Unable to see flows from our integrated cisco switches IN VCF Operations for Networks
search cancel

Unable to see flows from our integrated cisco switches IN VCF Operations for Networks

book

Article ID: 405580

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

 Unable to see flows from our integrated cisco switches IN VCF Operations for Networks 

  1. Raw flows are seen as we can see the tcp dump output as below:






  2. Collector logs at location /var/log/arkin/flow-processor/latest.log shows that deployed collector is not a physical collector deployed within Aria Operations for Network.

    YYYY-MM-DDT07:17:25.253Z INFO ipfix.v2.FiveTupleProcessingTask NFCAPD_vds run:465 checking.. last processed file was 1748675700. Got new files {/var/flows/vds/nfcapd/=[/var/flows/vds/nfcapd/nfcapd.202505310716], /var/flows/vds/sfcapd/=[/var/flows/vds/sfcapd/nfcapd.202505310716]}
    YYYY-MM-DDT07:17:25.253Z INFO ipfix.v2.FiveTupleProcessingTask NFCAPD_vds loadFeatureFlags:420 for cid 13778 enableNsxTcpRtt = true, enableNsxTcpRetransmissionCount = true, enableOpenSessionMetricForFlows = false
    YYYY-MM-DDT07:17:25.253Z INFO ipfix.v2.FiveTupleProcessingTask NFCAPD_vds run:497 processing flow files [/var/flows/vds/nfcapd/nfcapd.202505310716, /var/flows/vds/sfcapd/nfcapd.202505310716] at TS:1748675760
    YYYY-MM-DDT07:17:25.254Z INFO vnera.ipfix.IpfixProcessor_1 NFCAPD_vds load:73 Proxy type physical: false



Environment

  • VCF Operations for Networks 6.14.x
  • VCF Operations for Networks 9.0.x

Cause

This behaviors is expected  and you will not be able to see the flows and only the configuration and additional information is visible because the collector type is not a dedicate physical flow collector.

Resolution

For VCF Operations for Networks version 6.13 and 6.14.x

To fix the above issue, deploy physical flow collector (dedicated flow collector) as per below mentioned steps

  1. Login to Aria Operation for Networks GUI using username admin@local
  2. From the left navigation pane, go to Settings, Accounts and Data Sources.
  3. Click Add Source.
  4. Under Flows, select Physical Flow Collector (Netflow, sFlow)

    Note: sFlows are accepted only on a physical collector.

  5. On Add a new Physical Account or Source page, click Add Collector VM.
  6. The Add a new Operations for Networks Data Collector virtual appliance window is displayed. Click Copy to copy the shared secret to import the collector service ova in your VMware vCenter
  7. Click Done.
  8. In the Nickname text box, enter a nickname.
  9. In the Notes text box, add a note if necessary.
  10. Click Submit.

  11. Enable the Netflow on the Cisco Nexus 9k and do the reconfiguration to point it to the newly deployed dedicate physical flow collector's Ip address. Work with you network administrator as most oof this configuration is via CLI 
  12. Wait for a couple of hours(at max 2-3 hours) for each device for the flow number information to be seen against the  dedicate physical flow collector.

    Refer to documentation for how to Add a Physical Flow Collector for NetFlow and sFlow for more details 


For VCF Operations for Networks version 9.0.x

Follow instruction as per below

Add a Physical Flow Collector for NetFlow and sFlow 

Flow Support for Physical Devices

    Additional Information

    Important Notes

    • sFlow Support: sFlows are only accepted on a physical collector.
    • Log Verification: You can verify this issue by checking /var/log/arkin/flow-processor/latest.log on the collector. If the issue exists, you will see the entry: Proxy type physical: false.
    • CLI Configuration: Most Cisco device reconfigurations will require access via CLI; coordinate with your network administrator for these changes.