We are seeing double the traffic we expect from a Cisco ASR router in Network Flow Analysis
The issue stems from a misconfiguration of the router.
Release : 10.0
Component : NQRPTA - REPORTERANALYZER
In the router's netflow configuration ensure that you do NOT have both of the following on an interface (it should only be 'input'):
ip flow monitor NFAmonitor input
ip flow monitor NFAmonitor output
On many cisco routers, both are required. On Cisco ASR routers, having both of these enabled on an interface will send an incorrect amount (double) of Netflow traffic to NFA for analysis