We've just released UTM 9.707. As usual, the release will be rolled out in phases:
NUTM-12672 [Logging] IPFIX does not switch source and destination ports between inbound and outbound side of flow
Can u explain this please
IPFIX is a way of outputting log information about network flows seen by the UTM. TCP connections are two-way flows - a client-server flow and a server-client flow. IPFIX data shows the two halves of the flow separately.
Each half of the flow is identified by source IP address & port, and destination IP address & port.
For a connection from client 192.168.7.5 port 54345 to server 10.10.10.10 port 443, the two half-flows should be labelled as follows:
In this issue, it was noticed that sometimes the IPFIX data showed the ports on the server-client flow were the wrong way round, so you would get:
After installing 9.707, this issue should no longer be observed in IPFIX output.