<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netflow IPSec in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206998#M39121</link>
    <description>&lt;P&gt;K, did you confirm that collector is part of proper vpn enc domain?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2024 10:05:27 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-23T10:05:27Z</dc:date>
    <item>
      <title>Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206773#M39054</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I already configure the netflow on my checkpoint 5800 series and seem the netfow i working fine, i can see the checkpoint send the data to collector.&lt;/P&gt;&lt;P&gt;But when i check detailly why the netflow not send data if the destination located behind vpn site to site? I can see the checkpoint not send any data to our azure resource which using ipsec vpn site to site.&lt;/P&gt;&lt;P&gt;I do copy file from our onprem server to azure with private endpoint and capture the traffic using wireshark on collector server and found no data&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 04:00:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206773#M39054</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-22T04:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206775#M39055</link>
      <description>&lt;P&gt;Is tunnel up? If yes, is this only thing thats failing?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 04:13:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206775#M39055</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T04:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206790#M39057</link>
      <description>&lt;P&gt;yes of course the tunnel is up, i generate the traffic by copy file from onprem to azure and this will pass thru vpn tunnel.&lt;/P&gt;&lt;P&gt;es, i can see all traffic to the tunnel no log on netflow&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 05:27:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206790#M39057</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-22T05:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206830#M39067</link>
      <description>&lt;P&gt;Wait...to make sure we are on the same page here...are you saying that netflow traffic is actually going through the tunnel but you siomply canNOT see the log for it or am I totally mistaken when I say that?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 13:45:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206830#M39067</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T13:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206899#M39076</link>
      <description>&lt;P&gt;One good command you can also do is below&lt;/P&gt;
&lt;P&gt;example, say src is 1.1.1.1, dst is 2.2.2.2, dst port is 4434...it would go src ip, scr port. dst ip, dst port, protocol&lt;/P&gt;
&lt;P&gt;fw monitor -F "1.1.1.1,0,2.2.2.2,4434,0" -F "2.2.2.2,0,1.1.1.1,4434,0"&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 18:51:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206899#M39076</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T18:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206946#M39104</link>
      <description>&lt;P&gt;Hi..&lt;/P&gt;&lt;P&gt;We can see log on the checkpoint firewall but not see on the netflow collector.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:43:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206946#M39104</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-23T01:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206947#M39105</link>
      <description>&lt;P&gt;The traffic is shown on the log, just on netflow collector the traffic is unseen by capturing using wireshark on the collector&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206947#M39105</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-23T01:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206948#M39106</link>
      <description>&lt;P&gt;It might be simple fix as possibly restarting the collector...have you attempted so?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:44:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206948#M39106</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T01:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206949#M39107</link>
      <description>&lt;P&gt;Are you able to ping the fw from the collector itself?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:45:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206949#M39107</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T01:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206951#M39108</link>
      <description>&lt;P&gt;yes, actually the netflow is sending the data to the collector but i believe the netflow not send all traffic.&lt;/P&gt;&lt;P&gt;So i test by copy file from onprem to azure and the traffic not seen by collector, but if i test by browsing to the internet i can see the traffic on the collector.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206951#M39108</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-23T01:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206952#M39109</link>
      <description>&lt;P&gt;Only fails via vpn?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206952#M39109</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T01:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206954#M39110</link>
      <description>&lt;P&gt;Mostly yes, every day we have daily backup to azure and i not find this log on the collector. Usually on other firewall we can select netflow to be running on which interface, but i not see this on checkpoint. Are netflow on checkpoint will enabled on all interface including virtual interface like the tunnel?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:02:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206954#M39110</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-23T02:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206956#M39111</link>
      <description>&lt;P&gt;Well, what interface is it enabled on?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:04:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206956#M39111</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T02:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206957#M39112</link>
      <description>&lt;P&gt;You can see on the pic we cant select on which interface will be enabled&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206957#M39112</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-23T02:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206961#M39113</link>
      <description>&lt;P&gt;Apologies, its been some time since I did this, you are 100% right, just checked it in my lab. Sorry mate, not sure at this point, maybe better have TAC case open, might be worth remote session to check further.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:30:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206961#M39113</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T02:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206962#M39114</link>
      <description>&lt;P&gt;did you mean checkpoint netflow have some missing data or we can't selech on which interface netflow can be enabled?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:34:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206962#M39114</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-23T02:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206963#M39115</link>
      <description>&lt;P&gt;I dont believe there is missing data, looks right to me. No, you cant select the interface...k, silly ?, but did you make sure netflow collector is part of the enc domain?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:37:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206963#M39115</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T02:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206967#M39116</link>
      <description>&lt;P&gt;You can also verify it via clish -&amp;gt; show netflow and then tab for all the options&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206967#M39116</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T02:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206974#M39117</link>
      <description>&lt;P&gt;Here the result&lt;/P&gt;&lt;P&gt;show netflow all&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Fw rule: No&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Address Port Format Src Addr Enable&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;10.103.248.55 2055 IPFIX 10.103.253.10 yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;show netflow collector&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Collector IP Address 10.103.248.55&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Collector UDP Port 2055&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Export Format IPFIX&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Source Address 10.103.253.10&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Enabled yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;show netflow fwrule&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FW rule: No&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 03:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206974#M39117</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-02-23T03:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow IPSec</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206975#M39118</link>
      <description>&lt;P&gt;Seems fine. Did you make sure collector is part of the end domain?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 04:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Netflow-IPSec/m-p/206975#M39118</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T04:02:36Z</dc:date>
    </item>
  </channel>
</rss>

