Anyone have experience with exporting flows from checkpoint IP firewalls (running IPSO6x) ?
Unlike Cisco configuration, the control over the netflow export is limited.
It appears to export in/out flows for all interfaces on the systm when enabled.
As a result, in the RA the actual flow rates appear to be double counted.
Changing the flow export version from v5 to v9 (in an attempt to have RA leverage off the direction field) appears to make no difference.
Has anyone come across this behaviour ?