Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Netflow over IPSec only every 2 seconds

Hi,

I have a strange issue. I have a VPN between a C3745 and a ASA 5510. The VPN is up and traffic passes through... However, when it come to Netflow, there is a strage behaviour... ASA only receives packets every 2 seconds... The strange thing is that, if I remove the VPN config, traffic flows a lot more... Here is the router config....

crypto isakmp policy 10
hash md5
authentication pre-share
crypto isakmp key mypresharedkey address 1.1.1.1
crypto ipsec transform-set myset1 esp-des esp-md5-hmac
crypto map NETFLOW_MAP 5 ipsec-isakmp
set peer 1.1.1.1
set transform-set myset1
match address NETFLOW_ACL

sh access-lists NETFLOW_ACL
Extended IP access list NETFLOW_ACL
    2 permit ip host 10.10.10.3 host 172.16.0.8 (2066 matches)
    10 permit ip host 10.10.10.3 172.16.0.0 0.0.255.255 (29742615 match)

RPCO1INT1#sh run int loopback 0
Building configuration...

Current configuration : 100 bytes
!
interface Loopback0
ip address 10.10.10.3 255.255.255.255
end

interface FastEthernet0/0
ip address 1.1.1.2 255.255.255.192
no ip redirects
ip flow ingress
ip nat inside
ip virtual-reassembly
load-interval 30
speed 100
full-duplex
no cdp enable
crypto map NETFLOW_MAP
end

ip route 172.16.0.0 255.255.0.0 1.1.1.1
ip route 172.16.0.8 255.255.255.255 FastEthernet0/0

ip flow-export source Loopback0
ip flow-export version 5
ip flow-export destination 172.16.0.8 2055

Also, I noticed this netflow message:

RPCO1INT1#sh ip flow export
Flow export v5 is enabled for main cache
  Exporting flows to 10.160.94.8 (2055)
  Exporting using source interface Loopback0
  Version 5 flow records
  1270731035 flows exported in 43918935 udp datagrams
  0 flows failed due to lack of export packet
  4839235 export packets were sent up to process level
  0 export packets were dropped due to no fib
20547097 export packets were dropped due to adjacency issues
  0 export packets were dropped due to fragmentation failures
  0 export packets were dropped due to encapsulation fixup failures

Adjacency issues... It alwas increase fast while the sent uo to process level increases by 1 every 2 seconds...

Anyones has any clue to solve this??

Thanks

1 REPLY
Cisco Employee

Re: Netflow over IPSec only every 2 seconds

Hi,

There is a known interoperability problem with Netflow and IPSec, you can find more info about this limitation here:

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsk25481.

This has been addressed in IOS version 12.4(20)T and later, however you must use flexible netflow (as opposed to legacy netflow) to make it work by using the command "output-feature" under the flow exporter configuration. Hope this helps.

Thanks,

Wen

442
Views
0
Helpful
1
Replies