| Cisco IOS and IOS XE routers, Catalyst 9000 switches (Flexible NetFlow) |
Who talks to whom across sites and the internet; traffic spikes |
flow record (match IPv4 source and destination address, protocol, transport source and destination port; collect byte and packet counters), flow exporter X with destination <collector>, transport udp 2055, export-protocol netflow-v9 and template data timeout 60, flow monitor M with record and exporter X, then ip flow monitor M input on each interface. Offers v9 (default), IPFIX, and v5 (Catalyst 9300 from 17.12.1). The default export port is 9995, so 2055 must be set. The template timeout default is 600 seconds. The customer builds the record, so ports and counters are only sent if added. |
Partly (v9 gaps) |
log.exporter is <router IP> |
High |
| Fortinet FortiGate |
Traffic volume per host behind the firewall |
config system netflow > config collectors > edit 1 > set collector-ip <collector> > set collector-port 2055; then on each interface set netflow-sampler both. NetFlow v9 only ("not IPFIX"). Template resend template-tx-timeout 1800 seconds by default, so lower it. Reply-direction counters are in fields 23 and 24, which the Collector ignores. |
Partly (v9 gaps) |
log.exporter is <FortiGate IP> |
High |
| Ubiquiti UniFi gateways |
Traffic per device at small sites |
Settings > CyberSecure > Traffic Logging > enable NetFlow (IPFIX), with collector address and port. UniFi Network 8.5.6 or newer and gateway firmware 4.1 or newer; not on UniFi Express or UXG-Lite. Offers IPFIX, v9 and v5 per the 8.5.6 release notes. Ubiquiti calls the data "sampled". |
Partly (v9 gaps) |
log.exporter is <gateway IP> |
High |
| MikroTik RouterOS 7 |
Traffic per host on branch and ISP routers |
/ip traffic-flow set enabled=yes interfaces=<list>, then /ip traffic-flow target add dst-address=<collector> port=2055 version=9 (or ipfix). Offers v1, v5, v9 and IPFIX. Template resend v9-template-refresh every 20 packets. Traffic handled in hardware (offloaded) is not seen. |
Partly (v9 gaps) |
log.exporter is <router IP> |
High |
| SonicWall (SonicOS 7) |
Traffic volume per host behind the firewall |
Device > AppFlow > Flow Reporting > External Collector: enable "Send Flows and Real-Time Data To External Collector", choose the format, set collector IP and UDP port 2055, then "Generate ALL Templates" (a reboot may be needed). Offers v5 (the default), v9, IPFIX and "IPFIX with extensions". Choose v9 or plain IPFIX. |
Partly (v9 gaps) |
log.exporter is <firewall IP> |
Medium |
| Palo Alto Networks (PAN-OS) |
Flow data next to the richer firewall logs |
Device > Server Profiles > NetFlow > Add (up to 2 collectors, port 2055 is the default), then Network > Interfaces > Ethernet > (interface) > NetFlow Profile, and Commit. The largest models also need a service route. NetFlow v9 only, incoming direction only. Template refresh every 30 minutes or 20 packets. |
Partly (v9 gaps) |
log.exporter is <firewall IP> |
Medium |
| Cisco Meraki MX |
Traffic per client at Meraki sites |
Network-wide > Configure > General > Reporting > "NetFlow traffic reporting": Enabled, then collector IP and port. NetFlow v9 only, one collector per network, only routed or translated traffic. |
Partly (v9 gaps) |
log.exporter is <MX public or LAN IP as the Collector sees it> |
Medium |
| VMware vSphere Distributed Switch |
Traffic between virtual machines, which firewalls never see |
Networking > (switch) > Actions > Settings > Edit NetFlow: collector IP and port, observation domain ID, switch IP, timeouts, sampling rate (0 means every packet); then enable NetFlow on each distributed port group (Monitoring > NetFlow: Enabled). IPFIX only. |
