The Netflow / IPFIX protocol allows the collection of information about IP traffic passing through the network.
Devices that enable this protocol create "Netflow records" that are sent to a central aggregator. These packages contain information about what is happening in your infrastructure.
Never raw data is sent only statistical data, the information provided relates to layers 3 and 4, IP addresses, ports, protocols or other details.
Once this information is stored and analyzed, the administrator can clearly see the services running throughout his infrastructure.
If Fortinet supports FortiSwitch Netflow (v1, v5, v9) and IPFIX (Transfer IP Stream Information), this sampling information will provide new traffic statistics and topological insights in FortiAnalyzer (and FortiView) to see which users or devices on FortiSwitch have the most network traffic. can be used to see what you have created.
Netflow/IPFIX configuration in FortiSwitch managed by FortiGate
Netflow/IPFIX configuration in FortiSwitch managed by FortiGate
We can configure the parameters related to flow-tracking as follows
# conf switch-controller flow-tracking
# conf switch-controller flow-tracking
(flow-tracking) # get
sample-mode: perimeter
sample-rate: 512
format: netflow9
collector-ip: 0.0.0.0 > all-zero IP address implies
disabled
collector-port: 0
transport: udp
level: ip
filter: complies
with tcpdump/wireshark filter syntax
max-export-pkt-size: 512
timeout-general: 3600
timeout-icmp: 300
timeout-max: 604800
timeout-tcp: 3600
timeout-tcp-fin: 300
timeout-tcp-rst: 120
timeout-udp: 300 aggregates
Currently the following sampling options are available
Perimeter Sampling
RX traffic instances are enabled on all non-FortiSwitch ports, including access points and FortiLink, but on ISL ports, including access ports and FortiLink.Perimeter Sampling
Device-Ingress Sampling
RX traffic instances are enabled on all FortiSwitch ports.
Local sampling
Allowed in certain areas of FortiSwitch.
Yorumlar
Yorum Gönder