Caligare NetFlow - Knowledgebase
Search:     Advanced search
Browse by category:
Glossary | Contact Us

Cisco ASA and NetFlow

Add comment
Views: 2334
Votes: 0
Comments: 0

Several of our customers are using Cisco ASA device and they tried to export NetFlow v9 to Caligare Flow Inspector without success. After debuging we find the problem. In the ASA NetFlow there is missing a packet field in the netflow export. The number of packets is very important for CFI . Without it, the users cannot perform the most of statistics. NetFlow Security Event Logging or NetFlow Event Logs (NELs) (used by Cisco ASA) isn’t about traffic in and out of an interface. It’s more like syslog logging and RMON. Three event types can trigger a NetFlow record: flow-create, flow-denied and flow-teardown. All of these types have a different flow template, but no one export packet count. See NetFlow packet dump below.

Wireshark packet dump for Cisco ASA Netflow
Fig.: NetFlow packet dump on Cisco ASA


The result is Caligare Flow Inspector is NOT compatible with Cisco ASA due to missing a packet field. We hope Cisco will add a packet field in one of the next releases.

More sources:
Cisco ASA - NetFlow Collectors
Monitoring the Security Appliance

As alternative you can use FlowMon probes. The probe sniff all traffic going through the line. The main advantage of probe is its ability to analyze every packet at wire-speed up to 10 Gbps, it is L2/L3 invisible and can be connected to any point of your network. The probe can be connected to the user network in three ways: via mirrored port (SPAN); via Ethernet splitter (TAP); or via built-in splitter. See the following URL http://www.caligare.com/product/flowmon/ for more information about probes.

Also read
document On which Cisco device is netflow supported?

Others in this Category
document I configured NetFlow on Cat6500, but application shows only a few MBytes, whereas it should have been several GBytes.
document Is it possible to use the vrf interface as source of netflow packets?
document EARL NetFlow error messages
document How can I configure netflow on Cisco?
document "Unable to change flowmask" error message on Cisco 6500
document What means "TCAM Utilization" and "ICAM Utilization"?
document On which Cisco device is netflow supported?
document What is difference between "ip flow ingress" and "ip route-cache flow"?
document Is NetFlow version 9 supported on 3620? Where can I find the document to see the supported devices?
document NetFlow on a Cisco 4500 series. Do I need a NetFlow services card?
document Can I use a bridged IP traffic NetFlow on PFC3A?
document I would like to get NetFlow information from individual layer 2 switch ports.
document I'm seeing all in traffic passing through interface, but no out traffic.
document How can I enable netflow on Cisco 3550 or Cisco 3750 devices?
document What is diference between normal, fast and long mls aging?
» More articles



RSS