Solved

netflow on ASA 5500 series

Posted on 2015-01-21
2
105 Views
Last Modified: 2015-03-01
I have never configured netflow on the ASA and after my research, I see that you can configure netflow or NSEL. Are those the same thing? Is there any performance issue when implementing Netflow on the ASA? Any tips? Thanks
0
Comment
Question by:leblanc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 5

Accepted Solution

by:
Joey Yung earned 500 total points
ID: 40563790
The following link provided a good reference of NSEL:

https://www.plixer.com/blog/netflow/what-is-nsel-a-deeper-look-part-1/

BTW, I never try to enable netflow which is below ASA552x model.
0
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 40638438
Here's a good sample config. I'm assuming you're sending the Flow data to a host outside your organization and that the name of your outside interface is "outside".

snmp-server host outside 1.1.1.1 community SNMPNAME version 2c
snmp-server location LOCATION-NAME
snmp-server enable traps all
!
flow-export destination outside 1.1.1.1 2055
flow-export template timeout-rate 1
flow-export delay flow-create 60
!
access-list netflow-export extended permit ip any any
!
class-map netflow-export-class
 match access-list netflow-export
!
policy-map global_policy
 class inspection_default
   inspect snmp
 class netflow-export-class
  flow-export event-type all destination 1.1.1.1
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Great sound, comfort and fit, excellent build quality, versatility, compatibility. These are just some of the many reasons for choosing a headset from Sennheiser.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question