Installing NFO on Linux
This guide provides step-by-step instructions for installing NetFlow Optimizer (NFO) on Linux systems using either the RPM package manager (recommended for RHEL-based systems) or a TAR archive. You can choose to run the installation as a root user or configure the system to run as a non-root user for enhanced security.
Prerequisites
- Administrative Access: You must have root or sudo privileges to perform the installation.
- System Requirements: Ensure your host meets the memory and CPU requirements outlined in the NFO Installation Guide: System Requirements & Sizing.
- Supported Versions: See Supported Platforms for the Linux distributions supported by this release.
- Java Dependencies: NFO package includes 64-bit Java Runtime Environment (JRE) and Tomcat.
Network & Security Settings
Ensure your firewall allows the following traffic from your trusted IP ranges:
- TCP 22: SSH access for command-line management.
- TCP 8443: Management UI access.
- UDP 9995: Standard NetFlow/IPFIX ingestion (or your custom flow port).
- UDP 161/162: If using SNMP polling or traps.
Option 1: RPM Installation
The RPM method is the standard approach for distributions such as RHEL, CentOS, and Rocky Linux.
- Download the Package: Obtain the
flowintegrator-<version>-linux.x86_64.rpmfile from the NetFlow Logic Downloads page. Only<version>changes between releases; the rest of the file name is literal. - Install the Software: Execute the following command:
sudo rpm -ivh flowintegrator-*-linux.x86_64.rpm
Run this from the directory holding the downloaded package. The wildcard expects a single matching file; if you have kept packages from earlier releases in the same directory, use the full file name instead.
- Verify Service Status: Once installed, ensure the NFO service is running:
systemctl status tomcat_nfo
If the service is not running, see the Troubleshooting Guide for diagnosis steps.
Hardened Systems: RPM digest verification error
On systems with strict security policies (e.g. FIPS mode or custom RPM digest restrictions), the installation may fail with a digest verification error. If this occurs, retry with:
sudo rpm -ivh --nodigest flowintegrator-*-linux.x86_64.rpm
--nodigest disables RPM package digest verification. Use only if required by your environment and consult your security policy before proceeding.
Option 2: TAR Archive Installation
Use this method if you are installing on a distribution that does not support RPM or if you prefer manual placement of files.
- Download the Archive: Obtain the
flowintegrator-<version>-linux-x86_64.tar.gzfile from the NetFlow Logic Downloads page. Only<version>changes between releases; the rest of the file name is literal. - Extract Files: Create a directory (typically
/opt/flowintegrator) and extract the archive:
mkdir -p /opt/flowintegrator
tar -xzvf flowintegrator-*-linux-x86_64.tar.gz -C /opt/
- Run Install Script: Navigate to the extracted directory and run the setup script:
cd /opt/flowintegrator
./setup.sh -i
The setup.sh script includes an optional --doNotStartServices parameter, which prevents the NFO and EDFN services from starting automatically after installation. This is useful if post-installation actions (such as updating TLS certificates or modifying the "run-as" user) are required before the services go live.
Security Hardening: Running as Non-Root
By default, NFO runs as the root user. Follow this procedure to run both services under a dedicated nfo service account instead.
Both services use jsvc (Apache Commons Daemon) to manage the JVM process. jsvc starts as root, performs the privileged setup, then drops to the account named by its --tomcat-user argument. The systemd unit files therefore continue to run as root and do not need to be modified; the account change is made in the daemon scripts.
The NFO Repeater function and NFO Central require root privileges and cannot run as a non-root user.
1. Create the Service Account
Create a dedicated group and service account. nfo-group is the primary group of the nfo account and is used for file ownership in Step 3.
sudo groupadd nfo-group
sudo useradd --system --no-create-home --shell /sbin/nologin -g nfo-group nfo
Verify:
id nfo
2. Stop the Services
Switch to a root shell and stop both services:
sudo -i
systemctl stop nfi_updd.service
systemctl stop tomcat_nfo.service
3. Transfer Ownership of the Installation Directories
Transfer ownership of both installation directories to the new account. Replace /opt with your installation prefix if it differs.
chown --recursive nfo:nfo-group /opt/flowintegrator
chown --recursive nfo:nfo-group /opt/nfi-updater
Verify that the log directories and the PID file location are writable by the new account:
ls -la /opt/flowintegrator/tomcat/bin/
ls -la /opt/flowintegrator/logs/
ls -la /opt/nfi-updater/logs/
4. Update the Daemon Scripts
In both scripts, change the --tomcat-user argument from root to nfo.
