SonicOS 7.0 Device AppFlow
Connecting to an AppFlow Agent
The DEVICE | AppFlow > AppFlow Agent page enables you to establish a connection to a AppFlow Agent.
The AppFlow Agent role can be used in a distributed deployment. In this role, the AppFlow Agent runs a single service that collects SonicWall Flows on the default ports.
The single service that runs in this role is SonicWall Universal Management Suite - Flow Server. The flows are collected and stored in internal databases. To create reports out of these flows, you must have an AppFlow Agent in deployment, and set with the role of Console or All in One. You also need to ensure that these ports are open:
- UDP 2055
- UDP 5055
- TCP 9063
- TCP 9064
- TCP 9065
- TCP 9066
- TCP 9067
The AppFlow Agent has a fixed Syslog Facility (Local Use 0), Syslog Format (Default), and Server ID (firewall). Although the Event Profile value for the AppFlow Agent is set to 0 by default, all events are reported to your AppFlow Agent regardless of the profile. The AppFlow Agent is also exempted from Rate Limiting. AppFlow Agents can be enabled/disabled only in the Advanced Management section of the DEVICE | AppFlow > Flow Reporting | Settings page and not in the DEVICE | Log > Syslog page.
Was This Article Helpful?
Help us to improve our support portal