This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPFix flow export

Hi guys,

we currently evaluating Sophos firewalls in order to replace our old cisco routers. Everything is fine so far except one thing. We need to export flow data in Netflow 5 format.

 

As I can see, IPFix is supported right now, the output is done via ulogd. Unfortunately the export format is not working fine with our management tool (LiveAction).

I don't understand why the IPFix export marks all flows with ifindex 0 instead of the actual ifindex id, this kills all exported information, I guess thats not the way it should do it.

 

Is there a possibility to get another plugin for ulogd which exports flowdata as Netflow instead of IPFix?

I tried the following things:

 

-          Fprobe is running but it’s a mess with ifindex

-          Fporbe-ulog, needs kernel module ipt_ULOG.ko, not on the system and no kernel headers to recompile it

-          Ipt-netflow, needs to have compiled a new kernel module, as there are no kernel sources available this (best) option is out at the moment

Are the header packeds somewhere available?

 

Can we do something else in order to export Netflow 5 data, or is it possible to play with the IPFix output?

 

Thanks a lot,

Daniel



This thread was automatically locked due to age.
Parents Reply Children
  • Hello Scott,

    thanks for your replay. I have to make a decition now and it's not the way to go for me to send a feature request into the cloud and then hope someone picks it up.
    I would be happy with IPFix, but it's unusable as the current implementation not even sends the correct ifindex interface information to the collector.