HowTo Collect Flows: the Case of Palo Alto and Fortinet
Network devices export flow data in many flavors. Some vendors stick closely to the NetFlow/IPFIX standard, so collecting their flows is essentially plug-and-play. Others extend the standard with proprietary Information Elements (IEs) to expose vendor-specific details (e.g. application names, user identities, security verdicts, etc) which requires a bit of extra configuration on the collector side. In this post we revisit and update an older article on collecting proprietary flows with nProbe, using two widely deployed firewall vendors as concrete examples: Fortinet FortiGate and Palo Alto Networks. Two Different Approaches, One Collector FortiGate exports flow data …
