06-21-2023 06:12 AM - edited 06-21-2023 06:20 AM
Hello, Sorry for my bad english. I am a novice in networking and especially in the use of the Cisco ASA firewall. For a project at school I have to use SecurityOnion to monitor the traffic in a Cisco ASA firewall. The problem is that I was able to do this with PfSense, which natively supports port mirroring, which is not the case for ASA, from what I've read on this forum. So I thought of using a Cisco switch for port mirroring, but would I be able to see all the traffic coming in and out of the ASA with the switch connected to a ASA port?
06-21-2023 09:21 AM
Port mirroring could be an option, you can configure the switch to look at the inside and outside interfaces of the firewall and mirror their traffic. Another option would be to use NetFlow, in this case the firewall will send the traffic flows to a remote NetFlow collector, a free example of this would be the free version of PRTG.
06-21-2023 12:47 PM
Thank You @Aref Alsouqi for your answer. I will make research on PRTG. But I want to know my topology is exact? If Yes how can i see all the traffic from inside and outside at the same time? If you have a procedure I will be happy to learn
06-23-2023 09:16 AM
You're welcome. If you mirror the traffic of the inside and outside ports you would see all the traffic passing through. Same with NetFlow, if you send the flows from both the inside and outside interfaces it would feed the ingress and egress flows.
06-21-2023 12:54 PM
Hi
Which ASA is it? Some models does support port mirroring
06-22-2023 05:36 AM
Hello @Flavio Miranda; I'm using Asav 9.16 actually on GNS3. I'm training home to learn the basics.
06-22-2023 06:08 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide