What is NSEL? A Deeper Look – Part 2

Posted in ASA, NetFlow, NetFlow Analyzer, Scrutinizer on January 22nd, 2010 by scottr
what-is-nsel-a-deeper-look-part-2

A few months ago Nathan invited us to take a deeper look at NSEL. NSEL is the NetFlow exported from an ASA Firewall. He showed us how to enable and configure ASA for NetFlow.

Traditional NetFlow records upstream and downstream traffic between two end points as two different flows. In the case of an ASA device, most bidirectional flows are already assembled internally and are considered a single flow. So the flow records reported by NetFlow on an ASA Firewall will describe both directions of the flow.

Today I am going to do brief overview of what each of the templates is telling us.

Read more »

Tags: , , , , , , , , ,

Identify more than just the ingress and egress packet throughput on your ASA Firewall

Posted in ASA, NetFlow, Scrutinizer on October 15th, 2009 by scottr
identify-more-than-just-the-ingress-and-egress-packet-throughput-on-your-asa-firewall

NSEL (NetFlow Security Event Logging) is the type of NetFlow exported from an ASA Firewall. The purpose of NSEL is to track firewall events via NetFlow and to have a summary of all conversations associated with that event type.

The three most popular event types that trigger a NetFlow record are:

                                            * flow-create
                                            * flow-denied
                                            * flow-teardown

Read more »

Tags: , , , , , , , , , , , , , ,

Setting up the ASA to export NetFlow using Cisco ASDM 6.2

Posted in NetFlow on September 16th, 2009 by mike@plixer.com
setting-up-the-asa-to-export-netflow-using-cisco-asdm-6-2

Get started with Cisco ASDM 6.2
To setup the NetFlow export from your ASA which must be running version 8.2.1 or newer, bring up the Cisco ASDM (Adaptive Security Device Manager) and setup the NetFlow exporters:

loveMyTool4 Read more »

Michael Patterson
Scrutinizer Product Manager
Follow Me on Twitter
Tags: , , , , , , , , , , , , ,