- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-11-2017 11:17 PM - edited 09-13-2017 04:54 PM
Hello,
In the Traffic monitor logs, nothing is showing up for netflow.
Using PAN-OS 7.0.4.
Tried using port 2055 and 9996.
Tried to use default and MGT interface of Netflow and SNMP Trap under Device>Setup>Services>Service Route Configuration.
We have setup Netflow as per below:
Device>Server profiles>Netflow:
Packets: 50; Minutes: 1; Active Timeout: 1; PAN-OS Filed Type: selected; Host: 10.x.y.z; Port: 9996
Network>Interfaces>Ethernet:
Ethernet1/6 (External SSL VPN Interface)>Interface Type: Layer 2; Netflow Profile: Netflow
Can we monitor the NetFlow packets on the same PA device where you configure the netflow option?
Does the NetFlow configuration works in the PA HA environment?
Thanks in advance.
09-14-2017 12:57 PM
What Netflow collector are you using? I know in LiveNX (formely LiveAction) you have to change the flow to Firewall or All Flows to see data. Additionally, Palo Alto only exports ingress data of an interface (at least that is all I see), so you need to make sure you are looking at inbound traffic.
09-14-2017 12:57 PM
What Netflow collector are you using? I know in LiveNX (formely LiveAction) you have to change the flow to Firewall or All Flows to see data. Additionally, Palo Alto only exports ingress data of an interface (at least that is all I see), so you need to make sure you are looking at inbound traffic.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!