Partly (v9 gaps) |
log.exporter is <switch IP set in the NetFlow settings> |
Medium |
| pfSense and OPNsense |
Traffic per host on open-source firewalls |
pfSense: the softflowd package (Services > softflowd: interface, host, port, version; softflowd itself offers v1, v5, v9 and IPFIX), or on pfSense Plus 24.03 and later Firewall > Packet Flow Data (v5 or IPFIX; not in the free Community Edition). OPNsense: Reporting > NetFlow: interfaces, version (v5 or v9) and destinations as ip:port. |
Partly (v9 gaps) |
log.exporter is <firewall IP> |
Medium |
| WatchGuard Firebox |
Traffic volume behind the firewall |
Fireware 12.3 or later: System > NetFlow: enable, choose V5 or V9, set collector address and port, then Ingress and Egress per interface. V9 is needed for IPv6 and translated addresses. Records are sent when a flow ends (active timeout 30 minutes). |
Partly (v9 gaps) |
log.exporter is <Firebox IP> |
Medium |
| Check Point (Gaia R82) |
Traffic volume on Check Point gateways |
Gaia Portal > Network Management > NetFlow Export > Add, or add netflow collector ip <collector> port 2055 export-format Netflow_V9 enable yes then save config. Offers Netflow_V5, Netflow_V9 (the default) and IPFIX; up to 3 collectors. Records are sent after a connection ends (set netflow liveconn_interval for long connections). |
Partly (v9 gaps) |
log.exporter is <gateway IP> |
Medium |
| Juniper MX, SRX and EX |
Traffic on Juniper routers and firewalls |
Inline J-Flow: set services flow-monitoring version9 template T (or version-ipfix), a sampling instance with output flow-server <collector> port 2055, set chassis fpc 0 sampling-instance S, and a sampling filter on the interface. MX: v9 and IPFIX. SRX IPFIX on listed models from 19.4R1 and 20.1R1. EX4100, EX4400 and EX5200 use flow-based telemetry, which needs a license. Export is sampled. MX IPFIX puts flow times in fields 152 and 153, which the Collector does not read (use v9 on MX). |
Partly (v9 gaps; MX IPFIX also loses times) |
log.exporter is <device IP> |
Medium |
| HPE Aruba AOS-CX switches and AOS 10 gateways |
Traffic inside the campus network |
AOS-CX: flow record (match addresses, protocol and ports; collect counters), flow exporter X with destination <collector> and transport udp 2055, flow monitor M, then ip flow monitor M in on the interface. IPFIX only; the default port is 4739. Flow times are in microsecond fields, which the Collector does not read. AOS 10 gateways (Central): Devices > Gateways > Config > System > External Monitoring > IPFIX. |
Partly (v9 gaps; AOS-CX also loses flow times) |
log.exporter is <switch or gateway IP> |
Medium |
| Sophos Firewall |
Traffic volume behind the firewall |
System > Administration > Netflow: server name, IP and UDP port 2055 (up to 5 servers). NetFlow v5 only. Only traffic from rules with "Log firewall traffic" on is sent. |
Partly (v5 gaps) |
log.exporter is <firewall IP> |
Low |
| Cisco ASA (NSEL) |
Firewall connection events as flows |
flow-export destination <interface> <collector> 2055, then a global policy with flow-export event-type all destination <collector>. NetFlow v9 only (NSEL). Bytes are only in ASA fields 231 and 232, there is no packet count, and times are in fields 152 and 323, so none of these arrive. The ASA syslog integration (CISCO card) is the better source. |
Partly (v9 gaps; no times) |
log.exporter is <ASA IP> |
Low |
| Cisco Nexus 9000 |
Data center traffic |
feature netflow; flow exporter with destination, source <interface> (required, or flows are dropped), transport udp 2055, version 9; flow record; flow monitor; ip flow monitor <name> input on the interface. v9 only; the default port is 9995. |
Partly (v9 gaps) |
log.exporter is <switch IP> |
Low |
| Huawei (NetStream) |
Traffic on Huawei routers and switches |
ip netstream export version 9, ip netstream export source <ip>, ip netstream export host <collector> 2055, ip netstream export template timeout-rate <minutes> (30 on AR routers). NetEngine routers: v5, v9 and IPFIX; CloudEngine switches: v5, v8 and v9 (v8 is not decoded). Some models default to v5. The per-interface command was not checked. |
Partly (v9 gaps) |
log.exporter is <device IP> |
Low |
| Arista EOS |
Data center traffic |
flow tracking sampled > tracker T > exporter E > collector <collector> port 2055, format ipfix version 10; flow tracker sampled T on the interface. The template interval defaults to 1 hour, so lower it. Sampled tracking needs sFlow off; the default sample rate is 1 in 1,048,576. |
Partly (v9 gaps) |
log.exporter is <switch IP> |
Low |
| Linux hosts (softflowd) |
Flows from a Linux router or a mirror port |
softflowd -i eth0 -n <collector>:2055 -v 9. softflowd offers v1, v5 (the default), v9 and IPFIX. |
Partly (v9 gaps) |
log.exporter is <host IP> |
Low |
| Devices with sFlow only, or no export: HPE Aruba AOS-S (ProCurve), Dell OS10, Zyxel firewalls, Hyper-V |
Customers ask; the answer is no |
AOS-S and Dell OS10 document only sFlow. A Zyxel employee said in 2022 that ZyWALL has no NetFlow (newer uOS models unknown). Microsoft documents no built-in exporter for Hyper-V (not confirmed either way). Ubiquiti EdgeRouter: no current vendor documentation found (not confirmed). |
No: the Collector does not decode sFlow |
none |
Low |
Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)
Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.
Why
Routers, switches and firewalls from many vendors can export NetFlow or IPFIX to the UTMStack Collector (data type
netflow, UDP 2055). The NETFLOW card exists, but customers look for their own device. These would be guide-only entries under it.Be careful what these guides promise. Today the Collector and the NetFlow parser lose ports, protocol and byte counts for most export versions (table below and 4(d)). Guides should recommend NetFlow v9 or IPFIX and promise addresses only until 4(d) is fixed by the Collector and parser owners (see also #2724, the NetFlow dashboard, and #1736).
Checklist, most valuable first
The list in detail
Added at the product owner's request. The NETFLOW card already exists; these rows would be guide-only entries under it. UTMStack side for every row: on the Collector host run
utmstack_forwarder enable-integration netflow udp(UDP port 2055; the Collector has no TCP option for NetFlow), then point the device's flow export at<collector host>:2055.What arrives today. Checked in
collectors/forwarder/collector/netflow/(netflow.go,goflow.go,tehmaze.go,parser.go) anddefinitions/filters/netflow/netflow.yaml:origin.ip,target.ip)origin.port,target.port)protocol)log.srcPortandlog.dstPort.log.protois deleted andprotocolis never set.log.bytesandlog.packetsare deleted.[1 187]), and the parser removes the brackets and spaces. So 443 is stored as 1187, 445 as 1189, 3389 as 1361, while 22, 53 and 80 stay right.TCP).log.totalBytesandlog.totalPacketshold the byte list as text (1500 bytes is stored as0 0 5 220).The two claims passed on by another helper are confirmed, with one correction: for v1, v5, v6 and v7 both ports are missing, not only the destination port.
