Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
it-admins
New Contributor

Enabling NetFlow sampler on an aggregated interface ?

Hi all,

 

In the past I successfully configured my Fortigate, an FG101E v7.0.13 to send Netflow data to an Elastiflow server. At that time we had two separate internet connections WAN1 and WAN2. Today these two interfaces have been put in an aggregate called LAG_WAN.

 

I'm following this documentation: https://docs.fortinet.com/document/fortigate/7.0.13/administration-guide/998643/netflow

 

I can no longer do the `set-netflow sampler both` on the aggregated interfaces. The instruction ends with a parse error. I can do it on the LAG_WAN aggregate, but also I'm getting a few netflow packets, it's just garbage and is not the netflow for data that goes over my WAN1 and WAN2 interfaces.

 

Can anyone help me understand how to configure such an aggregated interface to send netflow data ?

 

Thanks,

 

Olivier.

1 REPLY 1
Dan_Eng52
Contributor

Hi there, 

 

In the past when I have used Netflow on environments that I am running SD-WAN setting the interface under the config system netflow is required. This is to ensure that the traffic flows over the interface you would like it to despite setting the source IP and necessary routing which isn't always enough. I would try and set:

 

config system netflow

set interface-select-method specify
set interface LAG_WAN
end 

 

Regards,

Dan. 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors