
(Fireware v12.5 or higher) Adjacent to the interface name, select Ingress, Egress, or both. If you enabled Sampling mode, in the Sample 1 out of every text box, type a number between 5 packets. (Optional) To enable Sampling Mode, select Enable Sampling. The collector is the server that collects NetFlow data from the Firebox. In the Collector Address text boxes, type the IP address and port of the collector. To configure NetFlow, from Policy Manager: (Fireware v12.3.x or v12.4.x) Select the check box next to the interface. (Fireware v12.5 or higher) Next to the interface name, select Ingress, Egress, or both. To enable NetFlow for an interface: Tip! To quickly find an interface, select an option from the Type or Zone drop-down lists. (Fireware v12.3.x and v12.4.x) From the list of interfaces, select Firebox. (Fireware v12.5 or higher) Select Monitor traffic generated by the Firebox or Monitor traffic destined for the Firebox. If you enabled Sampling mode, in the adjacent text box, type a number between 5 packets.
(Optional) To enable Sampling Mode, select the Sample every 1 out of check box. By default, the Active Flow Timeout value on the Firebox is 30 minutes. If the Active Flow Timeout value is lower on the collector, the collector might stop listening while the Firebox is sending data.
We recommend that you specify an Active Flow Timeout value that is lower than the Active Flow Timeout value on the collector. In the Active Flow Timeout text box, type a number between 1 and 60 minutes.The Firebox must be able to communicate with the collector at the specified IP address and port with the UDP protocol. In the Port text box, type the port configured on the collector.In the Collector Address text box, type the IPv4 or IPv6 address of the collector.In Fireware v12.7.1 or higher, post-NAT addresses appear in flow records if you select V9. To monitor IPv6 traffic, you must use V9. For the protocol version, select V5 or V9.To configure NetFlow, from Fireware Web UI: You can configure your Firebox as a NetFlow exporter in Fireware v12.3 or higher.įor detailed information about NetFlow, see About NetFlow.