SlideShare a Scribd company logo
1 of 49
NetFlow Analyzer - Part I
Getting the initial settings right
Welcome to a free training on
NetFlow Analyzer!
Trainer
Piyushree
NetFlow Analyzer product expert
Agenda
• Exporting flows
• Traffic grouping
• Application mapping
• Threshold based alerting
• In-depth traffic visibility
• Knowledge base and best practices
NetFlow Analyzer demo build 123086
Minimum system requirements
2.4 GHz quad-core
processor, or
equivalent
4GB RAM 50GB storage Windows/LinuxPostgreSQL/MSSQL
These specifications only apply when raw data is turned off and the flow rate is below 3,000
flows/sec. Requirements will vary with different settings.
Initial setup
Set up flow export Viewing & customizing
real-time traffic graphs
Configuring alerts
Step1 Step 2 Step 3
Step 1: Configuring flow export from interfaces
NetFlow sFlow J-Flow
IP FIX NetStream AppFlow
Devices supported by NetFlow Analyzer
https://www.manageengine.com/products/netflow/supported-devices.html
Where and how do you send flows?
Ways of exporting flows to NetFlow
Analyzer:
i. Manual configuration
ii. Using Network Configuration Manager
Ports to be considered:
• Server port: NetFlow Analyzer's web server port
• Listener port: Port on which NetFlow Analyzer
receives flows
• Both ports are configurable
Using Network Configuration Manager add-on
Benefits of using Network Configuration Manager:
• No need to write commands
• Predefined configlets
• Export flows from multiple interfaces in bulk
• Backup and restore configurations for devices
• Create new configlets
Apply
credentials
Select
interfaces
Export
flow
Add
devices
Creating/modifying a configlet
• In Network Configuration Manager, go to
Settings > Configlets. Add a new configlet
by creating a custom template.
• Select devices and enter flow
configuration commands.
• Execute the new configlet.
https://download.manageengine.com/prod
ucts/netflow/Help-doc-for-flow-export.pdf
Help guide on steps to configure flows :
Common problems faced after
exporting flows
#1. NetFlow Analyzer shows "No Data Available" in graphs, even after I've
configured flows.
Solution: Two possibilities
1. The device is not configured
correctly for exporting flows.
2. A firewall or access list is blocking
the UDP port.
• Check if flows are received with the
help of Wireshark.
• Yes- Check for windows firewall/IP
tables for any restrictions and template
timeout to 60 seconds.
• No- Correct the configuration by setting
the active timeout to 60 seconds.
#2. I've added five interfaces. Why is one of my interfaces, "Interface Gi0/1," not
listed in NetFlow Analyzer?
Solution:
The particular interface isn't configured
for exporting flows.
• Interface is not configured correctly.
• Check for correct interface along with
its export configurations.
Step 2: Visibility into real-time traffic details
Inventory
Flow analysis
Config management
IP SLA
Packet analysis
Traffic overview Real-time traffic graphs
Inventory: Flow Analysis
Traffic overview
Device
Device groups
Lay 4 & 7 applications DSCP-based QoS
Wireless LAN controllers
Interface
IP / interface group
Attacks
Know the who, when and what of
your network traffic.
- Applications
- Protocols
- QoS
- Source
- Destination
- Conversation
Gain detailed visibility
into traffic usage by
High utilization in one of your network links?
Snapshot summary
Device traffic details:
• Traffic speed
• Associated interfaces by speed, volume
and utilization
• Top applications and protocols
• Top QoS
• Top Source, destination and
conversation
• AS traffic
Group traffic details:
• Traffic by speed, volume, utilization
and packets
• Associated applications and protocols
• DSCP QoS traffic
• Source, destination and conversation
Application traffic details:
• Traffic usage by volume
