cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
972
Views
0
Helpful
1
Replies

ASA as a Prime Assurance Source

Marvin Rhoads
Hall of Fame
Hall of Fame

I'm looking over the documentation (reference) and experimenting with a system and it appears that an ASA's Netflow records cannot be properly parsed and read by Prime Infrastructure. (It appears the same holds for a Nexus 7010 but I've not tried to set it up to export just yet.)

My ASA is an 5585-X SSP 20 with software 9.2(2.4). Prime Infrastructure is 2.1 with all the latest device packs and patches. (The Nexus is running NX-OS 6.2(8a).)

I confirm the ASA's Netflow records are coming into PI on udp/9991. PI creates "Flexible Netflow upnprocessed" type templates and allows me to add the ASA as a licensed collector. It counts the flow records received but will not show me anything in the Service Assurance Performance Monitoring dashboard.

Can anyone confirm their experience?

 

UPDATE - Even though it's not listed in the support page, I was able to configure the Nexus and see the traffic in PI. I followed the example in the Nexus 7000 System Management Configuration Guide.

Now I'm trying to figure out how to make destinations display their DNS name instead of just IP address.

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Another thread pointed out that ASA Netflow support is explicitly NOT in PI 2.1 per the release notes.

Oh well....