cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
614
Views
0
Helpful
1
Replies

ASA as a Prime Assurance Source

Marvin Rhoads
VIP Community Legend VIP Community Legend
VIP Community Legend

I'm looking over the documentation (reference) and experimenting with a system and it appears that an ASA's Netflow records cannot be properly parsed and read by Prime Infrastructure. (It appears the same holds for a Nexus 7010 but I've not tried to set it up to export just yet.)

My ASA is an 5585-X SSP 20 with software 9.2(2.4). Prime Infrastructure is 2.1 with all the latest device packs and patches. (The Nexus is running NX-OS 6.2(8a).)

I confirm the ASA's Netflow records are coming into PI on udp/9991. PI creates "Flexible Netflow upnprocessed" type templates and allows me to add the ASA as a licensed collector. It counts the flow records received but will not show me anything in the Service Assurance Performance Monitoring dashboard.

Can anyone confirm their experience?

 

UPDATE - Even though it's not listed in the support page, I was able to configure the Nexus and see the traffic in PI. I followed the example in the Nexus 7000 System Management Configuration Guide.

Now I'm trying to figure out how to make destinations display their DNS name instead of just IP address.

1 Reply 1

Marvin Rhoads
VIP Community Legend VIP Community Legend
VIP Community Legend

Another thread pointed out that ASA Netflow support is explicitly NOT in PI 2.1 per the release notes.

Oh well....

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers