<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Advanced NetFlow Traffic Analysis - Next Generation Firewall Archives</title>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/advanced-netflow-traffic-analysis/" />
    <link rel="self" type="application/atom+xml" href="http://blog.tmcnet.com/advanced-netflow-traffic-analysis/next-generation-firewall/atom.xml" />
    <id>tag:blog.tmcnet.com,2012-01-03:/advanced-netflow-traffic-analysis//164</id>
    <updated>2013-06-01T16:02:38Z</updated>
    

<entry>
    <title>Palo Alto Networks NetFlow Export includes Firewall Event Field in PAN-OS 5.0</title>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/advanced-netflow-traffic-analysis/2012/11/palo-alto-networks-netflow-export-includes-firewall-event-field-in-pan-os-50.html" />
    <id>tag:blog.tmcnet.com,2012:/advanced-netflow-traffic-analysis//164.50343</id>

    <published>2012-11-25T15:31:43Z</published>
    <updated>2013-06-01T16:02:38Z</updated>

    <summary><![CDATA[Palo Alto Networks is showing further commitment to NetFlow Reporting by including a Firewall Event element in PAN-OS 5.0.&nbsp; This new field will provide a few new advantages to Firewall Administrators.&nbsp; These improvements to their NetFlow export can be seen...]]></summary>
    <author>
        <name>Michael Patterson</name>
        <uri>http://blog.tmcnet.com/advanced-netflow-traffic-analysis/</uri>
    </author>
    
        <category term="Firewall Event" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Netflow reporting" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Next Generation Firewall" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Palo Alto Networks" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="firewall event" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="firewallevent" label="Firewall Event" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="netflowreporting" label="Netflow reporting" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="nextgenerationfirewall" label="Next Generation Firewall" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="paloaltonetflowpartner" label="Palo Alto NetFlow Partner" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="paloaltonetworks" label="Palo Alto Networks" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="paloaltopanos50" label="Palo Alto Pan OS 5.0" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.tmcnet.com/advanced-netflow-traffic-analysis/">
        <![CDATA[Palo Alto Networks is showing further commitment to <a title="Palo Alto NetFlow Reporting" href="http://media.paloaltonetworks.com/documents/plixer.pdf">NetFlow Reporting</a> by including a Firewall Event element in <a title="Palo Alto Pan OS 5.0" href="http://media.paloaltonetworks.com/documents/whats-new-pan-os-5.0.pdf">PAN-OS 5.0</a>.&nbsp; This new field will provide a few new advantages to Firewall Administrators.&nbsp; These improvements to their NetFlow export can be seen in multiple ways:<br /><!-- pagebreak -->The ability to trend flows Deleted, Created or Denied for example allows administrators to gain visibility into historical baselines on how the Next Generation Firewall traditionally treats traffic headed for the internet. <br /><br /><img src="http://blog.tmcnet.com/advanced-netflow-traffic-analysis/images/paloAltoNetworksFirewallEventspng.png" alt="Palo Alto Networks Firewall Events" width="623" height="297" /><br /><br />If an abnormal spike or drop occurs in the above trend, administrators can drill in to find out what machines were involved and which applications were being used at the time.&nbsp; This data can also be bundled together with multiple firewalls to gain a more enterprise view of the corporate Internet behavior. <br /><br />Administrators can use the above report to set thresholds on volumes of unacceptable 'denied' events.&nbsp; If a host causes connections in a way that violates a threshold, unacceptable rates of denied violations can trigger events which lead to notifications.&nbsp; <br /><br /><img src="http://blog.tmcnet.com/advanced-netflow-traffic-analysis/images/paloAltoNetworksFirewallEventsByHost.png" alt="Palo Alto Networks Firewall Events By Host" width="620" height="358" />&nbsp;<br />Administrators can also use the NetFlow Reporting solution to filter for a specific host which might be having trouble communicating through the Next Generation Firewall.&nbsp; They can then run a Palo Alto Networks 'Events' report to find out what specifically is in the end systems traffic that is causing a "Flow Denied" event to occur. <br /><br /><a title="Palo Alto NetFlow Configuration" href="http://www.plixer.com/blog/netflow-reporting-2/how-to-configure-palo-alto-networks-netflow/">Configuring a Palo Alto Networks Firewall to export NetFlow</a> is straight forward process and the value gained is considerable.&nbsp; Industry leading NetFlow features include:<br />
<ul>
<li>Application Awareness: They use Deep Packet Inspection (DPI) to identify and separate applications that share ports such as TCP 80.</li>
<li>Username: If users have to authenticate with Active Director or LDAP, the firewall can tie the username to the flows.&nbsp; This eases trouble shooting efforts during times of forensic analysis.</li>
<li>Network Address Translation: This can be a big time saver when trying to find out what an IP address was internally before it was NAT'ed by the firewall.</li>
<li>Firewall Event: The newest edition to their export provides the values outlined above.</li>
<li>Syslog Correlation with NetFlow: The message log exported by the firewall can be formatted into IPFIX and correlated with the NetFlow data to ensure speedy identification of potential attacks</li>
</ul>
Vendors recognize that Flow technology is a primary feature necessary to be a contender in the Next Generation Firewall space.&nbsp; Clearly Palo Alto Networks understands which features matter most and has moved quickly to service the needs of their customer base and has partnered with Plixer to bring them to market. <br /><br />The combined <a title="Palo Alto NetFlow Partner" href="http://researchcenter.paloaltonetworks.com/2012/02/a-warm-welcome/">Plixer and Palo Alto</a> solution also includes:<br />
<ul>
<li>Host reputation monitoring</li>
<li>Enterprise application usage and performance monitoring</li>
<li>Mitigation of evolving threats</li>
<li>Audit trails of all internal and external traffic</li>
<li>The very best in network performance reporting</li>
</ul>
With thousands of customers, Scrutinizer plays a key role across global 2000 enterprises and governments.&nbsp; Scrutinizer can detect zero-day types of malware including APT attacks.<br /><br /><br />]]>
        
    </content>
</entry>

</feed>
