Cisco ASA 5505: Talk about NetFlow templates!

Posted in NetFlow Analyzer on July 13th, 2009 by mike@plixer.com
cisco-asa-5505-talk-about-netflow-templates

I received a WireShark capture from someone else the other day. He said that the default timeout was set for 30 minutes and believes that this is why the earlier capture he gave me had no templates.

He applied the following command on the Cisco ASA5505 running image asa821-k8:

“flow template timeout-rate 1″

His ASA5505 sent out about 20 different Cisco NetFlow v9 flow types and we still only captured about 15 of the ~20 templates.

asa5505WireShark
WireShark needs the templates to go back and decipher the flows captured prior. Else, you will see what is below in the WireShark capture. Notice that template 263 isn’t in the list above and this was in the same packet capture:

asa5505WireShark2

Another project for me: What does this mean:

asa5505WireShark3

I’m going to have to roll up my sleeves on this one. Time to dig in. Once I have the data collected, we can take a look at what we might be able to report on for network traffic analysis.

If you want to try this with your ASA hardware, here is a page to help you find the necessary enable ASA NetFlow commands .

Michael Patterson
Scrutinizer Product Manager
Follow Me on Twitter
Share and Enjoy:
  • Digg
  • StumbleUpon
  • Reddit
  • del.icio.us
  • Facebook
  • Yahoo! Buzz
  • Google Bookmarks
  • Technorati
  • Twitter
  • email
  • Print
Tags: , , , , , ,

2 Responses to “Cisco ASA 5505: Talk about NetFlow templates!”

  1. Dario Says:

    Did you sort out what were those 7233, 7235, etc? Figured out by now it is a bug on Wireshark ?

  2. Mike Patterson Says:

    Yes, we did but I wasn’t involved with the solution. I don’t know what the developers did. This is a useful document: http://www.cisco.com/en/US/docs/security/asa/asa81/netflow/netflow.html

Leave a Reply