Configuring Netflow with Extensions with SonicWall Scrutinizer

One external flow reporting option that works with Netflow with Extensions is the third-party collector called SonicWall Scrutinizer. This collector displays a range of reporting and analysis that is both Netflow and SonicWall flow aware.

To verify your Netflow with Extensions reporting configurations:
1
Click the Settings tab.
2
For Report Connections in the Settings section, select either of these radio buttons:

When enabled, the flows reported are based on the initiator or responder interface or on already existing firewall rules.

NOTE: This step is optional, but is required if flow reporting is done on selected interfaces.
3
Click the External Collector tab.
4
Select the Send Flows and Real-Time Data To External Collector checkbox.
5
Select IPFIX with extensions as the External Flow Reporting Format from the drop-down menu.
6
Specify the External Collector’s IP address in the provided field.
7
Optionally, for the Source IP to Use for Collector on a VPN Tunnel, specify the source IP if the external collector must be reached by a VPN tunnel.
NOTE: This step is required if the external collector must be reached by a VPN tunnel.
8
Specify the External Collector’s UDP port number in the provided field. The default port is 2055.
9
10
Click Accept.
11
Navigate to the Network > Interfaces page.
12
Confirm that Flow Reporting is enabled per interface by clicking the Configure icon of the interface you are requesting data from. The Edit Interface dialog displays.
13
Click the Advanced tab.
14
Ensure the Enable flow reporting check box is selected.
15
16