Pre R80.10 Netflow worked fine.
Now on R80.30 I have two flows that are identical -- but one only shows Outbound and the other only shows Inbound BUT -- and this is perplexing -- it is the exact same traffic for both inbound and outbound flows -- i.e. source and destination are the same.
Yes.. let that simmer for a while.
I have one rule that's configured on the firewall and it's a rule that a lot of web traffic hits on.
I'm using ManageEngine's Netflow Analyzer.
For this traffic, I would expect there should be one flow and it should include both inbound and outbound traffic on the one interface (the internal interface it's hitting).