Open /opt/flowintegrator/nfi.sh and locate this line in the start case block:
./daemon.sh --java-home ${JAVA_HOME} --service-start-wait-time 120 --tomcat-user root start
Change it to:
./daemon.sh --java-home ${JAVA_HOME} --service-start-wait-time 120 --tomcat-user nfo start
Then open /opt/nfi-updater/bin/nfiu_daemon, locate the equivalent line, and make the same change.
5. Start Services and Verify
systemctl start nfi_updd.service
systemctl start tomcat_nfo.service
Confirm the JVM worker processes are running as the nfo account:
ps -eo user,pid,args | grep '[j]svc'
The output should show nfo in the user column.
The non-root configuration is now complete. The remaining two steps are optional.
6. Create the Administrator Group (Optional)
The next two steps let designated administrators start, stop, and inspect the NFO services without a root login. They use a second group, nfo-admins, for human administrators. This is separate from nfo-group, which is the service account's primary group used for file ownership.
groupadd nfo-admins
# Add each administrator who needs to manage the services
usermod -aG nfo-admins <username>
7. Configure Sudoers for Service Administrators (Optional)
Create a dedicated drop-in file using visudo. Do not edit /etc/sudoers directly.
sudo visudo -f /etc/sudoers.d/flowintegrator
Insert the appropriate block for your init system and save the file.
For systemd-based systems (RHEL 7+, CentOS 7+, Ubuntu 16.04+, SUSE 12+)
## FlowIntegrator service management
## Grants members of the nfo-admins group the ability to manage
## the NFO and EDFN services without a root login.
%nfo-admins ALL=(root) NOPASSWD: \
/usr/bin/systemctl start tomcat_nfo.service, \
/usr/bin/systemctl stop tomcat_nfo.service, \
/usr/bin/systemctl restart tomcat_nfo.service, \
/usr/bin/systemctl reload tomcat_nfo.service, \
/usr/bin/systemctl status tomcat_nfo.service, \
/usr/bin/systemctl enable tomcat_nfo.service, \
/usr/bin/systemctl disable tomcat_nfo.service, \
/usr/bin/systemctl start nfi_updd.service, \
/usr/bin/systemctl stop nfi_updd.service, \
/usr/bin/systemctl restart nfi_updd.service, \
/usr/bin/systemctl reload nfi_updd.service, \
/usr/bin/systemctl status nfi_updd.service, \
/usr/bin/systemctl enable nfi_updd.service, \
/usr/bin/systemctl disable nfi_updd.service, \
/usr/bin/journalctl -u tomcat_nfo.service, \
/usr/bin/journalctl -u nfi_updd.service
For SysV init systems
Use this block on distributions that do not use systemd.
%nfo-admins ALL=(root) NOPASSWD: \
/etc/init.d/tomcat_nfo start, \
/etc/init.d/tomcat_nfo stop, \
/etc/init.d/tomcat_nfo restart, \
/etc/init.d/tomcat_nfo status, \
/etc/init.d/nfi_updd start, \
/etc/init.d/nfi_updd stop, \
/etc/init.d/nfi_updd restart, \
/etc/init.d/nfi_updd status
Set correct permissions on the file:
chmod 0440 /etc/sudoers.d/flowintegrator
Confirm that a member of nfo-admins can manage services without a root password:
sudo systemctl status tomcat_nfo.service
sudo systemctl status nfi_updd.service
The initial RPM installation (rpm -i) and daemon registration (register_daemon.sh -i) still require root, as they write to /etc/systemd/system/ or /etc/init.d/. The sudoers configuration above covers day-to-day operational management only.
TLS keystores (.tomcat_keystore, .updater_keystore, .truststore) are set to mode 600 during installation. After the ownership change in Step 3, they are owned by nfo and remain protected from other users.
Next Steps
Once the services are started, complete your setup in the web interface:
- Access the UI: Navigate to
https://<nfo-host>:8443in a supported browser. - Apply your license: Go to Licensing and upload your license file. NFO will not ingest or process data without a valid license.
- Configure inputs, outputs, and modules: Set up data ingestion, destinations, and processing logic.
- Verify health: Use the Status page to confirm the engine is receiving and processing data.
For full administration reference, see Platform Admin.