Aruba L2 Switch

Modified on Fri, 1 May at 12:06 PM

TABLE OF CONTENTS


Overview

We are providing you the steps to integrate your Aruba L2 Switch with ADR SIEM so that you can have Comprehensive visibility and Proactive Threat Detection in your Environment. There will be a log transfer between your firewall to CCE (Collection and Control Engine). In this document, we are guiding you through the steps for sflows forwarding.


Steps of Configuration

  1. Run this command:
    configure t
  2. Run this command:
    sflow 1 destination <CCE IP Address> 6343
  3. Run this command:
    sflow 1 polling all 20000
  4. Run this command:
    sflow 1 sampling all 120
  5. Run the exit command:
    exit
  6. Run this command
    display sflow


Verification (MSSP Only)

Verification can be done in two ways


On CCE

To check the sflows"

sudo tcpdump -i any port 6343 and host <Switch IP>


On UI

STEP1: Login to UI > SYSTEM> LOGS AND FLOWS COLLECTION STATUS.


STEP 2: > LOGS AND FLOWS COLLECTION STATUS.


STEP 3: >Inside SOURCE DEVICE IP, the IP address will reflected.




Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article