What a NetFlow guide must say:
dataSourcefor NetFlow is<exporter IP>:<exporter source port>, because the listener passesaddr.String()(the syslog listener strips the port; NetFlow does not). Filter onlog.exporter, which holds the IP alone:dataTypeisnetflowandlog.exporteris<device IP>.log.versionshows which format arrived (Netflow-V5,Netflow-V9,IPFIX). It is the quickest check that the device setting took effect.log.bytesIn,log.bytesOut,log.packetsInandlog.packetsOutare always0(constants in the Collector). A guide must not show them.definitions/rules/netflow/can fire as written (section 4(d)). A guide must not claim NetFlow detections yet.Short labels used in the "Works today?" column below:
log.firstandlog.last; the row says so where the vendor documents it.Filter for every row:
dataTypeisnetflowandlog.exporteris<device IP>. Addlog.versionis one ofNetflow-V9, IPFIXto check the format.Naming caution: most NetFlow vendors already have a syslog card, and the loose guide matching in section 4(c)(4) (
CollectorSetupandregistry.ts,matches()tests such asincludes('cisco'),includes('palo'),includes('sophos')) would open that vendor's syslog guide for any entry whose name contains cisco, fortigate or fortinet, mikrotik, sonic, palo, meraki, vmware, pfsense or sophos. Each NetFlow entry needs its own registered guide name.flow record(match IPv4 source and destination address, protocol, transport source and destination port; collect byte and packet counters),flow exporter Xwithdestination <collector>,transport udp 2055,export-protocol netflow-v9andtemplate data timeout 60,flow monitor Mwithrecordandexporter X, thenip flow monitor M inputon each interface. Offers v9 (default), IPFIX, and v5 (Catalyst 9300 from 17.12.1). The default export port is 9995, so 2055 must be set. The template timeout default is 600 seconds. The customer builds the record, so ports and counters are only sent if added.log.exporteris<router IP>config system netflow>config collectors>edit 1>set collector-ip <collector>>set collector-port 2055; then on each interfaceset netflow-sampler both. NetFlow v9 only ("not IPFIX"). Template resendtemplate-tx-timeout1800 seconds by default, so lower it. Reply-direction counters are in fields 23 and 24, which the Collector ignores.log.exporteris<FortiGate IP>log.exporteris<gateway IP>/ip traffic-flow set enabled=yes interfaces=<list>, then/ip traffic-flow target add dst-address=<collector> port=2055 version=9(oripfix). Offers v1, v5, v9 and IPFIX. Template resendv9-template-refreshevery 20 packets. Traffic handled in hardware (offloaded) is not seen.log.exporteris<router IP>log.exporteris<firewall IP>log.exporteris<firewall IP>log.exporteris<MX public or LAN IP as the Collector sees it>log.exporteris<switch IP set in the NetFlow settings>ip:port.log.exporteris<firewall IP>log.exporteris<Firebox IP>add netflow collector ip <collector> port 2055 export-format Netflow_V9 enable yesthensave config. Offers Netflow_V5, Netflow_V9 (the default) and IPFIX; up to 3 collectors. Records are sent after a connection ends (set netflow liveconn_intervalfor long connections).log.exporteris<gateway IP>set services flow-monitoring version9 template T(orversion-ipfix), a sampling instance withoutput flow-server <collector> port 2055,set chassis fpc 0 sampling-instance S, and a sampling filter on the interface. MX: v9 and IPFIX. SRX IPFIX on listed models from 19.4R1 and 20.1R1. EX4100, EX4400 and EX5200 use flow-based telemetry, which needs a license. Export is sampled. MX IPFIX puts flow times in fields 152 and 153, which the Collector does not read (use v9 on MX).log.exporteris<device IP>flow record(match addresses, protocol and ports; collect counters),flow exporter Xwithdestination <collector>andtransport udp 2055,flow monitor M, thenip flow monitor M inon the interface. IPFIX only; the default port is 4739. Flow times are in microsecond fields, which the Collector does not read. AOS 10 gateways (Central): Devices > Gateways > Config > System > External Monitoring > IPFIX.log.exporteris<switch or gateway IP>log.exporteris<firewall IP>flow-export destination <interface> <collector> 2055, then a global policy withflow-export event-type all destination <collector>. NetFlow v9 only (NSEL). Bytes are only in ASA fields 231 and 232, there is no packet count, and times are in fields 152 and 323, so none of these