Skip to content

v12 integrations: guides for devices that export NetFlow or IPFIX #2736

Description

@kryonsx

Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)

Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.

Why

Routers, switches and firewalls from many vendors can export NetFlow or IPFIX to the UTMStack Collector (data type netflow, UDP 2055). The NETFLOW card exists, but customers look for their own device. These would be guide-only entries under it.

Be careful what these guides promise. Today the Collector and the NetFlow parser lose ports, protocol and byte counts for most export versions (table below and 4(d)). Guides should recommend NetFlow v9 or IPFIX and promise addresses only until 4(d) is fixed by the Collector and parser owners (see also #2724, the NetFlow dashboard, and #1736).

Checklist, most valuable first

  • Cisco IOS and IOS XE routers, Catalyst 9000 switches (Flexible NetFlow) (High): Partly (v9 gaps)
  • Fortinet FortiGate (High): Partly (v9 gaps)
  • Ubiquiti UniFi gateways (High): Partly (v9 gaps)
  • MikroTik RouterOS 7 (High): Partly (v9 gaps)
  • SonicWall (SonicOS 7) (Medium): Partly (v9 gaps)
  • Palo Alto Networks (PAN-OS) (Medium): Partly (v9 gaps)
  • Cisco Meraki MX (Medium): Partly (v9 gaps)
  • VMware vSphere Distributed Switch (Medium): Partly (v9 gaps)
  • pfSense and OPNsense (Medium): Partly (v9 gaps)
  • WatchGuard Firebox (Medium): Partly (v9 gaps)
  • Check Point (Gaia R82) (Medium): Partly (v9 gaps)
  • Juniper MX, SRX and EX (Medium): Partly (v9 gaps; MX IPFIX also loses times)
  • HPE Aruba AOS-CX switches and AOS 10 gateways (Medium): Partly (v9 gaps; AOS-CX also loses flow times)
  • Sophos Firewall (Low): Partly (v5 gaps)
  • Cisco ASA (NSEL) (Low): Partly (v9 gaps; no times)
  • Cisco Nexus 9000 (Low): Partly (v9 gaps)
  • Huawei (NetStream) (Low): Partly (v9 gaps)
  • Arista EOS (Low): Partly (v9 gaps)
  • Linux hosts (softflowd) (Low): Partly (v9 gaps)
  • Devices with sFlow only, or no export: HPE Aruba AOS-S (ProCurve), Dell OS10, Zyxel firewalls, Hyper-V (Low): No: the Collector does not decode sFlow

The list in detail

Added at the product owner's request. The NETFLOW card already exists; these rows would be guide-only entries under it. UTMStack side for every row: on the Collector host run utmstack_forwarder enable-integration netflow udp (UDP port 2055; the Collector has no TCP option for NetFlow), then point the device's flow export at <collector host>:2055.

What arrives today. Checked in collectors/forwarder/collector/netflow/ (netflow.go, goflow.go, tehmaze.go, parser.go) and definitions/filters/netflow/netflow.yaml:

Export version Addresses (origin.ip, target.ip) Ports (origin.port, target.port) Protocol (protocol) Bytes and packets
NetFlow v1, v5, v6, v7 Yes No, neither port. The parser only picks up ports written in the bracketed v9 form (next row), and its last step deletes log.srcPort and log.dstPort. No. log.proto is deleted and protocol is never set. No. log.bytes and log.packets are deleted.
NetFlow v9 and IPFIX Yes Only ports below 256 are right. goflow2 v1.3.7 returns every v9 and IPFIX value as raw bytes, the Collector prints them as a byte list (port 443 becomes the text [1 187]), and the parser removes the brackets and spaces. So 443 is stored as 1187, 445 as 1189, 3389 as 1361, while 22, 53 and 80 stay right. Yes, as a name (for example TCP). Not as numbers. log.totalBytes and log.totalPackets hold the byte list as text (1500 bytes is stored as 0 0 5 220).
sFlow (any version) Nothing arrives. The Collector has no sFlow decoder. An sFlow datagram starts with a 32-bit version number, so the NetFlow reader sees version 0 and discards the packet ("unsupported NetFlow version").

The two claims passed on by another helper are confirmed, with one correction: for v1, v5, v6 and v7 both ports are missing, not only the destination port.

What a NetFlow guide must say:

  • Recommend NetFlow v9, or IPFIX where v9 is not offered. Both give addresses, protocol and ports below 256. NetFlow v5 gives addresses only. Until section 4(d) is fixed, a guide must not promise ports, byte counts or packet counts.
  • For v9 and IPFIX the Collector keeps templates per exporter (address and source port) and silently drops data until the matching template arrives. Errors that contain "template not found" are not even logged. Set the exporter's template resend interval low; the rows name the setting.
  • dataSource for NetFlow is <exporter IP>:<exporter source port>, because the listener passes addr.String() (the syslog listener strips the port; NetFlow does not). Filter on log.exporter, which holds the IP alone: dataType is netflow and log.exporter is <device IP>.
  • log.version shows which format arrived (Netflow-V5, Netflow-V9, IPFIX). It is the quickest check that the device setting took effect.
  • log.bytesIn, log.bytesOut, log.packetsIn and log.packetsOut are always 0 (constants in the Collector). A guide must not show them.
  • None of the 12 NetFlow correlation rules in definitions/rules/netflow/ can fire as written (section 4(d)). A guide must not claim NetFlow detections yet.

Short labels used in the "Works today?" column below:

  • "Partly (v9 gaps)": addresses and protocol arrive; ports of 256 and above are stored wrong; byte and packet counts are not usable numbers.
  • "Partly (v5 gaps)": only addresses arrive (no ports, protocol, bytes or packets).
  • The Collector reads flow times only from fields 21, 22, 150 and 151. A device that sends times in other fields gets flows without log.first and log.last; the row says so where the vendor documents it.

Filter for every row: dataType is netflow and log.exporter is <device IP>. Add log.version is one of Netflow-V9, IPFIX to check the format.

Naming caution: most NetFlow vendors already have a syslog card, and the loose guide matching in section 4(c)(4) (CollectorSetup and registry.ts, matches() tests such as includes('cisco'), includes('palo'), includes('sophos')) would open that vendor's syslog guide for any entry whose name contains cisco, fortigate or fortinet, mikrotik, sonic, palo, meraki, vmware, pfsense or sophos. Each NetFlow entry needs its own registered guide name.

