Next-Generation Firewall
Configure Netflow Exports (Strata Cloud Manager)
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
Configure Netflow Exports (Strata Cloud Manager)
- Create a NetFlow server profile.The profile defines which Netflow collectors will receive the exported records and specifies export parameters.
- Select ConfigurationNGFW and Prisma AccessObjectsLog ForwardingNetflow Server Profile and click Add Netflow Server Profile.In the General section, enter a Name to identify the profile.Specify the Active Timeout, which is the frequency in minutes at which the firewall exports records (default is 5).Select PAN-OS Field Types if you want the firewall to export App-ID and User-ID fields.In the Template Refresh Rate section, specify the rate at which the firewall refreshes NetFlow Templates in Minutes (default is 30) and Packets (exported records—default is 20), according to the requirements of your Netflow collector. The firewall refreshes the templates after either threshold is passed.Click Add Server.Add Netflow collectors (up to two per profile) that will receive records. For each collector, specify the following:
- Name to identify the collector.
- Host hostname or IP address.
- Access Port (default 2055).
Click Add to save the profile.To commit your changes, click Push ConfigPush.Assign the Netflow server profile to the firewall interfaces where traffic you want to analyze is ingressing.In this example, you assign the profile to an existing Ethernet interface.- Select Ethernet and click an interface name to edit it.You can export Netflow records for Layer 3, Layer 2, Tap, virtual wire, VLAN, tunnel, and Aggregate Ethernet. For aggregate Ethernet interfaces, you can export records for the individual sub-interfaces that data flows within the group.Select the Netflow server profile you configured.(Optional) To create a new Netflow profile click Create New.Click Save.Push Config to push your configuration changes.