<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD / FMC And Netflow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4110296#M1071491</link>
    <description>&lt;P&gt;Thanks Marvin, I was hoping you'd be the one to reply. Thank you very much for confirming my theory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a great weekend!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
    <pubDate>Sat, 27 Jun 2020 17:43:00 GMT</pubDate>
    <dc:creator>mlorincz</dc:creator>
    <dc:date>2020-06-27T17:43:00Z</dc:date>
    <item>
      <title>FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3919551#M17932</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any experience with a (v)FTD (6.4.0.4) using only a mangement interface for mangement and a passive interface for IDS, where stealthwatch shoud be apart of that solution also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Netflow has been configured through FMC with flexConfig. I can see the config is on the device with a show running-config in cli.&lt;/P&gt;&lt;P&gt;My stealthwatch collector is not getting any data.&lt;/P&gt;&lt;P&gt;I have been running a tcpdump port 2055 on both the FTD and the stealthwatch collector, but i have only seen one packet going between them, nothing else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have testes the collector with another netflow source, and that works and i can see the data in the stealthwatch management center.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it work with a passive interface or should it be routed or inline before it will work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3919551#M17932</guid>
      <dc:creator>pejedkcco</dc:creator>
      <dc:date>2020-02-21T17:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3919719#M17953</link>
      <description>&lt;P&gt;I've not done it with FTD passive interface but have done it with routed interface (on 6.4.0.4) feeding Stealthwatch.&lt;/P&gt;
&lt;P&gt;Have you configured the diagnostic interface (not br1 management) with an IP address? That's your Netflow (NSEL) source.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 15:46:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3919719#M17953</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-05T15:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3919997#M17969</link>
      <description>&lt;P&gt;Yes, there are an ip address on the diagnostic interface.&lt;/P&gt;&lt;P&gt;I can see through a tcpdump on the stealthwatch collector that there is 2 packets comming from the FTD and then all stops.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other sources work fine with the stealthwatch collector.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 05:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3919997#M17969</guid>
      <dc:creator>pejedkcco</dc:creator>
      <dc:date>2019-09-06T05:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3920172#M17976</link>
      <description>&lt;P&gt;Have you confirmed (check your show running-config) that your desired Netflow configuration was successfully pushed via Flexconfig?&lt;/P&gt;
&lt;P&gt;I followed the guide posted here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/configuring-nsel-netflow-on-cisco-firepower-threat-defense-ftd/ta-p/3646300" target="_blank"&gt;https://community.cisco.com/t5/security-documents/configuring-nsel-netflow-on-cisco-firepower-threat-defense-ftd/ta-p/3646300&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;...and had good results. My Stealthwatch has been getting Netflow events from FTD ever since.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 13:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/3920172#M17976</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-06T13:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4110139#M1071473</link>
      <description>&lt;P&gt;Anyone ever get netflow exporting from inside interface? packet-tracers show it being dropped by implicit deny at the end, but when sourced from mgmt-ip or another IP in the subnet it is allowed. Almost as if the netflow exporting isn't being sourced from a zone/interface. I'd rather not have to configure diagnostic interface, this is on a ASA5525 running ftd code.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figured if anyone would know the answer it's you smart people.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2020 00:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4110139#M1071473</guid>
      <dc:creator>mlorincz</dc:creator>
      <dc:date>2020-06-27T00:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4110234#M1071483</link>
      <description>&lt;P&gt;Currently it's only supported from the diagnostic interface. We expect this to change in Firepower 6.7 later this year.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2020 12:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4110234#M1071483</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-06-27T12:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4110296#M1071491</link>
      <description>&lt;P&gt;Thanks Marvin, I was hoping you'd be the one to reply. Thank you very much for confirming my theory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a great weekend!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2020 17:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4110296#M1071491</guid>
      <dc:creator>mlorincz</dc:creator>
      <dc:date>2020-06-27T17:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4260421#M1076766</link>
      <description>&lt;P&gt;This is likely due to packets not going through the full LINA flow when in inline / passive mode.&amp;nbsp; See this reference:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/214487-netflow-and-other-features-are-not-suppo.html#anc6" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/214487-netflow-and-other-features-are-not-suppo.html#anc6&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 23:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4260421#M1076766</guid>
      <dc:creator>David Mitchell</dc:creator>
      <dc:date>2020-12-17T23:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4270896#M1077194</link>
      <description>&lt;P&gt;hi came across this topic i have been asked to get netflow working to our 3rd party network tools from managengine and all the info was for versions 6.2 firmware but we are on 6.7 in our FTD to take advantage of the VTIs. do i still have to configure the diagnostic interface for netflow or can it use the management interface that was configured still new to this device&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 15:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4270896#M1077194</guid>
      <dc:creator>billystevenson24098</dc:creator>
      <dc:date>2021-01-12T15:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD / FMC And Netflow</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4582179#M1088789</link>
      <description>&lt;P&gt;** ignore ** &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 19:35:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-and-netflow/m-p/4582179#M1088789</guid>
      <dc:creator>mlorincz</dc:creator>
      <dc:date>2022-03-30T19:35:10Z</dc:date>
    </item>
  </channel>
</rss>

