cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
764
Views
0
Helpful
1
Replies

ASA as a Prime Assurance Source

Marvin Rhoads
Hall of Fame
Hall of Fame

I'm looking over the documentation (reference) and experimenting with a system and it appears that an ASA's Netflow records cannot be properly parsed and read by Prime Infrastructure. (It appears the same holds for a Nexus 7010 but I've not tried to set it up to export just yet.)

My ASA is an 5585-X SSP 20 with software 9.2(2.4). Prime Infrastructure is 2.1 with all the latest device packs and patches. (The Nexus is running NX-OS 6.2(8a).)

I confirm the ASA's Netflow records are coming into PI on udp/9991. PI creates "Flexible Netflow upnprocessed" type templates and allows me to add the ASA as a licensed collector. It counts the flow records received but will not show me anything in the Service Assurance Performance Monitoring dashboard.

Can anyone confirm their experience?

 

UPDATE - Even though it's not listed in the support page, I was able to configure the Nexus and see the traffic in PI. I followed the example in the Nexus 7000 System Management Configuration Guide.

Now I'm trying to figure out how to make destinations display their DNS name instead of just IP address.

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Another thread pointed out that ASA Netflow support is explicitly NOT in PI 2.1 per the release notes.

Oh well....

Review Cisco Networking for a $25 gift card