Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Netflow & 3200 Series

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Netflow & 3200 Series

L3 Networker

We need clarification if our 3260 firewall requires an L3 interface for Netflow exports. The link below, "HOW TO VERIFY AND TROUBLESHOOT NETFLOW," states a 3200 series cannot use the mgmt interface, but I can't find any other sources that state the mgmt interface cannot be used.

Also, to confirm, do we need a separate Netflow profile for each of the L3 sub-interfaces on the 3260 (link below)?
Thank you.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UuYCAU

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClzyCAC

Passionate about network infrastructure and all things Palo Alto Networks.
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@jeff6strings,

A netflow profile can be assigned to multiple interfaces without any issue. The article that you linked does a poor job of communicating what it's attempting to, but you need to assign the netflow profile to any logical interface you want to receive netflow information from. The assigned netflow profile itself however can be linked to the physical interface in addition to all of the logical sub-interfaces without issue, you don't need a new netflow profile for every assigned logical interface.

 

Assuming that it follows the 5200 and 7000 series, the 3200 can't pass netflow interface across the MGMT interface. You need to configure a service route through a dataplane interface as mentioned in the document. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@jeff6strings,

A netflow profile can be assigned to multiple interfaces without any issue. The article that you linked does a poor job of communicating what it's attempting to, but you need to assign the netflow profile to any logical interface you want to receive netflow information from. The assigned netflow profile itself however can be linked to the physical interface in addition to all of the logical sub-interfaces without issue, you don't need a new netflow profile for every assigned logical interface.

 

Assuming that it follows the 5200 and 7000 series, the 3200 can't pass netflow interface across the MGMT interface. You need to configure a service route through a dataplane interface as mentioned in the document. 

It sounded odd to have a profile for each interface and not share the same one.

Thank you for confirming the 3200 series Netflow question.

Jeff

 

Passionate about network infrastructure and all things Palo Alto Networks.
  • 1 accepted solution
  • 2224 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!