OPNsense Forum

Archive => 19.1 Legacy Series => Topic started by: gregober on June 24, 2019, 04:26:21 pm

Title: Flow export does not seem to work
Post by: gregober on June 24, 2019, 04:26:21 pm
It looks like if you are planning to use samplicate to send your flows to a remote NetFlow collector for enhanced analysis, flow is not exported.

Despite some tests using tcpdump on all interfaces to track down traffic sent to the specified host in the config "Destination", nothing seems to be sent to this IP address.

So I am wondering if there is not a bug in the samplicate package or if It has been tested with remote hosts.

Some old posts seem to point in the same direction.
https://forum.opnsense.org/index.php?topic=11755.msg53287#msg53287
https://forum.opnsense.org/index.php?topic=12433.msg57172#msg57172
Title: Re: Flow export does not seem to work
Post by: gregober on June 25, 2019, 05:35:39 pm
It looks like if you are planning to use samplicate to send your flows to a remote NetFlow collector for enhanced analysis, flow is not exported.

Despite some tests using tcpdump on all interfaces to track down traffic sent to the specified host in the config "Destination", nothing seems to be sent to this IP address.

So I am wondering if there is not a bug in the samplicate package or if It has been tested with remote hosts.

Some old posts seem to point in the same direction.
https://forum.opnsense.org/index.php?topic=11755.msg53287#msg53287
https://forum.opnsense.org/index.php?topic=12433.msg57172#msg57172

It is working as expected.
No problem with samplicator or OPNsense.
Title: Re: Flow export does not seem to work
Post by: franco on June 26, 2019, 10:19:40 pm
Glad to hear. We were having a discussion last week about how interfaces are selected and will be improving the validation for 19.7 because there is a bit of confusion and wrong GUI labels:

What is currently called "LAN interfaces" should be "listen interfaces" and all the netflow interfaces should be selected there. in the "WAN interfaces" selector the egress-only interfaces need to be selected again to match the listening interfaces.

But that's just a side-node.


Cheers,
Franco