Technology Why customers care How to turn on export (vendor setting; versions offered) Works today? Log Explorer filter Priority
Cisco IOS and IOS XE routers, Catalyst 9000 switches (Flexible NetFlow) Who talks to whom across sites and the internet; traffic spikes flow record (match IPv4 source and destination address, protocol, transport source and destination port; collect byte and packet counters), flow exporter X with destination <collector>, transport udp 2055, export-protocol netflow-v9 and template data timeout 60, flow monitor M with record and exporter X, then ip flow monitor M input on each interface. Offers v9 (default), IPFIX, and v5 (Catalyst 9300 from 17.12.1). The default export port is 9995, so 2055 must be set. The template timeout default is 600 seconds. The customer builds the record, so ports and counters are only sent if added. Partly (v9 gaps) log.exporter is <router IP> High
Fortinet FortiGate Traffic volume per host behind the firewall config system netflow > config collectors > edit 1 > set collector-ip <collector> > set collector-port 2055; then on each interface set netflow-sampler both. NetFlow v9 only ("not IPFIX"). Template resend template-tx-timeout 1800 seconds by default, so lower it. Reply-direction counters are in fields 23 and 24, which the Collector ignores. Partly (v9 gaps) log.exporter is <FortiGate IP> High
Ubiquiti UniFi gateways Traffic per device at small sites Settings > CyberSecure > Traffic Logging > enable NetFlow (IPFIX), with collector address and port. UniFi Network 8.5.6 or newer and gateway firmware 4.1 or newer; not on UniFi Express or UXG-Lite. Offers IPFIX, v9 and v5 per the 8.5.6 release notes. Ubiquiti calls the data "sampled". Partly (v9 gaps) log.exporter is <gateway IP> High
MikroTik RouterOS 7 Traffic per host on branch and ISP routers /ip traffic-flow set enabled=yes interfaces=<list>, then /ip traffic-flow target add dst-address=<collector> port=2055 version=9 (or ipfix). Offers v1, v5, v9 and IPFIX. Template resend v9-template-refresh every 20 packets. Traffic handled in hardware (offloaded) is not seen. Partly (v9 gaps) log.exporter is <router IP> High
SonicWall (SonicOS 7) Traffic volume per host behind the firewall Device > AppFlow > Flow Reporting > External Collector: enable "Send Flows and Real-Time Data To External Collector", choose the format, set collector IP and UDP port 2055, then "Generate ALL Templates" (a reboot may be needed). Offers v5 (the default), v9, IPFIX and "IPFIX with extensions". Choose v9 or plain IPFIX. Partly (v9 gaps) log.exporter is <firewall IP> Medium
Palo Alto Networks (PAN-OS) Flow data next to the richer firewall logs Device > Server Profiles > NetFlow > Add (up to 2 collectors, port 2055 is the default), then Network > Interfaces > Ethernet > (interface) > NetFlow Profile, and Commit. The largest models also need a service route. NetFlow v9 only, incoming direction only. Template refresh every 30 minutes or 20 packets. Partly (v9 gaps) log.exporter is <firewall IP> Medium
Cisco Meraki MX Traffic per client at Meraki sites Network-wide > Configure > General > Reporting > "NetFlow traffic reporting": Enabled, then collector IP and port. NetFlow v9 only, one collector per network, only routed or translated traffic. Partly (v9 gaps) log.exporter is <MX public or LAN IP as the Collector sees it> Medium
VMware vSphere Distributed Switch Traffic between virtual machines, which firewalls never see Networking > (switch) > Actions > Settings > Edit NetFlow: collector IP and port, observation domain ID, switch IP, timeouts, sampling rate (0 means every packet); then enable NetFlow on each distributed port group (Monitoring > NetFlow: Enabled). IPFIX only. Partly (v9 gaps) log.exporter is <switch IP set in the NetFlow settings> Medium
pfSense and OPNsense Traffic per host on open-source firewalls pfSense: the softflowd package (Services > softflowd: interface, host, port, version; softflowd itself offers v1, v5, v9 and IPFIX), or on pfSense Plus 24.03 and later Firewall > Packet Flow Data (v5 or IPFIX; not in the free Community Edition). OPNsense: Reporting > NetFlow: interfaces, version (v5 or v9) and destinations as ip:port. Partly (v9 gaps) log.exporter is <firewall IP> Medium
WatchGuard Firebox Traffic volume behind the firewall Fireware 12.3 or later: System > NetFlow: enable, choose V5 or V9, set collector address and port, then Ingress and Egress per interface. V9 is needed for IPv6 and translated addresses. Records are sent when a flow ends (active timeout 30 minutes). Partly (v9 gaps) log.exporter is <Firebox IP> Medium
Check Point (Gaia R82) Traffic volume on Check Point gateways Gaia Portal > Network Management > NetFlow Export > Add, or add netflow collector ip <collector> port 2055 export-format Netflow_V9 enable yes then save config. Offers Netflow_V5, Netflow_V9 (the default) and IPFIX; up to 3 collectors. Records are sent after a connection ends (set netflow liveconn_interval for long connections). Partly (v9 gaps) log.exporter is <gateway IP> Medium
Juniper MX, SRX and EX Traffic on Juniper routers and firewalls Inline J-Flow: set services flow-monitoring version9 template T (or version-ipfix), a sampling instance with output flow-server <collector> port 2055, set chassis fpc 0 sampling-instance S, and a sampling filter on the interface. MX: v9 and IPFIX. SRX IPFIX on listed models from 19.4R1 and 20.1R1. EX4100, EX4400 and EX5200 use flow-based telemetry, which needs a license. Export is sampled. MX IPFIX puts flow times in fields 152 and 153, which the Collector does not read (use v9 on MX). Partly (v9 gaps; MX IPFIX also loses times) log.exporter is <device IP> Medium
HPE Aruba AOS-CX switches and AOS 10 gateways Traffic inside the campus network AOS-CX: flow record (match addresses, protocol and ports; collect counters), flow exporter X with destination <collector> and transport udp 2055, flow monitor M, then ip flow monitor M in on the interface. IPFIX only; the default port is 4739. Flow times are in microsecond fields, which the Collector does not read. AOS 10 gateways (Central): Devices > Gateways > Config > System > External Monitoring > IPFIX. Partly (v9 gaps; AOS-CX also loses flow times) log.exporter is <switch or gateway IP> Medium
Sophos Firewall Traffic volume behind the firewall System > Administration > Netflow: server name, IP and UDP port 2055 (up to 5 servers). NetFlow v5 only. Only traffic from rules with "Log firewall traffic" on is sent. Partly (v5 gaps) log.exporter is <firewall IP> Low
Cisco ASA (NSEL) Firewall connection events as flows flow-export destination <interface> <collector> 2055, then a global policy with flow-export event-type all destination <collector>. NetFlow v9 only (NSEL). Bytes are only in ASA fields 231 and 232, there is no packet count, and times are in fields 152 and 323, so none of these arrive. The ASA syslog integration (CISCO card) is the better source. Partly (v9 gaps; no times) log.exporter is <ASA IP> Low
Cisco Nexus 9000 Data center traffic feature netflow; flow exporter with destination, source <interface> (required, or flows are dropped), transport udp 2055, version 9; flow record; flow monitor; ip flow monitor <name> input on the interface. v9 only; the default port is 9995. Partly (v9 gaps) log.exporter is <switch IP> Low
Huawei (NetStream) Traffic on Huawei routers and switches ip netstream export version 9, ip netstream export source <ip>, ip netstream export host <collector> 2055, ip netstream export template timeout-rate <minutes> (30 on AR routers). NetEngine routers: v5, v9 and IPFIX; CloudEngine switches: v5, v8 and v9 (v8 is not decoded). Some models default to v5. The per-interface command was not checked. Partly (v9 gaps) log.exporter is <device IP> Low
Arista EOS Data center traffic flow tracking sampled > tracker T > exporter E > collector <collector> port 2055, format ipfix version 10; flow tracker sampled T on the interface. The template interval defaults to 1 hour, so lower it. Sampled tracking needs sFlow off; the default sample rate is 1 in 1,048,576. Partly (v9 gaps) log.exporter is <switch IP> Low
Linux hosts (softflowd) Flows from a Linux router or a mirror port softflowd -i eth0 -n <collector>:2055 -v 9. softflowd offers v1, v5 (the default), v9 and IPFIX. Partly (v9 gaps) log.exporter is <host IP> Low
Devices with sFlow only, or no export: HPE Aruba AOS-S (ProCurve), Dell OS10, Zyxel firewalls, Hyper-V Customers ask; the answer is no AOS-S and Dell OS10 document only sFlow. A Zyxel employee said in 2022 that ZyWALL has no NetFlow (newer uOS models unknown). Microsoft documents no built-in exporter for Hyper-V (not confirmed either way). Ubiquiti EdgeRouter: no current vendor documentation found (not confirmed). No: the Collector does not decode sFlow none Low
Sources checked for this list (24 Sep 2026)

