CISCO-NETFLOW-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-NETFLOW-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2006-04-27

Category: Cisco Devices, Network Monitoring (RMON)

Description: Manages NetFlow cache configuration and export settings, providing traffic flow statistics organized by protocol and port.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring CISCO-NETFLOW-MIB with a free 30-day trial of IPNetwork Monitor.

What Is CISCO-NETFLOW-MIB?

CISCO-NETFLOW-MIB provides SNMP access to NetFlow cache configuration, export settings, and traffic-flow statistics on Cisco routers and switches, letting smaller organizations use NetFlow traffic accounting without a full flow-collector infrastructure. It exposes categories of data including per-interface NetFlow enablement, cache type/configuration, active and inactive flow counts, and flow timeout settings, alongside export configuration and statistics. From a monitoring standpoint it is primarily a traffic/performance-visibility MIB rather than a hardware-health one — cnfCIActiveFlows, cnfCIInactiveFlows, and cnfCICacheEntries reveal whether the flow cache is healthy or nearing capacity (which can affect flow-accounting accuracy), and cnfCINetflowEnable/cnfCIMcastNetflowEnable confirm the feature is actually turned on where expected. It relies on the underlying NetFlow export protocol and typically complements interface (ifTable) and export-destination configuration to fully characterize traffic flows. It is commonly deployed on Cisco routers/switches used for traffic accounting, billing, or security/anomaly analysis. Network engineers configuring cisco netflow monitoring use this MIB to pull NetFlow cache and template information directly over SNMP rather than only via the flow-collector protocol.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-NETFLOW-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco routers and switches

Monitoring Examples

An operator would poll cnfCIInterfaceTable/cnfCIInterfaceEntry to confirm cnfCINetflowEnable is set on the interfaces expected to be flow-monitored, then check cnfCICacheTable/cnfCICacheEntry for cnfCICacheType and cnfCICacheEnable to verify the cache is active. Watching cnfCIActiveFlows and cnfCIInactiveFlows against cnfCICacheEntries capacity flags a cache nearing exhaustion, which would cause dropped or aged-out flow records. cnfCIActiveTimeOut tuning affects how quickly long-lived flows are exported, which matters for accurate near-real-time traffic reporting.

What Can Be Monitored

  • per-interface NetFlow enablement
  • cache type and enablement
  • active and inactive flow counts
  • cache capacity/entries
  • active flow timeout setting
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From IF-MIB

InterfaceIndex
InterfaceIndexOrZero
ifIndexOBJECT-TYPE

From INET-ADDRESS-MIB

InetAddress
InetAddressPrefixLength
InetAddressType
InetAutonomousSystemNumber
InetPortNumber

From Q-BRIDGE-MIB

VlanIndex

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Counter64
Gauge32
Integer32
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
RowStatus
TEXTUAL-CONVENTION
TimeStamp
TruthValue

How to Use in IPNetwork Monitor

Example using cnfESSampledPacket OID:

Select a Cisco router or switch (NetFlow) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type cnfESSampledPacket into the Find box to locate it in the OID tree, then select it and click OK. It reports the number of Sampled Packet. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Manages NetFlow cache configuration, export statistics, and traffic analysis on Cisco routers.

Start monitoring Cisco routers and switches (NetFlow) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-NETFLOW-MIB