Link to home
Start Free TrialLog in
Avatar of maxdog0099
maxdog0099

asked on

Does the ASA 5510 and ASA 5520 support NetFlow?

I'm having a hard time finding any information on whether the ASA 5510 and ASA 5520 support netflow?
Avatar of giltjr
giltjr
Flag of United States of America image

Nope.
SOLUTION
Avatar of aconaway1
aconaway1
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of maxdog0099
maxdog0099

ASKER

Thanks everyone for the responses.  I didn't feel that netflow was supported, but could not find any supporting .docs or links to state that...
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
aconaway, thanks for the link.  It looks like with the 5580 they have released a new level (8.1) of ASA software which now does include NetFlow.  The next question is will the other ASA boxes get support for 8.1 and NetFlow?  I guess as Cisco releases more info we will find out.
NetFlow in a firewall is rare (does it even exist anywhere else?), but you'd think it would be helpful for a lot of people.  I imagine the NATting and CPU requirements make it very difficult to implement and run without doing huge rewrites and a huge processor upgrade.

I think I'd pay for it, though, just to have that functionality.  :)
While it's not Netflow, the ASDM 6 and IOS 8.0(3) provide a crude way of monitoring where your bandwidth is going.
Go to ASDM - Home - Firewall Dashboard and enable threat detection or enter the lines

threat-detection basic-threat
threat-detection statistics

You'll then have a Top 10 Usage Status Graph that you can use to view Bytes Transferred in last few hours.
Thanks for answering this.  I appreciate the help.
The netflow feature is a software option, and version 8.1 will get it on all the asa models, even the 5505.

According to Cisco:

"The feature was introduced in ASA 8.2.1/ASDM 6.2.1. For information on the feature itself, its functionality and limitations you can read here. The document below presents how to use ASDM to configure the ASA to send Neflow information to the Netflow collector."

This leads me to believe that any ASA that can run those versions of ASA/ASDM can run/support NetFlow.

https://supportforums.cisco.com/docs/DOC-6114;jsessionid=AB591CDEAFF6B779924BAC90890BEF10.node0