Hey Guys,
I have a question regarding reading Netflow info. I have a collector configured and it works perfectly fine. I noticed today that we saw a huge spike this morning for about 15 minutes, but the connection just shows from one ASA to another ASA. We have a P2P VPN between these, but why would it show the source and destination as these two devices, instead of the actual hosts?
The ports are random source and destination, and the protocol is 50. Can someone advise how this happens, and if this is something to be alarmed about? As always, thanks in advance for all your help.