Solved

Netflow Randomly Stopped Working

Posted on 2013-07-01
2
983 Views
Last Modified: 2013-07-26
I have a Cisco ASA 5515 and a 2921 ISR that I have configured to receive netflow data from.  Both devices have been working perfectly for several months.  All of a sudden, both devices stopped sending netflow packets at about the same time.  I performed an #clear ip flow stats on the 2921, and it appears to be working again.  I can find no such command for the ASA.  I rebuilt the configuration for netflow on the ASA with no success.  Does netflow fill up the cache after a while and stop sending flows?  Is there any way to configure some kind of circular logging for such data?  Is there any way to clear the cache on the ASA appliance?
0
Comment
Question by:marrj
  • 2
2 Comments
 
LVL 17

Expert Comment

by:surbabu140977
ID: 39297140
flow-export destination inside <IP> <port>
flow-export delay flow-create 30
flow-export template timeout-rate 1

Then policy-map/class map your choice with ACL.

Please remember ASA will support only version 9. (in your collector check for version mismatch)

Most of the times it will be collector issue. Every collector won't work great with ASA. You might need to contact your collector vendor. But try using solarwinds  Orion NTA 3.5 SP2 demo for testing, if it's collecting data then problem is in the software.

Best,
0
 
LVL 17

Accepted Solution

by:
surbabu140977 earned 500 total points
ID: 39297162
Plixer also seem to support it. Test any one (solarwinds or plixer) to see if netflow data is actually coming or not. If not coming, asa is the issue, if coming- your collector is the issue.

http://www.plixer.com/blog/netflow/netflow-security-event-logging-with-the-cisco-asa/

Best,
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question