How can we help?

How to configure NetFlow on Cisco devices with Firepower Management Center

Follow

These instructions assume:

  • You’re running Firepower Management Center (FMC) software version 6.2 or higher.
  • Firepower Threat Defence (FTD) devices are connected to your FMC device.
  • The date, time and time zone are correctly set on the Firepower devices.
  • You have login credentials and admin access to your Firepower Management Center.
  • The IP address of your Auvik collector is known.

If you have a shared collector and want to ensure that it receives netflow data to enable TrafficInsights, you will need to add the source IP address as a /32 in order for Auvik to register the flows from that specific address in the TrafficInsights portal. There may be some delay for the shared collector to receive the data after the change.

Note: Even if that source IP address is already being scanned, you must add a /32 targeting only the source IP address, due to some limitations, the collector can’t tell if it should be sent to site A or B.

Set the Auvik collector parameters

  1. Navigate to Objects
  2. Click on Objects Management
  3. Click on FlexConfig
  4. Click on Text Object
  5. Edit the netflow_Destination object

  6. In this variable, set the interface sending Netflow, the Auvik collector IP address, and the port

Note: You need to change the count to 3, it is 1 by default.

Create the FlexConfig Policy

  1. Navigate to Device
  2. Click on FlexConfig
  3. Click on New Policy
  4. Give a name to the policy
  5. Select the Firewall(s) to receive the policy
  6. Click Save

  7. Select the objects: Netflow_Add_Destination and Netflow_Set_Parameters
    It will look like this:
  8. Click Save
  9. Deploy on the target firewall
  10. Go to the Auvik portal
  11. Click on TrafficInsights
  12. Approve the flow

You may see a message in TrafficInsights informing you that no templates are being sent from the device. Do not troubleshoot it right away. Wait for about 30 to 60 minutes and check it again.

Was this article helpful?
3 out of 10 found this helpful
Have more questions? Submit a request