cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
484
Views
0
Helpful
3
Replies

IPSec Tunnel and NetFlow Packets

Chuan Liu
Level 1
Level 1

I have a 1841 router running IPSec with an ASA. F0/0 is the source interface. I also configured NetFlow, which is to be sent via the IPSec tunnel to the analyzer. The acl defining the IPSec interesting traffic covers the NetFlow source and destination addresses. But NetFlow traffic is not picked up by the tunnel. When I ping the destination from the router, the icmp traffic is picked up and goes through the tunnel. Are there ways to force NetFlow traffic to go to the tunnel?

Thanks.

1 Accepted Solution

Accepted Solutions

cleidh_mor
Level 1
Level 1

Is there a route to the netflow destination address? I've seen issues with traffic that was headed for a destination that wasn't in the routing table not being sent down a VPN.

View solution in original post

3 Replies 3

cleidh_mor
Level 1
Level 1

Is there a route to the netflow destination address? I've seen issues with traffic that was headed for a destination that wasn't in the routing table not being sent down a VPN.

Yes, I have a static host route. the traffic is always sent to the next hop router, not into the IPSec tunnel that is defined by the acl.

Hi,

The problem is solved by the static route pointing to the outgoing interface instead of the next-hop address.

Thanks for directing me to think in the correct way.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: