SlideShare a Scribd company logo
Free training on NetFlow Analyzer - Part I
Getting the initial settings right
Agenda
• Exporting flows
• Traffic grouping
• Application mapping
• Threshold based alerting
• In-depth traffic visibility
• Knowledge base and best practices
Demo on NetFlow Analyzer 123083
Minimum system requirements
2.4 GHz quad-core
processor, or
equivalent
4GB RAM 50GB storage Windows/LinuxPostgreSQL/MSSQL
These specifications only apply when raw data is turned off and the flow rate is below 3,000
flows/sec. Requirements will vary with different settings.
Initial setup
Set up flow export Viewing & customizing
real-time traffic graphs
Configuring alerts
Step1 Step 2 Step 3
Step 1: Configuring flow export from interfaces
NetFlow sFlow J-Flow
IP FIX NetStream AppFlow
Devices supported by NetFlow Analyzer
https://www.manageengine.com/products/netflow/supported-devices.html
Where and how do you send flows?
Ways of exporting flows to NetFlow
Analyzer:
i. Manual configuration
ii. Using Network Configuration Manager
Ports to be considered:
• Server port: NetFlow Analyzer's web server port
• Listener port: Port on which NetFlow Analyzer
receives flows
• Both ports are configurable
Using Network Configuration Manager
Benefits of using Network Configuration Manager:
• No need to write commands
• Predefined configlets
• Export flows from multiple interfaces in bulk
• Backup and restore configurations for devices
• Create new configlets
Apply
credentials
Select
interfaces
Export
flow
Add
devices
Creating/modifying a configlet
• In Network Configuration Manager, go to
Settings > Configlets. Add a new configlet
by creating a custom template.
• Select devices and enter flow
configuration commands.
• Execute the new configlet.
Common challenges faced after
exporting flows
#1. NetFlow Analyzer shows "No Data Available" in graphs, even after I've
configured flows.
Solution: Two possibilities
1. The device is not configured
correctly for exporting flows.
2. A firewall or access list is blocking
the UDP port.
• Check if flows are received with the
help of Wireshark.
• Yes- Check for windows firewall/IP
tables for any restrictions and template
timeout to 60 seconds.
• No- Correct the configuration by setting
the active timeout to 60 seconds.
#2. I've added five interfaces. Why is one of my interfaces, "Interface Gi0/1," not
listed in NetFlow Analyzer?
Solution:
The particular interface isn't configured
for exporting flows.
• Interface is not configured correctly.
• Check for correct interface along with
its export configurations.
Step 2: Visibility into real-time traffic details
Inventory
Flow analysis
Config management
IP SLA
Packet analysis
Traffic overview Real-time traffic graphs
Inventory: Flow Analysis
Traffic overview
Device
Device groups
Lay 4 & 7 applications DSCP-based QoS
Wireless LAN controllers
Interface
IP / interface group
Attacks
Know the who, when and what of
your network traffic.
- Applications
- Protocols
- QoS
- Source
- Destination
- Conversation
Gain detailed visibility
into traffic usage by
Visibility into Layer 7 application traffic
• Gain visibility into NBAR2 applications with Cisco AVC
monitoring (Application Visibility and Control).
• Advanced NBAR is used to identify web traffic, URL’s, file sharing
and random port application.
• View NBAR2 application, URL hit count (HTTP host report), QoS
class hierarchy and application response time monitoring
reports(ART monitoring).
Understand traffic for current QoS policies
Check the traffic usage by each DSCP value for policy
effectiveness.
Manage traffic usage by WLAN controllers
• Monitor Cisco WLAN controllers
and Meraki devices.
• Find the top traffic usage by access
points, SSIDs, applications, clients
etc.
• Troubleshoot a bandwidth spikes
by identifying consumption by
SSIDs, finding its top clients and
complete conversation details for
the selected time period.
Snapshot summary
Device traffic details:
• Traffic speed
• Associated interfaces by speed, volume
and utilization
• Top applications and protocols
• Top QoS
• Top Source, destination and
conversation
• AS traffic
Group traffic details:
• Traffic by speed, volume, utilization
and packets
• Associated applications and protocols
• DSCP QoS traffic
• Source, destination and conversation
Application traffic details:
• Traffic usage by volume
• Associated interfaces
QoS traffic details:
• Traffic usage by volume
• Associated interfaces
WLC traffic details:
• Controller traffic by speed, volume and
packets
• Associated access points
• Application traffic
• DSCP QoS traffic
• Conversation details with Client IPs and
SSIDs
Interface traffic details:
• Traffic by speed, volume, utilization and
packets
• Top applications and protocols
• Top Source, destination and
conversation by geo-location, network
and DNS name
• Top QoS traffic by DSCP and TOS
• SNMP/FNF NBAR, CBQoS
• Multicast report
• Medianet by volume, RTT, packet loss
• AVC
• Identify junk/unusual traffic that disrupts your critical services.
• Using advanced mining algorithm, ASAM detects internal and
