- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Netflow for R80.10
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Netflow for R80.10
Anyone ever send Netflow data to Stealthwatch, I'm can't find any data sheet that list the collectors that are compatible with Checkpoint Firewall.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is a standard, so it should just work.
Positive results on 80.10 ipfix / netflow 10 towards an nfsen based Flowmon collector.
Would be nice to see more extended npm ipfix fields:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm with the same problem trying to send Netflow to Stealthwatch.
Im using Check Point Sec. Gw Gaiga R80.30 with IPFIX (netflow 10) sending data Stealthwatch 7.0.0 but the error that STW show is "Invalid Template Data - Exporter has send invalid template data".
Any suggestions?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Most Netflow applications first want to read from the device via SNMP when you add the device to get information on the interfaces, so you also need to make sure this is allowed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
After some attempts, it worked perfectly with Netflow v5.
Stealthwatch v7.1.0 (as far as I could try) could not recognize Check Point netwflows v9 and IPFIX.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Late answer, but it seems in v9/ipfix packet from Gaia, "IP ToS" field is missing and it is required for Stealthwatch.
This field is available in v5, so no problem with it.
Still looking for resolution
