Hi all,
In the past I successfully configured my Fortigate, an FG101E v7.0.13 to send Netflow data to an Elastiflow server. At that time we had two separate internet connections WAN1 and WAN2. Today these two interfaces have been put in an aggregate called LAG_WAN.
I'm following this documentation: https://docs.fortinet.com/document/fortigate/7.0.13/administration-guide/998643/netflow
I can no longer do the `set-netflow sampler both` on the aggregated interfaces. The instruction ends with a parse error. I can do it on the LAG_WAN aggregate, but also I'm getting a few netflow packets, it's just garbage and is not the netflow for data that goes over my WAN1 and WAN2 interfaces.
Can anyone help me understand how to configure such an aggregated interface to send netflow data ?
Thanks,
Olivier.
Hi there,
In the past when I have used Netflow on environments that I am running SD-WAN setting the interface under the config system netflow is required. This is to ensure that the traffic flows over the interface you would like it to despite setting the source IP and necessary routing which isn't always enough. I would try and set:
config system netflow
set interface-select-method specify
set interface LAG_WAN
end
Regards,
Dan.
User | Count |
---|---|
1923 | |
1144 | |
769 | |
447 | |
279 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.