SlideShare a Scribd company logo
NetFlow Analyzer - Part I
Getting the initial settings right
Welcome to a free training on
NetFlow Analyzer!
Trainer
Piyushree
NetFlow Analyzer product expert
Agenda
• Exporting flows
• Traffic grouping
• Application mapping
• Threshold based alerting
• In-depth traffic visibility
• Knowledge base and best practices
NetFlow Analyzer demo build 123086
Minimum system requirements
2.4 GHz quad-core
processor, or
equivalent
4GB RAM 50GB storage Windows/LinuxPostgreSQL/MSSQL
These specifications only apply when raw data is turned off and the flow rate is below 3,000
flows/sec. Requirements will vary with different settings.
Initial setup
Set up flow export Viewing & customizing
real-time traffic graphs
Configuring alerts
Step1 Step 2 Step 3
Step 1: Configuring flow export from interfaces
NetFlow sFlow J-Flow
IP FIX NetStream AppFlow
Devices supported by NetFlow Analyzer
https://www.manageengine.com/products/netflow/supported-devices.html
Where and how do you send flows?
Ways of exporting flows to NetFlow
Analyzer:
i. Manual configuration
ii. Using Network Configuration Manager
Ports to be considered:
• Server port: NetFlow Analyzer's web server port
• Listener port: Port on which NetFlow Analyzer
receives flows
• Both ports are configurable
Using Network Configuration Manager add-on
Benefits of using Network Configuration Manager:
• No need to write commands
• Predefined configlets
• Export flows from multiple interfaces in bulk
• Backup and restore configurations for devices
• Create new configlets
Apply
credentials
Select
interfaces
Export
flow
Add
devices
Creating/modifying a configlet
• In Network Configuration Manager, go to
Settings > Configlets. Add a new configlet
by creating a custom template.
• Select devices and enter flow
configuration commands.
• Execute the new configlet.
https://download.manageengine.com/prod
ucts/netflow/Help-doc-for-flow-export.pdf
Help guide on steps to configure flows :
Common problems faced after
exporting flows
#1. NetFlow Analyzer shows "No Data Available" in graphs, even after I've
configured flows.
Solution: Two possibilities
1. The device is not configured
correctly for exporting flows.
2. A firewall or access list is blocking
the UDP port.
• Check if flows are received with the
help of Wireshark.
• Yes- Check for windows firewall/IP
tables for any restrictions and template
timeout to 60 seconds.
• No- Correct the configuration by setting
the active timeout to 60 seconds.
#2. I've added five interfaces. Why is one of my interfaces, "Interface Gi0/1," not
listed in NetFlow Analyzer?
Solution:
The particular interface isn't configured
for exporting flows.
• Interface is not configured correctly.
• Check for correct interface along with
its export configurations.
Step 2: Visibility into real-time traffic details
Inventory
Flow analysis
Config management
IP SLA
Packet analysis
Traffic overview Real-time traffic graphs
Inventory: Flow Analysis
Traffic overview
Device
Device groups
Lay 4 & 7 applications DSCP-based QoS
Wireless LAN controllers
Interface
IP / interface group
Attacks
Know the who, when and what of
your network traffic.
- Applications
- Protocols
- QoS
- Source
- Destination
- Conversation
Gain detailed visibility
into traffic usage by
High utilization in one of your network links?
Snapshot summary
Device traffic details:
• Traffic speed
• Associated interfaces by speed, volume
and utilization
• Top applications and protocols
• Top QoS
• Top Source, destination and
conversation
• AS traffic
Group traffic details:
• Traffic by speed, volume, utilization
and packets
• Associated applications and protocols
• DSCP QoS traffic
• Source, destination and conversation
Application traffic details:
• Traffic usage by volume
• Associated interfaces
QoS traffic details:
• Traffic usage by volume
• Associated interfaces
WLC traffic details:
• Controller traffic by speed, volume and
packets
• Associated access points
• Application traffic
• DSCP QoS traffic
• Conversation details with Client IPs and
SSIDs
Interface traffic details:
• Traffic by speed, volume, utilization and
packets
• Top applications and protocols
• Top Source, destination and
conversation by geo-location, network
and DNS name
• Top QoS traffic by DSCP and TOS
• SNMP/FNF NBAR, CBQoS
• Multicast report
• Medianet by volume, RTT, packet loss
• AVC
Visibility into Layer 7 application traffic
• Gain visibility into NBAR2 applications with Cisco AVC
monitoring (Application Visibility and Control).
• Advanced NBAR is used to identify web traffic, URL’s, file sharing
and random port application.
• View NBAR2 application, URL hit count (HTTP host report), QoS
class hierarchy and application response time monitoring
reports(ART monitoring).
Understand traffic for current QoS policies
Check the traffic usage by each DSCP value for policy
effectiveness.
Manage traffic usage by WLAN controllers
• Monitor Cisco WLAN controllers
and Meraki devices.
• Find the top traffic usage by access
points, SSIDs, applications, clients
etc.
• Troubleshoot a bandwidth spikes
by identifying consumption by
SSIDs, finding its top clients and
complete conversation details for
the selected time period.
• Identify junk/unusual traffic that disrupts your critical services.
• Using advanced mining algorithm, ASAM detects internal and
external security threats.
• ASAM classifies traffic as suspect flows, bad source and
destination, DDoS, and scans/probes.
Detect attacks with flow-based advanced security
analytics module
Tips to enhance visibility into your
traffic
My interfaces are named "IfIndex1" and "IfIndex2." How can I view the actual
name of devices and interfaces?
Solution: Three options
• Fetch name from router with SNMP
1. Create SNMP credential
v1/v2/v2 from discovery
2. Associate SNMP credentials
3. Edit device
• Fetch the DNS name.
• Enter your own name.
My interface utilization says it's above 100 percent. How do I set the correct
value?
Solution: Two possibilities
1. The speed is incorrect.
2. [OR] time sync problem.
• Set the proper IN and OUT speed in
bytes. Go to Inventory > Select
Interfaces > Set Speed.
• Make sure the device time and NFA
time is in sync
• Check flow filters
Most of the applications are listed as "_App". How do I map those applications
and also add my own applications?
Solution:
Application mapping for _App
• Interface >Application > _App >
Show port.
• Map application and define IP
address/ IP network/ IP range.
Application mapping for own apps
• Settings> netflow> mapping > add
Is there a way to view cumulative traffic?
Branches
VLANRelated appsNetwork subnet
Department
Traffic grouping
Sort traffic usage by groups
Types of groups
Device
Interface
IP
Application
DSCP
Benefits of creating groups:
• Monitor combined bandwidth usage to get
better picture of traffic consumption.
• Provide access to operators based on
groups.
• Provide better visibility to improve
troubleshooting.
Scenarios: Creating groups
How do I check traffic usage by different branches?
Solution
Create a device grouping for
different branches.
• Combine devices under a branch
to create groups.
• Generate group reports.
How do I monitor combined traffic for VLAN?
Solution
An un-routed VLAN will not send traffic like an
interface, but NetFlow Analyzer will discover
its associated interfaces.
• Create an Interface Group that
includes all of the VLAN's
interfaces to monitor the
cumulative traffic.
• Other option: failover, load
balancing, port channeling, and
aggregation.
How do I manage each of my customers' traffic ?
Solution
Create IP groups for each customer.
• Combine IPs to create groups.
• Generate group reports.
• Group based on IP range, network,
monitoring between sites.
• Other option: between sites and
department
How do I view business critical traffic and see how much bandwidth is used?
Solution
Create application groups.
• Combine apps to create a group.
• Find total utilization for each group.
• Pull combined traffic reports.
Simplified and customizable Inventory
Edit configurationCustom filters/sort
Custom views Quick search
Filter up to the last 30 days Create device group
Create device/interface/app
group
Inventory search
Set speed Set SNMP Zoom in graphs Generate instant reports
New in v12
Unmanage/delete device
Add to Network
Configuration Manager
Table/list/status viewConfigure NBAR & CBQoS
Service policy & ACL Clear alarm/add note
Various device-specific custom options
New in v12
Step 3: Alerting
Link down Link overutilized
Threshold violation Link slow
Alert Profiles
Preconfigured alerts:
• Link down
• No flow
Threshold based alerts
• IP range, IP address or IP network
• Based on port/protocol range
• Based on application
• Based on DSCP
I want to get alerted when the interface is over utilized in a WAN link?
Solution
• Set a threshold alert for overutilized
links.
• Provide a threshold value.
• Set up email/SMS notifications.
Thresholds based on multiple conditions
Select source Select criteria Define threshold Save alert profile
Alerts specific to below violation:
• Utilization
• Volume
• Speed
• Packets
Alert severity levels:
• Critical
• Trouble
• Attention
How do I set up notifications?
Types of notifications:
• Email
• SMS
• Trigger SNMP trap
• Modify an alarm's description.
• Get reports via email. New in v12
Step 1: Configure mail server settings.
Step 2: Set threshold.
Step 3: Provide an email address or phone number.
Step 4: Save alert.
Summary
Set up flow export
#1. Data not available
#2. Interfaces not listed
Viewing & customizing
bandwidth graphs
#1. Fetch device/interface name
#2. Utilization above 100%
#3. Map unknown applications
#4. Show DNS name
#5. Categorize traffic groups
#6. Customize time filter
Configuring alerts
#1. Set interface overutilized
alert
#2. Link down
Step1 Step 2 Step 3
Recent enhancements in NetFlow Analyzer
• 'Guest' user privilege has been added for NetFlow installation.
• Dashboard loading has been revamped and optimized.
• iPhone/Android and iPad application download links available in login.
• In the Inventory page, product based tabs have been moved horizontally.
• Quick links added for sending support mail, apply license, phone number, SIF,
User guide, Videos, Service pack, ThreadDump, DB Query & view Logs with a
support icon.
• Added an option to export to PDF and mail for individual graph reports.
• SFlow flow format for multiple MPLS can be added now.
• Added an option to configure billing with base cost as zero.
How NetFlow Analyzer scores high over others
• Detailed view of applications and QoS traffic
• Traffic grouping options (total traffic based on interfaces, IPs, apps, QoS and
grouped)
• Site to site total traffic view
• Alarms for IP groups
• Wireless LAN monitoring
• Attacks
• AS view
• and more....
Upcoming training on May 22nd
Part II: Diagnosing and troubleshooting traffic issues
faster
• Alarms
• Customizing data storage
• Troubleshooting with forensics
• Reporting and automation
• Capacity planning
• Traffic shaping
• Customizing dashboards
• Usage-based billing
Need more help?
youtube.com/opmanagertechvideos
help.netflowanalyzer.com
forums.manageengine.com/netflowanalyzer
netflowanalyzer-support@manageengine.com
+1 (888) 720-9500 / +1 (408) 916 - 9400
Thank you!
netflowanalyzer-support@manageengine.com