Sources for 3d (vendor documentation, checked 2026-09-24): Cisco Catalyst 9300 17.15 "Configuring Flexible NetFlow" and command reference, Cisco IOS "Flexible NetFlow" command reference and IPFIX export guide; Cisco ASA "NetFlow Implementation Guide"; documentation.meraki.com "NetFlow Overview"; Cisco Nexus 9000 NX-OS 10.6 "Configuring NetFlow"; juniper.net flow-monitoring guides ("IPFIX and version 9 templates", template-refresh-rate, "inline sampling", "flow-based telemetry"); manual.mikrotik.com "Traffic Flow"; help.ui.com article 32201256219799 and the UniFi Network 8.5.6 release notes; docs.fortinet.com FortiGate 7.6.6 CLI config system netflow and 8.0.1 "NetFlow"; docs.paloaltonetworks.com "Configure NetFlow Exports" and "NetFlow Templates"; SonicWall SonicOS 7.1 AppFlow "External Collector"; docs.sophos.com Sophos Firewall 22.0 "Netflow"; docs.netgate.com "NetFlow with softflowd" and "Packet Flow Data"; docs.opnsense.org "NetFlow exporter"; techdocs.broadcom.com vSphere 8.0 "Configure NetFlow Settings"; learn.microsoft.com "Overview of the Hyper-V Extensible Switch"; arubanetworking.hpe.com AOS-CX 10.15 and 10.16 "flow exporter" and "IPFIX", AOS-S 16.11 "sFlow", Central 2.5.8 "IPFIX"; support.huawei.com NetStream command references (read through search excerpts; the pages refused direct access); sc1.checkpoint.com R82 Gaia Administration Guide "NetFlow Export"; arista.com "Sampled Flow Tracking"; documentation.extremenetworks.com; dell.com SmartFabric OS10 user guide "sFlow"; watchguard.com Fireware "Configure NetFlow"; community.zyxel.com discussion 13480; github.com/irino/softflowd softflowd.8.

