Skip to main content
Sushilk
New Member
October 31, 2014
Question

sflow with wireshark

  • October 31, 2014
  • 3 replies
  • 9901 views

Hello,

I require to capture the traffic on wireshark.More or less the way if using SPAN port on Cisco switch.

So found if sflow can be used on Fortigate as I do not have any managed switch in our network.

 

Configured and sflow collector ip as the wireshark PC and enabled interface on fortigate internal interface.

 

I can see still not traffic does it captures except the one destined to or from the wireshark pc.

Any expert suggestions please.

 

Regards,

Sushil

    3 replies

    norouzi
    New Member
    October 31, 2014

    What is your exact configuration?

    There are two parts that you must enable.

     

    config system sflow set collector-ip <collector_ipv4> set collector_port <port_int> end

     

    and :

     

    config system interface edit <interface_name>

    set sflow-sampler {disable | enable}

    end

     

    Sushilk
    SushilkAuthor
    New Member
    October 31, 2014

    The config is as below

    config system sflow    set collector-ip 192.168.1.78    set collector-port 6343 end

    and internal gateway

    config sys interface     edit internal        set sflow-sampler enable        set sample-rate 512        set sample-direction both        set polling-interval 30     next end

    netmin
    New Member
    October 31, 2014

    Some tools that may help:

     

    This one should show some traffic, if sFlow is configured correctly: http://www.paessler.com/tools/sflowtester

    Using Wireshark & sflowtool on Linux: http://blog.sflow.com/2011/11/wireshark.html 

     

    sflowtool: http://www.inmon.com/technology/sflowTools.php

     

    the cmd variant on Windows, when sflowtool is located in the Wireshark directory: sflowtool.exe -t | wireshark.exe -k -i -

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.