Configuring sFlow with Multi-VRF
sFlow is a traffic-monitoring protocol that supports VRFs. sFlow provides traffic sampling on configured ports, based on sample rate and port information, to a collector. By default, sFlow uses the management VRF to send the samples to the collector.
Collectors can be added to individual VRFs so that collectors can be spread out across different VRFs. The sFlow forwarding port can belong to a non-default VRF, and captured sFlow packets will contain the correct sample routing next-hop information.
sFlow forwarding ports can come from ports belonging to any VRF. The port is not required to be in the same VRF as the collector. sFlow collects packets from all sFlow forwarding ports (even if they do not belong to a VRF), compiles the packets into the sFlow samples, and sends the samples to the particular collector with no filtering for VRF membership. For counter samples, sample statistics from each port are sent to each specified collector, even if the port and collector do not belong to a VRF instance.
To distinguish collected packets from different VRFs, refer to the VLAN data fields for each captured ingress packet. For example, when two collected packets are from different VRFs but have the same source or destination IP address and the same incoming or outgoing port, the VLAN data fields differ in the two samples. A VLAN or VE can belong to only one VRF. The collector does not have any VRF knowledge, but, based on the VLAN fields, the collector can distinguish which packet came from which VLAN or VRF.
To configure an sFlow collector and specify a VRF, enter the following command.
device(config)# sflow destination 10.10.10.vrf customer1
To disable the management VRF in sFlow, enter the following command.
device(config)# sflow management-vrf disable
To display sFlow configuration and statistics, enter the following command.
device(config)# show sflow sFlow version: 5 sFlow services are enabled. sFlow management VRF is disabled. sFlow agent IP address: 10.37.230.21 Collector IP 10.37.224.233, UDP 6343, Configured VRF: green UDP source port: 8888 (Default) Polling interval is 20 seconds. Configured default sampling rate: 1 per 500 packets. Actual default sampling rate: 1 per 500 packets. The maximum sFlow sample size: 128. sFlow exporting cpu-traffic is disabled. 100 UDP packets exported 80 sFlow flow samples collected. sFlow ports: ethe 4/1/5 Module Sampling Rates --------------------- Port Sampling Rates ------------------- Port=4/1/5, configured rate=500, actual rate=500