These instructions assume:
- The model of Check Point firewall is 600, 700, 1100, 1200R, or 1400.
- The version running on the firewall is R77.20.70 or higher.
- The date, time and time zone are correctly set on the firewall.
- You have Telnet or SSH credentials and access to your Check Point firewall.
- The IP address of your Auvik collector is known.
If you are using a shared collector and want TrafficInsights to associate flow data with the correct site, you must add the source IP address as a dedicated /32 network within Auvik.
For example:
192.168.1.10/32Even if the source IP address is already included in a larger monitored subnet, a dedicated /32 entry is required for TrafficInsights to correctly associate flow records with the appropriate site.
After making this change, it may take several minutes before flow data appears in TrafficInsights.
Access your firewall CLI
- Telnet or SSH into your firewall.
- Enter privileged mode by typing enable and entering your enable password.
Enable the NetFlow export format
- On your firewall, execute the following command. Replace AuvikCollectorIp with the IP of your Auvik collector and AuvikPort with one of the following ports: 2055, 2056, 4432, 4739, 6343, 9995, or 9996.
add netflow collector ip <AuvikCollectorIp> port <AuvikPort> export-format Netflow_V9 <AuvikCollectorIp> is-enabled true
- Run the following command to confirm the configuration.
show netflow collector ip <AuvikCollectorIp> port <AuvikPort>
References: