- CheckMates
- :
- Products
- :
- General Topics
- :
- Netflow
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Netflow
Hello,
We using solarwinds NTA to capture traffic conversation, but i can see the conversation for my checkpoint is from public ip to public ip. What can we do on checkpoint side so netflow only send conversation from client ip address (not natted ip address) to the internet?
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The IP addresses and TCP/UDP ports reported by NetFlow are the ones on which it expects to receive traffic.
Therefore, for NATed connections, one of the two directions of flow is reported with the NATed address.
This is, therefore, expected behavior.
See: https://support.checkpoint.com/results/sk/sk102041
