MetricSplit › Guides › Fortinet FortiGate
How to send NetFlow from a Fortinet FortiGate to a flow collector
FortiGate firewalls export flow records with NetFlow, configured in the CLI and switched on per interface.
What it sends
NetFlow v9 records (FortiOS's templates use v9 field names), one record per firewall session with both directions' counters (BYTES and OUT_BYTES), interface indexes, and an application ID with a table of application names and categories.
Steps
- Set the collector:
Fortinet's defaults: active-flow-timeout 1800 s, inactive-flow-timeout 15 s, template-tx-timeout 1800 s, template-tx-counter 20. (Newer FortiOS releases list collectors underconfig system netflow set collector-ip 192.0.2.10 set collector-port 2055 set source-ip 198.51.100.21 endconfig collectors; check your release.) - Set the active timeout to 60 seconds, the shortest FortiOS allows (Fortinet: 60 - 3600 seconds, default 1800):
FortiOS 6.4 and earlier count this setting in minutes (1 - 60): there,config system netflow set active-flow-timeout 60 endset active-flow-timeout 1. Why: MetricSplit works in 5-minute readings, so a long-running flow has to be reported at least every minute to land in the right reading. - Switch it on per interface (Fortinet: "samples every packet"):
config system interface edit "wan1" set netflow-sampler both next end - With VDOMs, configure it per VDOM with
config system vdom-netflow. - Let UDP from the FortiGate to the collector out, and send us the address it leaves from.
Check it's working
Fortinet's commands: diagnose sniffer packet any 'port 2055' 6 0 a shows packets leaving; diagnose test application sflowd 3 shows the NetFlow cache.
Vendor documentation
What MetricSplit does with flow records
MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence.