<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic flow-export from ASA5505 (Software is 8.4) to netflow collector  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/flow-export-from-asa5505-software-is-8-4-to-netflow-collector/m-p/2162453#M359616</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;This is work OK.&lt;/P&gt;&lt;P&gt;------------------------------------------------------ &lt;BR /&gt;Helping seriously ill children, all together. All information about this, is posted on my blog&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 24 Mar 2013 07:16:31 GMT</pubDate>
    <dc:creator>Oleg Volkov</dc:creator>
    <dc:date>2013-03-24T07:16:31Z</dc:date>
    <item>
      <title>flow-export from ASA5505 (Software is 8.4) to netflow collector through L2L IPSec tunnel</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-from-asa5505-software-is-8-4-to-netflow-collector/m-p/2162451#M359613</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hello&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have three ASA5505, two firewalls connected to central VPN hub.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the central inside network is &lt;STRONG&gt;192.168.0.0/24&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network A is &lt;STRONG&gt;192.168.1.0/24&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network B is &lt;STRONG&gt;192.168.2.0/24&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In one of this site (central), I have server with NetFlow collector.&lt;/P&gt;&lt;P&gt;I will collect the traffic information from all ASA at the my one server.&lt;/P&gt;&lt;P&gt;Now, in all of those firewall I use access lists like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(site A ASA)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VPNACL extended permit ip 192.168.1.0 255.255.255.0 192.168.0.0 255.255.255.0&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VPNACL extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Central site ASA)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VPNACL_TO_A extended permit ip 192.168.0.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VPNACL_TO_A extended permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And VPN working normally.&lt;/P&gt;&lt;P&gt;But I try to use flow-export and has a problem.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can I configure source IP address (or source interface - inside) for NetFlow packet, originate from ASA? (for example from site A)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is not possible I think, I can rewrite my access lists and permit udp traffic from outside interface to server IP like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VPNACL permit udp host &amp;lt;Outside IP site A&amp;gt; host &amp;lt;Inside IP the Server&amp;gt; eq 9996&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I do not understand, what port I must be use in access list on Central site ASA.&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VPNACL_A permit udp host &amp;lt;Inside IP the Server&amp;gt; host &amp;lt;Outside IP site A&amp;gt;&amp;nbsp; eq 9996&lt;/STRONG&gt; ? or, in this place, must be source port in the udp netflow packet?&lt;/P&gt;&lt;P&gt;Can I not specify port in thish ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;------------------------------------------------------ &lt;BR /&gt;Helping seriously ill children, all together. All information about this, is posted on my blog&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-from-asa5505-software-is-8-4-to-netflow-collector/m-p/2162451#M359613</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2019-03-12T01:18:30Z</dc:date>
    </item>
    <item>
      <title>flow-export from ASA5505 (Software is 8.4) to netflow collector</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-from-asa5505-software-is-8-4-to-netflow-collector/m-p/2162452#M359615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can source it from the inside interface using the flow-export command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;flow-export destination inside &lt;NETFLOW-COLLECTOR-IP&gt;&lt;/NETFLOW-COLLECTOR-IP&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Mar 2013 22:04:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-from-asa5505-software-is-8-4-to-netflow-collector/m-p/2162452#M359615</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2013-03-23T22:04:08Z</dc:date>
    </item>
    <item>
      <title>flow-export from ASA5505 (Software is 8.4) to netflow collector</title>
      <link>https://community.cisco.com/t5/network-security/flow-export-from-asa5505-software-is-8-4-to-netflow-collector/m-p/2162453#M359616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;This is work OK.&lt;/P&gt;&lt;P&gt;------------------------------------------------------ &lt;BR /&gt;Helping seriously ill children, all together. All information about this, is posted on my blog&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Mar 2013 07:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-export-from-asa5505-software-is-8-4-to-netflow-collector/m-p/2162453#M359616</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2013-03-24T07:16:31Z</dc:date>
    </item>
  </channel>
</rss>

