Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Netflow over IPSec only every 2 seconds


I have a strange issue. I have a VPN between a C3745 and a ASA 5510. The VPN is up and traffic passes through... However, when it come to Netflow, there is a strage behaviour... ASA only receives packets every 2 seconds... The strange thing is that, if I remove the VPN config, traffic flows a lot more... Here is the router config....

crypto isakmp policy 10
hash md5
authentication pre-share
crypto isakmp key mypresharedkey address
crypto ipsec transform-set myset1 esp-des esp-md5-hmac
crypto map NETFLOW_MAP 5 ipsec-isakmp
set peer
set transform-set myset1
match address NETFLOW_ACL

sh access-lists NETFLOW_ACL
Extended IP access list NETFLOW_ACL
    2 permit ip host host (2066 matches)
    10 permit ip host (29742615 match)

RPCO1INT1#sh run int loopback 0
Building configuration...

Current configuration : 100 bytes
interface Loopback0
ip address

interface FastEthernet0/0
ip address
no ip redirects
ip flow ingress
ip nat inside
ip virtual-reassembly
load-interval 30
speed 100
no cdp enable
crypto map NETFLOW_MAP

ip route
ip route FastEthernet0/0

ip flow-export source Loopback0
ip flow-export version 5
ip flow-export destination 2055

Also, I noticed this netflow message:

RPCO1INT1#sh ip flow export
Flow export v5 is enabled for main cache
  Exporting flows to (2055)
  Exporting using source interface Loopback0
  Version 5 flow records
  1270731035 flows exported in 43918935 udp datagrams
  0 flows failed due to lack of export packet
  4839235 export packets were sent up to process level
  0 export packets were dropped due to no fib
20547097 export packets were dropped due to adjacency issues
  0 export packets were dropped due to fragmentation failures
  0 export packets were dropped due to encapsulation fixup failures

Adjacency issues... It alwas increase fast while the sent uo to process level increases by 1 every 2 seconds...

Anyones has any clue to solve this??


Cisco Employee

Re: Netflow over IPSec only every 2 seconds


There is a known interoperability problem with Netflow and IPSec, you can find more info about this limitation here:

This has been addressed in IOS version 12.4(20)T and later, however you must use flexible netflow (as opposed to legacy netflow) to make it work by using the command "output-feature" under the flow exporter configuration. Hope this helps.