Technical Tip: Netflow sampler can not be enabled on an Vdom link interface
| Description | This article describes how to resolve the error 'Netflow sampler is not supported on Vdom link interface' when enabling the netflow sampler on the Vdom link interface. |
| Scope | FortiGate. |
| Solution | Creating a NetFlow sampler will not support the VDOM link interface.
For configuration and troubleshooting steps for NetFlow in FortiGate, see Technical Tip: How to Configure Netflow.
The role of the VDOM-Link interface: A vdom-link interface is a special internal software-based interface used to pass traffic between two Virtual Domains (VDOMs) within the same physical FortiGate. VDOM-Link Interface is not a physical port or a standard VLAN; it is a virtual pipeline. For more information about the VDOM, refer to Inter-VDOM routing.
For NetFlow (or sFlow) to function, the sampling engine must be able to inspect packets as they flow through a specific interface. The sampler taps into the packet forwarding path of that interface, creates flow records, and exports them to a collector. The sampling typically happens at a point in the data plane that is associated with a 'real' ingress or egress interface.
From FortiOS's perspective:
The NetFlow sampler can only sample traffic on the physical (or logical like VLAN) interfaces in VDOM-A and VDOM-B. The internal handoff point (vdom-link) is not equipped for flow sampling. |