More Related Content

What's hot

VXLAN and FRRouting
VXLAN and FRRoutingVXLAN and FRRouting
VXLAN and FRRoutingFaisal Reza
 
How to write a Neutron Plugin - if you really need to
How to write a Neutron Plugin - if you really need toHow to write a Neutron Plugin - if you really need to
How to write a Neutron Plugin - if you really need tosalv_orlando
 
Packet flow on openstack
Packet flow on openstackPacket flow on openstack
Packet flow on openstackAchhar Kalia
 
GLBP (gateway load balancing protocol)
GLBP (gateway load balancing protocol)GLBP (gateway load balancing protocol)
GLBP (gateway load balancing protocol)Netwax Lab
 
Application Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centreApplication Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centreCisco Canada
 
Reactive Microservices with Spring 5: WebFlux
Reactive Microservices with Spring 5: WebFlux Reactive Microservices with Spring 5: WebFlux
Reactive Microservices with Spring 5: WebFlux Trayan Iliev
 
Aci presentation
Aci presentationAci presentation
Aci presentationJoe Ryan
 
Ceph Introduction 2017
Ceph Introduction 2017  Ceph Introduction 2017
Ceph Introduction 2017 Karan Singh
 
Virtualized network with openvswitch
Virtualized network with openvswitchVirtualized network with openvswitch
Virtualized network with openvswitchSim Janghoon
 
Vxlan deep dive session rev0.5 final
Vxlan deep dive session rev0.5   finalVxlan deep dive session rev0.5   final
Vxlan deep dive session rev0.5 finalKwonSun Bae
 
Next Generation IP Transport
Next Generation IP TransportNext Generation IP Transport
Next Generation IP TransportMyNOG
 

What's hot (20)

NAT Ccna
NAT CcnaNAT Ccna
NAT Ccna
 
VXLAN and FRRouting
VXLAN and FRRoutingVXLAN and FRRouting
VXLAN and FRRouting
 
Ospf.ppt
Ospf.pptOspf.ppt
Ospf.ppt
 
How to write a Neutron Plugin - if you really need to
How to write a Neutron Plugin - if you really need toHow to write a Neutron Plugin - if you really need to
How to write a Neutron Plugin - if you really need to
 
Mininet Basics
Mininet BasicsMininet Basics
Mininet Basics
 
ACI Hands-on Lab
ACI Hands-on LabACI Hands-on Lab
ACI Hands-on Lab
 
Packet flow on openstack
Packet flow on openstackPacket flow on openstack
Packet flow on openstack
 
ACI MultiPod 구성
ACI MultiPod 구성ACI MultiPod 구성
ACI MultiPod 구성
 
Secured Internet Gateway for ISP with pfsense & FRR
Secured Internet Gateway for ISP with pfsense & FRRSecured Internet Gateway for ISP with pfsense & FRR
Secured Internet Gateway for ISP with pfsense & FRR
 
GLBP (gateway load balancing protocol)
GLBP (gateway load balancing protocol)GLBP (gateway load balancing protocol)
GLBP (gateway load balancing protocol)
 
SD WAN
SD WANSD WAN
SD WAN
 
Application Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centreApplication Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centre
 
Reactive Microservices with Spring 5: WebFlux
Reactive Microservices with Spring 5: WebFlux Reactive Microservices with Spring 5: WebFlux
Reactive Microservices with Spring 5: WebFlux
 
Aci presentation
Aci presentationAci presentation
Aci presentation
 
Ceph Introduction 2017
Ceph Introduction 2017  Ceph Introduction 2017
Ceph Introduction 2017
 
Meetup 23 - 02 - OVN - The future of networking in OpenStack
Meetup 23 - 02 - OVN - The future of networking in OpenStackMeetup 23 - 02 - OVN - The future of networking in OpenStack
Meetup 23 - 02 - OVN - The future of networking in OpenStack
 
Virtualized network with openvswitch
Virtualized network with openvswitchVirtualized network with openvswitch
Virtualized network with openvswitch
 
Vxlan deep dive session rev0.5 final
Vxlan deep dive session rev0.5   finalVxlan deep dive session rev0.5   final
Vxlan deep dive session rev0.5 final
 
Next Generation IP Transport
Next Generation IP TransportNext Generation IP Transport
Next Generation IP Transport
 
Cisco ASA Firewalls
Cisco ASA FirewallsCisco ASA Firewalls
Cisco ASA Firewalls
 

Similar to NetFlow Analyzer Training Part I: Getting the initial settings right

Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...ManageEngine, Zoho Corporation
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...ManageEngine, Zoho Corporation
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshootingManageEngine, Zoho Corporation
 
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...ManageEngine, Zoho Corporation
 
Monitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerMonitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerManageEngine
 
Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightSai Sundhar Padmanabhan
 
Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.ManageEngine, Zoho Corporation
 
The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines Netronome
 
1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.pptFarid Er
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.pptAssadLeo1
 
ONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAJunho Suh
 
NUVX Technologies general solutions
NUVX Technologies general solutionsNUVX Technologies general solutions
NUVX Technologies general solutionsNUVX
 
Azure Monitoring Overview
Azure Monitoring OverviewAzure Monitoring Overview
Azure Monitoring Overviewgjuljo
 

Similar to NetFlow Analyzer Training Part I: Getting the initial settings right (20)

Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Export flows, group traffic, map application traffic and more: NetFlow Analyz...
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings right
 
Network Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai SeminarNetwork Bandwidth management - Mumbai Seminar
Network Bandwidth management - Mumbai Seminar
 
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshooting
 
NFA - Middle East Workshop
NFA - Middle East WorkshopNFA - Middle East Workshop
NFA - Middle East Workshop
 
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
 
Monitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManagerMonitor and manage everything Cisco using OpManager
Monitor and manage everything Cisco using OpManager
 
Manageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An InsightManageengine Netflow analyzer - An Insight
Manageengine Netflow analyzer - An Insight
 
Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.Webinar: How to troubleshoot bandwidth hogs and take action.
Webinar: How to troubleshoot bandwidth hogs and take action.
 
The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines The Need for Complex Analytics from Forwarding Pipelines
The Need for Complex Analytics from Forwarding Pipelines
 
Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)Copy of learn_the_art_of_firewall_security(1)
Copy of learn_the_art_of_firewall_security(1)
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt1. Network monitoring and measurement-2.ppt
1. Network monitoring and measurement-2.ppt
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.ppt
 
Cloud Migration
Cloud MigrationCloud Migration
Cloud Migration
 
INT_Ch17.pptx
INT_Ch17.pptxINT_Ch17.pptx
INT_Ch17.pptx
 
ONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINAONS Summit 2017 SKT TINA
ONS Summit 2017 SKT TINA
 
NUVX Technologies general solutions
NUVX Technologies general solutionsNUVX Technologies general solutions
NUVX Technologies general solutions
 
Azure Monitoring Overview
Azure Monitoring OverviewAzure Monitoring Overview
Azure Monitoring Overview
 

More from ManageEngine, Zoho Corporation

NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020ManageEngine, Zoho Corporation
 
Overcome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesOvercome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesManageEngine, Zoho Corporation
 
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringModernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringManageEngine, Zoho Corporation
 
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020ManageEngine, Zoho Corporation
 
From web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersFrom web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTManageEngine, Zoho Corporation
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTManageEngine, Zoho Corporation
 
Monitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureMonitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureManageEngine, Zoho Corporation
 
Visibility-from web application interface to the database
Visibility-from web application interface to the databaseVisibility-from web application interface to the database
Visibility-from web application interface to the databaseManageEngine, Zoho Corporation
 
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network MapsFree OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network MapsManageEngine, Zoho Corporation
 

More from ManageEngine, Zoho Corporation (20)

Create seamless customer experiences
Create seamless customer experiencesCreate seamless customer experiences
Create seamless customer experiences
 
From web interface to database: Monitor what matters
From web interface to database: Monitor what mattersFrom web interface to database: Monitor what matters
From web interface to database: Monitor what matters
 
NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020NetFlow Analyzer Free Training Series Part I - May 2020
NetFlow Analyzer Free Training Series Part I - May 2020
 
Overcome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challengesOvercome real-time server and VM monitoring challenges
Overcome real-time server and VM monitoring challenges
 
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoringModernizing Cloud and Hyperconverged Infrastructure monitoring
Modernizing Cloud and Hyperconverged Infrastructure monitoring
 
Deliver seamless digital experience
Deliver seamless digital experienceDeliver seamless digital experience
Deliver seamless digital experience
 
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
 
From web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that mattersFrom web interface to the database:Monitor all that matters
From web interface to the database:Monitor all that matters
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - ESTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
 
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMTNetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
 
NetFlow Analyzer Product Overview
NetFlow Analyzer Product OverviewNetFlow Analyzer Product Overview
NetFlow Analyzer Product Overview
 
Monitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructureMonitoring cloud applications and hyperconverged infrastructure
Monitoring cloud applications and hyperconverged infrastructure
 
Building the right website monitoring strategy
Building the right website monitoring strategyBuilding the right website monitoring strategy
Building the right website monitoring strategy
 
Unlock the value of your big data infrastructure
Unlock the value of your big data infrastructureUnlock the value of your big data infrastructure
Unlock the value of your big data infrastructure
 
Key to optimal end user experience
Key to optimal end user experienceKey to optimal end user experience
Key to optimal end user experience
 
Monitoring cloud applications and containers
Monitoring cloud applications and containersMonitoring cloud applications and containers
Monitoring cloud applications and containers
 
implementing the right website monitoring strategy
 implementing the right website monitoring strategy implementing the right website monitoring strategy
implementing the right website monitoring strategy
 
Big data and non relational database
Big data and non relational databaseBig data and non relational database
Big data and non relational database
 
Visibility-from web application interface to the database
Visibility-from web application interface to the databaseVisibility-from web application interface to the database
Visibility-from web application interface to the database
 
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network MapsFree OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
 

Recently uploaded

Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...
Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...
Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...Anthony Dahanne
 
De mooiste recreatieve routes ontdekken met RouteYou en FME
De mooiste recreatieve routes ontdekken met RouteYou en FMEDe mooiste recreatieve routes ontdekken met RouteYou en FME
De mooiste recreatieve routes ontdekken met RouteYou en FMEJelle | Nordend
 
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.ILBeyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.ILNatan Silnitsky
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2
 
