I have a 1841 router running IPSec with an ASA. F0/0 is the source interface. I also configured NetFlow, which is to be sent via the IPSec tunnel to the analyzer. The acl defining the IPSec interesting traffic covers the NetFlow source and destination addresses. But NetFlow traffic is not picked up by the tunnel. When I ping the destination from the router, the icmp traffic is picked up and goes through the tunnel. Are there ways to force NetFlow traffic to go to the tunnel?
Is there a route to the netflow destination address? I've seen issues with traffic that was headed for a destination that wasn't in the routing table not being sent down a VPN.