Powered by Zoomin Software. For more details please contactZoomin

Flowmon 12.5 - Supported Flow Standards

NetFlow v9

  • Last Updated: April 5, 2026
  • 9 minute read
    • Flowmon Products
    • Flowmon
    • Documentation

Note:

In the following table, the value “Exported by default” refers to a monitoring port that has been configured to use NetFlow v9 as its export protocol.

ID Name Description Input Length (bytes) Probe Configuration Collector Configuration
1 NF9_IN_BYTES Incoming counter with length N x 8 bits for number of bytes associated with an IP Flow. 4/8 Exported by default Collected by default
2 NF9_IN_PACKETS Incoming counter with length N x 8 bits for the number of packets associated with an IP Flow. 4/8 Exported by default Collected by default
3 NF9_FLOWS_AGGR Number of flows that were aggregated; default for N is 4. 4/8 Not supported

Enabled by

Counter aggregated flows

4 NF9_IN_PROTOCOL IP protocol byte. 1 Exported by default Collected by default
5 NF9_SRC_TOS Type of Service byte setting when entering the incoming interface. 1

Enabled by

L3/L4 Extended

Collected by default
6 NF9_TCP_FLAGS Cumulative of all the TCP flags seen for this flow. 1 Exported by default Collected by default
7 NF9_L4_SRC_PORT TCP/UDP source port number, that is: FTP, Telnet, or equivalent. 2 Exported by default Collected by default
8 NF9_IPV4_SRC_ADDR IPv4 source address. 4 Exported by default Collected by default
9 NF9_SRC_MASK The number of contiguous bits in the source address subnet mask, that is: the submask in slash notation. 1 Not supported

Enabled by

SRC/DST mask, (dst) TOS, Direction

10 NF9_INPUT_SNMP Input interface index; default for N is 2 but higher values could be used. 4/2 Exported by default Collected by default
11 NF9_L4_DST_PORT TCP/UDP destination port number, that is: FTP, Telnet, or equivalent. 2 Exported by default Collected by default
12 NF9_IPV4_DST_ADDR IPv4 destination address. 4 Exported by default Collected by default
13 NF9_DST_MASK The number of contiguous bits in the destination address subnet mask, that is: the submask in slash notation. 1 Not supported

Enabled by

SRC/DST mask, (dst) TOS, Direction

14 NF9_OUTPUT_SNMP Output interface index; default for N is 2 but higher values could be used. 4/2

Exported by default

Configurable per monitoring port

Collected by default
15 NF9_V4_NEXT_HOP IPv4 address of next-hop router. 4 Not applicable

Enabled by

Next HOP IP address

16 NF9_SRC_AS Source BGP autonomous system number where N could be 2 or 4. 4/2

Enabled by

Use autonomous system list

Collected by default
17 NF9_DST_AS Destination BGP autonomous system number where N could be 2 or 4. 4/2

Enabled by

Use autonomous system list

Collected by default
18 NF9_BGP_V4_NEXT_HOP Next-hop router's IP address in the BGP domain. 4 Not applicable

Enabled by

BGP next HOP IP address

21 NF9_LAST_SWITCHED System uptime when the last packet of this flow was switched. 4 Exported by default Collected by default
22 NF9_FIRST_SWITCHED System uptime when the first packet of this flow was switched. 4 Exported by default Collected by default
23 NF9_OUT_BYTES Outgoing counter with length N x 8 bits for the number of bytes associated with an IP Flow. 4/8 Not applicable

Enabled by

Counter output bytes

24 NF9_OUT_PKTS Outgoing counter with length N x 8 bits for the number of packets associated with an IP Flow. 4/8 Not applicable

Enabled by

Counter output packets

27 NF9_IPV6_SRC_ADDR IPv6 Source Address. 16 Exported by default Collected by default
28 NF9_IPV6_DST_ADDR IPv6 Destination Address. 16 Exported by default Collected by default
29 NF9_IPV6_SRC_MASK Length of the IPv6 source mask in contiguous bits. 1 Not supported