Crafting the Perfect Measurement Sheet with PLM Integration
Crafting the Perfect Measurement Sheet with PLM IntegrationCrafting the Perfect Measurement Sheet with PLM Integration
Crafting the Perfect Measurement Sheet with PLM IntegrationWave PLM
 
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...informapgpstrackings
 
top nidhi software solution freedownload
top nidhi software solution freedownloadtop nidhi software solution freedownload
top nidhi software solution freedownloadvrstrong314
 
Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...
Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...
Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...Abortion Clinic
 
AI/ML Infra Meetup | ML explainability in Michelangelo
AI/ML Infra Meetup | ML explainability in MichelangeloAI/ML Infra Meetup | ML explainability in Michelangelo
AI/ML Infra Meetup | ML explainability in MichelangeloAlluxio, Inc.
 
A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1
A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1
A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1KnowledgeSeed
 
A Comprehensive Appium Guide for Hybrid App Automation Testing.pdf
A Comprehensive Appium Guide for Hybrid App Automation Testing.pdfA Comprehensive Appium Guide for Hybrid App Automation Testing.pdf
A Comprehensive Appium Guide for Hybrid App Automation Testing.pdfkalichargn70th171
 
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERRORTROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERRORTier1 app
 
AI/ML Infra Meetup | Perspective on Deep Learning Framework
AI/ML Infra Meetup | Perspective on Deep Learning FrameworkAI/ML Infra Meetup | Perspective on Deep Learning Framework
AI/ML Infra Meetup | Perspective on Deep Learning FrameworkAlluxio, Inc.
 
Advanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should KnowAdvanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should KnowPeter Caitens
 
Designing for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web ServicesDesigning for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web ServicesKrzysztofKkol1
 
AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...
AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...
AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...Alluxio, Inc.
 
AI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAG
AI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAGAI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAG
AI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAGAlluxio, Inc.
 
Mastering Windows 7 A Comprehensive Guide for Power Users .pdf
Mastering Windows 7 A Comprehensive Guide for Power Users .pdfMastering Windows 7 A Comprehensive Guide for Power Users .pdf
Mastering Windows 7 A Comprehensive Guide for Power Users .pdfmbmh111980
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke
 
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?XfilesPro
 

Recently uploaded (20)

Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...
Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...
Paketo Buildpacks : la meilleure façon de construire des images OCI? DevopsDa...
 
De mooiste recreatieve routes ontdekken met RouteYou en FME
De mooiste recreatieve routes ontdekken met RouteYou en FMEDe mooiste recreatieve routes ontdekken met RouteYou en FME
De mooiste recreatieve routes ontdekken met RouteYou en FME
 
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.ILBeyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
Crafting the Perfect Measurement Sheet with PLM Integration
Crafting the Perfect Measurement Sheet with PLM IntegrationCrafting the Perfect Measurement Sheet with PLM Integration
Crafting the Perfect Measurement Sheet with PLM Integration
 
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
 
top nidhi software solution freedownload
top nidhi software solution freedownloadtop nidhi software solution freedownload
top nidhi software solution freedownload
 
Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...
Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...
Abortion ^Clinic ^%[+971588192166''] Abortion Pill Al Ain (?@?) Abortion Pill...
 
AI/ML Infra Meetup | ML explainability in Michelangelo
AI/ML Infra Meetup | ML explainability in MichelangeloAI/ML Infra Meetup | ML explainability in Michelangelo
AI/ML Infra Meetup | ML explainability in Michelangelo
 
A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1
A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1
A Python-based approach to data loading in TM1 - Using Airflow as an ETL for TM1
 
A Comprehensive Appium Guide for Hybrid App Automation Testing.pdf
A Comprehensive Appium Guide for Hybrid App Automation Testing.pdfA Comprehensive Appium Guide for Hybrid App Automation Testing.pdf
A Comprehensive Appium Guide for Hybrid App Automation Testing.pdf
 
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERRORTROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
 
AI/ML Infra Meetup | Perspective on Deep Learning Framework
AI/ML Infra Meetup | Perspective on Deep Learning FrameworkAI/ML Infra Meetup | Perspective on Deep Learning Framework
AI/ML Infra Meetup | Perspective on Deep Learning Framework
 
Advanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should KnowAdvanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should Know
 
Designing for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web ServicesDesigning for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web Services
 
AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...
AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...
AI/ML Infra Meetup | Improve Speed and GPU Utilization for Model Training & S...
 