external security threats.
• ASAM classifies traffic as suspect flows, bad source and
destination, DDoS, and scans/probes.
Detect attacks with flow-based advanced security
analytics module
Tips to enhance visibility into your
traffic
My interfaces are named "IfIndex1" and "IfIndex2." How can I view the actual
name of devices and interfaces?
Solution: Three options
• Fetch name from router with SNMP
1. Create SNMP credential
v1/v2/v2 from discovery
2. Associate SNMP credentials
3. Edit device
• Fetch the DNS name.
• Enter your own name.
My interface utilization says it's above 100 percent. How do I set the correct
value?
Solution: Three possibilities
1. The speed is incorrect.
2. [OR] time sync problem.
3. [OR] GRE/ESP tunneling through
the device is double counted
• Set the proper IN and OUT speed in
bytes. Go to Inventory > Select
Interfaces > Set Speed.
• Make sure the device time and NFA
time is in sync
• Check flow filters
Most of the applications are listed as "_App". How do I map those applications
and also add my own applications?
Solution:
Application mapping for _App
• Interface >Application > _App >
Show port.
• Map application and define IP
address/ IP network/ IP range.
Application mapping for own apps
• Settings> netflow> mapping > add
Is there a way to view cumulative traffic?
Branches
VLANRelated appsNetwork subnet
Department
Traffic grouping
Sort traffic usage by groups
Types of groups
Device
Interface
IP
Application
DSCP
Benefits of creating groups:
• Monitor combined bandwidth usage to get
better picture of traffic consumption.
• Provide access to operators based on
groups.
• Provide better visibility to improve
troubleshooting.
Scenarios: Creating groups
How do I check traffic usage by different branches?
Solution
Create a device grouping for
different branches.
• Combine devices under a branch
to create groups.
• Generate group reports.
How do I monitor combined traffic for VLAN?
Solution
An un-routed VLAN will not send traffic like an
interface, but NetFlow Analyzer will discover
its associated interfaces.
• Create an Interface Group that
includes all of the VLAN's
interfaces to monitor the
cumulative traffic.
• Other option: failover, load
balancing, port channeling, and
aggregation.
How do I manage each of my customers' traffic ?
Solution
Create IP groups for each customer.
• Combine IPs to create groups.
• Generate group reports.
• Group based on IP range, network,
monitoring between sites.
• Other option: between sites and
department
How do I view business critical traffic and see how much bandwidth is used?
Solution
Create application groups.
• Combine apps to create a group.
• Find total utilization for each group.
• Pull combined traffic reports.
Simplified and customizable Inventory
Edit configurationCustom filters/sort
Custom views Quick search
Filter up to the last 30 days Create device group
Create device/interface/app
group
Inventory search
Set speed Set SNMP Zoom in graphs Generate instant reports
New in v12
Unmanage/delete device
Add to Network
Configuration Manager
Table/list/status viewConfigure NBAR & CBQoS
Service policy & ACL Clear alarm/add note
Various device-specific custom options
New in v12
Step 3: Alerting
Link down Link overutilized
Threshold violation Link slow
Alert Profiles
Preconfigured alerts:
• Link down
• No flow
Threshold based alerts
• IP range, IP address or IP network
• Based on port/protocol range
• Based on application
• Based on DSCP
I want to get alerted when the interface is over utilized in a WAN link?
Solution
• Set a threshold alert for overutilized
links.
• Provide a threshold value.
• Set up email/SMS notifications.
Thresholds based on multiple conditions
Select source Select criteria Define threshold Save alert profile
Alerts specific to below violation:
• Utilization
• Volume
• Speed
• Packets
Alert severity levels:
• Critical
• Trouble
• Attention
How do I set up notifications?
Types of notifications:
• Email
• SMS
• Trigger SNMP trap
• Modify an alarm's description.
• Get reports via email. New in v12
Step 1: Configure mail server settings.
Step 2: Set threshold.
Step 3: Provide an email address or phone number.
Step 4: Save alert.
Summary
Set up flow export
#1. Data not available
#2. Interfaces not listed
Viewing & customizing
bandwidth graphs
#1. Fetch device/interface name
#2. Utilization above 100%
#3. Map unknown applications
#4. Show DNS name
#5. Categorize traffic groups
#6. Customize time filter
Configuring alerts
#1. Set interface overutilized
alert
#2. Link down
Step1 Step 2 Step 3
Upcoming training on March 20th
Part II: Diagnosing and troubleshooting traffic issues
faster
• Alarms
• Customizing data storage
• Troubleshooting with forensics
• Reporting and automation
• Capacity planning
• Traffic shaping
• Customizing dashboards
• Usage-based billing
Need more help?
youtube.com/netflowanalyzertechvideos
help.netflowanalyzer.com
forums.manageengine.com/netflowanalyzer
netflowanalyzer-support@manageengine.com
+1 (888) 720-9500 / +1 (408) 916 - 9400
Thank you!
netflowanalyzer-support@manageengine.com

