Configuring Cisco ASA for NetFlow Export via CLI

Posted in ASA, NetFlow, NetFlow Analyzer, Network Traffic Analysis, Scrutinizer, Security on August 8th, 2010 by scottr
configuring-cisco-asa-for-netflow-export-via-cli

Over  the last few weeks I have taken a number of support calls from customers who were looking for some assistance configuring their Cisco ASA. So I figured that I would take this opportunity to revisit some older blog subjects.

In my opinion, the easiest way to get NSEL exporting from these security appliances is through the use of the ASDM interface. This simple, GUI-based firewall management tool allows you to quickly configure the Cisco ASA without having to use the cumbersome command-line interface.

And that brings me to the subject of this blog.

Configuring the Cisco ASA using the CLI is really not that much different that configuring NetFlow on any other router or switch. You define your timeout value, flow export destination, and which interface is going to send the export. The difference is that you need to set up a service policy, and access rules that allow the export. As well as define which events are going to get exported and where.

So let’s get started.

Read more »

Tags: , , , , , , , ,

Network Anomaly Detection with NetFlow and IPFIX Analysis

Posted in NetFlow, NetFlow Analyzer, Network Traffic Analysis, Network Traffic Monitor, Scrutinizer on August 3rd, 2010 by jimmyd
network-anomaly-detection-with-netflow-and-ipfix-analysis
I was working with a customer last week who only wanted TCP, UDP, HOPOPT and ICMP on the network.  In addition to that they wanted to be alarmed if any other transport protocol passed through their Cisco ASA .  I introduced them to the Top Network Transports gadget in Flow Analytics.
Read more »
____________________________________
Jim Dougherty aka "Jimmy D"
International Sales Channel Manager and
Netflow Evangelist for Plixer International!

Follow me on Twitter
http://twitter.com/jimmydnet
____________________________________
Tags: , , , , , , ,

NetFlow Analysis on the Move

Posted in ASA, NetFlow, NetFlow Analyzer, Network Traffic Analysis, Network Traffic Monitor, Scrutinizer, sFlow on July 23rd, 2010 by scottr
netflow-analysis-on-the-move

For most of the last year I have been working as a member of the  Technical Support Team here at Plixer International. But as of July 1st, I have moved from Technical Support to a Pre-Sales Support role on the Sales Team. In my new role I will be responsible for providing technical support for all pre-sales/evaluating customers.

I just want to say that it has been a pleasure working with the many customers that I’ve talked to over the last year. I wish you all much success in your Network Admin/IT endeavors.

If you are new to the NetFlow technology, I would welcome the opportunity to demonstrate the benefits of using NetFlow and our network analysis tool to open windows into what is going on over your network. The following information is made available via the flow packets: source IP address, destination IP address, source port number, destination port number, protocol type, type of services, and the router input interface.

Exporting flows to a NetFlow collector provides a deeper level of detail that was up to this point unavailable in network management. This type of information has proven invaluable in detecting worms, port scans, DDoS attacks, and other security threats and network misuse.

Read more »

Tags: , , , , , , , , ,

What is NetFlow?

Posted in ASA, NetFlow, NetFlow Analyzer, Network Problem Resolution, Network Traffic Analysis, Network Traffic Monitor, Scrutinizer, Security, sFlow on July 21st, 2010 by Jo-G
what-is-netflow

Okay, back to the basics. We’ve been working with Cisco NetFlow technology for many years now, but what is NetFlow?

NetFlow is a traffic profile monitoring technology developed by Darren Kerr and Barry Bruins at Cisco Systems, back in 1996. At that time, network monitoring mostly consisted of seeing how much traffic was traversing your network, but did not include what that traffic was.
Read more »

Tags: , , , , , , , , , , , , , , , , , ,

NetFlow Performance Analysis

Posted in ASA, NetFlow, NetFlow Analyzer, Scrutinizer on July 9th, 2010 by scottr
netflow-performance-analysis

At the support desk we often get asked questions about NetFlow technology and what, if any, performance impact enabling NetFlow will have on their routers or switches.

Cisco® NetFlow technology is an embedded feature within Cisco IOS routers and high end switches. NetFlow data records consist of information about source and destination addresses, along with the protocols and ports used in the end-to-end conversation. The NetFlow feature set allows for the tracking of individual IP flows as they are received at a Cisco router or switching device.

Network administrators can use the NetFlow flow records for a variety of purposes, including accounting, billing, network planning, traffic engineering and user or application monitoring.

Many customers who are new to NetFlow are naturally cautious about introducing it into their network. They need to understand the potential performance impact of enabling NetFlow before they are willing to deploy it. Cisco has released a NetFlow Performance Analysis paper that examines the CPU impact of enabling NetFlow services in various scenarios on several different Cisco hardware platforms.

Before you get too concerned about what the report is showing, look at those flow numbers. They represent a ”worst-case scenario” in terms of the traffic flows seen by the routers, and the results must be viewed in that context.

Now that you have decided to enable NetFlow on your routers and switching devices, it’s time to put that flow data to work for you.

