<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-5220 and Netflow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/205950#M60453</link>
    <description>&lt;P&gt;In our case we are exporting Netflow on one of our internal layer 3 routed interfaces.&amp;nbsp; We had to adjust the internal service route to accomidate this but it seems to work without issue.&amp;nbsp; We do of course have the extra burden of netflow traffic on that internal interface, but its not an issue in our case as we have a 20G trunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 498px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14276iC61766C2C1392440/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2018 14:33:20 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2018-03-16T14:33:20Z</dc:date>
    <item>
      <title>PA-5220 and Netflow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/205779#M60404</link>
      <description>&lt;P&gt;I have a PA-5220 and I am trying to configure a Netflow export out to my solarwinds server which is located at a remote site across a VPN tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am aware that I cannot use the MGMT interface to export netwflow with this particular device, but I am not all that thrilled about using any of the other interfaces, nor do I want to create a whole new subnet just for this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently setup another interface within the mgmt vlan that the MGMT ports also sit, but interestingly the Palo is complaining about duplicate IP conflict. That being said it functionally seems to be working out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But due to the error messages this doesn't seem like the way to go. Just curious what the rest of you might be doing, maybe there is a more obvious solution to this I haven't picked up on... or maybe I can just kill the error messages.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 21:48:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/205779#M60404</guid>
      <dc:creator>RenoRLaskey</dc:creator>
      <dc:date>2018-03-15T21:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 and Netflow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/205950#M60453</link>
      <description>&lt;P&gt;In our case we are exporting Netflow on one of our internal layer 3 routed interfaces.&amp;nbsp; We had to adjust the internal service route to accomidate this but it seems to work without issue.&amp;nbsp; We do of course have the extra burden of netflow traffic on that internal interface, but its not an issue in our case as we have a 20G trunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 498px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14276iC61766C2C1392440/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:33:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/205950#M60453</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-16T14:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 and Netflow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/205999#M60477</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84298"&gt;@RenoRLaskey&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Why cannot you use the management interface for your netflow export? We are and it works as expected. Check your 'Service Routes' config and it should tell you which interface is being used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14283i29C7590B1734F7AC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:24:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/205999#M60477</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-16T16:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 and Netflow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/206007#M60479</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The management interface is not supported for Netflow export (even though its in the list) on the new PAN-5220 hardware.&amp;nbsp; It has something to do with the way the traffic is processed by the dataplane in the new hardware that Netflow traffic is not sent to the management plane.&amp;nbsp; It took a case with Palo Alto to determine this and the fix (as its not or wasn't documented at the time).&amp;nbsp; On our new PAN-220 models, you can still export Netflow via the management interface like normal.&amp;nbsp; I'm not sure about the newer PAN-800 and PAN-32xx models.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the plus side, because Netflow is now processed differently, you can get exports from subinterfaces now as well, which apparently wasn't supported before (and the support engineer kept insiting that it still wasn't supported even though I was showing him flows in LiveNX).&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/206007#M60479</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-16T16:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 and Netflow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/206015#M60481</link>
      <description>&lt;P&gt;Thanks for the education&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7143"&gt;@mlinsemier&lt;/a&gt;,&amp;nbsp;I&amp;nbsp;dont have any of that fancy new hardware :).&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:34:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/206015#M60481</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-16T16:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 and Netflow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/206017#M60482</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Funny thing about this (and I would suggest reaching out to your account manager), it was less expensive for us to upgrade our PAN-5060 to PAN-5220 including subscriptions than it was to just renew the subscriptions on the older PAN-5060s.&amp;nbsp; Food for thought.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:37:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-and-netflow/m-p/206017#M60482</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-16T16:37:37Z</dc:date>
    </item>
  </channel>
</rss>

