How can we help?

How to configure NetFlow on Sophos SG firewalls

Follow

Sophos SG firewalls support IPFIX, which is compatible with Auvik TrafficInsights.

These instructions assume:

If you have a shared collector and want to ensure that it receives netflow data to enable TrafficInsights, you will need to add the source IP address as a /32 in order for Auvik to register the flows from that specific address in the TrafficInsights portal. There may be some delay for the shared collector to receive the data after the change.

Note: Even if that source IP address is already being scanned, you must add a /32 targeting only the source IP address, due to some limitations, the collector can’t tell if it should be sent to site A or B.

Access the Sophos SG web interface

  1. Open a web browser and type in your Sophos SG IP address.
  2. Log into the web admin console with an administrative (read-write) user.

Configure NetFlow

  1. Navigate to Logging & Reporting > Reporting Settings.
  2. Scroll down to IPFIX Accounting.
  3. Check Enable.
  4. Under OID, leave the default value of 1.
  5. Select the + icon to add a new collector. Use the following information:
    1. Name: A recognizable name for the Auvik collector
    2. Type: Host
    3. IPv4 Address: IP address of your Auvik collector
  6. Select Apply to save the settings.

 

Was this article helpful?
5 out of 7 found this helpful
Have more questions? Submit a request