NetFlow v9
- Last Updated: April 5, 2026
- 9 minute read
- Flowmon Products
- Flowmon
- Documentation
In the following table, the value “Exported by default” refers to a monitoring port that has been configured to use NetFlow v9 as its export protocol.
| ID | Name | Description | Input Length (bytes) | Probe Configuration | Collector Configuration |
|---|---|---|---|---|---|
| 1 | NF9_IN_BYTES | Incoming counter with length N x 8 bits for number of bytes associated with an IP Flow. | 4/8 | Exported by default | Collected by default |
| 2 | NF9_IN_PACKETS | Incoming counter with length N x 8 bits for the number of packets associated with an IP Flow. | 4/8 | Exported by default | Collected by default |
| 3 | NF9_FLOWS_AGGR | Number of flows that were aggregated; default for N is 4. | 4/8 | Not supported | Enabled by Counter aggregated flows |
| 4 | NF9_IN_PROTOCOL | IP protocol byte. | 1 | Exported by default | Collected by default |
| 5 | NF9_SRC_TOS | Type of Service byte setting when entering the incoming interface. | 1 | Enabled by L3/L4 Extended |
Collected by default |
| 6 | NF9_TCP_FLAGS | Cumulative of all the TCP flags seen for this flow. | 1 | Exported by default | Collected by default |
| 7 | NF9_L4_SRC_PORT | TCP/UDP source port number, that is: FTP, Telnet, or equivalent. | 2 | Exported by default | Collected by default |
| 8 | NF9_IPV4_SRC_ADDR | IPv4 source address. | 4 | Exported by default | Collected by default |
| 9 | NF9_SRC_MASK | The number of contiguous bits in the source address subnet mask, that is: the submask in slash notation. | 1 | Not supported | Enabled by SRC/DST mask, (dst) TOS, Direction |
| 10 | NF9_INPUT_SNMP | Input interface index; default for N is 2 but higher values could be used. | 4/2 | Exported by default | Collected by default |
| 11 | NF9_L4_DST_PORT | TCP/UDP destination port number, that is: FTP, Telnet, or equivalent. | 2 | Exported by default | Collected by default |
| 12 | NF9_IPV4_DST_ADDR | IPv4 destination address. | 4 | Exported by default | Collected by default |
| 13 | NF9_DST_MASK | The number of contiguous bits in the destination address subnet mask, that is: the submask in slash notation. | 1 | Not supported | Enabled by SRC/DST mask, (dst) TOS, Direction |
| 14 | NF9_OUTPUT_SNMP | Output interface index; default for N is 2 but higher values could be used. | 4/2 | Exported by default Configurable per monitoring port |
Collected by default |
| 15 | NF9_V4_NEXT_HOP | IPv4 address of next-hop router. | 4 | Not applicable | Enabled by Next HOP IP address |
| 16 | NF9_SRC_AS | Source BGP autonomous system number where N could be 2 or 4. | 4/2 | Enabled by Use autonomous system list |
Collected by default |
| 17 | NF9_DST_AS | Destination BGP autonomous system number where N could be 2 or 4. | 4/2 | Enabled by Use autonomous system list |
Collected by default |
| 18 | NF9_BGP_V4_NEXT_HOP | Next-hop router's IP address in the BGP domain. | 4 | Not applicable | Enabled by BGP next HOP IP address |
| 21 | NF9_LAST_SWITCHED | System uptime when the last packet of this flow was switched. | 4 | Exported by default | Collected by default |
| 22 | NF9_FIRST_SWITCHED | System uptime when the first packet of this flow was switched. | 4 | Exported by default | Collected by default |
| 23 | NF9_OUT_BYTES | Outgoing counter with length N x 8 bits for the number of bytes associated with an IP Flow. | 4/8 | Not applicable | Enabled by Counter output bytes |
| 24 | NF9_OUT_PKTS | Outgoing counter with length N x 8 bits for the number of packets associated with an IP Flow. | 4/8 | Not applicable | Enabled by Counter output packets |