More Related Content

What's hot

Monitoring network performance- Part 3_Free OpManager training
Monitoring network performance- Part 3_Free OpManager training Monitoring network performance- Part 3_Free OpManager training
Monitoring network performance- Part 3_Free OpManager training
ManageEngine, Zoho Corporation
 
Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3
ManageEngine, Zoho Corporation
 
Free OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automationFree OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automation
ManageEngine, Zoho Corporation
 
Free OpManager training Part 2 Monitoring Server Performance- season#3
Free OpManager training Part 2 Monitoring Server Performance- season#3Free OpManager training Part 2 Monitoring Server Performance- season#3
Free OpManager training Part 2 Monitoring Server Performance- season#3
ManageEngine, Zoho Corporation
 
OpManager Major Features
OpManager Major FeaturesOpManager Major Features
OpManager Major Features
tecanody
 
OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.
ManageEngine, Zoho Corporation
 
Monitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerMonitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManager
ManageEngine
 
New OpManager v12
New OpManager v12New OpManager v12
New OpManager v12
Inuit AB
 
Configlets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration ManagerConfiglets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration Manager
ManageEngine, Zoho Corporation
 
Proof of Concept Guide for ManageEngine OpManager
Proof of Concept Guide for ManageEngine OpManagerProof of Concept Guide for ManageEngine OpManager
Proof of Concept Guide for ManageEngine OpManager
ManageEngine, Zoho Corporation
 
Network fault management and IT automation training
Network fault management and IT automation trainingNetwork fault management and IT automation training
Network fault management and IT automation training
ManageEngine, Zoho Corporation
 
Best Network Performance Monitoring Tool
Best Network Performance Monitoring ToolBest Network Performance Monitoring Tool
Best Network Performance Monitoring Tool
Joe Shestak
 
Free training on NCM - Discovery & Disaster recovery
Free training on NCM - Discovery & Disaster recovery Free training on NCM - Discovery & Disaster recovery
Free training on NCM - Discovery & Disaster recovery
ManageEngine, Zoho Corporation
 
Network and server performance monitoring training
Network and server performance monitoring trainingNetwork and server performance monitoring training
Network and server performance monitoring training
ManageEngine, Zoho Corporation
 
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
ManageEngine, Zoho Corporation
 
Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)
ManageEngine, Zoho Corporation
 
Opmanager technical overview
Opmanager technical overviewOpmanager technical overview
Opmanager technical overview
ManageEngine, Zoho Corporation
 
Dashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centreDashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centre
ManageEngine, Zoho Corporation
 
Network Monitoring Basics
Network Monitoring BasicsNetwork Monitoring Basics
Network Monitoring Basics
Rob Dunn
 
[Season - 3 Free OpManager Training] Monitoring Server Performance
[Season - 3 Free OpManager Training] Monitoring Server Performance[Season - 3 Free OpManager Training] Monitoring Server Performance
[Season - 3 Free OpManager Training] Monitoring Server Performance
ManageEngine, Zoho Corporation
 

What's hot (20)

Monitoring network performance- Part 3_Free OpManager training
Monitoring network performance- Part 3_Free OpManager training Monitoring network performance- Part 3_Free OpManager training
Monitoring network performance- Part 3_Free OpManager training
 
Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3Free OpManager training Part1- Discovery and classification season#3
Free OpManager training Part1- Discovery and classification season#3
 
Free OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automationFree OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automation
 
Free OpManager training Part 2 Monitoring Server Performance- season#3
Free OpManager training Part 2 Monitoring Server Performance- season#3Free OpManager training Part 2 Monitoring Server Performance- season#3
Free OpManager training Part 2 Monitoring Server Performance- season#3
 
OpManager Major Features
OpManager Major FeaturesOpManager Major Features
OpManager Major Features
 
OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.
 
Monitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerMonitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManager
 
New OpManager v12
New OpManager v12New OpManager v12
New OpManager v12
 
Configlets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration ManagerConfiglets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration Manager
 
Proof of Concept Guide for ManageEngine OpManager
Proof of Concept Guide for ManageEngine OpManagerProof of Concept Guide for ManageEngine OpManager
Proof of Concept Guide for ManageEngine OpManager
 
Network fault management and IT automation training
Network fault management and IT automation trainingNetwork fault management and IT automation training
Network fault management and IT automation training
 
Best Network Performance Monitoring Tool
Best Network Performance Monitoring ToolBest Network Performance Monitoring Tool
Best Network Performance Monitoring Tool
 
Free training on NCM - Discovery & Disaster recovery
Free training on NCM - Discovery & Disaster recovery Free training on NCM - Discovery & Disaster recovery
Free training on NCM - Discovery & Disaster recovery
 
Network and server performance monitoring training
Network and server performance monitoring trainingNetwork and server performance monitoring training
Network and server performance monitoring training
 
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
 
Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)
 
Opmanager technical overview
Opmanager technical overviewOpmanager technical overview
Opmanager technical overview
 
Dashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centreDashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centre
 
Network Monitoring Basics
Network Monitoring BasicsNetwork Monitoring Basics
Network Monitoring Basics
 
