Palo Alto
To configure NetFlow on a Palo Alto firewall, follow these steps:
1. Define a NetFlow Profile
Go to Device → Server Profiles → NetFlow.
Click Add.
Give the profile a name.
Configure:
Collector IP address (your flow collector).
Port (default 2055 for NetFlow, or whatever your collector expects).
Protocol: UDP.
Active Timeout: Typically 1 minute (controls how often long-lived sessions are reported).
Inactive Timeout: Usually 15 seconds (when a session has been idle).
Select Template Refresh Rate (number of flows before resending template).
2. Attach NetFlow Profile to Interfaces
Go to Network → Interfaces.
Select the interface(s) you want to export flows for (e.g., WAN, LAN, DMZ).
Under the Advanced → NetFlow tab:
Enable NetFlow.
Choose the NetFlow profile you just created.
3. Commit the Configuration
Click Commit to push changes to the running config.
4. Verify
On the collector, you should start seeing flows.
On the firewall itself, you can check via CLI:
These confirm templates and exports are active.
Last updated
Was this helpful?
