Instiq
Chapter 4 · Network Assurance·v1.0.0·Updated 7/20/2026·~19 min

What's changed: Initial version

4.2Traffic visibility and measurement (NetFlow, SPAN, IP SLA)

Key points

Covers Flexible NetFlow for aggregating "who talked to whom and how much" (define a flow record, flow exporter, and flow monitor, then apply it to an interface), packet-copying with SPAN (same device), RSPAN (via a VLAN), and ERSPAN (across L3 using GRE), and IP SLA for actively measuring reachability, latency, and jitter with synthetic traffic and switching paths through object tracking--framed as the selection judgment of "which measurement confirms this symptom."

The job of visibility and measurement is to turn vague reports like "it is slow" or "it drops sometimes" into reproducible numbers. The key point is that the three methods answer different kinds of question. NetFlow answers the aggregate--"which host pairs consumed how much bandwidth"--but never shows packet contents. SPAN/ERSPAN shows per-packet facts--"what is the DSCP or the TCP flags on that packet actually set to"--but eats bandwidth if left running. IP SLA actively measures "what the latency, jitter, and reachability of this path are continuously, including hours with no users," and can tie a threshold breach to an action such as switching the path. The heart of this section is not mismatching the method to the question.

4.2.1The three components of Flexible NetFlow

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.