Zero'd packet count with Cisco ASA
-
reinaldo.gomes
- Posts: 59
- Joined: Wed Apr 02, 2014 9:29 am
Zero'd packet count with Cisco ASA
I have no idea why the packets count is shown as 0. The flow exporter is a Cisco ASA 5512 and the Incoming Flow Type on Nagios is "NetFlow".
Any thoughts?
Any thoughts?
You do not have the required permissions to view the files attached to this post.
Last edited by dwhitfield on Fri Sep 30, 2016 12:39 pm, edited 2 times in total.
Reason: marking with green check mark
Reason: marking with green check mark
Re: Zero'd packet count
Something looks wrong in your report, in the top, it says that it is only showing data from 16:10 to 16:15 which isn't 24 hours.
Try recreating that report or try one of the default ones and see if it still displays the wrong data.
Also, is the time in sync between the ASA and the NNA server?
If not, sometimes that causes the issue you are having.
Try recreating that report or try one of the default ones and see if it still displays the wrong data.
Also, is the time in sync between the ASA and the NNA server?
If not, sometimes that causes the issue you are having.
Be sure to check out our Knowledgebase for helpful articles and solutions!
-
reinaldo.gomes
- Posts: 59
- Joined: Wed Apr 02, 2014 9:29 am
Re: Zero'd packet count
The result, regarding packets count, is the same no matter which report (custom or default) I use. Even the queries show the same result.
The reason why it shows "24h" and "from 16:10 to 16:15" at the same time is because I did the following:
Dashboard -> Abnormal behavior -> Clicked on the 16:10's green tile -> Selected "Top Talking Source IP"
Regarding to the time sync, I've just noticed that the nagios server's system clock was sync'ed with the ASA, but the hardware clock wasn't. Not sure if that makes any difference, but now they're both sync'ed, and I restarted the source's process.
Anyway, it's still showing 0 packets
The reason why it shows "24h" and "from 16:10 to 16:15" at the same time is because I did the following:
Dashboard -> Abnormal behavior -> Clicked on the 16:10's green tile -> Selected "Top Talking Source IP"
Regarding to the time sync, I've just noticed that the nagios server's system clock was sync'ed with the ASA, but the hardware clock wasn't. Not sure if that makes any difference, but now they're both sync'ed, and I restarted the source's process.
Anyway, it's still showing 0 packets
Re: Zero'd packet count
After the syncing of the time, if it still showing 0 packets for new abnormal behavior of the old one?
If you select a good section of abnormal behavior, do you see the same issue?
If you select a good section of abnormal behavior, do you see the same issue?
Be sure to check out our Knowledgebase for helpful articles and solutions!
-
reinaldo.gomes
- Posts: 59
- Joined: Wed Apr 02, 2014 9:29 am
Re: Zero'd packet count
After syncing, it's still showing 0 packets, although there are plenty of bytes and other info, no matter which view, report, etc I use, nor which time range I select.
Re: Zero'd packet count
Does the standard Top 5 Talkers By Source IP (Last 24 Hours) report show correct data or is it exhibiting the same issue?
Can you change the flow version from v9 to v5 in the ASA and see if that resolves the issue?
Can you change the flow version from v9 to v5 in the ASA and see if that resolves the issue?
Be sure to check out our Knowledgebase for helpful articles and solutions!
-
reinaldo.gomes
- Posts: 59
- Joined: Wed Apr 02, 2014 9:29 am
Re: Zero'd packet count
Apparently it shows the correct data (IPs, Ports and Bytes), but it doesn't have a "packets" column:tgriep wrote:Does the standard Top 5 Talkers By Source IP (Last 24 Hours) report show correct data or is it exhibiting the same issue?
I can't:tgriep wrote:Can you change the flow version from v9 to v5 in the ASA and see if that resolves the issue?
"The ASA only supports NetFlow version 9 and there are no plans to support NetFlow version 5."
You do not have the required permissions to view the files attached to this post.
Re: Zero'd packet count
I have beet trying to recreate the issue but I cannot seem to do so.
It could be that the ASA isn't sending the information so it could be a configuration issue on the ASA firewall.
Can you post the configuration for that so I can view it?
What version of IOS is it running?
Also, can you click on the Reports Menu and run one of the default reports for that source and see if it reports the Packets?
It could be that the ASA isn't sending the information so it could be a configuration issue on the ASA firewall.
Can you post the configuration for that so I can view it?
What version of IOS is it running?
Also, can you click on the Reports Menu and run one of the default reports for that source and see if it reports the Packets?
Be sure to check out our Knowledgebase for helpful articles and solutions!
-
reinaldo.gomes
- Posts: 59
- Joined: Wed Apr 02, 2014 9:29 am
Re: Zero'd packet count
I'm very busy with some other tasks today, but come monday I should be able to resume the tests
Re: Zero'd packet count
Sounds good - let us know the answers to what @tgriep asked when you have a chance.
Former Nagios Employee