<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSM 4.4sp1 netflow configuration for ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csm-4-4sp1-netflow-configuration-for-asa/m-p/2230858#M920728</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running Cisco Security Manager 4.4 service pack 1 and our ASA's are all running 9.0.2/9.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've hit a problem with export to netflow from my ASA firewalls configured through CSM.&lt;/P&gt;&lt;P&gt;We configure the netflow export under platform/logging and enable flow export. Looking at the "show flow-export counters" on the ASA very few flows are exported however and no netflow shows up in our netflow analyzer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the deployment this is what is deployed (for netflow):&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;! COMMENT: Bulk request written; reading response...&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;Line# 2. (SUCCESS) Sent (Fri Jun 07 08:50:05 CEST 2013): flow-export template timeout-rate 1&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; Received (Fri Jun 07 08:50:05 CEST 2013): &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;Line# 3. (SUCCESS) Sent (Fri Jun 07 08:50:05 CEST 2013): flow-export destination outside 146.2.217.125 19996&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; Received (Fri Jun 07 08:50:05 CEST 2013): &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;Line# 4. (SUCCESS) Sent (Fri Jun 07 08:50:05 CEST 2013): flow-export delay flow-create 60&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I understand it I need to match what traffic to export to netflow which is setup as a service policy rule. I cannot find any option to export to netflow under the service policy rules however (only IPS,CXSC, Connection Settings, QoS, CSC, User statistics and Scansafe). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured a flexconfig to append to the configuration and this seems to export the data until the next time a policy is pushed. The configuration changes done by the flexconfig are then removed from the ASA and netflow stops working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My flexconfig (append) looks like this:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;access-list netflow-hosts extended permit ip any any&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;class-map NetFlow-traffic&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&amp;nbsp; match access-list netflow-hosts&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;policy-map global_policy&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; class NetFlow-traffic&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&amp;nbsp; flow-export event-type all destination X.X.X.X&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anybody found a way to get netflow export work correctly when configured using CSM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Michel&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:54:23 GMT</pubDate>
    <dc:creator>Michel Pedersen</dc:creator>
    <dc:date>2020-02-21T12:54:23Z</dc:date>
    <item>
      <title>CSM 4.4sp1 netflow configuration for ASA</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4sp1-netflow-configuration-for-asa/m-p/2230858#M920728</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running Cisco Security Manager 4.4 service pack 1 and our ASA's are all running 9.0.2/9.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've hit a problem with export to netflow from my ASA firewalls configured through CSM.&lt;/P&gt;&lt;P&gt;We configure the netflow export under platform/logging and enable flow export. Looking at the "show flow-export counters" on the ASA very few flows are exported however and no netflow shows up in our netflow analyzer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the deployment this is what is deployed (for netflow):&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;! COMMENT: Bulk request written; reading response...&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;Line# 2. (SUCCESS) Sent (Fri Jun 07 08:50:05 CEST 2013): flow-export template timeout-rate 1&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; Received (Fri Jun 07 08:50:05 CEST 2013): &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;Line# 3. (SUCCESS) Sent (Fri Jun 07 08:50:05 CEST 2013): flow-export destination outside 146.2.217.125 19996&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; Received (Fri Jun 07 08:50:05 CEST 2013): &lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;Line# 4. (SUCCESS) Sent (Fri Jun 07 08:50:05 CEST 2013): flow-export delay flow-create 60&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I understand it I need to match what traffic to export to netflow which is setup as a service policy rule. I cannot find any option to export to netflow under the service policy rules however (only IPS,CXSC, Connection Settings, QoS, CSC, User statistics and Scansafe). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured a flexconfig to append to the configuration and this seems to export the data until the next time a policy is pushed. The configuration changes done by the flexconfig are then removed from the ASA and netflow stops working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My flexconfig (append) looks like this:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;access-list netflow-hosts extended permit ip any any&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;class-map NetFlow-traffic&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&amp;nbsp; match access-list netflow-hosts&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;policy-map global_policy&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; class NetFlow-traffic&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&amp;nbsp; flow-export event-type all destination X.X.X.X&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anybody found a way to get netflow export work correctly when configured using CSM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Michel&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4sp1-netflow-configuration-for-asa/m-p/2230858#M920728</guid>
      <dc:creator>Michel Pedersen</dc:creator>
      <dc:date>2020-02-21T12:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: CSM 4.4sp1 netflow configuration for ASA</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4sp1-netflow-configuration-for-asa/m-p/2230859#M920729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try adding in the following line under flexconfig with the rest of your netflow configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;flow-export template timeout-rate 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are my flexconfig on my firewalls using CSM:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list global_mpc extended permit ip any any&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt;match access-list global_mpc&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; flow-export event-type all destination x.x.x.x&lt;/P&gt;&lt;P&gt;flow-export template timeout-rate 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 16:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4sp1-netflow-configuration-for-asa/m-p/2230859#M920729</guid>
      <dc:creator>wkho</dc:creator>
      <dc:date>2013-11-26T16:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: CSM 4.4sp1 netflow configuration for ASA</title>
      <link>https://community.cisco.com/t5/network-security/csm-4-4sp1-netflow-configuration-for-asa/m-p/2230860#M920730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We just upgraded to CSM 4.5 and I have verified that Netflow configuration is now fully supported there so no need to use a flexconfig to make it work anymore. In CSM 4.5 we can finally specify a service policy to match the netflow traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Case closed for us &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Michel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 16:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-4-4sp1-netflow-configuration-for-asa/m-p/2230860#M920730</guid>
      <dc:creator>Michel Pedersen</dc:creator>
      <dc:date>2013-11-26T16:45:37Z</dc:date>
    </item>
  </channel>
</rss>

