<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netflow, does it show Ingrees and Egrees? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/153012#M25628</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes thank you i unserstand.&lt;BR /&gt;&lt;BR /&gt;with value 0 i get all the Netflow data&lt;BR /&gt;with value 1 i dont receive any Netflow data&lt;BR /&gt;in my setup&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;my question was more,&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;who has experience with Netflow and Check Point, are Ingrees and Egrees charts visible or is this totally appliction dependend?&lt;BR /&gt;or is this not required because its all in one view and you can drill down into the session, and therefore IN and OUT is not required?&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2022 15:17:37 GMT</pubDate>
    <dc:creator>Thomas_Eichelbu</dc:creator>
    <dc:date>2022-07-14T15:17:37Z</dc:date>
    <item>
      <title>Netflow, does it show Ingrees and Egrees?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/152892#M25626</link>
      <description>&lt;P&gt;Hello Check Mates,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;perhaps a silly question, and perhaps a total application dependend question:&lt;/STRONG&gt;&lt;BR /&gt;We configured Netflow V9 on some gateways, we collect data in PRTG, pretty simple stuff, it has not many features.&lt;BR /&gt;But it show all together in "one graph". OK&lt;/P&gt;
&lt;P&gt;The customer said its not sufficient, he wants to measure the bits and bytes going through the firewalls. and not just simple bytes but also SRC &amp;amp; DST and services.&lt;BR /&gt;The tool we had was HPE IMC, we setup Netflow and wondered, it show all data in Ingrees graph, all data is in the inbound path.&lt;BR /&gt;The Outbound path is empty.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 949px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17174iEC0ED9DCB95964B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorThomas_Eichelbu_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;So iam asking myself, a rookie in Netflow, is this by design? Or is Check Point lacking some Netflow parameters?&lt;BR /&gt;Or is it a HP IMC related issue?&lt;BR /&gt;It seems all traffic which we produced is inside our Inbound graph ... so nothing is missing.&lt;BR /&gt;&lt;BR /&gt;Sofware is R81 + Take 58 (Clean Install)&lt;BR /&gt;All rules without Accounting! Here the documentation is very contradictory&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/Netflow-Export.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/Netflow-Export.htm&lt;/A&gt;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;You performed a Clean Install of&amp;nbsp;R81&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;UL&gt;
&lt;LI&gt;By default (value 1) the&amp;nbsp;NetFlow&amp;nbsp;export is enabled for traffic accepted by&amp;nbsp;&lt;STRONG&gt;all&lt;/STRONG&gt;&amp;nbsp;Access Control&amp;nbsp;rules.&lt;/LI&gt;
&lt;LI&gt;You can configure the value 0 to enable the&amp;nbsp;NetFlow&amp;nbsp;export&amp;nbsp;&lt;STRONG&gt;only&lt;/STRONG&gt;&amp;nbsp;for traffic accepted by&amp;nbsp;Access Control&amp;nbsp;rules with the&amp;nbsp;&lt;STRONG&gt;Track&lt;/STRONG&gt;&amp;nbsp;option&amp;nbsp;&lt;STRONG&gt;Log&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;Accounting&lt;/STRONG&gt;&amp;nbsp;you configured in&amp;nbsp;SmartConsole.&lt;/LI&gt;
&lt;/UL&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Important&lt;/STRONG&gt;&amp;nbsp;- If you configure the value 0, you must configure the applicable&amp;nbsp;Access Control&amp;nbsp;rules in&amp;nbsp;SmartConsole.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;0 -&amp;gt; Access Control&amp;nbsp;rules with the&amp;nbsp;&lt;STRONG&gt;Track&lt;/STRONG&gt;&amp;nbsp;option&amp;nbsp;&lt;STRONG&gt;Log&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;Accounting&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1 -&amp;gt; enabled for traffic accepted by&amp;nbsp;&lt;STRONG&gt;all&lt;/STRONG&gt;&amp;nbsp;Access Control&amp;nbsp;rules&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But the CLI says: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;SSPFW01&amp;gt; show netflow fwrule&lt;/P&gt;
&lt;P&gt;FW rule: 1 (NetFlow exports its records only for traffic accepted by Access Control rules configured in SmartConsole with the 'Track' option 'Log' and 'Accounting'&lt;/P&gt;
&lt;P&gt;SSPFW01&amp;gt; show netflow fwrule&lt;/P&gt;
&lt;P&gt;FW rule: 0 (NetFlow exports its records for traffic accepted by all Access Control rules)&lt;/P&gt;
&lt;P&gt;strange?&lt;BR /&gt;&lt;BR /&gt;perhaps somebody is expert here.&lt;/P&gt;
&lt;P&gt;best regards&lt;BR /&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 12:32:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/152892#M25626</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-07-13T12:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow, does it show Ingrees and Egrees?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/152928#M25627</link>
      <description>&lt;P&gt;From&amp;nbsp;&lt;SPAN&gt;sk102041&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Note&lt;STRONG style="font-family: inherit; background-color: #ffffff;"&gt;:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;1 - generate netflow records only for rules with accounting enabled. 0 - generate netflow records for all firewall rules (applicable only for R80.40 JHF T87 and above).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Note: “Starting with R81, NetFlow no longer requires Log/Accounting to be enabled and logging is off by default. There is the new ‘NetFlow FW rule’ option to configure NetFlow to report per FW rule by turning it on and enabling Log/Accounting per FW rule. This option is off by default so it must be enabled when upgrading from R80.20/30/40&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 23:33:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/152928#M25627</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-13T23:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow, does it show Ingrees and Egrees?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/153012#M25628</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes thank you i unserstand.&lt;BR /&gt;&lt;BR /&gt;with value 0 i get all the Netflow data&lt;BR /&gt;with value 1 i dont receive any Netflow data&lt;BR /&gt;in my setup&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;my question was more,&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;who has experience with Netflow and Check Point, are Ingrees and Egrees charts visible or is this totally appliction dependend?&lt;BR /&gt;or is this not required because its all in one view and you can drill down into the session, and therefore IN and OUT is not required?&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 15:17:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/153012#M25628</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-07-14T15:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow, does it show Ingrees and Egrees?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/153013#M25629</link>
      <description>&lt;P&gt;If I remember correctly the flow records should include "InputInt" and "OutputInt" interface index values to allow for appropriate charting, unsure if this is netflow version dependent would need to check it further.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 15:29:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/153013#M25629</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-14T15:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow, does it show Ingrees and Egrees?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/153734#M25864</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;well yes, a TAC Case is ongoing ... lets see what we find ...&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 09:55:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/153734#M25864</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-07-25T09:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow, does it show Ingrees and Egrees?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/166442#M29955</link>
      <description>&lt;P&gt;Dear Thomas,&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Thanks for your query, i am also want to know whether checkpoint provides the flow direction in netflow. OEMs like palo-alto is providing those information.&amp;nbsp; please share the TAC case report.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jan 2023 21:50:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-does-it-show-Ingrees-and-Egrees/m-p/166442#M29955</guid>
      <dc:creator>james-07</dc:creator>
      <dc:date>2023-01-01T21:50:31Z</dc:date>
    </item>
  </channel>
</rss>

