Monitoring traffic through the ASA

Unanswered Question
Aug 22nd, 2007
User Badges:

I have been using NetFlow to monitor incoming and outgoing traffic on my Cisco 1841 router. The 1841 router is just an edge router but my ASA 5510 is my firewall and where my remote site's VPN connection start and end. I've been seeing some high traffic on my router and since most of it's encrypted I can't tell who is causing all the traffic issues (actual source IP). I know the ASA doesn't support netflow so I wanted to see what other options I have to look more deeply at the traffic going through that device, unencrypted.


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
anandramapathy Thu, 08/23/2007 - 05:17
User Badges:
  • Bronze, 100 points or more

you can log to a syslog server / to the ASDM itself.

Try Kiwi's syslog server which is free for 5 clients.

Check the options under ASDM, logging.

choose the level of logging you want.

srue Thu, 08/23/2007 - 05:24
User Badges:
  • Blue, 1500 points or more

Do you have an internal router that you could enable netflow on?

bob.mckinley Thu, 08/23/2007 - 05:26
User Badges:

No, just a Cisco 3560 switch, which doesn't support Netflow.


This Discussion