The Netflow data the Palo Alto PA-220 firewall is sending displays registered (external) IP addresses for internal computer Internet traffic.
How can I configure the Netflow probe to use whichever templates will provide us with the LAN IP addresses?
Value Field Description Templates
225 postNATSourceIPv4Address The definition of this information element is identical to that of sourceIPv4Address, except that it reports a modified value that a NAT middlebox function caused after the packet passed the observation point . IPv4 with NAT standard IPv4 with NAT enterprise
226 postNATDestinationIPv4Address The definition of this information element is identical to that of destinationIPv4Address, except that it reports a modified value that a NAT middlebox function caused after the packet passed the observation point. IPv4 with NAT standard IPv4 with NAT enterprise
227 postNAPTSourceTransportPort The definition of this information element is identical to that of sourceTransportPort, except that it reports a modified value that a Network Address Port Translation (NAPT) middlebox function caused after the packet passed the observation point. IPv4 with NAT standard IPv4 with NAT enterprise
228 postNAPTDestinationTransportPort The definition of this information element is identical to that of destinationTransportPort, except that it reports a modified value that a Network Address Port Translation (NAPT) middlebox function caused after the packet passed the observation point.
Add comment