<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NetFlow through VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487854#M1055529</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just uninstalled and reinstalled the program I'm using to listen for NetFlows.  Since reboots to that server can only be done at night it took a little while   but now I'm sure that the listener is working correctly.  And yes, the NetFlows are using UDP on port 2055 and are going to 192.168.100.7.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jan 2006 13:44:05 GMT</pubDate>
    <dc:creator>depadua_chris</dc:creator>
    <dc:date>2006-01-05T13:44:05Z</dc:date>
    <item>
      <title>NetFlow through VPN</title>
      <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487848#M1055522</link>
      <description>&lt;P&gt;How do you encrypt NetFlows through a VPN connection?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've set the netflow destination to be on a network that is represented by interesting traffic.  I've also set the source of the netflow to be on the local network (interesting).  The source is Vlan1; not sure if that is a problem.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the netflows being created and sent (sh ip flow export) but the destination is not recieving.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or suggestions would be appreciated.  Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487848#M1055522</guid>
      <dc:creator>depadua_chris</dc:creator>
      <dc:date>2020-02-21T08:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: NetFlow through VPN</title>
      <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487849#M1055523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is the VPN working correctly? Check connectivity with an extended ping using your NetFlow IPs.&lt;/P&gt;&lt;P&gt;Is the traffic encrypted on the same box where NetFlow is running? Where is the VPN terminating? Where are packets dropped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jan 2006 20:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487849#M1055523</guid>
      <dc:creator>mheusinger</dc:creator>
      <dc:date>2006-01-01T20:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: NetFlow through VPN</title>
      <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487850#M1055525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I confirmed that the VPN is working correctly with the extended ping.  The traffic is being encrypted on the same box that is trying to send out the NetFlows.  The VPN is terminating on a PIX515 and as far as I can see it is not being blocked.  I also cannot see where the packets would be dropped.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2006 16:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487850#M1055525</guid>
      <dc:creator>depadua_chris</dc:creator>
      <dc:date>2006-01-03T16:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: NetFlow through VPN</title>
      <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487851#M1055526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, can you provide more details like hardware, IOS version and a config excerpt?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2006 16:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487851#M1055526</guid>
      <dc:creator>mheusinger</dc:creator>
      <dc:date>2006-01-03T16:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: NetFlow through VPN</title>
      <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487852#M1055527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a Cisco 871 running 12.4(4)T.  That is the remote vpn endpoint and it is also the device trying to send netflows.  The other endpoint is a PIX515E (Restricted License) running ver 7.02(2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SH RUN from 871&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map vpnmap 5 ipsec-isakmp &lt;/P&gt;&lt;P&gt; set peer xx.xx.xx.xx&lt;/P&gt;&lt;P&gt; set transform-set vpnset &lt;/P&gt;&lt;P&gt; match address meridentunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet4&lt;/P&gt;&lt;P&gt; ip address xx.xx.xx.xx xx.xx.xx.xx&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt; crypto map vpnmap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; ip address 192.168.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip flow-export source Vlan1&lt;/P&gt;&lt;P&gt;ip flow-export destination 192.168.100.7 2055&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended meridentunnel&lt;/P&gt;&lt;P&gt; permit ip 192.168.2.0 0.0.0.255 192.168.100.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that enough for you?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2006 17:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487852#M1055527</guid>
      <dc:creator>depadua_chris</dc:creator>
      <dc:date>2006-01-03T17:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: NetFlow through VPN</title>
      <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487853#M1055528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe that the part of the config that you posted looks reasonable. I do have one question: you are sending the net flow data to UDP port 2055 at address 192.168.100.7. Is this the correct address for the Net Flow collector and is the collector listening to this port for Net Flow data?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2006 17:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487853#M1055528</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2006-01-03T17:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: NetFlow through VPN</title>
      <link>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487854#M1055529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just uninstalled and reinstalled the program I'm using to listen for NetFlows.  Since reboots to that server can only be done at night it took a little while   but now I'm sure that the listener is working correctly.  And yes, the NetFlows are using UDP on port 2055 and are going to 192.168.100.7.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2006 13:44:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-through-vpn/m-p/487854#M1055529</guid>
      <dc:creator>depadua_chris</dc:creator>
      <dc:date>2006-01-05T13:44:05Z</dc:date>
    </item>
  </channel>
</rss>

