<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Netflow in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199412#M33301</link>
    <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;What should i do if in the netflow manager we see conversation from ip public to ip public? My goal is to capture netflow from LAN (internal private ip) to the destination (public ip)?&lt;/P&gt;</description>
    <pubDate>Fri, 01 Dec 2023 01:03:30 GMT</pubDate>
    <dc:creator>handiansudianto</dc:creator>
    <dc:date>2023-12-01T01:03:30Z</dc:date>
    <item>
      <title>Netflow</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199412#M33301</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;What should i do if in the netflow manager we see conversation from ip public to ip public? My goal is to capture netflow from LAN (internal private ip) to the destination (public ip)?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 01:03:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199412#M33301</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-12-01T01:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199413#M33302</link>
      <description>&lt;P&gt;Im not really clear what you are trying to do here. Just capture traffic or something else? If its capturing, then you can do something like this -&amp;gt; fw monitor -F "srcIP,srcport,dstIP,dstport,protocol"&lt;/P&gt;
&lt;P&gt;example&amp;nbsp; fw monitor -F "1.1.1.1,0,2.2.2.2,4434,0"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 01:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199413#M33302</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-01T01:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199415#M33303</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What i mean is i have Network Traffic Analyst (NTA) tools from solarwinds to capture all network conversation between the client to to the internet using netflow. I already enable netflow side but when i see on the solarwinds the conversation shown from our public IP as the source to the internet. I just want to know how we can get real client ip (private ip of the client) on the netflow, so we can see conversation traffic of each users.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 01:41:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199415#M33303</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-12-01T01:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199416#M33304</link>
      <description>&lt;P&gt;Ah, got it! Make sure its configured properly in netflow section of web UI or in clish with something like show netflow command. I can check in my lab tomorrow. If I recall right, there is an option in web UI for netflow to set the correct interface as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 01:44:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199416#M33304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-01T01:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199417#M33305</link>
      <description>&lt;P&gt;Thanks you, i believe i already configure the netflow but seem the netflow capture the traffic after NAT process so the real ip is not showing.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 01:46:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199417#M33305</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-12-01T01:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199418#M33306</link>
      <description>&lt;P&gt;You can always set manual NAT for it, just make sure you are not nattimg that host behind the fw, otherwise, it will show public IP.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 02:17:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199418#M33306</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-01T02:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199420#M33307</link>
      <description>&lt;P&gt;For awareness:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="notes.png" style="width: 875px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23489iDD120D04FCFB28A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="notes.png" alt="notes.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 03:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Netflow/m-p/199420#M33307</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-01T03:03:06Z</dc:date>
    </item>
  </channel>
</rss>

