config switch-controller flow-tracking
Configure FortiSwitch flow tracking and export via ipfix/netflow.
config switch-controller flow-tracking
Description: Configure FortiSwitch flow tracking and export via ipfix/netflow.
set sample-mode [local|perimeter|...]
set sample-rate {integer}
set format [netflow1|netflow5|...]
config collectors
Description: Configure collectors for the flow.
edit <name>
set ip {ipv4-address-any}
set port {integer}
set transport [udp|tcp|...]
next
end
set level [vlan|ip|...]
set max-export-pkt-size {integer}
set template-export-period {integer}
set timeout-general {integer}
set timeout-icmp {integer}
set timeout-max {integer}
set timeout-tcp {integer}
set timeout-tcp-fin {integer}
set timeout-tcp-rst {integer}
set timeout-udp {integer}
config aggregates
Description: Configure aggregates in which all traffic sessions matching the IP Address will be grouped into the same flow.
edit <id>
set ip {ipv4-classnet}
next
end
end
config switch-controller flow-tracking
Parameter |
Description |
Type |
Size |
Default |
||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
sample-mode |
Configure sample mode for the flow tracking. |
option |
- |
perimeter |
||||||||||||
|
|
|||||||||||||||
sample-rate |
Configure sample rate for the perimeter and device-ingress sampling. |
integer |
Minimum value: 0 Maximum value: 99999 |
512 |
||||||||||||
format |
Configure flow tracking protocol. |
option |
- |
netflow9 |
||||||||||||
|
|
|||||||||||||||
level |
Configure flow tracking level. |
option |
- |
ip |
||||||||||||
|
|
|||||||||||||||
max-export-pkt-size |
Configure flow max export packet size . |
integer |
Minimum value: 512 Maximum value: 9216 |
512 |
||||||||||||
template-export-period |
Configure template export period . |
integer |
Minimum value: 1 Maximum value: 60 |
5 |
||||||||||||
timeout-general |
Configure flow session general timeout . |
integer |
Minimum value: 60 Maximum value: 604800 |
3600 |
||||||||||||
timeout-icmp |
Configure flow session ICMP timeout . |
integer |
Minimum value: 60 Maximum value: 604800 |
300 |
||||||||||||
timeout-max |
Configure flow session max timeout . |
integer |
Minimum value: 60 Maximum value: 604800 |
604800 |
||||||||||||
timeout-tcp |
Configure flow session TCP timeout . |
integer |
Minimum value: 60 Maximum value: 604800 |
3600 |
||||||||||||
timeout-tcp-fin |
Configure flow session TCP FIN timeout . |
integer |
Minimum value: 60 Maximum value: 604800 |
300 |
||||||||||||
timeout-tcp-rst |
Configure flow session TCP RST timeout . |
integer |
Minimum value: 60 Maximum value: 604800 |
120 |
||||||||||||
timeout-udp |
Configure flow session UDP timeout . |
integer |
Minimum value: 60 Maximum value: 604800 |
300 |
config collectors
Parameter |
Description |
Type |
Size |
Default |
||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
ip |
Collector IP address. |
ipv4-address-any |
Not Specified |
0.0.0.0 |
||||||||
port |
Collector port number. |
integer |
Minimum value: 0 Maximum value: 65535 |
0 |
||||||||
transport |
Collector L4 transport protocol for exporting packets. |
option |
- |
udp |
||||||||
|
|
config aggregates
Parameter |
Description |
Type |
Size |
Default |
---|---|---|---|---|
ip |
IP address to group all matching traffic sessions to a flow. |
ipv4-classnet |
Not Specified |
0.0.0.0 0.0.0.0 |