How can we help?

How to configure NetFlow on Sophos SG firewalls

Follow

Sophos SG firewalls support IPFIX, which is compatible with Auvik TrafficInsights.

These instructions assume:

If you are using a shared collector and want TrafficInsights to associate flow data with the correct site, you must add the source IP address as a dedicated /32 network within Auvik.

For example:

192.168.1.10/32

Even if the source IP address is already included in a larger monitored subnet, a dedicated /32 entry is required for TrafficInsights to correctly associate flow records with the appropriate site.

After making this change, it may take several minutes before flow data appears in TrafficInsights.

Access the Sophos SG web interface

  1. Open a web browser and type in your Sophos SG IP address.
  2. Log into the web admin console with an administrative (read-write) user.

Configure NetFlow

  1. Navigate to Logging & Reporting > Reporting Settings.
  2. Scroll down to IPFIX Accounting.
  3. Check Enable.
  4. Under OID, leave the default value of 1.
  5. Select the + icon to add a new collector. Use the following information:
    1. Name: A recognizable name for the Auvik collector
    2. Type: Host
    3. IPv4 Address: IP address of your Auvik collector
  6. Select Apply to save the settings.

 

Was this article helpful?
5 out of 7 found this helpful
Have more questions? Submit a request