Done per technology

  • A guide-only entry with a real display name, a one-line description (all seven languages) and an icon.
  • A guide built from the shared template, with the vendor steps from the table, the exact setting, and how to check the logs arrived.
  • A "View logs" link that opens the Log Explorer with the filter from the table.
  • Checked once with the real product, or with a realistic sample sent the same way, and the logs show up under that filter.
  • Where the table says "Partly" or "No", the guide says plainly what the customer does not get yet.

Research notes this list relies on

4(d) NetFlow collector and parser gaps

Found while checking table 3d (code in collectors/forwarder/collector/netflow/ and definitions/filters/netflow/netflow.yaml):

  1. v9 and IPFIX numbers are written as byte lists. extractFieldValue in goflow.go prints each value with fmt.Sprintf("%v", value), and goflow2 v1.3.7 hands over raw []byte, so port 443 becomes [1 187]. Only the address fields go through toIP. Fix in the Collector: decode fields 1, 2, 4, 6, 7, 10, 11, 14, 16, 17, 61, 85 and 86 (and the prefix lengths) as big-endian unsigned numbers, whatever their length.
  2. The parser drops v1 to v7 ports, protocol and counters. It only extracts ports, protocol, bytes and packets from the bracketed v9 form, then deletes log.srcPort, log.dstPort, log.proto, log.bytes and log.packets. Fix: map the plain values to origin.port, target.port and protocol, and keep bytes and packets as numbers.
  3. The NetFlow rules use fields the parser never writes. Eight of the 12 rules in definitions/rules/netflow/ need origin.bytesSent, origin.packagesSent, log.duration, log.bytes or log.packets, which never exist after parsing. The other four need target.port values of 256 or more (443, 445, 3389, 500, 1194, 3333 and so on), which v9 and IPFIX store garbled and v5 does not store at all. tor_usage_detection also compares protocol with "6" while the parser writes TCP. So none of the 12 rules can fire as intended, and the garbled ports can make some match the wrong flows (for example port 8481 is stored as 3333, a mining-pool port in netflow_cryptomining_traffic).
  4. dataSource includes the exporter's source port. The NetFlow listener passes addr.String(), unlike the syslog listener, which strips the port. Strip it, so each device is one data source.
  5. Silent template wait. Data that arrives before its v9 or IPFIX template is dropped without a log line ("template not found" is filtered out in netflow.go). Logging it once per exporter would let support tell customers why nothing arrives.
  6. No sFlow. Devices that only export sFlow cannot use this channel; adding a decoder is new code, not a guide.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions