Hi all,
In the past I successfully configured my Fortigate, an FG101E v7.0.13 to send Netflow data to an Elastiflow server. At that time we had two separate internet connections WAN1 and WAN2. Today these two interfaces have been put in an aggregate called LAG_WAN.
I'm following this documentation: https://docs.fortinet.com/document/fortigate/7.0.13/administration-guide/998643/netflow
I can no longer do the `set-netflow sampler both` on the aggregated interfaces. The instruction ends with a parse error. I can do it on the LAG_WAN aggregate, but also I'm getting a few netflow packets, it's just garbage and is not the netflow for data that goes over my WAN1 and WAN2 interfaces.
Can anyone help me understand how to configure such an aggregated interface to send netflow data ?
Thanks,
Olivier.
Hi there,
In the past when I have used Netflow on environments that I am running SD-WAN setting the interface under the config system netflow is required. This is to ensure that the traffic flows over the interface you would like it to despite setting the source IP and necessary routing which isn't always enough. I would try and set:
config system netflow
set interface-select-method specify
set interface LAG_WAN
end
Regards,
Dan.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.