• Associated interfaces
QoS traffic details:
• Traffic usage by volume
• Associated interfaces
WLC traffic details:
• Controller traffic by speed, volume and
packets
• Associated access points
• Application traffic
• DSCP QoS traffic
• Conversation details with Client IPs and
SSIDs
Interface traffic details:
• Traffic by speed, volume, utilization and
packets
• Top applications and protocols
• Top Source, destination and
conversation by geo-location, network
and DNS name
• Top QoS traffic by DSCP and TOS
• SNMP/FNF NBAR, CBQoS
• Multicast report
• Medianet by volume, RTT, packet loss
• AVC
Visibility into Layer 7 application traffic
• Gain visibility into NBAR2 applications with Cisco AVC
monitoring (Application Visibility and Control).
• Advanced NBAR is used to identify web traffic, URL’s, file sharing
and random port application.
• View NBAR2 application, URL hit count (HTTP host report), QoS
class hierarchy and application response time monitoring
reports(ART monitoring).
Understand traffic for current QoS policies
Check the traffic usage by each DSCP value for policy
effectiveness.
Manage traffic usage by WLAN controllers
• Monitor Cisco WLAN controllers
and Meraki devices.
• Find the top traffic usage by access
points, SSIDs, applications, clients
etc.
• Troubleshoot a bandwidth spikes
by identifying consumption by
SSIDs, finding its top clients and
complete conversation details for
the selected time period.
• Identify junk/unusual traffic that disrupts your critical services.
• Using advanced mining algorithm, ASAM detects internal and
external security threats.
• ASAM classifies traffic as suspect flows, bad source and
destination, DDoS, and scans/probes.
Detect attacks with flow-based advanced security
analytics module
Tips to enhance visibility into your
traffic
My interfaces are named "IfIndex1" and "IfIndex2." How can I view the actual
name of devices and interfaces?
Solution: Three options
• Fetch name from router with SNMP
1. Create SNMP credential
v1/v2/v2 from discovery
2. Associate SNMP credentials
3. Edit device
• Fetch the DNS name.
• Enter your own name.
My interface utilization says it's above 100 percent. How do I set the correct
value?
Solution: Two possibilities
1. The speed is incorrect.
2. [OR] time sync problem.
• Set the proper IN and OUT speed in
bytes. Go to Inventory > Select
Interfaces > Set Speed.
• Make sure the device time and NFA
time is in sync
• Check flow filters
Most of the applications are listed as "_App". How do I map those applications
and also add my own applications?
Solution:
Application mapping for _App
• Interface >Application > _App >
Show port.
• Map application and define IP
address/ IP network/ IP range.
Application mapping for own apps
• Settings> netflow> mapping > add
Is there a way to view cumulative traffic?
Branches
VLANRelated appsNetwork subnet
Department
Traffic grouping
Sort traffic usage by groups
Types of groups
Device
Interface
IP
Application
DSCP
Benefits of creating groups:
• Monitor combined bandwidth usage to get
better picture of traffic consumption.
• Provide access to operators based on
groups.
• Provide better visibility to improve
troubleshooting.
Scenarios: Creating groups
How do I check traffic usage by different branches?
Solution
Create a device grouping for
different branches.
• Combine devices under a branch
to create groups.
• Generate group reports.
How do I monitor combined traffic for VLAN?
Solution
An un-routed VLAN will not send traffic like an
interface, but NetFlow Analyzer will discover
its associated interfaces.
• Create an Interface Group that
includes all of the VLAN's
interfaces to monitor the
cumulative traffic.
• Other option: failover, load
balancing, port channeling, and
aggregation.
How do I manage each of my customers' traffic ?
Solution
Create IP groups for each customer.
• Combine IPs to create groups.
• Generate group reports.
• Group based on IP range, network,
monitoring between sites.
• Other option: between sites and
department
How do I view business critical traffic and see how much bandwidth is used?
Solution
Create application groups.
• Combine apps to create a group.
• Find total utilization for each group.
• Pull combined traffic reports.
Simplified and customizable Inventory
Edit configurationCustom filters/sort
Custom views Quick search
Filter up to the last 30 days Create device group
Create device/interface/app
group
Inventory search
Set speed Set SNMP Zoom in graphs Generate instant reports
New in v12
Unmanage/delete device
Add to Network
Configuration Manager
Table/list/status viewConfigure NBAR & CBQoS
Service policy & ACL Clear alarm/add note
Various device-specific custom options
New in v12
Step 3: Alerting
Link down Link overutilized
Threshold violation Link slow
Alert Profiles
Preconfigured alerts:
• Link down
• No flow
Threshold based alerts
• IP range, IP address or IP network
• Based on port/protocol range
• Based on application
• Based on DSCP
I want to get alerted when the interface is over utilized in a WAN link?
Solution
• Set a threshold alert for overutilized
links.
• Provide a threshold value.
• Set up email/SMS notifications.
Thresholds based on multiple conditions
Select source Select criteria Define threshold Save alert profile
Alerts specific to below violation:
• Utilization
• Volume
• Speed
• Packets
Alert severity levels:
• Critical
• Trouble
• Attention
How do I set up notifications?
Types of notifications:
• Email
• SMS
• Trigger SNMP trap
• Modify an alarm's description.
• Get reports via email. New in v12
Step 1: Configure mail server settings.
Step 2: Set threshold.
Step 3: Provide an email address or phone number.
Step 4: Save alert.
Summary
Set up flow export
#1. Data not available
#2. Interfaces not listed
Viewing & customizing
bandwidth graphs
#1. Fetch device/interface name
#2. Utilization above 100%
#3. Map unknown applications
#4. Show DNS name
#5. Categorize traffic groups
#6. Customize time filter
Configuring alerts
#1. Set interface overutilized
alert
#2. Link down
Step1 Step 2 Step 3
Recent enhancements in NetFlow Analyzer
• 'Guest' user privilege has been added for NetFlow installation.
• Dashboard loading has been revamped and optimized.
• iPhone/Android and iPad application download links available in login.
• In the Inventory page, product based tabs have been moved horizontally.
• Quick links added for sending support mail, apply license, phone number, SIF,
User guide, Videos, Service pack, ThreadDump, DB Query & view Logs with a
support icon.
• Added an option to export to PDF and mail for individual graph reports.
• SFlow flow format for multiple MPLS can be added now.
• Added an option to configure billing with base cost as zero.
How NetFlow Analyzer scores high over others
• Detailed view of applications and QoS traffic
• Traffic grouping options (total traffic based on interfaces, IPs, apps, QoS and
grouped)
• Site to site total traffic view
• Alarms for IP groups
• Wireless LAN monitoring
• Attacks
• AS view
• and more....
Upcoming training on May 22nd
Part II: Diagnosing and troubleshooting traffic issues
faster
• Alarms
• Customizing data storage
• Troubleshooting with forensics
• Reporting and automation
• Capacity planning
• Traffic shaping
• Customizing dashboards
• Usage-based billing
Need more help?
youtube.com/opmanagertechvideos
help.netflowanalyzer.com
forums.manageengine.com/netflowanalyzer
netflowanalyzer-support@manageengine.com
+1 (888) 720-9500 / +1 (408) 916 - 9400
Thank you!
netflowanalyzer-support@manageengine.com

More Related Content

What's hot

VXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksVXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksAPNIC
 
MPLS L3 VPN Deployment
MPLS L3 VPN DeploymentMPLS L3 VPN Deployment
MPLS L3 VPN DeploymentAPNIC
 
Deploy MPLS Traffic Engineering
Deploy MPLS Traffic EngineeringDeploy MPLS Traffic Engineering
Deploy MPLS Traffic EngineeringAPNIC
 
The Basic Introduction of Open vSwitch
The Basic Introduction of Open vSwitchThe Basic Introduction of Open vSwitch
The Basic Introduction of Open vSwitchTe-Yen Liu
 
Troubleshooting BGP
Troubleshooting BGPTroubleshooting BGP
Troubleshooting BGPDuane Bodle
 
Encor chapter 1_packet forwarding
Encor chapter 1_packet forwardingEncor chapter 1_packet forwarding
Encor chapter 1_packet forwardingmerhatsidikmelke
 
Deeper Dive in Docker Overlay Networks
Deeper Dive in Docker Overlay NetworksDeeper Dive in Docker Overlay Networks
Deeper Dive in Docker Overlay NetworksDocker, Inc.
 
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpec
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpecОбеспечение безопасности сети оператора связи с помощью BGP FlowSpec
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpecCisco Russia
 
Introduction to OpenDaylight & Application Development
Introduction to OpenDaylight & Application DevelopmentIntroduction to OpenDaylight & Application Development
Introduction to OpenDaylight & Application DevelopmentMichelle Holley
 
MikroTik Multicast Routing [www.imxpert.co]
MikroTik Multicast Routing [www.imxpert.co]MikroTik Multicast Routing [www.imxpert.co]
MikroTik Multicast Routing [www.imxpert.co]Faisal Reza
 
DDoS Mitigation using BGP Flowspec
DDoS Mitigation using BGP Flowspec DDoS Mitigation using BGP Flowspec
DDoS Mitigation using BGP Flowspec APNIC
 
An Introduction to BGP Flow Spec
An Introduction to BGP Flow SpecAn Introduction to BGP Flow Spec
An Introduction to BGP Flow SpecShortestPathFirst
 
Segment Routing Advanced Use Cases - Cisco Live 2016 USA
Segment Routing Advanced Use Cases - Cisco Live 2016 USASegment Routing Advanced Use Cases - Cisco Live 2016 USA
Segment Routing Advanced Use Cases - Cisco Live 2016 USAJose Liste
 
BGP Advance Technique by Steven & James
BGP Advance Technique by Steven & JamesBGP Advance Technique by Steven & James
BGP Advance Technique by Steven & JamesFebrian ‎
 
Differences of the Cisco Operating Systems
Differences of the Cisco Operating SystemsDifferences of the Cisco Operating Systems
Differences of the Cisco Operating Systems美兰 曾
 
FastNetMon Advanced DDoS detection tool
FastNetMon Advanced DDoS detection toolFastNetMon Advanced DDoS detection tool
FastNetMon Advanced DDoS detection toolPavel Odintsov
 
Junos vs ios Troubleshooting comands
Junos vs ios Troubleshooting comands Junos vs ios Troubleshooting comands
Junos vs ios Troubleshooting comands sandeep kumar
 
GoBGP : yet another OSS BGPd
GoBGP : yet another OSS BGPdGoBGP : yet another OSS BGPd
GoBGP : yet another OSS BGPdPavel Odintsov
 

What's hot (20)

VXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksVXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building Blocks
 
MPLS L3 VPN Deployment
MPLS L3 VPN DeploymentMPLS L3 VPN Deployment
MPLS L3 VPN Deployment
 
Mininet Basics
Mininet BasicsMininet Basics
Mininet Basics
 
Deploy MPLS Traffic Engineering
Deploy MPLS Traffic EngineeringDeploy MPLS Traffic Engineering
Deploy MPLS Traffic Engineering
 
The Basic Introduction of Open vSwitch
The Basic Introduction of Open vSwitchThe Basic Introduction of Open vSwitch
The Basic Introduction of Open vSwitch
 
Troubleshooting BGP
Troubleshooting BGPTroubleshooting BGP
Troubleshooting BGP
 
Encor chapter 1_packet forwarding
Encor chapter 1_packet forwardingEncor chapter 1_packet forwarding
Encor chapter 1_packet forwarding
 
Deeper Dive in Docker Overlay Networks
Deeper Dive in Docker Overlay NetworksDeeper Dive in Docker Overlay Networks
Deeper Dive in Docker Overlay Networks
 
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpec
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpecОбеспечение безопасности сети оператора связи с помощью BGP FlowSpec
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpec
 
Introduction to OpenDaylight & Application Development
Introduction to OpenDaylight & Application DevelopmentIntroduction to OpenDaylight & Application Development
Introduction to OpenDaylight & Application Development
 
MikroTik Multicast Routing [www.imxpert.co]
MikroTik Multicast Routing [www.imxpert.co]MikroTik Multicast Routing [www.imxpert.co]
MikroTik Multicast Routing [www.imxpert.co]
 
DDoS Mitigation using BGP Flowspec
DDoS Mitigation using BGP Flowspec DDoS Mitigation using BGP Flowspec
DDoS Mitigation using BGP Flowspec
 
An Introduction to BGP Flow Spec
An Introduction to BGP Flow SpecAn Introduction to BGP Flow Spec
An Introduction to BGP Flow Spec
 
