cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
250
Views
1
Helpful
4
Replies

How ASA send NSEL data? I am confuse.

sir_yrwins
Level 1
Level 1

Cisco ASA send NSEL data . "Netflix Secure Event Logging. 

Hello I bit confuse how the 3 map are configure are and what they do. 

can some please tell me if I am correct how ASA is setup to send DATA to NSEL. 
Policy Map = setup to collect IP address
Class Map = setup to match policy
Service Map = setup to apply policy globally . 

  

4 Replies 4

tvotna
Spotlight
Spotlight

In ASA CLI this looks as follows. ACL defines traffic. Connections that match ACL will trigger NetFlow event generation. Class-map refers to ACL and policy-map (which is applied by default via service-policy CLI) activates the feature.

flow-export destination inside <IP> <UDP-port>
flow-export template timeout-rate 1
flow-export active refresh-interval 1

access-list netflow-hosts extended permit ip any any

class-map NetFlow-traffic
 match access-list netflow-hosts

policy-map global_policy
 class NetFlow-traffic
 flow-export event-type all destination <IP>

logging flow-export-syslogs disable

Last command is optional. It blocks flow creation/teardown syslogs to reduce load, because the same information is sent via NetFlow to NetFlow collector.