Trouble viewing Netflow data from ASA5510

Scrutinizer is an enterprise/business class NetFlow and sFlow analysis tool. Scrutinizer provides historical trends of the company's critical network interfaces as well as the details on:

Who: The end system causing the traffic
What: The application/protocol that is being used
When: The time frame it has been occurring for
Where: The network connection that is affected

Moderators: scottr, Moderator Team

Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Fri Jul 29, 2011 3:01 pm

Hi, I have configured my ASA5510 to export netflow to my Scrutinizer v8.6.1.14902 collector. All indications are the collector see's the netflow data as the device has showed up and under devices I can see the interfaces after updating via SNMP. I cannot seem to figure out how to view any data at all from the ASA. Everything shows no data and no templates. Other routers and switches are working fine. Have already verified that the Template timeout is set to 1 minute and the transmission delay is set to 15 seconds. Please help.

Thanks,
Mike
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Re: Trouble viewing Netflow data from ASA5510

Postby BenjaminM » Fri Jul 29, 2011 3:44 pm

Are you running the free version or the evaluation version?
-The evaluation version has full functionality while the free version is limited.
If the Device showing up in Scrutinizer? If it is gray, than the devices may be set to inactive in the device details? (located in the admin tab under definitions)
If you have Wireshark, you can go to edit> preferences >protocols>UDP and then verify UDP Checksums. If you inspect one of the netflow packets and the checksums are not correct than the operating system is throwing them away before they get to scrutinizer.
Benjamin Moore
Plixer International Tech Support
(207)324-8805 ex:4
Bio: viewtopic.php?f=20&t=2404
Twitter: http://twitter.com/ActiveBeerGeek/
User avatar
BenjaminM
 
Posts: 63
Joined: Tue Mar 01, 2011 11:33 am
Location: Sanford, Maine

Re: Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Fri Jul 29, 2011 3:57 pm

Ok, device is/was enabled and checksums are correct according to Wireshark. Wireshark running on the collector definitely shows plenty of CFLOW netflow v9 traffic coming from the ASA.

Thanks,
Mike
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Re: Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Fri Jul 29, 2011 3:58 pm

Sorry, I missed answering your other question.... I am using the 'Free' version.

Mike
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Re: Trouble viewing Netflow data from ASA5510

Postby mpatters » Fri Jul 29, 2011 7:34 pm

Hello,

Did you setup the ASA to export NetFlow correctly? http://media.plixer.com/screencasts/ciscoAsaConfigurationUsingAsdm/ciscoAsaConfigurationUsingAsdm.html

I've also posted a video on reporting on NetFlow from the ASA:
http://media.plixer.com/screencasts/scrutV7ASA/scrutV7ASA/scrutV7ASA.html

I hope these help.

Mike
Michael Patterson
Scrutinizer Product Manager
(207)324-8805 x222
Bio: viewtopic.php?f=20&t=1296
Blogs: http://www.plixer.com/blog/author/mikeplixercom/
Twitter: http://twitter.com/netflowpm
User avatar
mpatters
 
Posts: 248
Joined: Mon Oct 30, 2006 11:27 pm
Location: Sanford, Maine

Re: Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Mon Aug 01, 2011 8:55 am

Ok, it appears the ASA is setup correctly to export Netflow to my collector. Running Wireshark on my collector I see many packets of Netflow traffic being sent to the collector from the ASA. I simply can't seem to figure out where to view the flows etc inside Scrutinizer. The ASA device shows up in the device explorer however when I click 'Show Interfaces' it reports 'There are no interfaces that match your search'.
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Re: Trouble viewing Netflow data from ASA5510

Postby BenjaminM » Mon Aug 01, 2011 9:12 am

Hello Mike,

How many devices are you currently receiving NetFlow from? If you are running the free version as opposed to the evaluation version than Scrutinizer only supports 5 devices. If the ASA is the 6th than you may be experiencing these symptoms.

What color is the icon for the ASA in the device explorer?

