<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Flow-Export problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272935#M348169</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Try to clear the counters of the "flow-export" output by running the "&lt;STRONG&gt;clear flow-export counters&lt;/STRONG&gt;" command and then collect the output of the "&lt;STRONG&gt;show flow-export counters&lt;/STRONG&gt;" five minutes after the clearing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Share the output with us.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jun 2013 17:54:03 GMT</pubDate>
    <dc:creator>Favaloro.</dc:creator>
    <dc:date>2013-06-13T17:54:03Z</dc:date>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272932#M348165</link>
      <description>&lt;P&gt;I have followed this document for configuring my ASA5525-X running 9.1 for netflow export:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.draware.dk/fileadmin/SolarWinds/Guide/How_to_configure_Netflow_on_a_Cisco_ASA.pdf" target="_blank"&gt;http://www.draware.dk/fileadmin/SolarWinds/Guide/How_to_configure_Netflow_on_a_Cisco_ASA.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cant seem to get it to work though. I see the counter increasing, I see the ACL hit count going up, but my server is not getting into.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run a packet trace from my ASA to my Solarwinds server it says denied by an implicit deny.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the difference between the ACL Manager and Access Rules in ASDM?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272932#M348165</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2019-03-12T01:56:56Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272933#M348167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet tracer is for traffic going across the ASA not to or from the ASA itself. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL manager shows all the ACL's configured on the ASA (VPN, NAT, AAA, etc) and Access Rules shows only the ACL's applied to the interfaces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Juan Lombana&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 21:28:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272933#M348167</guid>
      <dc:creator>julomban</dc:creator>
      <dc:date>2013-06-12T21:28:37Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272934#M348168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ATIASA5525-01# show run | inc flow&amp;nbsp; &lt;/P&gt;&lt;P&gt;access-list flow-export-acl extended permit ip any any &lt;/P&gt;&lt;P&gt;flow-export destination inside 10.170.5.80 2055&lt;/P&gt;&lt;P&gt;flow-export template timeout-rate 5&lt;/P&gt;&lt;P&gt;flow-export delay flow-create 60&lt;/P&gt;&lt;P&gt;class-map flow-export-class&lt;/P&gt;&lt;P&gt; match access-list flow-export-acl&lt;/P&gt;&lt;P&gt; class flow-export-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; flow-export event-type all destination 10.170.5.80&lt;/P&gt;&lt;P&gt;ATIASA5525-01# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp &lt;/P&gt;&lt;P&gt; class flow-export-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; flow-export event-type all destination 10.170.5.80&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;&amp;nbsp; inspect icmp &lt;BR /&gt; class flow-export-class&lt;BR /&gt;&amp;nbsp; flow-export event-type all destination 10.170.5.80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone see any reason why this wouldnet work? If more clips of the running config is needed, let me know. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 17:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272934#M348168</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2013-06-13T17:32:39Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272935#M348169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Try to clear the counters of the "flow-export" output by running the "&lt;STRONG&gt;clear flow-export counters&lt;/STRONG&gt;" command and then collect the output of the "&lt;STRONG&gt;show flow-export counters&lt;/STRONG&gt;" five minutes after the clearing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Share the output with us.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 17:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272935#M348169</guid>
      <dc:creator>Favaloro.</dc:creator>
      <dc:date>2013-06-13T17:54:03Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272936#M348171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is about 30 minutes as I got caught up doing other things. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;destination: inside 10.170.5.80 2055&lt;BR /&gt;&amp;nbsp; Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; packets sent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6891&lt;BR /&gt;&amp;nbsp; Errors:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; block allocation failure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; invalid interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; template send failure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no route to collector&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; source port allocation failure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;ATIASA5525-01# &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 18:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272936#M348171</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2013-06-13T18:44:33Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272937#M348173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Can you confirm the Netflow collector is actively listening on port 2055?&lt;/P&gt;&lt;P&gt;Can you confirm the packets are making it to the server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the ASA the only device reporting to that same server? If not, are the other devices having issues with it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember, the ASA works with Netflow v9 only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 19:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272937#M348173</guid>
      <dc:creator>Favaloro.</dc:creator>
      <dc:date>2013-06-13T19:07:23Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272938#M348175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have about 7 riverbeds exporting just fine to it on port 2055. I also have a 3845 exporting to it. All devices are fine. Just seems to be the ASA. From the asa I can ping the netflow server, and vice versa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 19:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272938#M348175</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2013-06-13T19:10:56Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272939#M348177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Just to be sure, let's try to get a packet capture and confirm that the Netflow information from the ASA is arriving to the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the Netflow collector application you are using?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 20:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272939#M348177</guid>
      <dc:creator>Favaloro.</dc:creator>
      <dc:date>2013-06-13T20:24:23Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272940#M348178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Using Solarwinds NTA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What protocol of traffic should I be seeing from the ASA to the Netflow Collector?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see syslog, SNMP, and Cflow traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 14:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272940#M348178</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2013-06-14T14:30:04Z</dc:date>
    </item>
    <item>
      <title>Flow-Export problem</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272941#M348179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; UGH!&amp;nbsp; Solarwinds NTA issue, hotfix#3 for version 3.10.0 fixes the issue for ASA OS 8.4 and higher.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 15:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-problem/m-p/2272941#M348179</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2013-06-14T15:01:09Z</dc:date>
    </item>
  </channel>
</rss>