Enabled by

SRC/DST mask, (dst) TOS, Direction

30 NF9_IPV6_DST_MASK Length of the IPv6 destination mask in contiguous bits. 1 Not supported

Enabled by

SRC/DST mask, (dst) TOS, Direction

31 NF9_IPV6_FLOW_LABEL IPv6 flow label as per RFC 2460 definition. 4 Not supported Collected by default
32 NF9_ICMP_TYPE Internet Control Message Protocol (ICMP) packet type; reported as ((ICMP Type*256) + ICMP code). 2 Exported by default Collected by default
34 NF9_SAMPLING_INTERVAL When using sampled NetFlow, the rate at which packets are sampled, for example: a value of 100 indicates that one of every 100 packets is sampled. 4 Exported by default Collected by default
35 NF9_SAMPLING_ALGORITHM The type of algorithm used for sampled NetFlow: 0x01 Deterministic Sampling ,0x02 Random Sampling. 1 Exported by default Collected by default
38 NF9_ENGINE_TYPE Type of flow switching engine: RP = 0, VIP/Linecard = 1. 1 Not applicable Collected by default
39 NF9_ENGINE_ID ID number of the flow switching engine. 1 Not applicable Collected by default
48 NF9_FLOW_SAMPLER_ID Identifier shown in "show flow-sampler". 1/2/4 Not supported Collected by default
49 NF9_FLOW_SAMPLER_MODE The type of algorithm used for sampling data: 0x02 random sampling. Use in connection with NF9_FLOW_SAMPLER_ID. 1 Not supported Collected by default
50 NF9_FLOW_SAMPLER_RANDOM_INTERVAL Packet interval at which to sample. Use in connection with NF9_FLOW_SAMPLER_MODE. 2/4 Not supported Collected by default
55 NF9_DST_TOS Type of Service byte setting when exiting outgoing interface. 1 Not applicable Collected by default
56 NF9_IN_SRC_MAC Incoming source MAC address. 6

Enabled by

MAC

Enabled by

In SRC/out DST MAC address

57 NF9_OUT_DST_MAC Outgoing destination MAC address. 6 Not applicable

Enabled by

In SRC/out DST MAC address

58 NF9_SRC_VLAN Virtual LAN identifier associated with ingress interface. 2

Enabled by

VLAN

Enabled by

SRC/DST VLAN ID labels

59 NF9_DST_VLAN Virtual LAN identifier associated with egress interface. 2 Not applicable

Enabled by

SRC/DST VLAN ID labels

61 NF9_DIRECTION Flow direction: 0 - ingress flow, 1 - egress flow. 1 Not applicable

Enabled by

SRC/DST mask, (dst) TOS, Direction

62 NF9_V6_NEXT_HOP IPv6 address of the next-hop router. 16 Not applicable

Enabled by

Next HOP IP address

63 NF9_BPG_V6_NEXT_HOP Next-hop router in the BGP domain. 16 Not applicable

Enabled by

BGP next HOP IP address

70 NF9_MPLS_LABEL_1 MPLS label at position 1 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3

Enabled by

MPLS

Enabled by

MPLS labels 1-10

71 NF9_MPLS_LABEL_2 MPLS label at position 2 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3

Enabled by

MPLS

Enabled by

MPLS labels 1-10

72 NF9_MPLS_LABEL_3 MPLS label at position 3 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3

Enabled by

MPLS

Enabled by

MPLS labels 1-10

73 NF9_MPLS_LABEL_4 MPLS label at position 4 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3

Enabled by

MPLS

Enabled by

MPLS labels 1-10

74 NF9_MPLS_LABEL_5 MPLS label at position 5 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3 Not supported

Enabled by

MPLS labels 1-10

75 NF9_MPLS_LABEL_6 MPLS label at position 6 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3 Not supported

Enabled by

MPLS labels 1-10

76 NF9_MPLS_LABEL_7 MPLS label at position 7 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3 Not supported

Enabled by

MPLS labels 1-10

77 NF9_MPLS_LABEL_8 MPLS label at position 8 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3 Not supported

Enabled by

MPLS labels 1-10

78 NF9_MPLS_LABEL_9 MPLS label at position 9 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3 Not supported

Enabled by

MPLS labels 1-10

79 NF9_MPLS_LABEL_10 MPLS label at position 10 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. 3 Not supported

Enabled by

MPLS labels 1-10

80 NF9_IN_DST_MAC Incoming destination MAC address. 6

Enabled by

MAC

Enabled by

In DST/out SRC MAC address

81 NF9_OUT_SRC_MAC Outgoing source MAC address. 6 Not applicable

Enabled by

In DST/out SRC MAC address

89 NF9_FORWARDING_STATUS Forwarding status is encoded on 1 byte with the 2 left bits giving the status and the 6 remaining bits giving the reason code. 1 Not applicable Collected by default
128 NF9_BGP_ADJ_NEXT_AS The autonomous system (AS) number of the first AS in the AS path to the destination IP address. The path is deduced by looking up the destination IP address of the Flow in the BGP routing information base. If the AS path information for this Flow is only available as an unordered AS set (and not as an ordered AS sequence), then the value of this Information Element is 0. 4 Not applicable

Enabled by

BGP adjacent prev/next AS

129 NF9_BGP_ADJ_PREV_AS The autonomous system (AS) number of the last AS in the AS path from the source IP address. The path is deduced by looking up the source IP address of the Flow in the BGP routing information base. If the AS path information for this Flow is only available as an unordered AS set (and not as an ordered AS sequence), then the value of this Information Element is 0. In case of BGP asymmetry, the bgpPrevAdjacentAsNumber might not be able to report the correct value. 4 Not applicable

