Cisco Systems ASA 5510 Network Router User Manual


  Open as PDF
of 2086
 
CHAPTER
77-1
Cisco ASA 5500 Series Configuration Guide using ASDM
77
Configuring NetFlow Secure Event Logging (NSEL)
This chapter describes how to configure NSEL, a security logging mechanism that is built on NetFlow
Version 9 technology, and how to handle events and syslog messages through NSEL.
This chapter includes the following sections:
Information About NSEL, page 77-1
Licensing Requirements for NSEL, page 77-3
Prerequisites for NSEL, page 77-3
Guidelines and Limitations, page 77-3
Configuring NSEL, page 77-4
Monitoring NSEL, page 77-6
Where to Go Next, page 77-7
Additional References, page 77-7
Feature History for NSEL, page 77-8
Information About NSEL
The ASA and ASASM support NetFlow Version 9 services. For more information about NetFlow
services, see the “RFCs” section on page 77-8.
The ASA and ASASM implementations of NSEL provide a stateful, IP flow tracking method that exports
records that indicate significant events in a flow. In stateful flow tracking, tracked flows go through a
series of state changes. NSEL events are used to export data about flow status and are triggered by the
event that caused the state change.
The significant events that are tracked include flow-create, flow-teardown, flow-denied (excluding those
flows that are denied by EtherType ACLs), and flow-update. In addition, the ASA and ASASM
implementation of NSEL generates periodic NSEL events and flow-update events to provide periodic
byte counters over the duration of the flow. These events are usually time-driven, which makes them
more in line with traditional Netflow; however, these events may also be triggered by state changes in
the flow.
Each NSEL record has an event ID and an extended event ID field, which describes the flow event.
The ASA and ASASM implementations of NSEL provide the following major functions:
Tracks flow-create, flow-teardown, and flow-denied events, and generates appropriate NSEL data
records.