<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netflow on ASA with Manage Engine NTA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691228#M562244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks I have attached the packet capture file. i have not enabled ping on the asa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 May 2011 17:26:53 GMT</pubDate>
    <dc:creator>chelsea4ever</dc:creator>
    <dc:date>2011-05-16T17:26:53Z</dc:date>
    <item>
      <title>Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691224#M562240</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have been trying to use the netflow features V9 with Manage engine NTA. I configured the ASA for netflow via ASDM. When i go to the webconsole of the Manage Engine i get this message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt; No device is currently exporting NetFlow / sFlow packets to NetFlow Analyzer. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Listening for NetFlow / sFlow Packets at Port 9996 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i decided to verify my configuration using the # show flow-export counters&lt;/P&gt;&lt;P&gt;and i had this output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciscoasa# sh flow-export counters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;destination: inside 192.168.1.10 9996&lt;BR /&gt;&amp;nbsp; Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; packets sent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 180&lt;BR /&gt;&amp;nbsp; Errors:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; block allocation failure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; invalid interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; template send failure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;no route to collector&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By looking at the last line made me think i had no route to the collector from the ASA. What do i need to do.&lt;/P&gt;&lt;P&gt;I have attached the running configuration of my ASA. Help me to sort this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A class="boldTxt blueLink" title="Add policy enabled device" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:33:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691224#M562240</guid>
      <dc:creator>chelsea4ever</dc:creator>
      <dc:date>2019-03-11T20:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691225#M562241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hi, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;You are missing a couple of commands there, please add &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; "&gt;flow-export destination inside 192.168.1.10 &lt;PORT that="" collector="" should="" listen="" to=""&gt;&lt;BR /&gt;&lt;/PORT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; "&gt;flow-export template timeout-rate 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to ping the collector from the ASA. You can use the following guide for reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-6113"&gt;https://supportforums.cisco.com/docs/DOC-6113&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any questions, let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 16:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691225#M562241</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-16T16:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691226#M562242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply. the 2 commands u mentioned are already in my config &lt;/P&gt;&lt;P&gt;Pls refer to my attached doc. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 17:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691226#M562242</guid>
      <dc:creator>chelsea4ever</dc:creator>
      <dc:date>2011-05-16T17:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691227#M562243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ohh, Didnt see those... can you run a packet capture?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture test interface inside match udp any any eq 9996&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then download the capture as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://192.168.1.1/capture/test/pcap"&gt;https://192.168.1.1/capture/test/pcap&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, were you able to ping the server from the ASA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 17:16:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691227#M562243</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-16T17:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691228#M562244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks I have attached the packet capture file. i have not enabled ping on the asa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 17:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691228#M562244</guid>
      <dc:creator>chelsea4ever</dc:creator>
      <dc:date>2011-05-16T17:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691229#M562245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue ist that there is no template for the NTA to read the netflow data, however, the packets are being sent. Would you please take this command out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;flow-export delay flow-create 60&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, take a capture for 2 minutes and then send it to me again.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 17:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691229#M562245</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-16T17:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691230#M562246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have taken the command off and have attached the captured file. thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 17:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691230#M562246</guid>
      <dc:creator>chelsea4ever</dc:creator>
      <dc:date>2011-05-16T17:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691231#M562247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I can see that the firewall its doing its job, from this point now you will need to troubleshoot the server. On the attached capture you can see that the firewall is sending the flow information, in the previous capture I was not able to see it because the template didnt arrived. Now with this new capture, I can see the template and I can see that the flow is being sent to the collector.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that this is not an ASA problem, but you can start wireshark on the server to see if you get the template and if you see the flows, if you do, it would be an application issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 18:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691231#M562247</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-16T18:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691232#M562248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you finally managed to sort the issue out. Windows 7 firewall was the issue. disabled it and works without any issue &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 19:02:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691232#M562248</guid>
      <dc:creator>chelsea4ever</dc:creator>
      <dc:date>2011-05-16T19:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691233#M562249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Excellent, I thought of something like that. I am glad that everything is working. Thank you for posting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 19:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691233#M562249</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-16T19:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691234#M562250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for helping me out. btw i have to ask when i issued the&amp;nbsp; sh flow-export counters command why did i get a no route to collector output. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 19:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691234#M562250</guid>
      <dc:creator>chelsea4ever</dc:creator>
      <dc:date>2011-05-16T19:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow on ASA with Manage Engine NTA</title>
      <link>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691235#M562252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, if you notice, the counter is on 0, so it did not have issues with no route to collector, If the collector would have been on a non-directly connected network and the ASA wouldnt have a route to it, you would be able to see the counter incrementing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 19:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netflow-on-asa-with-manage-engine-nta/m-p/1691235#M562252</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-16T19:17:13Z</dc:date>
    </item>
  </channel>
</rss>