AI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAG
AI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAGAI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAG
AI/ML Infra Meetup | Reducing Prefill for LLM Serving in RAG
 
Mastering Windows 7 A Comprehensive Guide for Power Users .pdf
Mastering Windows 7 A Comprehensive Guide for Power Users .pdfMastering Windows 7 A Comprehensive Guide for Power Users .pdf
Mastering Windows 7 A Comprehensive Guide for Power Users .pdf
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
 
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
 

NetFlow Analyzer Training Part I: Getting the initial settings right

  • 1. NetFlow Analyzer - Part I Getting the initial settings right
  • 2. Welcome to a free training on NetFlow Analyzer!
  • 4. Agenda • Exporting flows • Traffic grouping • Application mapping • Threshold based alerting • In-depth traffic visibility • Knowledge base and best practices
  • 5. NetFlow Analyzer demo build 123086
  • 6. Minimum system requirements 2.4 GHz quad-core processor, or equivalent 4GB RAM 50GB storage Windows/LinuxPostgreSQL/MSSQL These specifications only apply when raw data is turned off and the flow rate is below 3,000 flows/sec. Requirements will vary with different settings.
  • 7. Initial setup Set up flow export Viewing & customizing real-time traffic graphs Configuring alerts Step1 Step 2 Step 3
  • 8. Step 1: Configuring flow export from interfaces NetFlow sFlow J-Flow IP FIX NetStream AppFlow
  • 9. Devices supported by NetFlow Analyzer https://www.manageengine.com/products/netflow/supported-devices.html
  • 10. Where and how do you send flows? Ways of exporting flows to NetFlow Analyzer: i. Manual configuration ii. Using Network Configuration Manager Ports to be considered: • Server port: NetFlow Analyzer's web server port • Listener port: Port on which NetFlow Analyzer receives flows • Both ports are configurable
  • 11. Using Network Configuration Manager add-on Benefits of using Network Configuration Manager: • No need to write commands • Predefined configlets • Export flows from multiple interfaces in bulk • Backup and restore configurations for devices • Create new configlets Apply credentials Select interfaces Export flow Add devices
  • 12. Creating/modifying a configlet • In Network Configuration Manager, go to Settings > Configlets. Add a new configlet by creating a custom template. • Select devices and enter flow configuration commands. • Execute the new configlet.
  • 14. Common problems faced after exporting flows
  • 15. #1. NetFlow Analyzer shows "No Data Available" in graphs, even after I've configured flows. Solution: Two possibilities 1. The device is not configured correctly for exporting flows. 2. A firewall or access list is blocking the UDP port. • Check if flows are received with the help of Wireshark. • Yes- Check for windows firewall/IP tables for any restrictions and template timeout to 60 seconds. • No- Correct the configuration by setting the active timeout to 60 seconds.
  • 16. #2. I've added five interfaces. Why is one of my interfaces, "Interface Gi0/1," not listed in NetFlow Analyzer? Solution: The particular interface isn't configured for exporting flows. • Interface is not configured correctly. • Check for correct interface along with its export configurations.
  • 17. Step 2: Visibility into real-time traffic details Inventory Flow analysis Config management IP SLA Packet analysis Traffic overview Real-time traffic graphs
  • 18. Inventory: Flow Analysis Traffic overview Device Device groups Lay 4 & 7 applications DSCP-based QoS Wireless LAN controllers Interface IP / interface group Attacks
  • 19. Know the who, when and what of your network traffic. - Applications - Protocols - QoS - Source - Destination - Conversation Gain detailed visibility into traffic usage by
  • 20. High utilization in one of your network links?
  • 21. Snapshot summary Device traffic details: • Traffic speed • Associated interfaces by speed, volume and utilization • Top applications and protocols • Top QoS • Top Source, destination and conversation • AS traffic Group traffic details: • Traffic by speed, volume, utilization and packets • Associated applications and protocols • DSCP QoS traffic • Source, destination and conversation Application traffic details: • Traffic usage by volume • Associated interfaces QoS traffic details: • Traffic usage by volume • Associated interfaces WLC traffic details: • Controller traffic by speed, volume and packets • Associated access points • Application traffic • DSCP QoS traffic • Conversation details with Client IPs and SSIDs Interface traffic details: • Traffic by speed, volume, utilization and packets • Top applications and protocols • Top Source, destination and conversation by geo-location, network and DNS name • Top QoS traffic by DSCP and TOS • SNMP/FNF NBAR, CBQoS • Multicast report • Medianet by volume, RTT, packet loss • AVC