Enabled by

BGP adjacent prev/next AS

95 NF9_NBAR2_APP_TAG 8 bits of engine ID, followed by n bits of classification. 4 Not supported

Enabled by

NBAR2 application tag

85 NF_F_FLOW_BYTES Running byte counter for a permanent flow. 4/8 Not applicable

Enabled by

NSEL Common block

148 NF_F_CONN_ID An identifier of a unique flow for the device. 4 Not applicable

Enabled by

NSEL Common block

152 NF_F_FLOW_CREATE_TIME_MSEC The time that the flow was created, which is included in extended flow-teardown events in which the flow-create event was not sent earlier. The flow duration can be determined with the event time for the flow-teardown and flow-create times. 8 Not applicable

Enabled by

NSEL Common block

153 NF_F_FLOW_END_TIME_MSEC The time when the flow ended. 8 Not applicable Collected by default
176 NF_F_ICMP_TYPE ICMP type value. 1 Not applicable

Enabled by

NSEL Common block

177 NF_F_ICMP_CODE ICMP code value. 1 Not applicable

Enabled by

NSEL Common block

178 NF_F_ICMP_TYPE_IPV6 ICMP IPv6 type value. 1 Not applicable

Enabled by

NSEL Common block

179 NF_F_ICMP_CODE_IPV6 ICMP IPv6 code value. 1 Not applicable

Enabled by

NSEL Common block

231 NF_F_FWD_FLOW_DELTA_BYTES The delta number of bytes from source to destination. 4/8 Not applicable

Enabled by

NSEL Common block

232 NF_F_REV_FLOW_DELTA_BYTES The delta number of bytes from destination to source. 4/8 Not applicable

Enabled by

Counter output bytes

233 NF_F_FW_EVENT84 Indicates a firewall event. 1 Not applicable

Enabled by

NSEL Common block

323 NF_F_EVENT_TIME_MSEC The time that the event occurred, which comes from IPFIX. Use 324 for time in microseconds, and 325 for time in nanoseconds. 8 Not applicable Collected by default
33000 NF_F_INGRESS_ACL_ID

The input ACL that permitted or denied the flow. All ACL IDs are composed of the following three, four-byte values:

  • Hash value or ID of the ACL name

  • Hash value, ID, or line of an ACE within the ACL

  • Hash value or ID of an extended ACE configuration.

12 Not applicable

Enabled by

NSEL ACL ingress/egress acl ID

33001 NF_F_EGRESS_ACL_ID The output ACL that permitted or denied a flow. 12 Not applicable

Enabled by

NSEL ACL ingress/egress acl ID

33002 NF_F_FW_EXT_EVENT Extended event code. These values provide additional information about the event. 2 Not applicable

Enabled by

NSEL Common block

40000 NF_F_USERNAME AAA username. 20/65 Not applicable

Enabled by

NSEL username

40001 NF_F_XLATE_SRC_ADDR_IPV4 Source IPv4 address. 4 Not applicable

Enabled by

NSEL xlate IPv4 address

40002 NF_F_XLATE_DST_ADDR_IPV4 Destination IPv4 address. 4 Not applicable

Enabled by

NSEL xlate IPv4 address

40003 NF_F_XLATE_SRC_PORT Post NATT Source Transport Port. 2 Not applicable

Enabled by

NSEL xlate ports

40004 NF_F_XLATE_DST_PORT Post NATT Destination Transport Port. 2 Not applicable

Enabled by

NSEL xlate ports

40005 NF_F_FW_EVENT

High-level event code. Values are as follows:

0-Collected by default (ignore), 1-Flow created, 2-Flow deleted, 3-Flow denied, 4-Flow alert, 5-Flow update.

1 Not applicable

Enabled by

NSEL Common block

230 NF_N_NAT_EVENT Indicates a NAT event. 1 Not applicable

Enabled by

NEL Common block

234 NF_N_INGRESS_VRFID An unique identifier of the VRF name where the packets of this flow are being received. This identifier is unique per Metering Process. 4 Not applicable

Enabled by

NEL Common block

225 NF_N_NAT_INSIDE_GLOBAL_IPV4 The definition of this Information Element is identical to the definition of the Information Element 'sourceIPv4Address', except that it reports a modified value caused by a NAT middlebox function after the packet passed the Observation Point. 4 Not applicable

Enabled by

NEL global IPv4 address

226 NF_N_NAT_OUTSIDE_GLOBAL_IPV4 The definition of this Information Element is identical to the definition of Information Element 'destinationIPv4Address', except that it reports a modified value caused by a NAT middlebox function after the packet passed the Observation Point. 4 Not applicable

Enabled by

NEL global IPv4 address

227 NF_N_POST_NAPT_SRC_PORT The definition of this Information Element is identical to the definition of Information Element 'sourceTransportPort', except that it reports a modified value caused by a Network Address Port Translation (NAPT) middlebox function after the packet passed the Observation Point. 2 Not applicable

Enabled by

NEL Common block

228 NF_N_POST_NAPT_DST_PORT The definition of this Information Element is identical to the definition of Information Element 'destinationTransportPort', except that it reports a modified value caused by a Network Address Port Translation (NAPT) middlebox function after the packet passed the Observation Point. 2 Not applicable

Enabled by

NEL Common block

TitleResults for “How to create a CRG?”Also Available inAlert