| 27 | NF9_IPV6_SRC_ADDR | IPv6 Source Address. | 16 | Exported by default | Collected by default |
| 28 | NF9_IPV6_DST_ADDR | IPv6 Destination Address. | 16 | Exported by default | Collected by default |
| 29 | NF9_IPV6_SRC_MASK | Length of the IPv6 source mask in contiguous bits. | 1 | Not supported | Enabled by SRC/DST mask, (dst) TOS, Direction |
| 30 | NF9_IPV6_DST_MASK | Length of the IPv6 destination mask in contiguous bits. | 1 | Not supported | Enabled by SRC/DST mask, (dst) TOS, Direction |
| 31 | NF9_IPV6_FLOW_LABEL | IPv6 flow label as per RFC 2460 definition. | 4 | Not supported | Collected by default |
| 32 | NF9_ICMP_TYPE | Internet Control Message Protocol (ICMP) packet type; reported as ((ICMP Type*256) + ICMP code). | 2 | Exported by default | Collected by default |
| 34 | NF9_SAMPLING_INTERVAL | When using sampled NetFlow, the rate at which packets are sampled, for example: a value of 100 indicates that one of every 100 packets is sampled. | 4 | Exported by default | Collected by default |
| 35 | NF9_SAMPLING_ALGORITHM | The type of algorithm used for sampled NetFlow: 0x01 Deterministic Sampling ,0x02 Random Sampling. | 1 | Exported by default | Collected by default |
| 38 | NF9_ENGINE_TYPE | Type of flow switching engine: RP = 0, VIP/Linecard = 1. | 1 | Not applicable | Collected by default |
| 39 | NF9_ENGINE_ID | ID number of the flow switching engine. | 1 | Not applicable | Collected by default |
| 48 | NF9_FLOW_SAMPLER_ID | Identifier shown in "show flow-sampler". | 1/2/4 | Not supported | Collected by default |
| 49 | NF9_FLOW_SAMPLER_MODE | The type of algorithm used for sampling data: 0x02 random sampling. Use in connection with NF9_FLOW_SAMPLER_ID. | 1 | Not supported | Collected by default |
| 50 | NF9_FLOW_SAMPLER_RANDOM_INTERVAL | Packet interval at which to sample. Use in connection with NF9_FLOW_SAMPLER_MODE. | 2/4 | Not supported | Collected by default |
| 55 | NF9_DST_TOS | Type of Service byte setting when exiting outgoing interface. | 1 | Not applicable | Collected by default |
| 56 | NF9_IN_SRC_MAC | Incoming source MAC address. | 6 | Enabled by MAC |
Enabled by In SRC/out DST MAC address |
| 57 | NF9_OUT_DST_MAC | Outgoing destination MAC address. | 6 | Not applicable | Enabled by In SRC/out DST MAC address |
| 58 | NF9_SRC_VLAN | Virtual LAN identifier associated with ingress interface. | 2 | Enabled by VLAN |
Enabled by SRC/DST VLAN ID labels |
| 59 | NF9_DST_VLAN | Virtual LAN identifier associated with egress interface. | 2 | Not applicable | Enabled by SRC/DST VLAN ID labels |
| 61 | NF9_DIRECTION | Flow direction: 0 - ingress flow, 1 - egress flow. | 1 | Not applicable | Enabled by SRC/DST mask, (dst) TOS, Direction |
| 62 | NF9_V6_NEXT_HOP | IPv6 address of the next-hop router. | 16 | Not applicable | Enabled by Next HOP IP address |
| 63 | NF9_BPG_V6_NEXT_HOP | Next-hop router in the BGP domain. | 16 | Not applicable | Enabled by BGP next HOP IP address |
| 70 | NF9_MPLS_LABEL_1 | MPLS label at position 1 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Enabled by MPLS |
Enabled by MPLS labels 1-10 |
| 71 | NF9_MPLS_LABEL_2 | MPLS label at position 2 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Enabled by MPLS |
Enabled by MPLS labels 1-10 |
| 72 | NF9_MPLS_LABEL_3 | MPLS label at position 3 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Enabled by MPLS |
Enabled by MPLS labels 1-10 |
| 73 | NF9_MPLS_LABEL_4 | MPLS label at position 4 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Enabled by MPLS |
Enabled by MPLS labels 1-10 |
| 74 | NF9_MPLS_LABEL_5 | MPLS label at position 5 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Not supported | Enabled by MPLS labels 1-10 |
