<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netflow questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547858#M111886</link>
    <description>&lt;P&gt;Hello !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im having issue with my netflow configuration on the PA5260.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not receiving any log on my Qradar where as i have configure the netflow by following the&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJzCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJzCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The following Step have beeen done:&lt;/P&gt;
&lt;P&gt;1. Netflow profil created&lt;/P&gt;
&lt;P&gt;2. Profil applied on a subinterface&lt;/P&gt;
&lt;P&gt;3. use of ae3 interface in a service route.&lt;/P&gt;
&lt;P&gt;4. connectivite between ae3 interface and the Qradar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thansk in advance for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 09:39:53 GMT</pubDate>
    <dc:creator>Nathus</dc:creator>
    <dc:date>2023-06-30T09:39:53Z</dc:date>
    <item>
      <title>Netflow questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547672#M111864</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we apply a Netflow profile to an interface, does it capture the ingress, egress or both flows?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we apply the same profile to the Inside and the Outside interface, and we have a flow which passes both of them, will we send duplicated information about this flow to the remote Netflow Analyzer?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 08:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547672#M111864</guid>
      <dc:creator>ichakarov</dc:creator>
      <dc:date>2023-06-29T08:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547701#M111868</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300386"&gt;@ichakarov&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use it to export statistics about the IP traffic &lt;STRONG&gt;ingressing&lt;/STRONG&gt; the interfaces.&lt;/P&gt;
&lt;P&gt;All Palo Alto Networks firewalls support NetFlow Version 9. The firewalls support &lt;STRONG&gt;only unidirectional NetFlow, not bidirectional&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source: &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/netflow-monitoring" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/netflow-monitoring&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 12:11:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547701#M111868</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-06-29T12:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547858#M111886</link>
      <description>&lt;P&gt;Hello !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im having issue with my netflow configuration on the PA5260.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not receiving any log on my Qradar where as i have configure the netflow by following the&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJzCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJzCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The following Step have beeen done:&lt;/P&gt;
&lt;P&gt;1. Netflow profil created&lt;/P&gt;
&lt;P&gt;2. Profil applied on a subinterface&lt;/P&gt;
&lt;P&gt;3. use of ae3 interface in a service route.&lt;/P&gt;
&lt;P&gt;4. connectivite between ae3 interface and the Qradar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thansk in advance for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 09:39:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547858#M111886</guid>
      <dc:creator>Nathus</dc:creator>
      <dc:date>2023-06-30T09:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547859#M111887</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bellow is my netflow config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show | match netflow&lt;BR /&gt;set deviceconfig system route service netflow source address 10.10.10.14/29&lt;BR /&gt;set deviceconfig system route service netflow source interface ae3.600&lt;BR /&gt;set network interface tunnel units tunnel.11 netflow-profile NetFlow_SOC_Qradar&lt;BR /&gt;set network interface tunnel units tunnel.14 netflow-profile NetFlow_SOC_Qradar&lt;BR /&gt;set shared server-profile netflow NetFlow_SOC_Qradar server Qradar host 1.1.1.1/24&lt;BR /&gt;set shared server-profile netflow NetFlow_SOC_Qradar server Qradar port 2055&lt;BR /&gt;set shared server-profile netflow NetFlow_SOC_Qradar template-refresh-rate minutes 1&lt;BR /&gt;set shared server-profile netflow NetFlow_SOC_Qradar template-refresh-rate packets 20&lt;BR /&gt;set shared server-profile netflow NetFlow_SOC_Qradar active-timeout 1&lt;BR /&gt;set shared server-profile netflow NetFlow_SOC_Qradar export-enterprise-fields no&lt;BR /&gt;set shared admin-role Monitor-full-access role device webui device server-profile netflow read-only&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 09:44:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-questions/m-p/547859#M111887</guid>
      <dc:creator>Nathus</dc:creator>
      <dc:date>2023-06-30T09:44:50Z</dc:date>
    </item>
  </channel>
</rss>

