Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Canot make Solarwinds Real-Time NetFlow Analyzer and pfsense netflow to work

    Scheduled Pinned Locked Moved Traffic Monitoring
    17 Posts 6 Posters 10.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TedStriker
      last edited by

      I don't think pfflow is available on pfsense any more. I read a few days ago about a patch someone had created to fix the bug, but can't find it again!

      I used Manage Engine Netflow Analyzer trial and that was ok with the softflowd output, looks like Solarwinds is just a bit fussier.

      Pfflowd is available on OpenBSD so you could build a dedicated box just for that but it's a bit of a faff for what should be a simple process.

      1 Reply Last reply Reply Quote 0
      • S
        Snailkhan
        last edited by

        hi
        is it resolved in the latest incarnation of pfsense ?

        1 Reply Last reply Reply Quote 0
        • J
          jvodan
          last edited by

          The following patch is suppose to fix the issue for softflowd
          https://github.com/pwarren/softflowd/issues/3

          Oh well now I need to work out how to compile for a pfsense target

          1 Reply Last reply Reply Quote 0
          • S
            Snailkhan
            last edited by

            @jvodan:

            The following patch is suppose to fix the issue for softflowd
            https://github.com/pwarren/softflowd/issues/3

            Oh well now I need to work out how to compile for a pfsense target

            I hope someone more knowledgeable then us do it.

            1 Reply Last reply Reply Quote 0
            • S
              Snailkhan
              last edited by

              any idea if this is resolved ?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                If you have a manged switch that supports netflow, you could make the switch(es) export flows to Solarwinds instead of the firewall itself.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • S
                  Snailkhan
                  last edited by

                  @jimp:

                  If you have a manged switch that supports netflow, you could make the switch(es) export flows to Solarwinds instead of the firewall itself.

                  as this is a small network between few neighbours so no managed switch only 15-20 clients from one uplink .

                  i had earlier cisco 1841 which was working fine with this free solarwind tool for troubleshooting network performance on need basis.

                  any chance if it will be fixed in pfsense ?

                  1 Reply Last reply Reply Quote 0
                  • A
                    antonylogicmonitor
                    last edited by

                    I will hazard a guess:

                    The PFSense netflow output does not include the OUTPUT_SNMP field.

                    This is not a mandatory field but without it, netflow data reporting can be… less than 100% accurate.

                    The same is true (i.e. the same field is absent) on certain Meraki devices - see the very bottom of this page:
                    https://documentation.meraki.com/MX-Z/Monitoring_and_Reporting/NetFlow_Overview

                    "SolarWinds NTA ignores NetFlow packets that do not contain either an SNMP ingress or egress interface index" - although that page says MX models do include this, plenty of other Meraki devices don't, meaning that their netflow data is discarded by SolarWinds.

                    I have recently checked the netflow output from a PFSense device and the OUTPUT_SNMP field was absent from that data. I suspect that this is why the OP is not seeing traffic within SolarWinds.

                    1 Reply Last reply Reply Quote 0
                    • T
                      TedStriker
                      last edited by

                      @antony@logicmonitor:

                      I will hazard a guess:

                      The PFSense netflow output does not include the OUTPUT_SNMP field.

                      This is not a mandatory field but without it, netflow data reporting can be… less than 100% accurate.

                      The same is true (i.e. the same field is absent) on certain Meraki devices - see the very bottom of this page:
                      https://documentation.meraki.com/MX-Z/Monitoring_and_Reporting/NetFlow_Overview

                      "SolarWinds NTA ignores NetFlow packets that do not contain either an SNMP ingress or egress interface index" - although that page says MX models do include this, plenty of other Meraki devices don't, meaning that their netflow data is discarded by SolarWinds.

                      I have recently checked the netflow output from a PFSense device and the OUTPUT_SNMP field was absent from that data. I suspect that this is why the OP is not seeing traffic within SolarWinds.

                      Yes, that is the problem and a patch has been referenced above - not sure anyone knows how to apply the patch though!

                      1 Reply Last reply Reply Quote 0
                      • S
                        Snailkhan
                        last edited by

                        I wish it to be applied in pfsense softflowd.. Or will it just remain a wish?  :'(

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.