Skip to main content
gonzo
New Member
June 14, 2017
Question

Enabling sFlow/Netflow on Fortigate 60D

  • June 14, 2017
  • 4 replies
  • 24892 views

Hello,

 

I've been enabling sFlow/Netflow on all our Cisco Firewalls and Routers, and all the data is successfully showing up.  I've now been asked to enable it on a Fortigate Firewall which I have no experience with (Fortigate 60D v5.0,build0208 GA Patch 3).

 

I've added the following but nothing is coming through on the Netflow server:

 

config system sflow set collector-ip 192.168.18.159 set collector-port 9996 end config system interface  edit internal set sflow-sampler enable set sample-rate 512 set sample-direction both set polling-interval 30

 

edit WAN set sflow-sampler enable set sample-rate 512 set sample-direction both set polling-interval 30

 

edit DMZ set sflow-sampler enable set sample-rate 512 set sample-direction both set polling-interval 30

 

Maybe the flows are being sent via the wrong interface and can't get to the sFlow/Netflow server?  The sFLow/Netflow server is at a remote site via a router that sits on the same VLAN as the 'internal' interface.

 

FIREWALL # diagnose sniffer packet 'host 192.168.18.159' 6 0 a interfaces=[host 192.168.18.159] filters=[6] pcap_open_live: ioctl: No such device for host 192.168.18.159

 

Thanks

 

 

 

4 replies

emnoc
New Member
June 14, 2017

Your on the right track but did you enable it  if your in a vdom

 

e.g

 

config system vdom-sflow     set vdom-sflow enable

    set collector-ip 192.168.18.159     set collector-port 9996     set source-ip 0.0.0.0  <-----change this to set the src_ip

end

 

Also are you 100% sure the FGT60D support sflow and for that fortiosVersion ?

 

Ken

 

 

 

 

emnoc
New Member
June 14, 2017

FWIW ,  RTFM  for release notes bugs,fixes,notes.......

 

 

"171529 sFlow does not work correctly with NPU interfaces." http://docs.fortinet.com/uploaded/files/1032/FortiOS-v5.0-Patch-Release-3-Release-Notes.pdf     That fortiOS version is quite older,  and you should really upgrade imho.   ken  

 

gonzo
gonzoAuthor
New Member
June 15, 2017

just noticed only inbound traffic is showing too.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!