<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 is sending netflow records instead of netflow flows in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571225#M610152</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well as I mentioned originally - I ran packet sniffer Wire Shark to verify that yes indeed the packets from the ASA are getting to the Solar Winds server.&amp;nbsp; It's just that they are ver 9 and most of my routers are sending v5 netflow packets.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Sep 2010 22:38:08 GMT</pubDate>
    <dc:creator>mmedwid</dc:creator>
    <dc:date>2010-09-30T22:38:08Z</dc:date>
    <item>
      <title>ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571218#M610145</link>
      <description>&lt;P&gt;Following the URL below I setup netflow on my ASA to be able to analyze traffic through the firewall.&amp;nbsp; My netflow analyzer is Solar Winds Netflow Traffic Analyzer buit it is not perceiving receipt of the packets although I know from wire shark they are getting there.&amp;nbsp; I noticed a difference in the packets from the ASA and the routers is that the ASA netflow packets are "records" whereas all the routers send netflow "flows".&amp;nbsp; Why the difference?&amp;nbsp; Can I get the ASA to send "flows".&amp;nbsp; If no - might there be some way for Solar Winds to be able to process ASA netflow records?&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/document/30476/configuring-netflow-asa-asdm" target="_blank"&gt;https://supportforums.cisco.com/docs/DOC-6114&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571218#M610145</guid>
      <dc:creator>mmedwid</dc:creator>
      <dc:date>2019-03-11T18:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571219#M610146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA supports the new netflow v9 nsel and it doesnt function like your normal router netflow.&amp;nbsp; What you are seeing is correct as we will generate a netflow data record for connections that are building or being torn down.&amp;nbsp; There are a few other events as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check out this doc as it will provide more information on the nsel netflow v9 .&amp;nbsp; Your collector must support the cisco ASA firewall.&amp;nbsp; I believe there is a version of the solarwinds that does have this support.&amp;nbsp; There are not many collectors that do support it so you will need to check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please check out:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/monitor_nsel.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/monitor_nsel.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 20:23:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571219#M610146</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-09-30T20:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571220#M610147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to Solar Winds &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;HR class="dotted" /&gt;&lt;DIV class="question"&gt;&lt;P&gt;&lt;STRONG&gt;Which versions of NetFlow does Orion NetFlow Traffic Analyzer support?&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="answer"&gt;&lt;P&gt;Orion NetFlow Traffic Analyzer can collect data from all devices that support NetFlow v5, NetFlow v9, sFlow, or J-Flow. NetFlow v9 devices are supported using NetFlow v5 data formats.&lt;/P&gt;&lt;/DIV&gt;&lt;HR class="dotted" /&gt;&lt;DIV class="question"&gt;&lt;P&gt;&lt;STRONG&gt;Can Orion NTA analyze NetFlow from Cisco ASA devices?&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="answer"&gt;&lt;P&gt;Yes, Orion NTA supports all Cisco Adaptive Security Appliance (ASA) models.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what Netflow v9 devices are supported using v5 data formats.&amp;nbsp; ??&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.solarwinds.com/products/orion/nta/faq.aspx"&gt;http://www.solarwinds.com/products/orion/nta/faq.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 20:32:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571220#M610147</guid>
      <dc:creator>mmedwid</dc:creator>
      <dc:date>2010-09-30T20:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571221#M610148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks good.&amp;nbsp; Your solarwinds should be able to interpret the nsel v9 being sent by the ASA.&amp;nbsp; You mentioned you received records, so it sounds like its working.&amp;nbsp; As for seeing the same info as you saw on your router, the nsel is different and wont be able to provide the same type of data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 20:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571221#M610148</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-09-30T20:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571222#M610149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It could be that I have 3.5 Netflow TA and they are up to 3.7.&amp;nbsp; Downloading now...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 20:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571222#M610149</guid>
      <dc:creator>mmedwid</dc:creator>
      <dc:date>2010-09-30T20:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571223#M610150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I upgraded solar winds netflow analyzer to 3.7 but it still is not perceiving receipt of the netflow packets from the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 22:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571223#M610150</guid>
      <dc:creator>mmedwid</dc:creator>
      <dc:date>2010-09-30T22:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571224#M610151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the solarwinds is not seeing any data from the ASA?&amp;nbsp; If that is the case, then you will probably want to run a sniffer trace on the interface going towards the solarwinds to make sure the ASA is sending out the data.&amp;nbsp; If it is sending the data, then you may want to open a case with solarwinds on the data not showing up on the collector.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 22:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571224#M610151</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-09-30T22:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571225#M610152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well as I mentioned originally - I ran packet sniffer Wire Shark to verify that yes indeed the packets from the ASA are getting to the Solar Winds server.&amp;nbsp; It's just that they are ver 9 and most of my routers are sending v5 netflow packets.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 22:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571225#M610152</guid>
      <dc:creator>mmedwid</dc:creator>
      <dc:date>2010-09-30T22:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571226#M610153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it sounds like something on the processing side of the solarwinds if its not showing any traffic from the ASA since you had verified it was sending it via the wireshark earlier.&amp;nbsp; I would probably suggest checking with them if there is some knob or something to turn on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 22:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571226#M610153</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-09-30T22:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571227#M610154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your Cisco ASA running at least version 8.2 or more recent?&amp;nbsp; This firewall and its NetFlow support have been blogged about extensively on the plixer blog.&amp;nbsp; Also, it might be worth trying a different NetFlow Analyzer like Scrutinizer just to gather more details around the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NetFlows exported by the Cisco ASA. Check out this PDF:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.plixer.com/files/netflow-on-the-asa-11-18-09.pdf"&gt;&lt;SPAN style="color: #2f6681;"&gt;http://www.plixer.com/files/netflow-on-the-asa-11-18-09.pdf&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; * no export of ToS&lt;/P&gt;&lt;P&gt;&amp;nbsp; * no packet count&lt;/P&gt;&lt;P&gt;&amp;nbsp; * bidirectional flows (reply flow is added to the initiating flow) non rfc 5103 compliant&lt;/P&gt;&lt;P&gt;&amp;nbsp; * no active timeout&lt;/P&gt;&lt;P&gt;&amp;nbsp; * no TCP flags&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would consider testing the issue with another NetFlow Analyzer. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 09:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571227#M610154</guid>
      <dc:creator>jakewilson</dc:creator>
      <dc:date>2010-10-01T09:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571228#M610155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well having spent $$ on Solar Winds Netflow TA - they gotta just make it work.&amp;nbsp; They claim it supports ASA and netflow 9 so it's on them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're running 8.2(1)11 btw.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 16:17:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571228#M610155</guid>
      <dc:creator>mmedwid</dc:creator>
      <dc:date>2010-10-01T16:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 is sending netflow records instead of netflow flows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571229#M610156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our product manager posted a new Cisco ASA video today:&lt;/P&gt;&lt;P&gt;&lt;A href="http://media.plixer.com/screencasts/scrutV7ASA/scrutV7ASA/scrutV7ASA.html"&gt;http://media.plixer.com/screencasts/scrutV7ASA/scrutV7ASA/scrutV7ASA.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps it will help our friends at solarwinds. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Warm Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jake&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 00:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-is-sending-netflow-records-instead-of-netflow-flows/m-p/1571229#M610156</guid>
      <dc:creator>jakewilson</dc:creator>
      <dc:date>2010-10-06T00:08:40Z</dc:date>
    </item>
  </channel>
</rss>

