What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general. You are invited to get involved by asking and answering questions!

Learn more

PRTG Network Monitor

Intuitive to Use. Easy to manage.
300.000 administrators have chosen PRTG to monitor their network. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free Download

Top Tags


View all Tags

Netflow with PRTG 8.2 and Sonicwall NSA2400.

Votes:

0

Your Vote:

Up

Down

I have PRTG 8.2 installed and trying to collect netflow data from a Sonicwall NSA 2400 running Firmware SonicOS Enhanced 5.8.0.1-31o. I ran the netflow tester and I am seeing packets, but nothing shows up in PRTG.

netflow prtg sonicwall

Created on Jan 29, 2011 3:57:23 AM by  DAN KINSMAN (0) 1

Last change on Jan 31, 2011 11:17:28 AM by  Daniel Zobel [Product Manager]



4 Replies

Votes:

0

Your Vote:

Up

Down

Dear Dan,

can you please provide more details? Which version of Netflow is exported by the Sonicwall?

Best Regards.

Created on Jan 31, 2011 11:37:21 AM by  Torsten Lindner [Paessler Support]



Votes:

0

Your Vote:

Up

Down

The Sonicwall is exporting "Netflow version-5" It does have the ability to use either version 5 or 9, and I have tried both. It appeared to export once with version 5 and then stopped. It returned about 5 minutes of flow data and have gotten nothing since then.

Created on Jan 31, 2011 4:56:42 PM by  DAN KINSMAN (0) 1



Votes:

0

Your Vote:

Up

Down

I'm sure you are aware that only one application can listen on the incoming port, either the Tester or PRTG, so just to check is the Active Flow Timeout in PRTG set higher then it is set in the Sonicwall?

Created on Jan 31, 2011 5:41:25 PM by  Torsten Lindner [Paessler Support]



Votes:

0

Your Vote:

Up

Down

I have found an active flow timeout of 9 minutes within a netflow V9 sensor will work well with a Sonicwall 2400 running SonicOS Enhanced 5.8.0.3-40o and set to send periodic updates every 10 seconds.

The default mode of realtime with bulk sends all the data collected which can be several weeks worth of data which the gives you the dropped data message.

I will be updating an NSA 4500 Sonicwall later today and will report back on whether this is suitable for this device as well.

Created on Jul 28, 2011 1:44:39 PM by  mutl3y (0) 1



Please log in or register to enter your reply.


Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.