
WANGUARD 5.2 User Manual & Administrator's Guide
All received fows can be stored in an efcient binary format and queried in Reports » Collectons.
●
Graphs Accuracy
Low values increase the Sensor's accuracy but the Flow Sensor will use more RAM.
●
Repeater IP:Port
Send all incoming fows to another host and port by enabling the packet repeater.
●
Comments
Comments about the Sensor confguraton can be saved here. Not visible elsewhere.
To start the Sensor click gray square buton from the Side Region.
Afer setng a Sensor as Actve you should see if it starts properly by watching the Events – see page 58.
If the Flow Sensor starts without errors, but you can't see any data afer more than 5 minutes, please check
the following:
✔
You have correctly confgured the fow exporter to send fows to the server for each of the confgured
interfaces.
✔
The server is receiving the fow packets on the confgured port. You can verify this with a tool like
tcpdump
.
The syntax is “tcpdump -i <interface_usually_eth0> -n -c 100 udp and <destnaton_port>”.
✔
The local frewall is allowing the Flow Sensor to receive the fow packets. You can check if the frewall is
enabled with the
iptables
command. The syntax is “iptables -L -n -v”.
✔
Both the server and the fow exporter reside in the same tme-zone. The clocks must be synchronized with
NTP.
✔
The fow exporter's actve/inactve fow tmeout setngs are less than 300 seconds. Flows sent with a delay
of more than 300 seconds are automatcally discarded.
✔
If you have “Mixed” interfaces then the IP Zone you have selected for the Flow Sensor must contain all your
subnets.
- 49 -
Содержание Wanguard 5.2
Страница 1: ......