<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 8.2 NSEL netflow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171905#M859977</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For what it is worth, I talked to someone from Netflow Auditor today and they said they should be able to parse this data with Version 4 which comes out in June sometime. I am going to download version 4 and get a trial key when it is available to test this capability. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 May 2009 16:06:00 GMT</pubDate>
    <dc:creator>delawarecity</dc:creator>
    <dc:date>2009-05-20T16:06:00Z</dc:date>
    <item>
      <title>ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171902#M859974</link>
      <description>&lt;P&gt;I recently updated to ASA code version 8.2, and am trying ti find a utility that can read/interperate the NSEL output, and hopefully give some bandwidth stats.  I ahve tried orion, scrutanizer, and advantnet.  the first two didnt report anything, and adventnet only reported some IP address, but did not recognize the interface names or give any data bandwidths.  It just said index1 and index2 for the interfaces.  &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171902#M859974</guid>
      <dc:creator>ryancolson</dc:creator>
      <dc:date>2019-03-11T15:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171903#M859975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The adaptive security appliance implementation of NSEL is a stateful, IP flow tracking method that exports only those records that indicate significant events in a flow. In stateful flow tracking, tracked flows go through a series of state changes. NSEL events are used to export data about flow status, and are triggered by the event that caused the state change. &lt;/P&gt;&lt;P&gt;NSEL has the following prerequisites: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢IP address and hostname assignments must be unique throughout the NetFlow configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢You must have at least one configured collector before you can use NSEL. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢You must configure NSEL collectors before you can configure filters via Modular Policy Framework. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 14:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171903#M859975</guid>
      <dc:creator />
      <dc:date>2009-05-15T14:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171904#M859976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok I still dont know what I am supposed to use to read the flow logs/exports.  As I have said two of the three I have tried showed absolutely nothing, and the 3rd didnt seem to be able to make much sense of it.  Besides MARS, what can I use to read NSEL?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 May 2009 04:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171904#M859976</guid>
      <dc:creator>ryancolson</dc:creator>
      <dc:date>2009-05-17T04:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171905#M859977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For what it is worth, I talked to someone from Netflow Auditor today and they said they should be able to parse this data with Version 4 which comes out in June sometime. I am going to download version 4 and get a trial key when it is available to test this capability. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 16:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171905#M859977</guid>
      <dc:creator>delawarecity</dc:creator>
      <dc:date>2009-05-20T16:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171906#M859978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Leave it to Cisco to implement "Netflow" that doesn't work well with any collectors.  This is almost as bad as netflow support for the SUP720's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to get this working as far as exporting you can go here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/monitor.html#wp1109506" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/monitor.html#wp1109506&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the basics of what you need.&lt;/P&gt;&lt;P&gt;flow-export destination &lt;INTERFACE nameif=""&gt; &lt;COLLECTOR ip=""&gt; &lt;PORT number=""&gt;&lt;/PORT&gt;&lt;/COLLECTOR&gt;&lt;/INTERFACE&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map netflow_export_class&lt;/P&gt;&lt;P&gt; match any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!             &lt;/P&gt;&lt;P&gt;policy-map netflow_export_policy&lt;/P&gt;&lt;P&gt; class netflow_export_class&lt;/P&gt;&lt;P&gt;  flow-export event-type all destination &lt;COLLECTOR ip=""&gt;&lt;/COLLECTOR&gt;&lt;/P&gt;&lt;P&gt;!             &lt;/P&gt;&lt;P&gt;service-policy netflow_export_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "match any" and "flow-export event-type all" lines force the export of ALL NSEL events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless you have MARS, your collector probably will get the packets and pull ifindex numbers for the interfaces, both physical and virtual, but you will not get any of the payload data from the netflow packets.  I am very disappointed in this revelation, but sadly, not surprised.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 May 2009 17:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171906#M859978</guid>
      <dc:creator>kghutton</dc:creator>
      <dc:date>2009-05-29T17:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171907#M859979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The NSEL record generated by netflow configuration in 8.2 is based on NetFlow version 9, which as been an RFC since 2004.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ietf.org/rfc/rfc3954.txt" target="_blank"&gt;http://www.ietf.org/rfc/rfc3954.txt&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 04:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171907#M859979</guid>
      <dc:creator>plumbis</dc:creator>
      <dc:date>2009-06-02T04:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171908#M859980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any netflow collector that understands NetFlow v9 should be able to collect the netflow data from your ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 04:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171908#M859980</guid>
      <dc:creator>plumbis</dc:creator>
      <dc:date>2009-06-02T04:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171909#M859981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thats the thing- I have tried several that do support V9 and they cant read from the ASA(but they can read from a 1721 exporting in V9 just fine)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 10:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171909#M859981</guid>
      <dc:creator>ryancolson</dc:creator>
      <dc:date>2009-06-02T10:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2 NSEL netflow</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171910#M859982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;v9 is pretty straight forward and I know that it can be read in wireshark if you collected packet captures to verify. Is there something specifically that your collector isn't dealing well with? I know I've seen problems where collectors are looking for the bytes in the flow which is ID 1, but that is never sent by the ASA as ID 1 is the number of bytes since the last update. The ASA uses ID 85 which is the total bytes sent. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 03:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-nsel-netflow/m-p/1171910#M859982</guid>
      <dc:creator>plumbis</dc:creator>
      <dc:date>2009-06-03T03:42:11Z</dc:date>
    </item>
  </channel>
</rss>