| 75 | NF9_MPLS_LABEL_6 | MPLS label at position 6 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Not supported | Enabled by MPLS labels 1-10 |
| 76 | NF9_MPLS_LABEL_7 | MPLS label at position 7 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Not supported | Enabled by MPLS labels 1-10 |
| 77 | NF9_MPLS_LABEL_8 | MPLS label at position 8 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Not supported | Enabled by MPLS labels 1-10 |
| 78 | NF9_MPLS_LABEL_9 | MPLS label at position 9 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Not supported | Enabled by MPLS labels 1-10 |
| 79 | NF9_MPLS_LABEL_10 | MPLS label at position 10 in the stack. This comprises 20 bits of MPLS label, 3 EXP (experimental) bits, and 1 S (end-of-stack) bit. | 3 | Not supported | Enabled by MPLS labels 1-10 |
| 80 | NF9_IN_DST_MAC | Incoming destination MAC address. | 6 | Enabled by MAC |
Enabled by In DST/out SRC MAC address |
| 81 | NF9_OUT_SRC_MAC | Outgoing source MAC address. | 6 | Not applicable | Enabled by In DST/out SRC MAC address |
| 89 | NF9_FORWARDING_STATUS | Forwarding status is encoded on 1 byte with the 2 left bits giving the status and the 6 remaining bits giving the reason code. | 1 | Not applicable | Collected by default |
| 128 | NF9_BGP_ADJ_NEXT_AS | The autonomous system (AS) number of the first AS in the AS path to the destination IP address. The path is deduced by looking up the destination IP address of the Flow in the BGP routing information base. If the AS path information for this Flow is only available as an unordered AS set (and not as an ordered AS sequence), then the value of this Information Element is 0. | 4 | Not applicable | Enabled by BGP adjacent prev/next AS |
| 129 | NF9_BGP_ADJ_PREV_AS | The autonomous system (AS) number of the last AS in the AS path from the source IP address. The path is deduced by looking up the source IP address of the Flow in the BGP routing information base. If the AS path information for this Flow is only available as an unordered AS set (and not as an ordered AS sequence), then the value of this Information Element is 0. In case of BGP asymmetry, the bgpPrevAdjacentAsNumber might not be able to report the correct value. | 4 | Not applicable | Enabled by BGP adjacent prev/next AS |
| 95 | NF9_NBAR2_APP_TAG | 8 bits of engine ID, followed by n bits of classification. | 4 | Not supported | Enabled by NBAR2 application tag |
| 85 | NF_F_FLOW_BYTES | Running byte counter for a permanent flow. | 4/8 | Not applicable | Enabled by NSEL Common block |
| 148 | NF_F_CONN_ID | An identifier of a unique flow for the device. | 4 | Not applicable | Enabled by NSEL Common block |
| 152 | NF_F_FLOW_CREATE_TIME_MSEC | The time that the flow was created, which is included in extended flow-teardown events in which the flow-create event was not sent earlier. The flow duration can be determined with the event time for the flow-teardown and flow-create times. | 8 | Not applicable | Enabled by NSEL Common block |
| 153 | NF_F_FLOW_END_TIME_MSEC | The time when the flow ended. | 8 | Not applicable | Collected by default |
| 176 | NF_F_ICMP_TYPE | ICMP type value. | 1 | Not applicable | Enabled by NSEL Common block |
| 177 | NF_F_ICMP_CODE | ICMP code value. | 1 | Not applicable | Enabled by NSEL Common block |
| 178 | NF_F_ICMP_TYPE_IPV6 | ICMP IPv6 type value. | 1 | Not applicable | Enabled by NSEL Common block |
| 179 | NF_F_ICMP_CODE_IPV6 | ICMP IPv6 code value. | 1 | Not applicable | Enabled by NSEL Common block |