[Season - 3 Free OpManager Training] Monitoring Server Performance
[Season - 3 Free OpManager Training] Monitoring Server Performance[Season - 3 Free OpManager Training] Monitoring Server Performance
[Season - 3 Free OpManager Training] Monitoring Server Performance
 

Similar to Export flows, group traffic, map application traffic and more: NetFlow Analyzer Training

NetFlow Analyzer Training Part I: Getting the initial settings right
NetFlow Analyzer Training Part I: Getting the initial settings rightNetFlow Analyzer Training Part I: Getting the initial settings right
NetFlow Analyzer Training Part I: Getting the initial settings right
ManageEngine, Zoho Corporation
 
Network Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai SeminarNetwork Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai Seminar
ManageEngine, Zoho Corporation
 
NFA - Middle East Workshop
NFA - Middle East WorkshopNFA - Middle East Workshop
NFA - Middle East Workshop
ManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
ManageEngine, Zoho Corporation
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshooting
ManageEngine, Zoho Corporation
 
Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.
ManageEngine, Zoho Corporation
 
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
ManageEngine, Zoho Corporation
 
Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An Insight
Sai Sundhar Padmanabhan
 
The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines
Netronome
 
Cloud Migration
Cloud MigrationCloud Migration
Cloud Migration
Jolyne Marie
 
1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt
Farid Er
 
KKBOX WWDC17 Security - Antony
KKBOX WWDC17 Security - AntonyKKBOX WWDC17 Security - Antony
KKBOX WWDC17 Security - Antony
Liyao Chen
 
ahmed eltokhy netflownetflownetflow.pptx
ahmed eltokhy netflownetflownetflow.pptxahmed eltokhy netflownetflownetflow.pptx
ahmed eltokhy netflownetflownetflow.pptx
FutureTechnologies3
 
INT_Ch17.pptx
INT_Ch17.pptxINT_Ch17.pptx
INT_Ch17.pptx
NguyenLong773850
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
Aruba, a Hewlett Packard Enterprise company
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.ppt
AssadLeo1
 
ONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINA
Junho Suh
 
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PROIDEA
 
NETFLOW ANALYZER 9600 - AN OVERVIEW
NETFLOW ANALYZER 9600 - AN OVERVIEWNETFLOW ANALYZER 9600 - AN OVERVIEW
NETFLOW ANALYZER 9600 - AN OVERVIEW
NetFlow Analyzer
 
NUVX Technologies general solutions
NUVX Technologies general solutionsNUVX Technologies general solutions
NUVX Technologies general solutions
NUVX
 

Similar to Export flows, group traffic, map application traffic and more: NetFlow Analyzer Training (20)

NetFlow Analyzer Training Part I: Getting the initial settings right
NetFlow Analyzer Training Part I: Getting the initial settings rightNetFlow Analyzer Training Part I: Getting the initial settings right
NetFlow Analyzer Training Part I: Getting the initial settings right
 
Network Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai SeminarNetwork Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai Seminar
 
NFA - Middle East Workshop
NFA - Middle East WorkshopNFA - Middle East Workshop
NFA - Middle East Workshop
 
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshooting
 
Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.
 
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
 
Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An Insight
 
The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines
 
Cloud Migration
Cloud MigrationCloud Migration
Cloud Migration
 
1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt
 
KKBOX WWDC17 Security - Antony
KKBOX WWDC17 Security - AntonyKKBOX WWDC17 Security - Antony
KKBOX WWDC17 Security - Antony
 
ahmed eltokhy netflownetflownetflow.pptx
ahmed eltokhy netflownetflownetflow.pptxahmed eltokhy netflownetflownetflow.pptx
ahmed eltokhy netflownetflownetflow.pptx
 
INT_Ch17.pptx
INT_Ch17.pptxINT_Ch17.pptx
INT_Ch17.pptx
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.ppt
 
ONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINA
 
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
 
NETFLOW ANALYZER 9600 - AN OVERVIEW
NETFLOW ANALYZER 9600 - AN OVERVIEWNETFLOW ANALYZER 9600 - AN OVERVIEW
NETFLOW ANALYZER 9600 - AN OVERVIEW
 
NUVX Technologies general solutions
NUVX Technologies general solutionsNUVX Technologies general solutions
NUVX Technologies general solutions
 

More from ManageEngine, Zoho Corporation

Create seamless customer experiences
Create seamless customer experiencesCreate seamless customer experiences
Create seamless customer experiences
ManageEngine, Zoho Corporation
 
From web interface to database: Monitor what matters
From web interface to database: Monitor what mattersFrom web interface to database: Monitor what matters
From web interface to database: Monitor what matters
ManageEngine, Zoho Corporation
 
NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020
ManageEngine, Zoho Corporation
 
Overcome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesOvercome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challenges
ManageEngine, Zoho Corporation
 
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringModernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoring
ManageEngine, Zoho Corporation
 
Deliver seamless digital experience
Deliver seamless digital experienceDeliver seamless digital experience
Deliver seamless digital experience
ManageEngine, Zoho Corporation
 
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
ManageEngine, Zoho Corporation
 
From web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersFrom web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that matters
ManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
ManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
ManageEngine, Zoho Corporation
 
NetFlow Analyzer Product Overview
NetFlow Analyzer Product OverviewNetFlow Analyzer Product Overview
NetFlow Analyzer Product Overview
ManageEngine, Zoho Corporation
 
Monitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureMonitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructure
ManageEngine, Zoho Corporation
 
Building the right website monitoring strategy
Building the right website monitoring strategyBuilding the right website monitoring strategy
Building the right website monitoring strategy
ManageEngine, Zoho Corporation
 
Unlock the value of your big data infrastructure
Unlock the value of your big data infrastructureUnlock the value of your big data infrastructure
Unlock the value of your big data infrastructure
ManageEngine, Zoho Corporation
 
Key to optimal end user experience
Key to optimal end user experienceKey to optimal end user experience
Key to optimal end user experience
ManageEngine, Zoho Corporation
 
Monitoring cloud applications and containers
Monitoring cloud applications and containersMonitoring cloud applications and containers
Monitoring cloud applications and containers
ManageEngine, Zoho Corporation
 
implementing the right website monitoring strategy
 implementing the right website monitoring strategy implementing the right website monitoring strategy
implementing the right website monitoring strategy
ManageEngine, Zoho Corporation
 
Big data and non relational database
Big data and non relational databaseBig data and non relational database
Big data and non relational database
ManageEngine, Zoho Corporation
 
Visibility-from web application interface to the database
Visibility-from web application interface to the databaseVisibility-from web application interface to the database
Visibility-from web application interface to the database
ManageEngine, Zoho Corporation
 
OpUtils Free training
OpUtils Free training OpUtils Free training
OpUtils Free training
ManageEngine, Zoho Corporation
 

More from ManageEngine, Zoho Corporation (20)

Create seamless customer experiences
Create seamless customer experiencesCreate seamless customer experiences
Create seamless customer experiences
 
From web interface to database: Monitor what matters
From web interface to database: Monitor what mattersFrom web interface to database: Monitor what matters
From web interface to database: Monitor what matters
 
NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020
 
Overcome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesOvercome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challenges
 
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringModernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoring
 
Deliver seamless digital experience
Deliver seamless digital experienceDeliver seamless digital experience
Deliver seamless digital experience
 
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
 
From web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersFrom web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that matters
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
 
NetFlow Analyzer Product Overview
NetFlow Analyzer Product OverviewNetFlow Analyzer Product Overview
NetFlow Analyzer Product Overview
 
Monitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureMonitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructure
 
Building the right website monitoring strategy
Building the right website monitoring strategyBuilding the right website monitoring strategy
Building the right website monitoring strategy
 
Unlock the value of your big data infrastructure
Unlock the value of your big data infrastructureUnlock the value of your big data infrastructure
Unlock the value of your big data infrastructure
 
Key to optimal end user experience
Key to optimal end user experienceKey to optimal end user experience
Key to optimal end user experience
 
Monitoring cloud applications and containers
Monitoring cloud applications and containersMonitoring cloud applications and containers
Monitoring cloud applications and containers
 
implementing the right website monitoring strategy
 implementing the right website monitoring strategy implementing the right website monitoring strategy
implementing the right website monitoring strategy
 
Big data and non relational database
Big data and non relational databaseBig data and non relational database
Big data and non relational database
 
Visibility-from web application interface to the database
Visibility-from web application interface to the databaseVisibility-from web application interface to the database
Visibility-from web application interface to the database
 
OpUtils Free training
OpUtils Free training OpUtils Free training
OpUtils Free training
 

Recently uploaded

GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
Green Software Development
 
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling ExtensionsUI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
Peter Muessig
 
316895207-SAP-Oil-and-Gas-Downstream-Training.pptx
316895207-SAP-Oil-and-Gas-Downstream-Training.pptx316895207-SAP-Oil-and-Gas-Downstream-Training.pptx
316895207-SAP-Oil-and-Gas-Downstream-Training.pptx
ssuserad3af4
 
socradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdfsocradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdf
SOCRadar
 
Oracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptxOracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptx
Remote DBA Services
 
Using Query Store in Azure PostgreSQL to Understand Query Performance
Using Query Store in Azure PostgreSQL to Understand Query PerformanceUsing Query Store in Azure PostgreSQL to Understand Query Performance
Using Query Store in Azure PostgreSQL to Understand Query Performance
Grant Fritchey
 
Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...
Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...
Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...
XfilesPro
 
Webinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for EmbeddedWebinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for Embedded
ICS
 
KuberTENes Birthday Bash Guadalajara - Introducción a Argo CD
KuberTENes Birthday Bash Guadalajara - Introducción a Argo CDKuberTENes Birthday Bash Guadalajara - Introducción a Argo CD
KuberTENes Birthday Bash Guadalajara - Introducción a Argo CD
rodomar2
 
Lecture 2 - software testing SE 412.pptx
Lecture 2 - software testing SE 412.pptxLecture 2 - software testing SE 412.pptx
Lecture 2 - software testing SE 412.pptx
TaghreedAltamimi
 
Artificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension FunctionsArtificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension Functions
Octavian Nadolu
 
Modelling Up - DDDEurope 2024 - Amsterdam
Modelling Up - DDDEurope 2024 - AmsterdamModelling Up - DDDEurope 2024 - Amsterdam
Modelling Up - DDDEurope 2024 - Amsterdam
Alberto Brandolini
 
Measures in SQL (SIGMOD 2024, Santiago, Chile)
Measures in SQL (SIGMOD 2024, Santiago, Chile)Measures in SQL (SIGMOD 2024, Santiago, Chile)
Measures in SQL (SIGMOD 2024, Santiago, Chile)
Julian Hyde
 
All you need to know about Spring Boot and GraalVM
All you need to know about Spring Boot and GraalVMAll you need to know about Spring Boot and GraalVM
All you need to know about Spring Boot and GraalVM
Alina Yurenko
 
Top Benefits of Using Salesforce Healthcare CRM for Patient Management.pdf
Top Benefits of Using Salesforce Healthcare CRM for Patient Management.pdfTop Benefits of Using Salesforce Healthcare CRM for Patient Management.pdf
Top Benefits of Using Salesforce Healthcare CRM for Patient Management.pdf
VALiNTRY360
 
How Can Hiring A Mobile App Development Company Help Your Business Grow?
How Can Hiring A Mobile App Development Company Help Your Business Grow?How Can Hiring A Mobile App Development Company Help Your Business Grow?
How Can Hiring A Mobile App Development Company Help Your Business Grow?
ToXSL Technologies
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
Łukasz Chruściel
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
Drona Infotech
 
zOS Mainframe JES2-JES3 JCL-JECL Differences
zOS Mainframe JES2-JES3 JCL-JECL DifferenceszOS Mainframe JES2-JES3 JCL-JECL Differences
zOS Mainframe JES2-JES3 JCL-JECL Differences
YousufSait3
 
Hand Rolled Applicative User Validation Code Kata
Hand Rolled Applicative User ValidationCode KataHand Rolled Applicative User ValidationCode Kata
Hand Rolled Applicative User Validation Code Kata
Philip Schwarz
 

Recently uploaded (20)

GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
 
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling ExtensionsUI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
 
316895207-SAP-Oil-and-Gas-Downstream-Training.pptx
316895207-SAP-Oil-and-Gas-Downstream-Training.pptx316895207-SAP-Oil-and-Gas-Downstream-Training.pptx
316895207-SAP-Oil-and-Gas-Downstream-Training.pptx
 
socradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdfsocradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdf
 
Oracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptxOracle Database 19c New Features for DBAs and Developers.pptx
Oracle Database 19c New Features for DBAs and Developers.pptx
 
Using Query Store in Azure PostgreSQL to Understand Query Performance
Using Query Store in Azure PostgreSQL to Understand Query PerformanceUsing Query Store in Azure PostgreSQL to Understand Query Performance
Using Query Store in Azure PostgreSQL to Understand Query Performance
 
Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...
Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...
Everything You Need to Know About X-Sign: The eSign Functionality of XfilesPr...
 
Webinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for EmbeddedWebinar On-Demand: Using Flutter for Embedded
Webinar On-Demand: Using Flutter for Embedded
 
KuberTENes Birthday Bash Guadalajara - Introducción a Argo CD
KuberTENes Birthday Bash Guadalajara - Introducción a Argo CDKuberTENes Birthday Bash Guadalajara - Introducción a Argo CD
KuberTENes Birthday Bash Guadalajara - Introducción a Argo CD
 
Lecture 2 - software testing SE 412.pptx
Lecture 2 - software testing SE 412.pptxLecture 2 - software testing SE 412.pptx
Lecture 2 - software testing SE 412.pptx
 
Artificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension FunctionsArtificia Intellicence and XPath Extension Functions
Artificia Intellicence and XPath Extension Functions
 
Modelling Up - DDDEurope 2024 - Amsterdam
Modelling Up - DDDEurope 2024 - AmsterdamModelling Up - DDDEurope 2024 - Amsterdam
Modelling Up - DDDEurope 2024 - Amsterdam
 
Measures in SQL (SIGMOD 2024, Santiago, Chile)
Measures in SQL (SIGMOD 2024, Santiago, Chile)Measures in SQL (SIGMOD 2024, Santiago, Chile)
Measures in SQL (SIGMOD 2024, Santiago, Chile)
 
All you need to know about Spring Boot and GraalVM
All you need to know about Spring Boot and GraalVMAll you need to know about Spring Boot and GraalVM
All you need to know about Spring Boot and GraalVM
 
Top Benefits of Using Salesforce Healthcare CRM for Patient Management.pdf
Top Benefits of Using Salesforce Healthcare CRM for Patient Management.pdfTop Benefits of Using Salesforce Healthcare CRM for Patient Management.pdf
Top Benefits of Using Salesforce Healthcare CRM for Patient Management.pdf
 