What version of the ASA software are you running?
Benjamin Moore
Plixer International Tech Support
(207)324-8805 ex:4
Bio: viewtopic.php?f=20&t=2404
Twitter: http://twitter.com/ActiveBeerGeek/
User avatar
BenjaminM
 
Posts: 63
Joined: Tue Mar 01, 2011 11:33 am
Location: Sanford, Maine

Re: Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Mon Aug 01, 2011 9:54 am

The ASA is only the third device. All three icons are green in the device explorer panel. ASA is running 8.2(5). ASDM version is 6.4(5).

Thanks
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Re: Trouble viewing Netflow data from ASA5510

Postby BenjaminM » Mon Aug 01, 2011 10:37 am

Can you call into our Presales Tech Support line? 207-324-8805 x257
Benjamin Moore
Plixer International Tech Support
(207)324-8805 ex:4
Bio: viewtopic.php?f=20&t=2404
Twitter: http://twitter.com/ActiveBeerGeek/
User avatar
BenjaminM
 
Posts: 63
Joined: Tue Mar 01, 2011 11:33 am
Location: Sanford, Maine

Re: Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Wed Aug 03, 2011 8:43 am

Ok I called in Monday afternoon and the guy who answered advised everyone was tied up at that time and that someone would return my call. So far I have not heard from anyone.

Thanks,
Mike
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Re: Trouble viewing Netflow data from ASA5510

Postby BenjaminM » Wed Aug 03, 2011 9:26 am

Hello Mike,

We only provide Technical Support over the phone for customers who own the product or who are evaluating to purchase. Support for free customers can only be provided through the forums here. I apologize for the inconvenience.

Have you had a chance to view our blog post on configuring ASA via ASDM?
http://www.plixer.com/blog/netflow/sett ... -asdm-6-2/
Benjamin Moore
Plixer International Tech Support
(207)324-8805 ex:4
Bio: viewtopic.php?f=20&t=2404
Twitter: http://twitter.com/ActiveBeerGeek/
User avatar
BenjaminM
 
Posts: 63
Joined: Tue Mar 01, 2011 11:33 am
Location: Sanford, Maine

Re: Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Wed Aug 03, 2011 9:57 am

Ok I understand. Was simply following the instructions that were posted above. I have reviewed and followed the instructions posted above Not sure where to go from here.

Mike
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Re: Trouble viewing Netflow data from ASA5510

Postby tomp » Wed Aug 03, 2011 10:16 am

Can you post portions of your config related to NetFlow,

For instance, here is part of mine:

flow-export destination Inside xxx.xxx.xxx.xxx 2055
flow-export template timeout-rate 1
flow-export delay flow-create 15
!
class-map flow_export_class
match any
!
policy-map global_policy
description flow_export_policy
class inspection_default
inspect dns migrated_dns_map_1
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
class flow_export_class
flow-export event-type all destination xxx.xxx.xxx.xxx
User avatar
tomp
Site Admin
 
Posts: 289
Joined: Wed Jul 27, 2005 9:53 am
Location: Sunny Sanford Maine

Re: Trouble viewing Netflow data from ASA5510

Postby tomp » Wed Aug 03, 2011 10:17 am

Additionally: what image version are you running on your ASA?
User avatar
tomp
Site Admin
 
Posts: 289
Joined: Wed Jul 27, 2005 9:53 am
Location: Sunny Sanford Maine

Re: Trouble viewing Netflow data from ASA5510

Postby mbrooks@esi911.com » Wed Aug 03, 2011 12:55 pm

name xxx.xxx.xxx.xxx mbrooks-pc
flow-export destination Inside mbrooks-pc 9996
flow-export template timeout-rate 1
flow-export delay flow-create 15

class-map global-class
match any

policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp
inspect pptp
inspect http
inspect ip-options
class global-class
flow-export event-type all destination mbrooks-pc
class class-default
!

I am running ASA image 8.2(5). ASDM is 6.4(5).

Thanks,
Mike
mbrooks@esi911.com
 
Posts: 11
Joined: Wed Oct 15, 2008 12:36 pm

Next

Return to Scrutinizer

Who is online

Users browsing this forum: No registered users and 0 guests

Who is online

In total there are 0 users online :: 0 registered, 0 hidden and 0 guests (based on users active over the past 5 minutes)
Most users ever online was 60 on Thu Jun 25, 2009 9:07 am

Users browsing this forum: No registered users and 0 guests