| 231 | NF_F_FWD_FLOW_DELTA_BYTES | The delta number of bytes from source to destination. | 4/8 | Not applicable | Enabled by NSEL Common block |
| 232 | NF_F_REV_FLOW_DELTA_BYTES | The delta number of bytes from destination to source. | 4/8 | Not applicable | Enabled by Counter output bytes |
| 233 | NF_F_FW_EVENT84 | Indicates a firewall event. | 1 | Not applicable | Enabled by NSEL Common block |
| 323 | NF_F_EVENT_TIME_MSEC | The time that the event occurred, which comes from IPFIX. Use 324 for time in microseconds, and 325 for time in nanoseconds. | 8 | Not applicable | Collected by default |
| 33000 | NF_F_INGRESS_ACL_ID | The input ACL that permitted or denied the flow. All ACL IDs are composed of the following three, four-byte values:
|
12 | Not applicable | Enabled by NSEL ACL ingress/egress acl ID |
| 33001 | NF_F_EGRESS_ACL_ID | The output ACL that permitted or denied a flow. | 12 | Not applicable | Enabled by NSEL ACL ingress/egress acl ID |
| 33002 | NF_F_FW_EXT_EVENT | Extended event code. These values provide additional information about the event. | 2 | Not applicable | Enabled by NSEL Common block |
| 40000 | NF_F_USERNAME | AAA username. | 20/65 | Not applicable | Enabled by NSEL username |
| 40001 | NF_F_XLATE_SRC_ADDR_IPV4 | Source IPv4 address. | 4 | Not applicable | Enabled by NSEL xlate IPv4 address |
| 40002 | NF_F_XLATE_DST_ADDR_IPV4 | Destination IPv4 address. | 4 | Not applicable | Enabled by NSEL xlate IPv4 address |
| 40003 | NF_F_XLATE_SRC_PORT | Post NATT Source Transport Port. | 2 | Not applicable | Enabled by NSEL xlate ports |
| 40004 | NF_F_XLATE_DST_PORT | Post NATT Destination Transport Port. | 2 | Not applicable | Enabled by NSEL xlate ports |
| 40005 | NF_F_FW_EVENT | High-level event code. Values are as follows: 0-Collected by default (ignore), 1-Flow created, 2-Flow deleted, 3-Flow denied, 4-Flow alert, 5-Flow update. |
1 | Not applicable | Enabled by NSEL Common block |
| 230 | NF_N_NAT_EVENT | Indicates a NAT event. | 1 | Not applicable | Enabled by NEL Common block |
| 234 | NF_N_INGRESS_VRFID | An unique identifier of the VRF name where the packets of this flow are being received. This identifier is unique per Metering Process. | 4 | Not applicable | Enabled by NEL Common block |
| 225 | NF_N_NAT_INSIDE_GLOBAL_IPV4 | The definition of this Information Element is identical to the definition of the Information Element 'sourceIPv4Address', except that it reports a modified value caused by a NAT middlebox function after the packet passed the Observation Point. | 4 | Not applicable | Enabled by NEL global IPv4 address |
| 226 | NF_N_NAT_OUTSIDE_GLOBAL_IPV4 | The definition of this Information Element is identical to the definition of Information Element 'destinationIPv4Address', except that it reports a modified value caused by a NAT middlebox function after the packet passed the Observation Point. | 4 | Not applicable | Enabled by NEL global IPv4 address |
| 227 | NF_N_POST_NAPT_SRC_PORT | The definition of this Information Element is identical to the definition of Information Element 'sourceTransportPort', except that it reports a modified value caused by a Network Address Port Translation (NAPT) middlebox function after the packet passed the Observation Point. | 2 | Not applicable | Enabled by NEL Common block |
| 228 | NF_N_POST_NAPT_DST_PORT | The definition of this Information Element is identical to the definition of Information Element 'destinationTransportPort', except that it reports a modified value caused by a Network Address Port Translation (NAPT) middlebox function after the packet passed the Observation Point. | 2 | Not applicable | Enabled by NEL Common block |