Compared to "normal" NetFlow the following limitations apply:
- You will not see the real time data: The NSEL monitoring sends a NetFlow data packet only after a connection has been torn down. If a connection is active for minutes or hours, the ASA sends one NetFlow packet with the total of the connection. This causes peaks in PRTG's graphs while showing too little traffic before that.
- Flows on the ASA are bidirectional (all counters for a flow will increase for traffic flowing in and out)
- NetFlow 9 monitoring on the ASA comes at a price: CPU load.