Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Canot make Solarwinds Real-Time NetFlow Analyzer and pfsense netflow to work

    Scheduled Pinned Locked Moved Traffic Monitoring
    17 Posts 6 Posters 10.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Snailkhan
      last edited by

      i cannot find pfflow in packages.

      1 Reply Last reply Reply Quote 0
      • T
        TedStriker
        last edited by

        I don't think pfflow is available on pfsense any more. I read a few days ago about a patch someone had created to fix the bug, but can't find it again!

        I used Manage Engine Netflow Analyzer trial and that was ok with the softflowd output, looks like Solarwinds is just a bit fussier.

        Pfflowd is available on OpenBSD so you could build a dedicated box just for that but it's a bit of a faff for what should be a simple process.

        1 Reply Last reply Reply Quote 0
        • S
          Snailkhan
          last edited by

          hi
          is it resolved in the latest incarnation of pfsense ?

          1 Reply Last reply Reply Quote 0
          • J
            jvodan
            last edited by

            The following patch is suppose to fix the issue for softflowd
            https://github.com/pwarren/softflowd/issues/3

            Oh well now I need to work out how to compile for a pfsense target

            1 Reply Last reply Reply Quote 0
            • S
              Snailkhan
              last edited by

              @jvodan:

              The following patch is suppose to fix the issue for softflowd
              https://github.com/pwarren/softflowd/issues/3

              Oh well now I need to work out how to compile for a pfsense target

              I hope someone more knowledgeable then us do it.

              1 Reply Last reply Reply Quote 0
              • S
                Snailkhan
                last edited by

                any idea if this is resolved ?

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  If you have a manged switch that supports netflow, you could make the switch(es) export flows to Solarwinds instead of the firewall itself.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • S
                    Snailkhan
                    last edited by

                    @jimp:

                    If you have a manged switch that supports netflow, you could make the switch(es) export flows to Solarwinds instead of the firewall itself.

                    as this is a small network between few neighbours so no managed switch only 15-20 clients from one uplink .

                    i had earlier cisco 1841 which was working fine with this free solarwind tool for troubleshooting network performance on need basis.

                    any chance if it will be fixed in pfsense ?

                    1 Reply Last reply Reply Quote 0
                    • A
                      antonylogicmonitor
                      last edited by

                      I will hazard a guess:

                      The PFSense netflow output does not include the OUTPUT_SNMP field.

                      This is not a mandatory field but without it, netflow data reporting can be… less than 100% accurate.

                      The same is true (i.e. the same field is absent) on certain Meraki devices - see the very bottom of this page:
                      https://documentation.meraki.com/MX-Z/Monitoring_and_Reporting/NetFlow_Overview

                      "SolarWinds NTA ignores NetFlow packets that do not contain either an SNMP ingress or egress interface index" - although that page says MX models do include this, plenty of other Meraki devices don't, meaning that their netflow data is discarded by SolarWinds.

                      I have recently checked the netflow output from a PFSense device and the OUTPUT_SNMP field was absent from that data. I suspect that this is why the OP is not seeing traffic within SolarWinds.

                      1 Reply Last reply Reply Quote 0
                      • T
                        TedStriker
                        last edited by

                        @antony@logicmonitor:

                        I will hazard a guess:

                        The PFSense netflow output does not include the OUTPUT_SNMP field.

                        This is not a mandatory field but without it, netflow data reporting can be… less than 100% accurate.

                        The same is true (i.e. the same field is absent) on certain Meraki devices - see the very bottom of this page:
                        https://documentation.meraki.com/MX-Z/Monitoring_and_Reporting/NetFlow_Overview

                        "SolarWinds NTA ignores NetFlow packets that do not contain either an SNMP ingress or egress interface index" - although that page says MX models do include this, plenty of other Meraki devices don't, meaning that their netflow data is discarded by SolarWinds.

                        I have recently checked the netflow output from a PFSense device and the OUTPUT_SNMP field was absent from that data. I suspect that this is why the OP is not seeing traffic within SolarWinds.

                        Yes, that is the problem and a patch has been referenced above - not sure anyone knows how to apply the patch though!

                        1 Reply Last reply Reply Quote 0
                        • S
                          Snailkhan
                          last edited by

                          I wish it to be applied in pfsense softflowd.. Or will it just remain a wish?  :'(

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.