Hello All!
I hope someone can give a hint or point me to read somewhere to resolve this. I dont feel comfortable with this issue I have now
lol, my tracking is incomplete
Thanks. Here it is:
Hey there
Thanks for the useful log! I just found it, and going to read as much as possible and get from there to improve. Have question, or eventually to redirect me to a forum when I can read and discuss this. I have enabled Netflow v9 on my corporate 2811 and added NBAR support. All seems to work well. NBAR is active just on one interface, as for Netflow 9, it is active on 14 interfaces, and one is source, the local fast ethernet interface. Have this:
ip flow-export source FastEthernet0/0
ip flow-export version 9
ip flow-export template options export-stats
ip flow-export template options timeout-rate 120
ip flow-export template options refresh-rate 25
ip flow-export template refresh-rate 60
ip flow-export destination 10.0.0.222 2055
ip flow-export destination 10.0.0.222 3055
And for each tunnel I have ip route-cache flow in action.
Now I noticed yesterday an interesting thing. I do unc (\\) type of connection to a remote computer, via one of our IP VPN connections, effectively thru one of the tunnels. I transfered from that remote computer to mine, anywhere between 9MB-10MB. But these are not available in my graphs. I use ManageEngine Netflow analyzer 5 for collecting and presenting Netflow 9 and NBAR exports from my 2811 Cisco router. The application registered ONLY around 500K-600K as traffic between my computer and the remote one.
Right now checked if for any reason the session is active on the remote computer, and somehow the flow was not ended, but that doesnt seem to be the case.
Do you think you can advise and suggest where to look for this?
/Ola
I hope someone can give a hint or point me to read somewhere to resolve this. I dont feel comfortable with this issue I have now
Hey there
Thanks for the useful log! I just found it, and going to read as much as possible and get from there to improve. Have question, or eventually to redirect me to a forum when I can read and discuss this. I have enabled Netflow v9 on my corporate 2811 and added NBAR support. All seems to work well. NBAR is active just on one interface, as for Netflow 9, it is active on 14 interfaces, and one is source, the local fast ethernet interface. Have this:
ip flow-export source FastEthernet0/0
ip flow-export version 9
ip flow-export template options export-stats
ip flow-export template options timeout-rate 120
ip flow-export template options refresh-rate 25
ip flow-export template refresh-rate 60
ip flow-export destination 10.0.0.222 2055
ip flow-export destination 10.0.0.222 3055
And for each tunnel I have ip route-cache flow in action.
Now I noticed yesterday an interesting thing. I do unc (\\) type of connection to a remote computer, via one of our IP VPN connections, effectively thru one of the tunnels. I transfered from that remote computer to mine, anywhere between 9MB-10MB. But these are not available in my graphs. I use ManageEngine Netflow analyzer 5 for collecting and presenting Netflow 9 and NBAR exports from my 2811 Cisco router. The application registered ONLY around 500K-600K as traffic between my computer and the remote one.
Right now checked if for any reason the session is active on the remote computer, and somehow the flow was not ended, but that doesnt seem to be the case.
Do you think you can advise and suggest where to look for this?
/Ola