<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, this is a bit unclear how in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/leveraging-netflow-data/m-p/2686173#M1027121</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is a bit unclear how to actually&amp;nbsp;do it but my understanding is that you need an extra&amp;nbsp;Sourcefire 3D managed sensor to&amp;nbsp;leverage netflow data. So there's no native netflow support in defense center.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From user guide&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Discovery-Config.html#61546&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; line-height: normal;"&gt;Because the FireSIGHT System uses managed devices to analyze NetFlow data, your deployment must include at least one managed device that can monitor your NetFlow-enabled devices. At least one sensing interface on that managed device must be connected to a network where it can collect the data that your NetFlow-enabled devices export. Because the sensing interfaces on managed devices do not usually have IP addresses, the system does not support the direct collection of NetFlow records.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2015 14:21:55 GMT</pubDate>
    <dc:creator>akjellerstedt</dc:creator>
    <dc:date>2015-06-10T14:21:55Z</dc:date>
    <item>
      <title>Leveraging netflow data</title>
      <link>https://community.cisco.com/t5/network-security/leveraging-netflow-data/m-p/2686172#M1027120</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I'm trying to understand how Sourcefire/Firepower uses my netflow data. I have a Virtual Defence Center up and running and four ASAs with Firepower services reporting to it. All data flows seems to work and I've even done some IPS tests with promising results.&lt;/P&gt;&lt;P&gt;However I have a few Cisco routers in my network that I would also like to use in the System but so far I haven't figured out how. For example, should I have the routers send flow data to the Defence Center or to the Firepower modules in the ASAs? When I follow the Network Discovery steps in the user manual I get to set up a discovery policy using the netflow sources but those policies are only deployed to the Firepower modules in the ASAs.&lt;/P&gt;&lt;P&gt;I realize the discovery information will not be as complete using only netflow data as it is with traffic flowing through the ASAs but it will still improve my visibility.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Fredrik&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/leveraging-netflow-data/m-p/2686172#M1027120</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2019-03-12T12:41:39Z</dc:date>
    </item>
    <item>
      <title>Hi, this is a bit unclear how</title>
      <link>https://community.cisco.com/t5/network-security/leveraging-netflow-data/m-p/2686173#M1027121</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is a bit unclear how to actually&amp;nbsp;do it but my understanding is that you need an extra&amp;nbsp;Sourcefire 3D managed sensor to&amp;nbsp;leverage netflow data. So there's no native netflow support in defense center.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From user guide&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Discovery-Config.html#61546&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; line-height: normal;"&gt;Because the FireSIGHT System uses managed devices to analyze NetFlow data, your deployment must include at least one managed device that can monitor your NetFlow-enabled devices. At least one sensing interface on that managed device must be connected to a network where it can collect the data that your NetFlow-enabled devices export. Because the sensing interfaces on managed devices do not usually have IP addresses, the system does not support the direct collection of NetFlow records.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 14:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/leveraging-netflow-data/m-p/2686173#M1027121</guid>
      <dc:creator>akjellerstedt</dc:creator>
      <dc:date>2015-06-10T14:21:55Z</dc:date>
    </item>
    <item>
      <title>So if I understand this</title>
      <link>https://community.cisco.com/t5/network-security/leveraging-netflow-data/m-p/2686174#M1027122</link>
      <description>&lt;P&gt;So if I understand this correctly, there is no point sending netflow data to the FireSIGHT/Sourcefire Virtual DC? And I don't suppose the Firepower module in my ASAs can use the netflow data?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 09:32:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/leveraging-netflow-data/m-p/2686174#M1027122</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2015-06-11T09:32:05Z</dc:date>
    </item>
  </channel>
</rss>

