05-18-2009 08:13 AM
Can MARS parse the NSEL (netflow) output from a version 8.2 ASA appliance?
Should I send the output to MARS or wait for a MARS update?
05-20-2009 02:05 AM
Yes it does, please check Table 2 on the following link:
Please rate if helpful.
Regards
Farrukh
05-20-2009 05:37 AM
Thanks for reply.
I forgot that the higher end ASA models were able to generate netflows at the 8.1 level. I guess the capability to parse v9 netflow was probably added to MARS at that time. The lower end models only received that capability in version 8.2. Since there was no 8.2 version to select in MARS, I wasn't sure if it would work correctly.
05-20-2009 11:13 AM
Are you sure that 8.2 supports netflow for the lower ASA models? I don't see this mentioned in the release notes:
http://www.cisco.com/en/US/docs/security/asa/asa82/release/notes/asarn82.html#wp229690
Regards
Farrukh
05-20-2009 11:19 AM
Check this link:
Cut and paste from article:
Cisco NetFlow Secure Event Logging: This feature was originally introduced on the Cisco ASA 5580, and is now extended to other Cisco ASA models to provide administrators with more comprehensive event logging information.
05-20-2009 10:37 PM
Ahh ok, I hope its true :)
Thanks for the link.
Regards
Farrukh
05-21-2009 05:42 AM
Update:
I just received my first reports based on the netflow data from our ASA 5510. The ASA is generating netflow and MARS is parsing it correctly.
05-21-2009 12:33 PM
Thanks for the update :)
Regards
Farrukh
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: