I have a scenario where in the Core Switch (6500) is running only as Layer 2. And this switch is connected to a Firewall via trunk links. Behind the core switch is access switches on where the user and server farm is connected. The server's/user's gateway is the firewall.
I want to implement netflow at the core but the flow monitor command is not supported on the trunk ports. The core switch only has one SVI, which is only meant for management traffic (like ssh, tacacs, snmp, ntp). Whats the other way to implement netflow on the Core so it capture all user and server traffics.
Personally I don't believe you able to achieve what you looking to do over L2, what kind of FW you have If this is ASA you can able to achieve, or any other FW if this is next-generation one you should able to use Netflow feature.
ASA Configuration sample for NSEL:
FTD Configuration sample for NSEL: