Hi guys,
we currently evaluating Sophos firewalls in order to replace our old cisco routers. Everything is fine so far except one thing. We need to export flow data in Netflow 5 format.
As I can see, IPFix is supported right now, the output is done via ulogd. Unfortunately the export format is not working fine with our management tool (LiveAction).
I don't understand why the IPFix export marks all flows with ifindex 0 instead of the actual ifindex id, this kills all exported information, I guess thats not the way it should do it.
Is there a possibility to get another plugin for ulogd which exports flowdata as Netflow instead of IPFix?
I tried the following things:
- Fprobe is running but it’s a mess with ifindex
- Fporbe-ulog, needs kernel module ipt_ULOG.ko, not on the system and no kernel headers to recompile it
- Ipt-netflow, needs to have compiled a new kernel module, as there are no kernel sources available this (best) option is out at the moment
Are the header packeds somewhere available?
Can we do something else in order to export Netflow 5 data, or is it possible to play with the IPFix output?
Thanks a lot,
Daniel
This thread was automatically locked due to age.