MetricSplit › Guides › Palo Alto Networks
How to send NetFlow from a Palo Alto Networks firewall to a flow collector
PAN-OS firewalls export NetFlow per interface, using a NetFlow server profile.
What it sends
NetFlow v9 records for traffic entering each interface the profile is applied to: addresses, ports, protocol, ToS, TCP flags, incoming bytes and packets, input and output interface, first and last seen, direction. App-ID and User-ID are in extra "enterprise" fields when PAN-OS Field Types is on.
Steps
- Device › Server Profiles › NetFlow: add a profile. Template Refresh Rate (Palo Alto's defaults: 30 minutes, 20 packets), Active Timeout (default 5 minutes), and optionally PAN-OS Field Types (exports App-ID and User-ID fields).
- In the same profile, set Active Timeout to 1 minute, the shortest PAN-OS allows (Palo Alto: 1 - 60 minutes, default 5). Why: MetricSplit works in 5-minute readings, so a long-running flow has to be reported at least every minute to land in the right reading.
- Add the collector (up to two per profile): a name, the server (192.0.2.10) and the port (default 2055).
- Network › Interfaces › Ethernet: assign the profile to each interface whose incoming traffic you want; to see both directions of the internet link, assign it to the internet interface and the inside interfaces.
- PA-7000, PA-7500, PA-5500, PA-5450 and PA-5200 Series: set a service route for NetFlow (Device › Setup › Services), as these can't send it from the management interface. Then Commit.
Check it's working
A packet capture on the collector (tcpdump -ni any udp port 2055) shows whether records arrive; PAN-OS's own monitoring is described in the guide linked below.
Vendor documentation
What MetricSplit does with flow records
MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence.