cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
746
Views
0
Helpful
2
Replies

Bandwidth and Conversations

oneirishpollack
Level 1
Level 1

Our network is designed as follows:

Access Switch ---  (VLANS)  ----> Core Switch (SVIs)   -----Inside --> ASA 5510 --Outside-----> Edge Router

Our internal traffic gets PAT'd to a specific outside address based on the VLAN it is on.

We are trying to track what specific internal (private) addresses are utilizing the most bandwidth and where they are going.

I have setup netflows on the edge router and am able to send them to our Foglight NMS. The only problem is that I get the PAT'd external address as the source and the destination address. Since that address is a pool address for all the devices on a VLAN, it doesn't narrow down the specific machine on the inside that is sending.

I have also setup netflows on my L3 Core switch and am able to send them to our Foglight NMS. The only problem there is that I get the individual (inside) private addresses, but with a destinating of the SVIs (gateway). So that doesn't narrow down where they are going.

In short, using the ASA, NMS, or some other method (sniffer?), what is the best way to collect the source (inside address) to destination (outside address) to determine the amount of data, the speific inside device, and the specific outside address it is going to? I would like to so this both ways - inside to outside and outside to inside.

It would provide with something like the example below:

Source        Destination        Port/Protocol/Application  Packets       KBps

10.9.3.12     8.8.4.4              80                                    79502          106,1816


Thanks for any and all suggestions you can provide. 

1 Accepted Solution

Accepted Solutions

brett.harding
Level 1
Level 1

Hi,

I suspect you are performing PAT on the ASA. It is strange that flows from the Core Switch are showing all destinations as the SVI interface, do you have proxy arp enabled? You may want to look at implementing netflow on your ASA5510. Netflow v9 is support on the ASA platform starting with version ASA 8.2.1/ASDM 6.2.1

Hope that helps

Cheers

Brett

View solution in original post

2 Replies 2

brett.harding
Level 1
Level 1

Hi,

I suspect you are performing PAT on the ASA. It is strange that flows from the Core Switch are showing all destinations as the SVI interface, do you have proxy arp enabled? You may want to look at implementing netflow on your ASA5510. Netflow v9 is support on the ASA platform starting with version ASA 8.2.1/ASDM 6.2.1

Hope that helps

Cheers

Brett

Thanks. Upgrading to ASA 8.2 and then following the instructions below did the trick:

https://supportforums.cisco.com/servlet/JiveServlet/showImage/102-6114-4-1786/sp5.JPG

Review Cisco Networking for a $25 gift card