<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How PA 5220 appliance sends netflow packet when configured in HA and Vsys Mode. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/234054#M67087</link>
    <description>&lt;P&gt;Currently, we have two PA 5220 appliance deployed in HA mode and would like to configure Netflow profile to monitor statistic. But as per the documentation we need to change the service route other than Management interface for 5200 and 7000 series appliance. So I have changed the service route with subinterface and resp IP where Netflow server is reachable as per routing table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, my question is that only active firewall sends NetFlow statistics to Netflow server as these are in HA pair... which command help me to show the statistics and packet sends to NetFlow successfully. As per my knowledge the below command shows the statistics on the 5220 appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;debug dataplane netflow statistics&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Oct 2018 05:42:29 GMT</pubDate>
    <dc:creator>AR00473455</dc:creator>
    <dc:date>2018-10-05T05:42:29Z</dc:date>
    <item>
      <title>How PA 5220 appliance sends netflow packet when configured in HA and Vsys Mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/233864#M67037</link>
      <description>&lt;P&gt;How PA 5220 appliance sends NetFlow packet when configured in HA and Vsys Mode. does the firewall find egress interface by looking into routing table for Netflow packets? If it is Yes, So why we need to change service route on PA 5220 appliance,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondly, As appliance in HA pair so it sends statistics about active firewall only ?? Also would like to know about how other PA firewall models sends NetFlow packets and what is the purpose of service route to these model as well.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 10:50:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/233864#M67037</guid>
      <dc:creator>AR00473455</dc:creator>
      <dc:date>2018-10-04T10:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: How PA 5220 appliance sends netflow packet when configured in HA and Vsys Mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/233945#M67061</link>
      <description>&lt;P&gt;huh?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not really certain what you're asking and trying to have clarified.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's my understanding that on the 5200 series platform the internal hardware was redesigned and changed how netflow is allowed out of the firewall.&amp;nbsp; As such a new separate&amp;nbsp;interface for NF has to be utilized when wanting to send NF from the firewall.&amp;nbsp; (BTW this change actually created a critical bug in the 5200 and anything less than 8.0.8 will crash a 5200 sending NF.)&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 15:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/233945#M67061</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-10-04T15:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: How PA 5220 appliance sends netflow packet when configured in HA and Vsys Mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/234054#M67087</link>
      <description>&lt;P&gt;Currently, we have two PA 5220 appliance deployed in HA mode and would like to configure Netflow profile to monitor statistic. But as per the documentation we need to change the service route other than Management interface for 5200 and 7000 series appliance. So I have changed the service route with subinterface and resp IP where Netflow server is reachable as per routing table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, my question is that only active firewall sends NetFlow statistics to Netflow server as these are in HA pair... which command help me to show the statistics and packet sends to NetFlow successfully. As per my knowledge the below command shows the statistics on the 5220 appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;debug dataplane netflow statistics&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 05:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/234054#M67087</guid>
      <dc:creator>AR00473455</dc:creator>
      <dc:date>2018-10-05T05:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: How PA 5220 appliance sends netflow packet when configured in HA and Vsys Mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/234113#M67110</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It depends on how your HA is setup, active-active or active-passive. If its active-passive, then the 'passive' firewall is not passing traffic so there is no netflow. If active-active, then the secondary PAN is passing traffic and should be sending netflow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 13:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-pa-5220-appliance-sends-netflow-packet-when-configured-in-ha/m-p/234113#M67110</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-05T13:38:31Z</dc:date>
    </item>
  </channel>
</rss>

