Skip to main content

WatchGuard Firebox M390 Configuration

This document outlines the steps to configure WatchGuard Firebox M390 for NetFlow export with ObserveOps Flow Explorer.

Configuration Steps

Navigate to System > NetFlow in the Fireware Web UI.

Select Enable NetFlow.

For the protocol version, select V5 or V9. Use V9 to monitor IPv6 traffic.

In the Collector Address field, enter {MOTADATA_NETFLOW_SERVER_IP}.

In the Port field, enter 2055.

In the Active Flow Timeout field, enter a value between 1 and 60 minutes.

note

Set the Active Flow Timeout on the Firebox lower than the value configured on the collector to avoid data loss. The default value is 30 minutes.

To enable NetFlow for an interface, select Ingress, Egress, or both next to the interface name.

After completing the configuration, navigate to Menu > Flow Explorer and select Explorer to view the active flow data.