• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 866
  • Last Modified:

Help with Netflow from Adtran router to a collector inside the firewall

I am having trouble getting flows exported to a collector inside my firewall.  The ip of the collector is 192.168.xx.8.  The ip of the inside ethernet of the adtran is 65.222.xxx.241.  The inside ip of the firewall is 192.168.xx.1.  Any suggestions?
0
sckautie
Asked:
sckautie
1 Solution
 
lrmooreCommented:
PIX firewall:
For example purposes:
Where "9996" is the port you are using for netflow
Where outside IP of PIX = 65.222.xxx.242

static (inside,outside) udp interface 9996 192.168.xx.8 9996 netmask 255.255.255.255
access-list outside_access_in permit udp host 65.222.xxx.241 host 65.222.xxx.242  eq 9996
0
 
ngravattCommented:
i would just setup NAT exemption rules on the firewall.  My netflow server is 10.15.6.6 and my outside router has an IP of 70.15037.129.  Here is the access rule and nat exemption rules i have on my firewall

access-list acl_out extended permit udp host 70.150.37.129 host 10.15.6.66 eq 2055

NAT exemption
access-list inside_nat0_outbound extended permit ip host 10.15.6.66 host 70.150.37.129
access-list outside_nat0_outbound extended permit ip host 70.150.37.129 host 10.15.6.66

default netflow on cisco is port 2055
0

Featured Post

Never miss a deadline with monday.com

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now