In our environment, we have Checkpoint SMB devices which is managed by 6600 device in datacenter. when we enable netflow in checkpoint device it captured only the encrypted traffic in Netflow where its not capturing unencrypted traffic which is passing through internet.
In netflow enabled device SNMP and UDP is flowing where TCP is missed.