How Can Hiring A Mobile App Development Company Help Your Business Grow?
How Can Hiring A Mobile App Development Company Help Your Business Grow?How Can Hiring A Mobile App Development Company Help Your Business Grow?
How Can Hiring A Mobile App Development Company Help Your Business Grow?
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
 
zOS Mainframe JES2-JES3 JCL-JECL Differences
zOS Mainframe JES2-JES3 JCL-JECL DifferenceszOS Mainframe JES2-JES3 JCL-JECL Differences
zOS Mainframe JES2-JES3 JCL-JECL Differences
 
Hand Rolled Applicative User Validation Code Kata
Hand Rolled Applicative User ValidationCode KataHand Rolled Applicative User ValidationCode Kata
Hand Rolled Applicative User Validation Code Kata
 

Export flows, group traffic, map application traffic and more: NetFlow Analyzer Training

  • 1. Free training on NetFlow Analyzer - Part I Getting the initial settings right
  • 2.
  • 3. Agenda • Exporting flows • Traffic grouping • Application mapping • Threshold based alerting • In-depth traffic visibility • Knowledge base and best practices
  • 4. Demo on NetFlow Analyzer 123083
  • 5. Minimum system requirements 2.4 GHz quad-core processor, or equivalent 4GB RAM 50GB storage Windows/LinuxPostgreSQL/MSSQL These specifications only apply when raw data is turned off and the flow rate is below 3,000 flows/sec. Requirements will vary with different settings.
  • 6. Initial setup Set up flow export Viewing & customizing real-time traffic graphs Configuring alerts Step1 Step 2 Step 3
  • 7. Step 1: Configuring flow export from interfaces NetFlow sFlow J-Flow IP FIX NetStream AppFlow
  • 8. Devices supported by NetFlow Analyzer https://www.manageengine.com/products/netflow/supported-devices.html
  • 9. Where and how do you send flows? Ways of exporting flows to NetFlow Analyzer: i. Manual configuration ii. Using Network Configuration Manager Ports to be considered: • Server port: NetFlow Analyzer's web server port • Listener port: Port on which NetFlow Analyzer receives flows • Both ports are configurable
  • 10. Using Network Configuration Manager Benefits of using Network Configuration Manager: • No need to write commands • Predefined configlets • Export flows from multiple interfaces in bulk • Backup and restore configurations for devices • Create new configlets Apply credentials Select interfaces Export flow Add devices
  • 11. Creating/modifying a configlet • In Network Configuration Manager, go to Settings > Configlets. Add a new configlet by creating a custom template. • Select devices and enter flow configuration commands. • Execute the new configlet.
  • 12. Common challenges faced after exporting flows
  • 13. #1. NetFlow Analyzer shows "No Data Available" in graphs, even after I've configured flows. Solution: Two possibilities 1. The device is not configured correctly for exporting flows. 2. A firewall or access list is blocking the UDP port. • Check if flows are received with the help of Wireshark. • Yes- Check for windows firewall/IP tables for any restrictions and template timeout to 60 seconds. • No- Correct the configuration by setting the active timeout to 60 seconds.
  • 14. #2. I've added five interfaces. Why is one of my interfaces, "Interface Gi0/1," not listed in NetFlow Analyzer? Solution: The particular interface isn't configured for exporting flows. • Interface is not configured correctly. • Check for correct interface along with its export configurations.
  • 15. Step 2: Visibility into real-time traffic details Inventory Flow analysis Config management IP SLA Packet analysis Traffic overview Real-time traffic graphs
  • 16. Inventory: Flow Analysis Traffic overview Device Device groups Lay 4 & 7 applications DSCP-based QoS Wireless LAN controllers Interface IP / interface group Attacks
  • 17. Know the who, when and what of your network traffic. - Applications - Protocols - QoS - Source - Destination - Conversation Gain detailed visibility into traffic usage by
  • 18. Visibility into Layer 7 application traffic • Gain visibility into NBAR2 applications with Cisco AVC monitoring (Application Visibility and Control). • Advanced NBAR is used to identify web traffic, URL’s, file sharing and random port application. • View NBAR2 application, URL hit count (HTTP host report), QoS class hierarchy and application response time monitoring reports(ART monitoring).
  • 19. Understand traffic for current QoS policies Check the traffic usage by each DSCP value for policy effectiveness.
  • 20. Manage traffic usage by WLAN controllers • Monitor Cisco WLAN controllers and Meraki devices. • Find the top traffic usage by access points, SSIDs, applications, clients etc. • Troubleshoot a bandwidth spikes by identifying consumption by SSIDs, finding its top clients and complete conversation details for the selected time period.
  • 21. Snapshot summary Device traffic details: • Traffic speed • Associated interfaces by speed, volume and utilization • Top applications and protocols • Top QoS • Top Source, destination and conversation • AS traffic Group traffic details: • Traffic by speed, volume, utilization and packets • Associated applications and protocols • DSCP QoS traffic • Source, destination and conversation Application traffic details: • Traffic usage by volume • Associated interfaces QoS traffic details: • Traffic usage by volume • Associated interfaces WLC traffic details: • Controller traffic by speed, volume and packets • Associated access points • Application traffic • DSCP QoS traffic • Conversation details with Client IPs and SSIDs Interface traffic details: • Traffic by speed, volume, utilization and packets • Top applications and protocols • Top Source, destination and conversation by geo-location, network and DNS name • Top QoS traffic by DSCP and TOS • SNMP/FNF NBAR, CBQoS • Multicast report • Medianet by volume, RTT, packet loss • AVC
  • 22. • Identify junk/unusual traffic that disrupts your critical services. • Using advanced mining algorithm, ASAM detects internal and external security threats. • ASAM classifies traffic as suspect flows, bad source and destination, DDoS, and scans/probes. Detect attacks with flow-based advanced security analytics module
  • 23. Tips to enhance visibility into your traffic
  • 24. My interfaces are named "IfIndex1" and "IfIndex2." How can I view the actual name of devices and interfaces? Solution: Three options • Fetch name from router with SNMP 1. Create SNMP credential v1/v2/v2 from discovery 2. Associate SNMP credentials 3. Edit device • Fetch the DNS name. • Enter your own name.
  • 25. My interface utilization says it's above 100 percent. How do I set the correct value? Solution: Three possibilities 1. The speed is incorrect. 2. [OR] time sync problem. 3. [OR] GRE/ESP tunneling through the device is double counted • Set the proper IN and OUT speed in bytes. Go to Inventory > Select Interfaces > Set Speed. • Make sure the device time and NFA time is in sync • Check flow filters
  • 26. Most of the applications are listed as "_App". How do I map those applications and also add my own applications? Solution: Application mapping for _App • Interface >Application > _App > Show port. • Map application and define IP address/ IP network/ IP range. Application mapping for own apps • Settings> netflow> mapping > add
  • 27. Is there a way to view cumulative traffic? Branches VLANRelated appsNetwork subnet Department Traffic grouping
  • 28. Sort traffic usage by groups Types of groups Device Interface IP Application DSCP Benefits of creating groups: • Monitor combined bandwidth usage to get better picture of traffic consumption. • Provide access to operators based on groups. • Provide better visibility to improve troubleshooting.
  • 30. How do I check traffic usage by different branches? Solution Create a device grouping for different branches. • Combine devices under a branch to create groups. • Generate group reports.
  • 31. How do I monitor combined traffic for VLAN? Solution An un-routed VLAN will not send traffic like an interface, but NetFlow Analyzer will discover its associated interfaces. • Create an Interface Group that includes all of the VLAN's interfaces to monitor the cumulative traffic. • Other option: failover, load balancing, port channeling, and aggregation.
  • 32. How do I manage each of my customers' traffic ? Solution Create IP groups for each customer. • Combine IPs to create groups. • Generate group reports. • Group based on IP range, network, monitoring between sites. • Other option: between sites and department
  • 33. How do I view business critical traffic and see how much bandwidth is used? Solution Create application groups. • Combine apps to create a group. • Find total utilization for each group. • Pull combined traffic reports.
  • 34. Simplified and customizable Inventory Edit configurationCustom filters/sort Custom views Quick search
  • 35. Filter up to the last 30 days Create device group Create device/interface/app group Inventory search Set speed Set SNMP Zoom in graphs Generate instant reports New in v12 Unmanage/delete device Add to Network Configuration Manager Table/list/status viewConfigure NBAR & CBQoS Service policy & ACL Clear alarm/add note Various device-specific custom options New in v12
  • 36. Step 3: Alerting Link down Link overutilized Threshold violation Link slow
  • 37. Alert Profiles Preconfigured alerts: • Link down • No flow Threshold based alerts • IP range, IP address or IP network • Based on port/protocol range • Based on application • Based on DSCP
  • 38. I want to get alerted when the interface is over utilized in a WAN link? Solution • Set a threshold alert for overutilized links. • Provide a threshold value. • Set up email/SMS notifications.
  • 39. Thresholds based on multiple conditions Select source Select criteria Define threshold Save alert profile Alerts specific to below violation: • Utilization • Volume • Speed • Packets Alert severity levels: • Critical • Trouble • Attention
  • 40. How do I set up notifications? Types of notifications: • Email • SMS • Trigger SNMP trap • Modify an alarm's description. • Get reports via email. New in v12 Step 1: Configure mail server settings. Step 2: Set threshold. Step 3: Provide an email address or phone number. Step 4: Save alert.
  • 41. Summary Set up flow export #1. Data not available #2. Interfaces not listed Viewing & customizing bandwidth graphs #1. Fetch device/interface name #2. Utilization above 100% #3. Map unknown applications #4. Show DNS name #5. Categorize traffic groups #6. Customize time filter Configuring alerts #1. Set interface overutilized alert #2. Link down Step1 Step 2 Step 3
  • 42. Upcoming training on March 20th Part II: Diagnosing and troubleshooting traffic issues faster • Alarms • Customizing data storage • Troubleshooting with forensics • Reporting and automation • Capacity planning • Traffic shaping • Customizing dashboards • Usage-based billing