Configuring Cisco ASA 5500 series


 

ASA NetFlow export is dependent on the version of ASA software running. ASA version 8.2 software supports NetFlow export across all ASA models. The following fields must be included in the ASA configuration to export flow data to the NetFlow Analyzer .

 

The following commands must be included in your global service policy for NetFlow export to function.

 

(config)# flow-export destination inside NetFlow Analyzer server IP address 9996
(config)# flow-export template timeout-rate 1
(config)# flow-export delay flow-create 60
(config)# logging flow-export syslogs disable
(config)# access-list netflow-export extended permit ip any any
(config)# class-map netflow-export-class
(config-cmap)#match access-list netflow-export
(config)# policy-map netflow-export-policy
(config-pmap)# class netflow-export-class
(config-pmap-c)# flow-export event-type any destination NetFlow Analyzer server IP

(config)#service-policy netflow_export_policy global


For more clarification regarding this, please go to http://forums.manageengine.com/#topic/49000003577055

Copyright © 2010, ZOHO Corp. All Rights Reserved.
ManageEngine