Netflow Export
Introduction
NetFlow is an industry standard for traffic monitoring. It is a network protocol developed by Cisco for collecting network traffic patterns and volume. It lets one host (the Exporter) send information about network flows to another host (the Collector). A network flow is a unidirectional stream of packets that share a set of characteristics.
You can configure Security Gateways and Cluster Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. Members that run on Gaia
Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. Operating System as an Exporter of NetFlow records for all the traffic they inspect.
The Collector is supplied by a different vendor, and is configured separately.
NetFlow Export configuration is a list of collectors, to which the service sends records:
-
To enable NetFlow, configure at least one collector.
-
To disable NetFlow, make sure no collectors are configured.
You can configure up to three collectors. NetFlow records go to all configured collectors. If you configure three collectors, each record is sent three times.
Regardless of which NetFlow export format you choose, Gaia operating system exports values as set of fields.

-
Source IP address
-
Destination IP address
-
Source port
-
Destination port
-
Ingress physical interface index (defined by SNMP)
-
Egress physical interface index (defined by SNMP)
-
Packet count for this flow
-
Byte count for this flow
-
Start of flow timestamp (FIRST_SWITCHED)
-
End of flow timestamp (LAST_SWITCHED)
-
IP protocol number
-
TCP flags from the flow (TCP only)
|
Notes:
|
For more information, see sk102041: NetFlow support by Gaia OS.
Configuration Procedure
-
Configure the Netflow Export settings on Gaia
You can configure these settings either in Gaia Portal
Web interface for the Check Point Gaia operating system., or in Gaia Clish
The name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell)..
Configuring the NetFlow settings In Gaia Portal
-
In the left navigation tree, click Network Management > NetFlow Export.
-
Click Add.
-
Enter the required data for each collector:
Configuring the NetFlow settings In Gaia Clish
Note - You must run these commands in Gaia gClish
The name of the global command line shell in Check Point Gaia operating system for Security Appliances connected to Check Point Quantum Maestro Orchestrators. Commands you run in this shell apply to all Security Appliances in the Security Group. of the applicable Security Group.
Syntax
-
To add a Netflow collector:
-
To change settings of a Netflow collector:
-
To show a Netflow collector:
-
To delete a Netflow collector:
Important - After you add, configure, or delete features, run the "
save config
" command to save the settings permanently. -
-
In SmartConsole, configure the explicit Access Control rule
-
From the left navigation panel, click Security Policies.
-
Open the applicable policy.
-
In the top left corner, click Access Control > Policy.
-
Add an explicit rule
Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. for the traffic that you wish to export with Netflow:
Important - In the
Track
column, you must selectLog
andAccounting
. -
Publish the SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. session.
-
Install the Access Control policy on the Security Group object.
-