Mpls technology
Mpls technologyMpls technology
Mpls technology
 
Segment Routing Advanced Use Cases - Cisco Live 2016 USA
Segment Routing Advanced Use Cases - Cisco Live 2016 USASegment Routing Advanced Use Cases - Cisco Live 2016 USA
Segment Routing Advanced Use Cases - Cisco Live 2016 USA
 
BGP Advance Technique by Steven & James
BGP Advance Technique by Steven & JamesBGP Advance Technique by Steven & James
BGP Advance Technique by Steven & James
 
Differences of the Cisco Operating Systems
Differences of the Cisco Operating SystemsDifferences of the Cisco Operating Systems
Differences of the Cisco Operating Systems
 
FastNetMon Advanced DDoS detection tool
FastNetMon Advanced DDoS detection toolFastNetMon Advanced DDoS detection tool
FastNetMon Advanced DDoS detection tool
 
Junos vs ios Troubleshooting comands
Junos vs ios Troubleshooting comands Junos vs ios Troubleshooting comands
Junos vs ios Troubleshooting comands
 
GoBGP : yet another OSS BGPd
GoBGP : yet another OSS BGPdGoBGP : yet another OSS BGPd
GoBGP : yet another OSS BGPd
 

Similar to NetFlow Analyzer Training Part I: Getting the initial settings right

Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...ManageEngine, Zoho Corporation
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...ManageEngine, Zoho Corporation
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshootingManageEngine, Zoho Corporation
 
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...ManageEngine, Zoho Corporation
 
Monitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerMonitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerManageEngine
 
Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightSai Sundhar Padmanabhan
 
Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.ManageEngine, Zoho Corporation
 
The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines Netronome
 
1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.pptFarid Er
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.pptAssadLeo1
 
ONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAJunho Suh
 
NUVX Technologies general solutions
NUVX Technologies general solutionsNUVX Technologies general solutions
NUVX Technologies general solutionsNUVX
 
Azure Monitoring Overview
Azure Monitoring OverviewAzure Monitoring Overview
Azure Monitoring Overviewgjuljo
 

Similar to NetFlow Analyzer Training Part I: Getting the initial settings right (20)

Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings right
 
Network Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai SeminarNetwork Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai Seminar
 
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshooting
 
NFA - Middle East Workshop
NFA - Middle East WorkshopNFA - Middle East Workshop
NFA - Middle East Workshop
 
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
 
Monitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerMonitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManager
 
Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An Insight
 
Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.
 
The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines
 
Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.ppt
 
Cloud Migration
Cloud MigrationCloud Migration
Cloud Migration
 
INT_Ch17.pptx
INT_Ch17.pptxINT_Ch17.pptx
INT_Ch17.pptx
 
ONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINA
 
NUVX Technologies general solutions
NUVX Technologies general solutionsNUVX Technologies general solutions
NUVX Technologies general solutions
 
Azure Monitoring Overview
Azure Monitoring OverviewAzure Monitoring Overview
Azure Monitoring Overview
 

More from ManageEngine, Zoho Corporation

NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020ManageEngine, Zoho Corporation
 
Overcome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesOvercome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesManageEngine, Zoho Corporation
 
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringModernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringManageEngine, Zoho Corporation
 
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020ManageEngine, Zoho Corporation
 
From web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersFrom web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTManageEngine, Zoho Corporation
 
Monitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureMonitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureManageEngine, Zoho Corporation
 
Visibility-from web application interface to the database
Visibility-from web application interface to the databaseVisibility-from web application interface to the database
Visibility-from web application interface to the databaseManageEngine, Zoho Corporation
 
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network MapsFree OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network MapsManageEngine, Zoho Corporation
 

More from ManageEngine, Zoho Corporation (20)

Create seamless customer experiences
Create seamless customer experiencesCreate seamless customer experiences
Create seamless customer experiences
 
From web interface to database: Monitor what matters
From web interface to database: Monitor what mattersFrom web interface to database: Monitor what matters
From web interface to database: Monitor what matters
 
NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020
 
Overcome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesOvercome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challenges
 
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringModernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoring
 
