SonicWall
To configure IPFIX (Internet Protocol Flow Information Export) on a SonicWall firewall, follow these steps:
Log in to the SonicWall management interface
Open your web browser and enter the IP address of your SonicWall firewall. Log in using your administrator credentials.
Navigate to the Flow Reporting settings
In the SonicWall management interface, navigate to the following path:
Manage > System Setup > Network > Flow Reporting
Enable Flow Reporting
Check the Enable Flow Reporting checkbox to enable IPFIX on your SonicWall firewall.
Configure IPFIX settings
Enter the required information for the IPFIX collector, such as the IP address, port, and template timeout:
- Collector IP Address: Enter the IP address of NetObserv Flow to which you want to send flow data.
- Collector UDP Port: Enter the UDP port number on which the collector is listening (for example,
4739
). - Template Timeout: Specify the interval, in minutes, at which the SonicWall firewall will send IPFIX template records to the collector. The default value is 30 minutes. We recommend a value no greater than
5
. - Select the interfaces: Choose the interfaces on which you want to enable IPFIX. This can be done using the Interface dropdown menu. You can select multiple interfaces by holding the
Ctrl
key while clicking on the desired interfaces.
Apply the changes
Click the Accept button at the top-right corner of the page to save and apply your IPFIX configuration.
Verify the configuration
To confirm that IPFIX is correctly configured, you can check the Flow Reporting page for the status of the feature, as well as the settings you just configured.
Once you have completed these steps, your SonicWall firewall will start exporting IPFIX flow data to the specified ElastiFlow NetObserv Flow. Make sure NetObserv Flow is set up to receive and process the exported data for analysis and monitoring purposes.