Problem with multiple Netflow profiles

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Problem with multiple Netflow profiles

L2 Linker

Hello,

I encounter a problem using multiple netflow profiles on our PA-500 running PAN-OS 4.1.8

I have defined 3 different neflow profiles, each refers to a specific port on the same host.

Each profile is assigned to exactly one physical layser 3 interface.

The first profile delivers reasonable data to my flow receiver (Paessler PRTG Network Monitor), but the two other profiles dont seem to work.

The corresponding monitor channel simply gets no data.

Anybody has a hint how to resolve this problem?

Thanks,

dweide

1 accepted solution

Accepted Solutions

I updated to 5.0.0 and all Netflows work now.

View solution in original post

5 REPLIES 5

L6 Presenter

Try restarting log rcvr process with this command

debug software restart log-receiver

If that does not work then remove the netflow profile on the interface that is working and apply netflow profile only to the interfaces that are not working and run the below command to see whether PAN is exporting any kind of netflow records for these interfaces.

debug log-receiver netflow statistics

Also, what kind of interfaces are these tunnel, Vlan, Loopback, Sub-interfaces or regular L2 , L3 interfaces ? Which software version ?.

Also, Can you apply the Netflow profile which is working to other two interfaces that are not working and see if you are receiving any data on the Netflow server ? This is to rule out the issues on the Netflow server side.

Dear sdurga,

thanks for your debugging hints!

Restarting the process didnt fix the problem.

I reassigned the netflow profiles as suggested and found that everything is working fine as long as I use only one profile:

  • cli shows that netflow packets are sent at reasonable rate(debug log-receiver netflow statistics)
  • netflow data is send on the correct port defined in the profile (proved by the fact that the receiver is display the flows in the correct channel)
  • each profile alone works on each interface

The situation changes if I assign a second profile to one of my L3 interfaces:

  • netflow receiver gets only data for one interface
  • cli statistics shows that the second netflow profile is only generating data for each timeout interval (i.e. one packet each 5 minutes)
  • it seems that data is only generated for the lowest interface number

All interfaces are plain L3 type on the same virtual router. Software version is 4.1.8

Regards,

Detlev Weide

So if I am not wrong only one Netflow profile will work at a time. Adding another (second) Netflow profile simultaneously to another Interface will not work. This is not expected behavior, please open a ticket with support. In the mean while I will try to see on my device if I am also seeing the same behavior.

Thanks,

Sandeep T

I opened a case and my problem seems to be reproducable.

I will post an update as soon as I get a fix.

I updated to 5.0.0 and all Netflows work now.

  • 1 accepted solution
  • 3595 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!