Palo Alto NetFlow Source Interface Issue

Trying to get NetFlow on 5020 and I believe I'm running into this issue -   (+) NTA Palo alto sflow issue - Forum - NetFlow Traffic Analyzer (NTA) - THWACK (solarwinds.com)  

Configure NetFlow Exports (paloaltonetworks.com)

I'm able to collect flow from the Interfaces as virtual, but its ugly when reviewing flow since the device receiving flow is "unknown" since SNMP monitoring is directed to the management plane and netflow is coming from the data plane, and we cannot monitor SNMP on the data plane.

How do people handle this situation?

Parents
  • Under Setup > Interfaces > _your_mgmt_interface_ > Network Services, make sure SNMP is checked.
    In the same window, make sure that the SolarWinds Platform polling server IP address is added in the Permitted section.

    Under Setup > Services > Services Features, if you have "Use Management Interface for all" in your Service Route Configuration, then no need to make any changes. However, if you have it set to custom, then you'll need to make sure that NetFlow is set to use default for both source and interface.

    Under Setup > Operations > Miscellaneous, make sure that SNMP is copnfigured

    Under Server Profiles > Netflow, make sure that the SolarWinds Platform poller that is receiving the flow is defined on port 2055, with 1 Minute refresh, 20 Packets, 1 minute timeout. We don't want PAN-OS field types.

Reply
  • Under Setup > Interfaces > _your_mgmt_interface_ > Network Services, make sure SNMP is checked.
    In the same window, make sure that the SolarWinds Platform polling server IP address is added in the Permitted section.

    Under Setup > Services > Services Features, if you have "Use Management Interface for all" in your Service Route Configuration, then no need to make any changes. However, if you have it set to custom, then you'll need to make sure that NetFlow is set to use default for both source and interface.

    Under Setup > Operations > Miscellaneous, make sure that SNMP is copnfigured

    Under Server Profiles > Netflow, make sure that the SolarWinds Platform poller that is receiving the flow is defined on port 2055, with 1 Minute refresh, 20 Packets, 1 minute timeout. We don't want PAN-OS field types.

Children
No Data