Learn how to configure NetFlow devices and collect more detailed network traffic data with WhatsUp Gold NetFlow Monitor when using Firewalls and VPN tunnels. Enabling a second NetFlow router before the firewall will enable the NetFlow collector to see the client's ip address that originated the packet instead of the firewall's natted IP address. Accessing the client's internal ip address will enable you to view specific details and troubleshoot client specific issues.
In the case of the VPN tunnel, its not being NATed. The original packet has been encrypted and encapsulated using GRE with the source and destination IP address of the firewalls.
her209 4 months ago