Zero'd packet count with Cisco ASA

This support forum board is for support questions relating to Nagios Network Analyzer, our network traffic and bandwidth analysis solution.
reinaldo.gomes
Posts: 59
Joined: Wed Apr 02, 2014 9:29 am

Zero'd packet count with Cisco ASA

Post by reinaldo.gomes »

I have no idea why the packets count is shown as 0. The flow exporter is a Cisco ASA 5512 and the Incoming Flow Type on Nagios is "NetFlow".
Any thoughts?
Sem título.png
You do not have the required permissions to view the files attached to this post.
Last edited by dwhitfield on Fri Sep 30, 2016 12:39 pm, edited 2 times in total.
Reason: marking with green check mark
User avatar
tgriep
Madmin
Posts: 9190
Joined: Thu Oct 30, 2014 9:02 am

Re: Zero'd packet count

Post by tgriep »

Something looks wrong in your report, in the top, it says that it is only showing data from 16:10 to 16:15 which isn't 24 hours.
Try recreating that report or try one of the default ones and see if it still displays the wrong data.
Also, is the time in sync between the ASA and the NNA server?
If not, sometimes that causes the issue you are having.
Be sure to check out our Knowledgebase for helpful articles and solutions!
reinaldo.gomes
Posts: 59
Joined: Wed Apr 02, 2014 9:29 am

Re: Zero'd packet count

Post by reinaldo.gomes »

The result, regarding packets count, is the same no matter which report (custom or default) I use. Even the queries show the same result.

The reason why it shows "24h" and "from 16:10 to 16:15" at the same time is because I did the following:
Dashboard -> Abnormal behavior -> Clicked on the 16:10's green tile -> Selected "Top Talking Source IP"

Regarding to the time sync, I've just noticed that the nagios server's system clock was sync'ed with the ASA, but the hardware clock wasn't. Not sure if that makes any difference, but now they're both sync'ed, and I restarted the source's process.

Anyway, it's still showing 0 packets :cry:
User avatar
tgriep
Madmin
Posts: 9190
Joined: Thu Oct 30, 2014 9:02 am

Re: Zero'd packet count

Post by tgriep »

After the syncing of the time, if it still showing 0 packets for new abnormal behavior of the old one?
If you select a good section of abnormal behavior, do you see the same issue?
Be sure to check out our Knowledgebase for helpful articles and solutions!
reinaldo.gomes
Posts: 59
Joined: Wed Apr 02, 2014 9:29 am

Re: Zero'd packet count

Post by reinaldo.gomes »

After syncing, it's still showing 0 packets, although there are plenty of bytes and other info, no matter which view, report, etc I use, nor which time range I select.
User avatar
tgriep
Madmin
Posts: 9190
Joined: Thu Oct 30, 2014 9:02 am

Re: Zero'd packet count

Post by tgriep »

Does the standard Top 5 Talkers By Source IP (Last 24 Hours) report show correct data or is it exhibiting the same issue?
Can you change the flow version from v9 to v5 in the ASA and see if that resolves the issue?
Be sure to check out our Knowledgebase for helpful articles and solutions!
reinaldo.gomes
Posts: 59
Joined: Wed Apr 02, 2014 9:29 am

Re: Zero'd packet count

Post by reinaldo.gomes »

tgriep wrote:Does the standard Top 5 Talkers By Source IP (Last 24 Hours) report show correct data or is it exhibiting the same issue?
Apparently it shows the correct data (IPs, Ports and Bytes), but it doesn't have a "packets" column:
Sem título.png
tgriep wrote:Can you change the flow version from v9 to v5 in the ASA and see if that resolves the issue?
I can't:

"The ASA only supports NetFlow version 9 and there are no plans to support NetFlow version 5."
You do not have the required permissions to view the files attached to this post.
User avatar
tgriep
Madmin
Posts: 9190
Joined: Thu Oct 30, 2014 9:02 am

Re: Zero'd packet count

Post by tgriep »

I have beet trying to recreate the issue but I cannot seem to do so.
It could be that the ASA isn't sending the information so it could be a configuration issue on the ASA firewall.
Can you post the configuration for that so I can view it?
What version of IOS is it running?
Also, can you click on the Reports Menu and run one of the default reports for that source and see if it reports the Packets?
Be sure to check out our Knowledgebase for helpful articles and solutions!
reinaldo.gomes
Posts: 59
Joined: Wed Apr 02, 2014 9:29 am

Re: Zero'd packet count

Post by reinaldo.gomes »

I'm very busy with some other tasks today, but come monday I should be able to resume the tests
rkennedy
Posts: 6579
Joined: Mon Oct 05, 2015 11:45 am

Re: Zero'd packet count

Post by rkennedy »

Sounds good - let us know the answers to what @tgriep asked when you have a chance.
Former Nagios Employee
Locked