<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Netflow concerns in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228893#M357588</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Christian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I Haven't see any issues with CPU&lt;/P&gt;&lt;P&gt;2) There were some major changes in the flow export in 8.4(5) which were reversed in a few following versions and then I believe put back to the format introduced in 8.4(5). Only a few &lt;A href="http://www.plixer.com/blog/cisco-netflow/cisco-asa-netflow-flow-export-active-refresh-interval-problems/"&gt;NetFlow collectors&lt;/A&gt; can deal with this change. &lt;/P&gt;&lt;P&gt;3) I agree with Julio.&amp;nbsp; make sure the template record is exported each minute&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 May 2013 00:52:15 GMT</pubDate>
    <dc:creator>jakewilson</dc:creator>
    <dc:date>2013-05-24T00:52:15Z</dc:date>
    <item>
      <title>ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228892#M357587</link>
      <description>&lt;P&gt;Good Morning&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was asked to enable netflow in an ASA Firewall for Orion/Solarwinds server monitoration. Firewall is a 5550, with 4G RAM, and no extra modules but SSM-4GE. This firewall has 5 DMZ segments and ans specific segment for internet traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are segments as unique subinterfaces in physical interfaces. Other segments as individual subinterfaces in the same physical interface (but individual VLANs)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually firewall CPU flows between 30% to 40%. Rarely to 50%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 - How dangerous or risky could be implement netflow in this firewall?...This firewall is very critical for the customer. My concern is regrading CPU, traffic generated, memory, etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 - In a month, firewall will be migrated from 8.2 software version to 8.4 software version. Is there any incompatibility in some commands?...Would be recommended to perform netflow configuration after software upgrade?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3 - How could it be implemented for Orion monitoring, regarding each individual sub-interface (and so, each VLAN assigned)?&lt;/P&gt;&lt;P&gt;I there any recommendation regarding configuration, best practices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228892#M357587</guid>
      <dc:creator>Christian Jorge</dc:creator>
      <dc:date>2019-03-12T01:48:01Z</dc:date>
    </item>
    <item>
      <title>ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228893#M357588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Christian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I Haven't see any issues with CPU&lt;/P&gt;&lt;P&gt;2) There were some major changes in the flow export in 8.4(5) which were reversed in a few following versions and then I believe put back to the format introduced in 8.4(5). Only a few &lt;A href="http://www.plixer.com/blog/cisco-netflow/cisco-asa-netflow-flow-export-active-refresh-interval-problems/"&gt;NetFlow collectors&lt;/A&gt; can deal with this change. &lt;/P&gt;&lt;P&gt;3) I agree with Julio.&amp;nbsp; make sure the template record is exported each minute&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 00:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228893#M357588</guid>
      <dc:creator>jakewilson</dc:creator>
      <dc:date>2013-05-24T00:52:15Z</dc:date>
    </item>
    <item>
      <title>ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228894#M357589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My new question is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer wants I configure netflow for a single interface for now. We check the firewall status, behaviour, etc.&lt;/P&gt;&lt;P&gt;Next time we configure netflow for a second interface and so on until all interfaces be included to netflow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you guys recommend I perform this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All&amp;nbsp; articles I found treated netflow configuration using global policy-map.&lt;/P&gt;&lt;P&gt;I think of creating a new policy-map and input this as&amp;nbsp; service-policy by interface, but I'm afraid regarding have same&amp;nbsp; service-policy repeated in eadh interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 20:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228894#M357589</guid>
      <dc:creator>Christian Jorge</dc:creator>
      <dc:date>2013-06-19T20:25:23Z</dc:date>
    </item>
    <item>
      <title>ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228895#M357590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Instead of creating a new serivce policy, I recommend adding it to an existing service policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sylvester&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 12:08:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228895#M357590</guid>
      <dc:creator>smetieh001</dc:creator>
      <dc:date>2013-06-20T12:08:31Z</dc:date>
    </item>
    <item>
      <title>ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228896#M357591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now I have only the global policy-map. No other kind of policy-map created&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 13:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228896#M357591</guid>
      <dc:creator>Christian Jorge</dc:creator>
      <dc:date>2013-06-20T13:14:28Z</dc:date>
    </item>
    <item>
      <title>ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228897#M357592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it means you can create a service policy for an interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new class-map&lt;/STRONG&gt;&lt;BR /&gt; class-map netflow_int_class&lt;BR /&gt;match any (or a pre-defined acl if you like. i.e access-list netflow_acl permit IP any any)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a policy-map&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Policy-map netflow_Int_policy&lt;BR /&gt;class netflow_int_class&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apply Service-policy to an interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Service-policy netflow_Int_policy interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 13:42:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228897#M357592</guid>
      <dc:creator>smetieh001</dc:creator>
      <dc:date>2013-06-20T13:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228898#M357593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've had that idea to configure a new policy-map (besides that global policy-map), use that new policy-map to perform netwflow action and apply individually in each interesting interface as service-policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking the firewall overhead in the final step, applying that service policy in all interfaces compared to apllying as global policy-map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In summary: what's the overhead using the same policy-map explicitly in all interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Update: I read something that netflow can't be applied using a separated/unique policy-map. Only permitted to use the global one. Anyone could confirm this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 13:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228898#M357593</guid>
      <dc:creator>Christian Jorge</dc:creator>
      <dc:date>2013-06-20T13:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Netflow concerns</title>
      <link>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228899#M357594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gentlemen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any new idea, recommendation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 14:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-netflow-concerns/m-p/2228899#M357594</guid>
      <dc:creator>Christian Jorge</dc:creator>
      <dc:date>2013-06-27T14:21:14Z</dc:date>
    </item>
  </channel>
</rss>

