cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
785
Views
0
Helpful
1
Replies

How to implement Netflow through VPN tunnel on the WAN router

jackawang
Level 5
Level 5

Site-to-site IPSec VPN tunnel is built between the hub datacenter and a remote site using ASA5505. The remote site ASA connects to a Cisco C2811 router and then goes to the ISP edge. The requirement is to enable Netflow on the WAN router and collect data. The Netflow Analyser (Solarwinds-Orion) resides in the hub datacenter's LAN.

Netflow Analyzer (10.1.1.10) --- (10.1.1.1)ASA1(123.1.2.1) ---- (123.1.2.2)Router1(125.5.5.5) ---->Internet< ----- (126.6.6.6)Router2(100.2.2.2)----(100.2.2.1)ASA2(10.2.1.1)---LAN

I'd like to get Netflow stats on the WAN routers between IPSec devices. And the stats need to be encrypted. In other words, I do not want to send Netflow data across the public network. My thought was to send Netflow data through the IPSec tunnel. How can I accomplish this?

1 Reply 1

jackawang
Level 5
Level 5

I've heard "same-security-traffic permit intra-interface" needs to be configured on the ASA2 outside interface. Does anyone have a complete thought how to make it work? Any idea would be appreciated.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: