cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
204
Views
0
Helpful
1
Replies

Cisco Netflow ASA

John Apricena
Level 1
Level 1

Hey Guys,

 

I have a question regarding reading Netflow info. I have a collector configured and it works perfectly fine. I noticed today that we saw a huge spike this morning for about 15 minutes, but the connection just shows from one ASA to another ASA. We have a P2P VPN between these, but why would it show the source and destination as these two devices, instead of the actual hosts?

The ports are random source and destination, and the protocol is 50. Can someone advise how this happens, and if this is something to be alarmed about? As always, thanks in advance for all your help.

1 Reply 1

John Apricena
Level 1
Level 1

If you need any more info from me regarding this, please let me know.

Review Cisco Networking products for a $25 gift card