do you need ingress or Egress on the interface?
You cannot transfer Netflow packets over a site to site tunnel. You would need to set up an EZVPN. Its a known cisco issue.
Netflow also works fine if you use a GRE/IPSec configuration, which one of the easiest tunnel methods to set up and manage. Here's a sample config using pre-shared keys. For more scalability use DMVPN with a CA.
crypto isakmp policy 1
crypto isakmp key foo address 220.127.116.11
crypto isakmp keepalive 20
crypto ipsec transform-set 3DES_SHA_TUNNEL esp-3des esp-sha-hmac
crypto ipsec profile GRE
set transform-set 3DES_SHA_TUNNEL
ip address 10.1.1.1 255.255.255.252
ip mtu 1400
ip tcp adjust-mss 1260
tunnel source FastEthernet0/0
tunnel destination 18.104.22.168
tunnel protection ipsec profile GRE