I encounter a problem using multiple netflow profiles on our PA-500 running PAN-OS 4.1.8
I have defined 3 different neflow profiles, each refers to a specific port on the same host.
Each profile is assigned to exactly one physical layser 3 interface.
The first profile delivers reasonable data to my flow receiver (Paessler PRTG Network Monitor), but the two other profiles dont seem to work.
The corresponding monitor channel simply gets no data.
Anybody has a hint how to resolve this problem?
Solved! Go to Solution.
Try restarting log rcvr process with this command
debug software restart log-receiver
If that does not work then remove the netflow profile on the interface that is working and apply netflow profile only to the interfaces that are not working and run the below command to see whether PAN is exporting any kind of netflow records for these interfaces.
debug log-receiver netflow statistics
Also, what kind of interfaces are these tunnel, Vlan, Loopback, Sub-interfaces or regular L2 , L3 interfaces ? Which software version ?.
Also, Can you apply the Netflow profile which is working to other two interfaces that are not working and see if you are receiving any data on the Netflow server ? This is to rule out the issues on the Netflow server side.
thanks for your debugging hints!
Restarting the process didnt fix the problem.
I reassigned the netflow profiles as suggested and found that everything is working fine as long as I use only one profile:
The situation changes if I assign a second profile to one of my L3 interfaces:
All interfaces are plain L3 type on the same virtual router. Software version is 4.1.8
So if I am not wrong only one Netflow profile will work at a time. Adding another (second) Netflow profile simultaneously to another Interface will not work. This is not expected behavior, please open a ticket with support. In the mean while I will try to see on my device if I am also seeing the same behavior.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!