Tech Tip: NFA 9.2.1 New Supported NetFlow Fields

Document created by Christopher_Walsh Employee on Oct 16, 2014
Version 1Show Document
  • View in full screen mode

In order to Support Cisco ASA Device NFA 9.2.1 will now support new NetFlow fields.

The main change is that ASA Devices use bidirectional fields for Octets/Bytes.

 

Below are the new required NetFlow Fields for NFA 9.2.1:

 

One of the following: 1 - IN_BYTES, 85 - IN_PERMANENT_BYTES, 231 - For ASA devices we need both FW_INITIATOR_OCTETS, and 232 - FW_RESPONDER_OCTETS

4 - PROTOCOL

7 - L4_SRC_PORT

8 - IPV4_SRC_ADDR

10 - INPUT_SNMP

11 - L4_DST_PORT

12 - IPV4_DST_ADDR

14 - OUTPUT_SNMP

 

You can still use Wireshark to capture and decode the NetFlow to see if you have the required fields as shown in the Tech Tip below:

Tech Tips: How to determine if a NetFlow enabled device is sending the correct fields

Attachments

    Outcomes