Let us show you how our NetFlow and sFlow Analysis Tool provides the best custom reporting engine on the market today, supporting leading edge technologies like Cisco ASA, Flexible NetFlow, IPFIX, and NBAR.

Give me a call – (207)324-8805

-Scott

Tags: , , , , , , , , , , , , ,

NetFlow Rap Star meets High School Student

Posted in ASA, NetFlow, NetFlow Analyzer, Network Traffic Analysis, Network Traffic Monitor, Scrutinizer, sFlow on June 25th, 2010 by scottr
netflow-rap-star-meets-high-school-student

My daughter recently started a temporary Marketing position here at Plixer. And as with most people when they get their first job, she was very nervous about the new environment she would be coming into.

Adding to her nervous tension was the opportunity to see and meet Mix Master Mitch in person.

While I would not lump her in with the usual NetFlow maniacs that follow Mitch from town to town, I am sure she was aware of his superstar status and had seen the Mix Master’s videos (who hasn’t?). For the first few days, she would try to avoid the famous artist for fear of embarrassment. It wasn’t until Mitch left an autographed 8×10 on her desk that she finally was able to relax around the Rap legend.

Don’t miss your chance to see Mitch and his NetFlow posse live as the tour heads out to sunny Las Vegas next week for Cisco Live!

Stop by the Plixer booth and let the team show you how our NetFlow and sFlow Analysis Tool provides the best custom reporting engine on the market today, supporting leading edge techologies like Cisco ASA, Flexible NetFlow, IPFIX, and NBAR.

Put our network monitoring and analysis tools to work for you today.

Give us a call – (207) 324-8805

-Scott

Tags: , , , , , , , , ,

NetFlow Analysis is a Must in Today’s Network

Posted in ASA, NetFlow, NetFlow Analyzer, Network Traffic Analysis, Scrutinizer, sFlow on June 11th, 2010 by scottr
netflow-analysis-is-a-must-in-todays-network

Why do you want to know what is going on in the traffic flow of a network?

What’s the point?

Why doesn’t utilization alone cut it?

Network Administrators don’t typically have a lot of time on a day-to-day basis. There is always some fire to fight, some network or user issue that comes up. Most times your juggling more than one issue at a time. So you find yourself spending most of your time trying to keep the network running and the users happy.

A Network Administrator’s abilities are only as good as his awareness of what happens on his network.

Monitoring and maintaining your network traffic and bandwidth utilization used to be an overlooked aspect of your job. But evolution of technology has changed the makeup of networks everywhere and has forced network managers to include Flow analysis and monitoring in their network management strategies.

Network Flow Analysis is the art of studying the traffic on a computer network. It is the  industry-standard method of collecting and recording network traffic. Flow analysis lets you see what types of traffic passed between hosts, without having to reproduce the problem.

Read more »

Tags: , , , , , , , , , , , , , , ,

Watch the NetFlow Reporting and Network Traffic Analysis Webinar

Posted in ASA, NetFlow, NetFlow Analyzer, Network Traffic Analysis on June 10th, 2010 by Jon Mills
watch-the-netflow-reporting-and-network-traffic-analysis-webinar

For those of you that missed Plixer’s recent series of webinars, aimed at getting the most out of NetFlow using their latest and greatest NetFlow and sFlow analyzer, there is still hope. A recording of the webinar has been made available online for your viewing pleasure. Just click the image below to watch this 40 minute presentation.

Michael Patterson, Scrutinizer Product Manager, covered a range of topics in this traffic monitoring centric presentation.

Read more »


Jon Mills
Marketing & Public Relations Manager
Follow Me On Twitter
Tags: , , , , , , , , ,

Case Study: Lawrence Technological University

Posted in ASA, NetFlow, NetFlow Analyzer, Network Problem Resolution, Network Traffic Analysis, Network Traffic Monitor, Scrutinizer, Security on June 9th, 2010 by Jo-G
case-study-lawrence-technological-university

Lawrence Technological University is among Michigan’s largest independent colleges and also Michigan’s first completely wireless laptop campuses, as well as one of the largest wireless networks in the Midwest.

This recently published case study demonstrates how successful network traffic analysis can be performed using NetFlow reporting with Scrutinizer NetFlow Analyzer. Monitoring NetFlow exported from devices such as Cisco ASA’s, routers, switches, and numerous other NetFlow compatible devices simplifies the task of managing your network, whether wired or, in LTU’s case, fully wireless.

Read more »

Tags: , , , , , , , , ,

NetFlow from a Checkpoint Firewall

Posted in NetFlow, NetFlow Analyzer on June 6th, 2010 by mike@plixer.com
netflow-from-a-checkpoint-firewall

I wonder how many firewalls (IP Security Appliances) have been sold to date.  Since we have been in business, we have purchased 4. I can’t imagine a company being attached to the internet without one.  

Currently we have both a SonicWALL and a Cisco ASA.   It is great to see that some firewalls such as the Cisco ASA, Fortinet  and Checkpoint are now supporting NetFlow.  Read more »

Michael Patterson
Scrutinizer Product Manager
Tags: , , , , ,