Monitoring traffic through the ASA

Unanswered Question
Aug 22nd, 2007

I have been using NetFlow to monitor incoming and outgoing traffic on my Cisco 1841 router. The 1841 router is just an edge router but my ASA 5510 is my firewall and where my remote site's VPN connection start and end. I've been seeing some high traffic on my router and since most of it's encrypted I can't tell who is causing all the traffic issues (actual source IP). I know the ASA doesn't support netflow so I wanted to see what other options I have to look more deeply at the traffic going through that device, unencrypted.

Thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
anandramapathy Thu, 08/23/2007 - 05:17

you can log to a syslog server / to the ASDM itself.

Try Kiwi's syslog server which is free for 5 clients.

Check the options under ASDM, logging.

choose the level of logging you want.

srue Thu, 08/23/2007 - 05:24

Do you have an internal router that you could enable netflow on?

Actions

This Discussion