Deliver seamless digital experience
Deliver seamless digital experienceDeliver seamless digital experience
Deliver seamless digital experience
 
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
 
From web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersFrom web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that matters
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
 
NetFlow Analyzer Product Overview
NetFlow Analyzer Product OverviewNetFlow Analyzer Product Overview
NetFlow Analyzer Product Overview
 
Monitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureMonitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructure
 
Building the right website monitoring strategy
Building the right website monitoring strategyBuilding the right website monitoring strategy
Building the right website monitoring strategy
 
Unlock the value of your big data infrastructure
Unlock the value of your big data infrastructureUnlock the value of your big data infrastructure
Unlock the value of your big data infrastructure
 
Key to optimal end user experience
Key to optimal end user experienceKey to optimal end user experience
Key to optimal end user experience
 
Monitoring cloud applications and containers
Monitoring cloud applications and containersMonitoring cloud applications and containers
Monitoring cloud applications and containers
 
implementing the right website monitoring strategy
 implementing the right website monitoring strategy implementing the right website monitoring strategy
implementing the right website monitoring strategy
 
Big data and non relational database
Big data and non relational databaseBig data and non relational database
Big data and non relational database
 
Visibility-from web application interface to the database
Visibility-from web application interface to the databaseVisibility-from web application interface to the database
Visibility-from web application interface to the database
 
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network MapsFree OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
 

Recently uploaded

Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxbodapatigopi8531
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...harshavardhanraghave
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVshikhaohhpro
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxComplianceQuest1
 
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...MyIntelliSource, Inc.
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...panagenda
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providermohitmore19
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...OnePlan Solutions
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...kellynguyen01
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️anilsa9823
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsAlberto González Trastoy
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfkalichargn70th171
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...MyIntelliSource, Inc.
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionSolGuruz
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdfWave PLM
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...Health
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerThousandEyes
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsJhone kinadey
 

Recently uploaded (20)

Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptx
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docx
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
Try MyIntelliAccount Cloud Accounting Software As A Service Solution Risk Fre...
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with Precision
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial Goals
 

NetFlow Analyzer Training Part I: Getting the initial settings right

  • 1. NetFlow Analyzer - Part I Getting the initial settings right
  • 2. Welcome to a free training on NetFlow Analyzer!
  • 4. Agenda • Exporting flows • Traffic grouping • Application mapping • Threshold based alerting • In-depth traffic visibility • Knowledge base and best practices
  • 5. NetFlow Analyzer demo build 123086
  • 6. Minimum system requirements 2.4 GHz quad-core processor, or equivalent 4GB RAM 50GB storage Windows/LinuxPostgreSQL/MSSQL These specifications only apply when raw data is turned off and the flow rate is below 3,000 flows/sec. Requirements will vary with different settings.
  • 7. Initial setup Set up flow export Viewing & customizing real-time traffic graphs Configuring alerts Step1 Step 2 Step 3
  • 8. Step 1: Configuring flow export from interfaces NetFlow sFlow J-Flow IP FIX NetStream AppFlow
  • 9. Devices supported by NetFlow Analyzer https://www.manageengine.com/products/netflow/supported-devices.html
  • 10. Where and how do you send flows? Ways of exporting flows to NetFlow Analyzer: i. Manual configuration ii. Using Network Configuration Manager Ports to be considered: • Server port: NetFlow Analyzer's web server port • Listener port: Port on which NetFlow Analyzer receives flows • Both ports are configurable
  • 11. Using Network Configuration Manager add-on Benefits of using Network Configuration Manager: • No need to write commands • Predefined configlets • Export flows from multiple interfaces in bulk • Backup and restore configurations for devices • Create new configlets Apply credentials Select interfaces Export flow Add devices
  • 12. Creating/modifying a configlet • In Network Configuration Manager, go to Settings > Configlets. Add a new configlet by creating a custom template. • Select devices and enter flow configuration commands. • Execute the new configlet.
  • 14. Common problems faced after exporting flows
  • 15. #1. NetFlow Analyzer shows "No Data Available" in graphs, even after I've configured flows. Solution: Two possibilities 1. The device is not configured correctly for exporting flows. 2. A firewall or access list is blocking the UDP port. • Check if flows are received with the help of Wireshark. • Yes- Check for windows firewall/IP tables for any restrictions and template timeout to 60 seconds. • No- Correct the configuration by setting the active timeout to 60 seconds.
  • 16. #2. I've added five interfaces. Why is one of my interfaces, "Interface Gi0/1," not listed in NetFlow Analyzer? Solution: The particular interface isn't configured for exporting flows. • Interface is not configured correctly. • Check for correct interface along with its export configurations.
  • 17. Step 2: Visibility into real-time traffic details Inventory Flow analysis Config management IP SLA Packet analysis Traffic overview Real-time traffic graphs
  • 18. Inventory: Flow Analysis Traffic overview Device Device groups Lay 4 & 7 applications DSCP-based QoS Wireless LAN controllers Interface IP / interface group Attacks
  • 19. Know the who, when and what of your network traffic. - Applications - Protocols - QoS - Source - Destination - Conversation Gain detailed visibility into traffic usage by
  • 20. High utilization in one of your network links?
  • 21. Snapshot summary Device traffic details: • Traffic speed • Associated interfaces by speed, volume and utilization • Top applications and protocols • Top QoS • Top Source, destination and conversation • AS traffic Group traffic details: • Traffic by speed, volume, utilization and packets • Associated applications and protocols • DSCP QoS traffic • Source, destination and conversation Application traffic details: • Traffic usage by volume • Associated interfaces QoS traffic details: • Traffic usage by volume • Associated interfaces WLC traffic details: • Controller traffic by speed, volume and packets • Associated access points • Application traffic • DSCP QoS traffic • Conversation details with Client IPs and SSIDs Interface traffic details: • Traffic by speed, volume, utilization and packets • Top applications and protocols • Top Source, destination and conversation by geo-location, network and DNS name • Top QoS traffic by DSCP and TOS • SNMP/FNF NBAR, CBQoS • Multicast report • Medianet by volume, RTT, packet loss • AVC
  • 22. Visibility into Layer 7 application traffic • Gain visibility into NBAR2 applications with Cisco AVC monitoring (Application Visibility and Control). • Advanced NBAR is used to identify web traffic, URL’s, file sharing and random port application. • View NBAR2 application, URL hit count (HTTP host report), QoS class hierarchy and application response time monitoring reports(ART monitoring).
  • 23. Understand traffic for current QoS policies Check the traffic usage by each DSCP value for policy effectiveness.
  • 24. Manage traffic usage by WLAN controllers • Monitor Cisco WLAN controllers and Meraki devices. • Find the top traffic usage by access points, SSIDs, applications, clients etc. • Troubleshoot a bandwidth spikes by identifying consumption by SSIDs, finding its top clients and complete conversation details for the selected time period.
  • 25. • Identify junk/unusual traffic that disrupts your critical services. • Using advanced mining algorithm, ASAM detects internal and external security threats. • ASAM classifies traffic as suspect flows, bad source and destination, DDoS, and scans/probes. Detect attacks with flow-based advanced security analytics module
  • 26. Tips to enhance visibility into your traffic
