We're started an sFlow monitor on our Firewall. So far it's working great. Right now we only see "WWW" traffice and "MAIL" traffic. Is there a way to split this up into POP3/IMAP/HTTP/HTTPS?


Article Comments

in the sensor settings in the Channel Configuration section select "Detail" for the WEB and MAIL.


Oct, 2011 - Permalink

It looks like there is just details for POP3 and SMTP. I assume this monitors port 110 and 25. We are using POP3S and SMTP3 (ports 995 and 465) Can we change that anywhere?


Oct, 2011 - Permalink

Hallo,

you could create your own custom sFlow sensors and add the channels yourself. Please take a look at

https://kb.paessler.com/knowledgebase/en/topic/2143-can-i-add-custom-channels-to-standard-packet-sniffer-and-netflow-sensors


Oct, 2011 - Permalink