1] quit
# Set the inactive aging time to 100 seconds and enable FIN- and RST-based aging.
[SwitchA] ip netstream timeout inactive 100 [SwitchA] ip netstream tcp-flag enable
# Set the source IP address of the exported packets carrying original flow statistics to 10.1.2.1, the destination IP address to 10.1.2.2, and the destination port number to 6000.
[SwitchA] ip netstream export source 10.1.2.1 [SwitchA] ip netstream export host 10.1.2.2 6000
# Set the version of the exported packets to V9.
[SwitchA] ip netstream export version 9
# Enable flow statistics on GE0/0/1 for incoming and outgoing packets.
[SwitchA] interface gigabitethernet 0/0/1 [SwitchA-GigabitEthernet0/0/1] ip netstream inbound [SwitchA-GigabitEthernet0/0/1] ip netstream outbound [SwitchA-GigabitEthernet0/0/1] quit [SwitchA] quit
# After the configuration is complete, the NetStream server receives the statistics packets from the device. Run the display ip netstream statistics command on the local device to view NetStream statistics.
<SwitchA> display ip netstream statistics slot 0 ===== Netstream statistics: ===== Origin/Flexible ingress entries : 35 Origin/Flexible ingress packets : 381920 Origin/Flexible ingress octets : 125269760 Origin/Flexible egress entries : 0 Origin/Flexible egress packets : 0 Origin/Flexible egress octets : 0 Origin/Flexible total entries : 35 Handle origin entries : 35 Handle As aggre entries : 0 Handle ProtPort aggre entries : 0 Handle SrcPrefix aggre entries : 0 Handle DstPrefix aggre entries : 0 Handle Prefix aggre entries : 0 Handle AsTos aggre entries : 0 Handle ProtPortTos aggre entries : 0 Handle SrcPreTos aggre entries : 0 Handle DstPreTos aggre entries : 0 Handle PreTos aggre entries : 0
SwitchA configuration file
# sysname SwitchA # vlan batch 100 200 300 400 # ip netstream timeout inactive 100 ip netstream export version 9 ip netstream export source 10.1.2.1 ip netstream export host 10.1.2.2 6000 # ip netstream tcp-flag enable # interface Vlanif100 ip address 10.1.1.1 255.255.255.0 # interface Vlanif200 ip address 10.1.2.1 255.255.255.0 # interface Vlanif300 ip address 10.1.3.1 255.255.255.0 # interface Vlanif400 ip address 10.1.4.1 255.255.255.0 # interface GigabitEthernet0/0/1 port link-type hybrid port hybrid pvid vlan 100 port hybrid untagged vlan 100 ip netstream inbound ip netstream outbound ip netstream sampler fix-packets 1200 inbound ip netstream sampler fix-packets 1200 outbound # interface GigabitEthernet0/0/2 port link-type hybrid port hybrid pvid vlan 200 port hybrid untagged vlan 200 # interface GigabitEthernet0/0/3 port link-type hybrid port hybrid pvid vlan 300 port hybrid untagged vlan 300 # interface GigabitEthernet0/0/4 port link-type hybrid port hybrid pvid vlan 400 port hybrid untagged vlan 400 # return