- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: netfow seems broken on 1500
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
netfow seems broken on 1500
i enabled netflow to send data to an elk stack instance. Nothing showed up. Ran a packet capture.. nothing in capture..
netstat -an | grep 2055 ...nada
did a strace on the netflow process and i see over and over
9984 openat(AT_FDCWD, "/proc/ppk/netflow-conf", O_RDWR) = -1 ENOENT (No such file or directory)
which for sure doesn't exist. Sad panda, case opened. Oh and yes I rebooted after turned on netflow.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Per sk159772 it should be supported, which version/build are you running?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is Check Point's 1550 Appliance R80.20.01 - Build 909 - this is to fix the kernel panic in the other thread.
I noticed some extra config options opened up now and I don't understand what they do. The docs are good enough to tell me the arguments are IP and port. That cleared up a lot.
set netflow collector for-ip x.x.x.x for-port 2055
I have no idea what a for-ip and for-port is but it seems to auto fill with the collector ip and port. ¯\_(ツ)_/¯
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you configure the net flow collector following SMB 1500 Appliance Series R80.20.01 CLI Reference Guide p.627ff ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Indeed, this is broken on 15xx; We suspect similar issue on other releases
We are working to fix it
Thanks
Amir
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hot off the presses.
Netflow support is indeed broken and the support page is going to be updated to reflect Netflow being unsupported on R80.20 Gaia Embedded.
It is planned to be fixed but there is no ETA. At least I wasn't told to go RFE myself so hurrah for that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That is very disturbing news actually 😟
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@John_Fleming where this info coming from? sk159772 says Netflow is supported on R80.20.x with the only limitations related to CLI config.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there any update regarding this issue?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Netflow is supported on Gaia SMB R80.20.x versions and can be configured via CLI only
