Configuring sFlow

You must first enable sFlow globally and then sFlow forwarding can be enabled on an individual port or LAG port or both, and sFlow parameters can be configured.
The commands explained in this procedure apply to both sFlow version 2 and sFlow version 5. For commands specific to sFlow version 5, refer to Configuring sFlow version 5.
  1. Enter global configuration mode.
    device# configure terminal
  2. Enable sFlow.
    device(config)# sflow enable
  3. Specify an sFlow collector with an IPv4 or IPv6 destination address.
    device(config)# sflow destination 10.10.10.1
    device(config)# sflow destination ipv6 2001:DB8:0::0b:02a
    In the first example, a collector with IPv4 address 10.10.10.1 is listening for sFlow data on UDP port 6343. In the second example, a collector with IPv6 address 2001:DB8::0b:02a is listening for sFlow data on UDP port 6343.
    Note: You can specify up to four collectors. You can specify more than one collector with the same IP address if the UDP port numbers are unique. You can have up to four unique combinations of IP addresses and UDP port numbers.
  4. (Optional) Change the poll interval.
    device(config)# sflow polling-interval 30

    The poll interval value ranges from 0 through 4294967295 seconds. The default polling interval is 20 seconds. If you set the polling interval to 0, counter data sampling is disabled.

    Note: The interval value applies to all interfaces on which sFlow is enabled. If multiple ports are enabled for sFlow, the RUCKUS ICX device staggers transmission of the counter data to smooth performance.
  5. (Optional) Change the sampling rate using one of the following methods:
    • Sampling rate can be changed globally (default).
    • Sampling rate can be changed on an individual port.
    • Sampling rate can be changed on a static or dynamic LAG.
    device(config)# sflow sample 2048
    device(config)# interface 1/1/1
    device(config-if-1/1/1)# sflow sample 8192
    device(config)# lag test static id 1
    device(config-lag-test)# ports ethernet 1/1/1 to 1/1/4
    device(config-lag-test)# sflow sample 8192

    The sampling rate is a fraction in the form 1/N, meaning that, on average, one out of every N packets is sampled. The sflow sample command in global configuration mode or port mode specifies N, the denominator of the fraction. The sampling rate must be set depending on the input traffic rate.

    On RUCKUS ICX 7250, ICX 7450, ICX 7550, ICX 7650, ICX 7750, and ICX 7850 devices, the CPU-bound sFlow sample packets are rate-limited to 50 samples per second to avoid high CPU utilization.

    Note: You can change a module sampling rate only by changing the sampling rate of a port on that module.
    Note: You can configure an individual port or a static LAG or a dynamic LAG to use a different sampling rate than the global default sampling rate. This is useful in cases where ports have different bandwidths.
  6. Change the sFlow source port.
    device(config)# sflow source-port 8000
    By default, sFlow sends data to the collector using UDP source port 8888, but you can change the source UDP port to any port number ranging from 1025 through 65535.
  7. Enable sFlow forwarding.
    To enable sFlow forwarding, you must first enable sFlow on a global basis using the sflow enable command, then enable on individual interfaces or LAG ports or both using the sflow forwarding command.
    1. Enable sFlow forwarding on individual interfaces.
      device(config)# interface ethernet 1/1/1 to 1/1/8
      device(config-mif-1/1/1-1/1/8)# sflow forwarding
    2. Enable sFlow forwarding on individual LAG ports.
      device(config)# lag test static id 1
      device(config-lag-test)# ports ethernet 1/1/1 to 1/1/8
      device(config-lag-test)# sflow forwarding
      Note: sFlow forwarding is supported on LAG and LACP LAG ports.
      Note: When a management port is used, sFlow can be received only from active units in a stack (not from all units). However, if you use a management VLAN with a data port, sFlow is received normally. To receive sFlow from all units in a stack, you must use a data port.
      Note: When you enable sFlow forwarding on an 802.1X-enabled interface, the samples taken from the interface include the username used to obtain access to either or both the inbound and outbound ports, if that information is available. For information about 802.1X, refer to the "Flexible Authentication" chapter in the RUCKUS FastIron Security Configuration Guide.
  8. Configure sFlow version 5 features if your device supports sFlow version 5.

The following example shows how to enable sFlow globally with the destination as an IPv4 address. sFlow parameters are configured.

device# configure terminal
device(config)# sflow enable
device(config)# sflow destination 10.10.10.1 
device(config)# sflow polling-interval 30
device(config)# sflow sample 2048
device(config)# sflow source-port 8000

The following example shows how to enable sFlow globally with the destination as an IPv6 address on Ethernet port 1/1/1, and then enable sFlow forwarding on Ethernet ports 1/1/1 through 1/1/8. sFlow parameters are configured.

device# configure terminal
device(config)# sflow enable
device(config)# sflow destination ipv6 2001:DB8:0::0b:02a
device(config)# sflow polling-interval 30
device(config)# interface 1/1/1
device(config-if-1/1/1)# sflow sample 8192
device(config)# sflow source-port 8000
device(config)# interface ethernet 1/1/1 to 1/1/8
device(config-mif-1/1/1-1/1/8)# sflow forwarding

The following example shows how to enable sFlow globally with the destination as an IPv4 address, and then enable sFlow forwarding on Ethernet ports 1/1/1 through 1/1/8, within the LAG. sFlow parameters are configured.

device# configure terminal
device(config)# sflow enable
device(config)# sflow destination 10.10.10.1
device(config)# sflow polling-interval 30
device(config)# sflow source-port 8000
device(config)# lag test static id 1
device(config-lag-test)# ports ethernet 1/1/1 to 1/1/8
device(config-lag-test)# sflow sample 8192
device(config-lag-test)# ports ethernet 1/1/1 to 1/1/8
device(config-lag-test)# sflow forwarding