arrive. The ASA syslog integration (CISCO card) is the better source.log.exporteris<ASA IP>feature netflow;flow exporterwithdestination,source <interface>(required, or flows are dropped),transport udp 2055,version 9;flow record;flow monitor;ip flow monitor <name> inputon the interface. v9 only; the default port is 9995.log.exporteris<switch IP>ip netstream export version 9,ip netstream export source <ip>,ip netstream export host <collector> 2055,ip netstream export template timeout-rate <minutes>(30 on AR routers). NetEngine routers: v5, v9 and IPFIX; CloudEngine switches: v5, v8 and v9 (v8 is not decoded). Some models default to v5. The per-interface command was not checked.log.exporteris<device IP>flow tracking sampled>tracker T>exporter E>collector <collector> port 2055,format ipfix version 10;flow tracker sampled Ton the interface. The template interval defaults to 1 hour, so lower it. Sampled tracking needs sFlow off; the default sample rate is 1 in 1,048,576.log.exporteris<switch IP>softflowd -i eth0 -n <collector>:2055 -v 9. softflowd offers v1, v5 (the default), v9 and IPFIX.log.exporteris<host IP>Sources checked for this list (24 Sep 2026)
Sources for 3d (vendor documentation, checked 2026-09-24): Cisco Catalyst 9300 17.15 "Configuring Flexible NetFlow" and command reference, Cisco IOS "Flexible NetFlow" command reference and IPFIX export guide; Cisco ASA "NetFlow Implementation Guide"; documentation.meraki.com "NetFlow Overview"; Cisco Nexus 9000 NX-OS 10.6 "Configuring NetFlow"; juniper.net flow-monitoring guides ("IPFIX and version 9 templates",
template-refresh-rate, "inline sampling", "flow-based telemetry"); manual.mikrotik.com "Traffic Flow"; help.ui.com article 32201256219799 and the UniFi Network 8.5.6 release notes; docs.fortinet.com FortiGate 7.6.6 CLIconfig system netflowand 8.0.1 "NetFlow"; docs.paloaltonetworks.com "Configure NetFlow Exports" and "NetFlow Templates"; SonicWall SonicOS 7.1 AppFlow "External Collector"; docs.sophos.com Sophos Firewall 22.0 "Netflow"; docs.netgate.com "NetFlow with softflowd" and "Packet Flow Data"; docs.opnsense.org "NetFlow exporter"; techdocs.broadcom.com vSphere 8.0 "Configure NetFlow Settings"; learn.microsoft.com "Overview of the Hyper-V Extensible Switch"; arubanetworking.hpe.com AOS-CX 10.15 and 10.16 "flow exporter" and "IPFIX", AOS-S 16.11 "sFlow", Central 2.5.8 "IPFIX"; support.huawei.com NetStream command references (read through search excerpts; the pages refused direct access); sc1.checkpoint.com R82 Gaia Administration Guide "NetFlow Export"; arista.com "Sampled Flow Tracking"; documentation.extremenetworks.com; dell.com SmartFabric OS10 user guide "sFlow"; watchguard.com Fireware "Configure NetFlow"; community.zyxel.com discussion 13480; github.com/irino/softflowdsoftflowd.8.Done per technology
Research notes this list relies on
4(d) NetFlow collector and parser gaps
Found while checking table 3d (code in
collectors/forwarder/collector/netflow/anddefinitions/filters/netflow/netflow.yaml):extractFieldValueingoflow.goprints each value withfmt.Sprintf("%v", value), and goflow2 v1.3.7 hands over raw[]byte, so port 443 becomes[1 187]. Only the address fields go throughtoIP. Fix in the Collector: decode fields 1, 2, 4, 6, 7, 10, 11, 14, 16, 17, 61, 85 and 86 (and the prefix lengths) as big-endian unsigned numbers, whatever their length.log.srcPort,log.dstPort,log.proto,log.bytesandlog.packets. Fix: map the plain values toorigin.port,target.portandprotocol, and keep bytes and packets as numbers.definitions/rules/netflow/needorigin.bytesSent,origin.packagesSent,log.duration,log.bytesorlog.packets, which never exist after parsing. The other four needtarget.portvalues of 256 or more (443, 445, 3389, 500, 1194, 3333 and so on), which v9 and IPFIX store garbled and v5 does not store at all.tor_usage_detectionalso comparesprotocolwith"6"while the parser writesTCP. So none of the 12 rules can fire as intended, and the garbled ports can make some match the wrong flows (for example port 8481 is stored as 3333, a mining-pool port innetflow_cryptomining_traffic).dataSourceincludes the exporter's source port. The NetFlow listener passesaddr.String(), unlike the syslog listener, which strips the port. Strip it, so each device is one data source.netflow.go). Logging it once per exporter would let support tell customers why nothing arrives.