cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
190
Views
0
Helpful
1
Replies

Cisco Netflow ASA

John Apricena
Level 1
Level 1

Hey Guys,

 

I have a question regarding reading Netflow info. I have a collector configured and it works perfectly fine. I noticed today that we saw a huge spike this morning for about 15 minutes, but the connection just shows from one ASA to another ASA. We have a P2P VPN between these, but why would it show the source and destination as these two devices, instead of the actual hosts?

The ports are random source and destination, and the protocol is 50. Can someone advise how this happens, and if this is something to be alarmed about? As always, thanks in advance for all your help.

1 Reply 1

John Apricena
Level 1
Level 1

If you need any more info from me regarding this, please let me know.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: