Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Canot make Solarwinds Real-Time NetFlow Analyzer and pfsense netflow to work

    Scheduled Pinned Locked Moved Traffic Monitoring
    17 Posts 6 Posters 10.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      doktornotor Banned
      last edited by

      Solarwinds? Considered using something else? I mean, the idiot who cannot understand what "needed" means, calls himself a "Solarwinds Head Geek, M.S., MCITP:EA, MCDBA, MCSA, MVP" would seem like a damn good reason to not touch their products even with a 10ft pole.

      1 Reply Last reply Reply Quote 0
      • S
        Snailkhan
        last edited by

        anyhelp ?
        i need to make it work with netflow.

        1 Reply Last reply Reply Quote 0
        • T
          TedStriker
          last edited by

          I have also tried running softflowd on a ubuntu box with no pfsense etc and get the same result. Wiresharking does indeed show the interface numbers to be set to zero.

          Apparently pfflow does it properly so I'm going to look into using that with openBSD

          This is part of a packet from softflowd showing the zero interfaces

          pdu 1/7
              SrcAddr: 172.31.6.120
              DstAddr: 172.18.140.43
              NextHop: 0.0.0.0
              InputInt: 0
              OutputInt: 0
              Packets: 11
              Octets: 7944
              [Duration: 29.514000000 seconds]
              SrcPort: 389
              DstPort: 55995
              Padding: 00
              TCP Flags: 0x1e
              Protocol: TCP (6)
              IP ToS: 0x00
              SrcAS: 0
              DstAS: 0
              SrcMask: 0 (prefix: 172.31.6.120/32)
              DstMask: 0 (prefix: 172.18.140.43/32)
              Padding: 0000

          1 Reply Last reply Reply Quote 0
          • S
            Snailkhan
            last edited by

            i cannot find pfflow in packages.

            1 Reply Last reply Reply Quote 0
            • T
              TedStriker
              last edited by

              I don't think pfflow is available on pfsense any more. I read a few days ago about a patch someone had created to fix the bug, but can't find it again!

              I used Manage Engine Netflow Analyzer trial and that was ok with the softflowd output, looks like Solarwinds is just a bit fussier.

              Pfflowd is available on OpenBSD so you could build a dedicated box just for that but it's a bit of a faff for what should be a simple process.

              1 Reply Last reply Reply Quote 0
              • S
                Snailkhan
                last edited by

                hi
                is it resolved in the latest incarnation of pfsense ?

                1 Reply Last reply Reply Quote 0
                • J
                  jvodan
                  last edited by

                  The following patch is suppose to fix the issue for softflowd
                  https://github.com/pwarren/softflowd/issues/3

                  Oh well now I need to work out how to compile for a pfsense target

                  1 Reply Last reply Reply Quote 0
                  • S
                    Snailkhan
                    last edited by

                    @jvodan:

                    The following patch is suppose to fix the issue for softflowd
                    https://github.com/pwarren/softflowd/issues/3

                    Oh well now I need to work out how to compile for a pfsense target

                    I hope someone more knowledgeable then us do it.

                    1 Reply Last reply Reply Quote 0
                    • S
                      Snailkhan
                      last edited by

                      any idea if this is resolved ?

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        If you have a manged switch that supports netflow, you could make the switch(es) export flows to Solarwinds instead of the firewall itself.

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • S
                          Snailkhan
                          last edited by

                          @jimp:

                          If you have a manged switch that supports netflow, you could make the switch(es) export flows to Solarwinds instead of the firewall itself.

                          as this is a small network between few neighbours so no managed switch only 15-20 clients from one uplink .

                          i had earlier cisco 1841 which was working fine with this free solarwind tool for troubleshooting network performance on need basis.

                          any chance if it will be fixed in pfsense ?

                          1 Reply Last reply Reply Quote 0
                          • A
                            antonylogicmonitor
                            last edited by

                            I will hazard a guess:

                            The PFSense netflow output does not include the OUTPUT_SNMP field.

                            This is not a mandatory field but without it, netflow data reporting can be… less than 100% accurate.

                            The same is true (i.e. the same field is absent) on certain Meraki devices - see the very bottom of this page:
                            https://documentation.meraki.com/MX-Z/Monitoring_and_Reporting/NetFlow_Overview

                            "SolarWinds NTA ignores NetFlow packets that do not contain either an SNMP ingress or egress interface index" - although that page says MX models do include this, plenty of other Meraki devices don't, meaning that their netflow data is discarded by SolarWinds.

                            I have recently checked the netflow output from a PFSense device and the OUTPUT_SNMP field was absent from that data. I suspect that this is why the OP is not seeing traffic within SolarWinds.

                            1 Reply Last reply Reply Quote 0
                            • T
                              TedStriker
                              last edited by

                              @antony@logicmonitor:

                              I will hazard a guess:

                              The PFSense netflow output does not include the OUTPUT_SNMP field.

                              This is not a mandatory field but without it, netflow data reporting can be… less than 100% accurate.

                              The same is true (i.e. the same field is absent) on certain Meraki devices - see the very bottom of this page:
                              https://documentation.meraki.com/MX-Z/Monitoring_and_Reporting/NetFlow_Overview

                              "SolarWinds NTA ignores NetFlow packets that do not contain either an SNMP ingress or egress interface index" - although that page says MX models do include this, plenty of other Meraki devices don't, meaning that their netflow data is discarded by SolarWinds.

                              I have recently checked the netflow output from a PFSense device and the OUTPUT_SNMP field was absent from that data. I suspect that this is why the OP is not seeing traffic within SolarWinds.

                              Yes, that is the problem and a patch has been referenced above - not sure anyone knows how to apply the patch though!

                              1 Reply Last reply Reply Quote 0
                              • S
                                Snailkhan
                                last edited by

                                I wish it to be applied in pfsense softflowd.. Or will it just remain a wish?  :'(

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.