  • 27. My interfaces are named "IfIndex1" and "IfIndex2." How can I view the actual name of devices and interfaces? Solution: Three options • Fetch name from router with SNMP 1. Create SNMP credential v1/v2/v2 from discovery 2. Associate SNMP credentials 3. Edit device • Fetch the DNS name. • Enter your own name.
  • 28. My interface utilization says it's above 100 percent. How do I set the correct value? Solution: Two possibilities 1. The speed is incorrect. 2. [OR] time sync problem. • Set the proper IN and OUT speed in bytes. Go to Inventory > Select Interfaces > Set Speed. • Make sure the device time and NFA time is in sync • Check flow filters
  • 29. Most of the applications are listed as "_App". How do I map those applications and also add my own applications? Solution: Application mapping for _App • Interface >Application > _App > Show port. • Map application and define IP address/ IP network/ IP range. Application mapping for own apps • Settings> netflow> mapping > add
  • 30. Is there a way to view cumulative traffic? Branches VLANRelated appsNetwork subnet Department Traffic grouping
  • 31. Sort traffic usage by groups Types of groups Device Interface IP Application DSCP Benefits of creating groups: • Monitor combined bandwidth usage to get better picture of traffic consumption. • Provide access to operators based on groups. • Provide better visibility to improve troubleshooting.
  • 33. How do I check traffic usage by different branches? Solution Create a device grouping for different branches. • Combine devices under a branch to create groups. • Generate group reports.
  • 34. How do I monitor combined traffic for VLAN? Solution An un-routed VLAN will not send traffic like an interface, but NetFlow Analyzer will discover its associated interfaces. • Create an Interface Group that includes all of the VLAN's interfaces to monitor the cumulative traffic. • Other option: failover, load balancing, port channeling, and aggregation.
  • 35. How do I manage each of my customers' traffic ? Solution Create IP groups for each customer. • Combine IPs to create groups. • Generate group reports. • Group based on IP range, network, monitoring between sites. • Other option: between sites and department
  • 36. How do I view business critical traffic and see how much bandwidth is used? Solution Create application groups. • Combine apps to create a group. • Find total utilization for each group. • Pull combined traffic reports.
  • 37. Simplified and customizable Inventory Edit configurationCustom filters/sort Custom views Quick search
  • 38. Filter up to the last 30 days Create device group Create device/interface/app group Inventory search Set speed Set SNMP Zoom in graphs Generate instant reports New in v12 Unmanage/delete device Add to Network Configuration Manager Table/list/status viewConfigure NBAR & CBQoS Service policy & ACL Clear alarm/add note Various device-specific custom options New in v12
  • 39. Step 3: Alerting Link down Link overutilized Threshold violation Link slow
  • 40. Alert Profiles Preconfigured alerts: • Link down • No flow Threshold based alerts • IP range, IP address or IP network • Based on port/protocol range • Based on application • Based on DSCP
  • 41. I want to get alerted when the interface is over utilized in a WAN link? Solution • Set a threshold alert for overutilized links. • Provide a threshold value. • Set up email/SMS notifications.
  • 42. Thresholds based on multiple conditions Select source Select criteria Define threshold Save alert profile Alerts specific to below violation: • Utilization • Volume • Speed • Packets Alert severity levels: • Critical • Trouble • Attention
  • 43. How do I set up notifications? Types of notifications: • Email • SMS • Trigger SNMP trap • Modify an alarm's description. • Get reports via email. New in v12 Step 1: Configure mail server settings. Step 2: Set threshold. Step 3: Provide an email address or phone number. Step 4: Save alert.
  • 44. Summary Set up flow export #1. Data not available #2. Interfaces not listed Viewing & customizing bandwidth graphs #1. Fetch device/interface name #2. Utilization above 100% #3. Map unknown applications #4. Show DNS name #5. Categorize traffic groups #6. Customize time filter Configuring alerts #1. Set interface overutilized alert #2. Link down Step1 Step 2 Step 3
  • 45. Recent enhancements in NetFlow Analyzer • 'Guest' user privilege has been added for NetFlow installation. • Dashboard loading has been revamped and optimized. • iPhone/Android and iPad application download links available in login. • In the Inventory page, product based tabs have been moved horizontally. • Quick links added for sending support mail, apply license, phone number, SIF, User guide, Videos, Service pack, ThreadDump, DB Query & view Logs with a support icon. • Added an option to export to PDF and mail for individual graph reports. • SFlow flow format for multiple MPLS can be added now. • Added an option to configure billing with base cost as zero.
  • 46. How NetFlow Analyzer scores high over others • Detailed view of applications and QoS traffic • Traffic grouping options (total traffic based on interfaces, IPs, apps, QoS and grouped) • Site to site total traffic view • Alarms for IP groups • Wireless LAN monitoring • Attacks • AS view • and more....
  • 47. Upcoming training on May 22nd Part II: Diagnosing and troubleshooting traffic issues faster • Alarms • Customizing data storage • Troubleshooting with forensics • Reporting and automation • Capacity planning • Traffic shaping • Customizing dashboards • Usage-based billing