How to configure a SonicWall device for AppFlow Reports with PRTG

Description

The SonicWall security appliance provides the ability to send IPFix and NetFlow data to an external collector, like Paessler PRTG Network Monitor. This will let you see network usage, source and destination IP and ports, etc.

NOTE: only IPFix can be enable at this time, IPFix with extensions are not supported by PRTG.

Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.



PRTG Configuration After you added the device, Add a sensor:

  1. Under "Technology Used", select "Netflow, sFlow, jFlow" then select "IPFIX (Custom)" sensor from the "Matching Sensor Types" list.
    Image
  2. Set "Receive IPFIX Packets on UDP Port", default port is 2055
  3. Set the Active Flow Timeout (Minutes) to 9
    Image
  4. Click Continue to finish the sensor's creation


SonicWall configuration Under Manage | AppFlow | Flow Reporting | External collector:

  1. Enable "Send Flows and Real-Time Data To External Collector"
  2. Set "External Collector's IP address" with the PRTG Server IP
  3. For more accurate reporting check the box to report on connection opened, closed, and report every 100 Kilobytes exchanged. 
  4. Once setup on both sides is finished, click on "General ALL Templates" as well to force synchronization of the PRTG Server.

Image
It may take a few minutes for data to be displayed:

Image

Resolution for SonicOS 6.2 and Below

The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.


PRTG Configuration After you added the device, Add a sensor:

  1. Under "Technology Used", select "Netflow, sFlow, jFlow" then select "IPFIX (Custom)" sensor from the "Matching Sensor Types" list.
    Image
  2. Set "Receive IPFIX Packets on UDP Port", default port is 2055
  3. Set the Active Flow Timeout (Minutes) to 9
    Image
  4. Click Continue to finish the sensor's creation


SonicWall configuration Under AppFlow, Flow Reporting, External collector:

  1. Enable "Send Flows and Real-Time Data To External Collector"
  2. Set "External Collector's IP address" with the PRTG Server IP
  3. For more accurate reporting check the box to report on connection opened, closed, and report on 100 Kylobytes exchanged. 
  4. Once setup on both sides is finished, click on "General ALL Templates" as well to force synchronization of the PRTG Server.

Image
It may take a few minutes for data to be displayed:

Image

Related Articles

  • How to block ICMP (Ping ) using Application control
    Read More
  • SonicWall GEN8 TZ and NSa Firewalls FAQ
    Read More
  • How to configure Link Aggregation
    Read More
not finding your answers?