<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netflow export into IPsec tunnel... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310925#M80502</link>
    <description>&lt;P&gt;Here's the result of my command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM# set deviceconfig system route service netflow source interface ethernet1/2 address 10.0.0.222&lt;/P&gt;&lt;P&gt;Server error : route -&amp;gt; service -&amp;gt; netflow -&amp;gt; source -&amp;gt; interface 'ethernet1/2' is not a valid reference&lt;BR /&gt;route -&amp;gt; service -&amp;gt; netflow -&amp;gt; source -&amp;gt; interface is invalid&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;the interface exists:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt; show interface all&lt;/P&gt;&lt;P&gt;total configured hardware interfaces: 4&lt;/P&gt;&lt;P&gt;name id speed/duplex/state mac address&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ethernet1/1 16 auto/auto/up 0a:9d:bd:58:88:13&lt;BR /&gt;ethernet1/2 17 auto/auto/up 0a:24:dc:a2:f2:67&lt;BR /&gt;loopback 3 [n/a]/[n/a]/up ba:db:ee:fb:ad:03&lt;BR /&gt;tunnel 4 [n/a]/[n/a]/up ba:db:ee:fb:ad:04&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2020 00:23:42 GMT</pubDate>
    <dc:creator>megrez80</dc:creator>
    <dc:date>2020-02-13T00:23:42Z</dc:date>
    <item>
      <title>Netflow export into IPsec tunnel...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310898#M80499</link>
      <description>&lt;P&gt;I'm trying to get netflow to export through a vpn tunnel on my PA-VM V9.1 firewall. My route and policy into the tunnel for the target collector is working because I can ping the collector through the tunnel. So I figure I need to change the default service route for netflow, but I'm unable to specify any of the dataplane interfaces/addresses either in the UI or the CLI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 21:21:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310898#M80499</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-02-12T21:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow export into IPsec tunnel...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310911#M80500</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131948"&gt;@megrez80&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you share a screenshot of what you are seeing when you attempt to modify the service route? This should be as simple as specifying the follow CLI command or doing it in the GUI, there shouldn't be anything special you need.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;set deviceconfig system route service netflow source interface &amp;lt;value&amp;gt; address &amp;lt;value&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 22:47:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310911#M80500</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-12T22:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow export into IPsec tunnel...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310925#M80502</link>
      <description>&lt;P&gt;Here's the result of my command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM# set deviceconfig system route service netflow source interface ethernet1/2 address 10.0.0.222&lt;/P&gt;&lt;P&gt;Server error : route -&amp;gt; service -&amp;gt; netflow -&amp;gt; source -&amp;gt; interface 'ethernet1/2' is not a valid reference&lt;BR /&gt;route -&amp;gt; service -&amp;gt; netflow -&amp;gt; source -&amp;gt; interface is invalid&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;the interface exists:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt; show interface all&lt;/P&gt;&lt;P&gt;total configured hardware interfaces: 4&lt;/P&gt;&lt;P&gt;name id speed/duplex/state mac address&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ethernet1/1 16 auto/auto/up 0a:9d:bd:58:88:13&lt;BR /&gt;ethernet1/2 17 auto/auto/up 0a:24:dc:a2:f2:67&lt;BR /&gt;loopback 3 [n/a]/[n/a]/up ba:db:ee:fb:ad:03&lt;BR /&gt;tunnel 4 [n/a]/[n/a]/up ba:db:ee:fb:ad:04&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 00:23:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310925#M80502</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-02-13T00:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow export into IPsec tunnel...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310936#M80504</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131948"&gt;@megrez80&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you tab autocomplete when you are entering in that command, do you actually get the interface and the address to populate correctly? The main reason I ask is that the address doesn't appear to be correct, I would expect the full cidr notation. Not sure if you sanitized it and accidentally removed the CIDR or if you are hand typing the entire command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can attempt to modify the XML file and load it back into the firewall and see if it validates the configuration; the following would need to go under &amp;lt;deviceconfig&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;          &amp;lt;route&amp;gt;
            &amp;lt;service&amp;gt;
              &amp;lt;entry name="autofocus"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="crl-status"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="deployments"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="dns"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="edl-updates"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="email"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="http"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="kerberos"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="ldap"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="mdm"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="mfa"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="netflow"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="ntp"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="paloalto-networks-services"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="panorama"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="proxy"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="radius"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="scep"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="snmp"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="syslog"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="tacplus"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="uid-agent"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="url-updates"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="vmmonitor"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
              &amp;lt;entry name="wildfire-private"&amp;gt;
                &amp;lt;source&amp;gt;
                  &amp;lt;address&amp;gt;10.0.0.222/32&amp;lt;/address&amp;gt;
                  &amp;lt;interface&amp;gt;ethernet1/2&amp;lt;/interface&amp;gt;
                &amp;lt;/source&amp;gt;
              &amp;lt;/entry&amp;gt;
            &amp;lt;/service&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should have something that looks like this already within the deviceconfig section, just replace it with what is specified above and update the cidr notation to whatever you actually have configured.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;          &amp;lt;route&amp;gt;
            &amp;lt;service/&amp;gt;
	  &amp;lt;/route&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 02:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/310936#M80504</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-13T02:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow export into IPsec tunnel...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/311065#M80529</link>
      <description>&lt;P&gt;Using autocomplete does not display any of the ethernet interfaces, only the loopback interface that I created (and tried to use).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I exported the running-config.xml file and modified it for the netflow service, but I'm getting an error trying to import it back in:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;scp import configuration from myuser@myhost.mydom.com:mypath&lt;BR /&gt;myuser@myhost.mydom.com's password:&lt;BR /&gt;/tmp/cli.tmp.b2CqGy: Not a directory&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 13:44:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/311065#M80529</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-02-13T13:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow export into IPsec tunnel...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/311106#M80534</link>
      <description>&lt;P&gt;An update:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got the netflow into the tunnel using my loopback interface in the netflow service route configuration. I had initially not configured the&amp;nbsp;loopback interface in a zone and using the virtual router. Once I did that, and moved my policy above all others, things started flowing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's still a mystery though why the ethernet interfaces don't show up in the UI or CLI when trying to configure a service route.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 16:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-export-into-ipsec-tunnel/m-p/311106#M80534</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-02-13T16:03:19Z</dc:date>
    </item>
  </channel>
</rss>