  • 22. Visibility into Layer 7 application traffic • Gain visibility into NBAR2 applications with Cisco AVC monitoring (Application Visibility and Control). • Advanced NBAR is used to identify web traffic, URL’s, file sharing and random port application. • View NBAR2 application, URL hit count (HTTP host report), QoS class hierarchy and application response time monitoring reports(ART monitoring).
  • 23. Understand traffic for current QoS policies Check the traffic usage by each DSCP value for policy effectiveness.
  • 24. Manage traffic usage by WLAN controllers • Monitor Cisco WLAN controllers and Meraki devices. • Find the top traffic usage by access points, SSIDs, applications, clients etc. • Troubleshoot a bandwidth spikes by identifying consumption by SSIDs, finding its top clients and complete conversation details for the selected time period.
  • 25. • Identify junk/unusual traffic that disrupts your critical services. • Using advanced mining algorithm, ASAM detects internal and external security threats. • ASAM classifies traffic as suspect flows, bad source and destination, DDoS, and scans/probes. Detect attacks with flow-based advanced security analytics module
  • 26. Tips to enhance visibility into your traffic
  • 27. My interfaces are named "IfIndex1" and "IfIndex2." How can I view the actual name of devices and interfaces? Solution: Three options • Fetch name from router with SNMP 1. Create SNMP credential v1/v2/v2 from discovery 2. Associate SNMP credentials 3. Edit device • Fetch the DNS name. • Enter your own name.
  • 28. My interface utilization says it's above 100 percent. How do I set the correct value? Solution: Two possibilities 1. The speed is incorrect. 2. [OR] time sync problem. • Set the proper IN and OUT speed in bytes. Go to Inventory > Select Interfaces > Set Speed. • Make sure the device time and NFA time is in sync • Check flow filters
  • 29. Most of the applications are listed as "_App". How do I map those applications and also add my own applications? Solution: Application mapping for _App • Interface >Application > _App > Show port. • Map application and define IP address/ IP network/ IP range. Application mapping for own apps • Settings> netflow> mapping > add
  • 30. Is there a way to view cumulative traffic? Branches VLANRelated appsNetwork subnet Department Traffic grouping
  • 31. Sort traffic usage by groups Types of groups Device Interface IP Application DSCP Benefits of creating groups: • Monitor combined bandwidth usage to get better picture of traffic consumption. • Provide access to operators based on groups. • Provide better visibility to improve troubleshooting.
  • 33. How do I check traffic usage by different branches? Solution Create a device grouping for different branches. • Combine devices under a branch to create groups. • Generate group reports.
  • 34. How do I monitor combined traffic for VLAN? Solution An un-routed VLAN will not send traffic like an interface, but NetFlow Analyzer will discover its associated interfaces. • Create an Interface Group that includes all of the VLAN's interfaces to monitor the cumulative traffic. • Other option: failover, load balancing, port channeling, and aggregation.
  • 35. How do I manage each of my customers' traffic ? Solution Create IP groups for each customer. • Combine IPs to create groups. • Generate group reports. • Group based on IP range, network, monitoring between sites. • Other option: between sites and department
  • 36. How do I view business critical traffic and see how much bandwidth is used? Solution Create application groups. • Combine apps to create a group. • Find total utilization for each group. • Pull combined traffic reports.
  • 37. Simplified and customizable Inventory Edit configurationCustom filters/sort Custom views Quick search
  • 38. Filter up to the last 30 days Create device group Create device/interface/app group Inventory search Set speed Set SNMP Zoom in graphs Generate instant reports New in v12 Unmanage/delete device Add to Network Configuration Manager Table/list/status viewConfigure NBAR & CBQoS Service policy & ACL Clear alarm/add note Various device-specific custom options New in v12
  • 39. Step 3: Alerting Link down Link overutilized Threshold violation Link slow
  • 40. Alert Profiles Preconfigured alerts: • Link down • No flow Threshold based alerts • IP range, IP address or IP network • Based on port/protocol range • Based on application • Based on DSCP
  • 41. I want to get alerted when the interface is over utilized in a WAN link? Solution • Set a threshold alert for overutilized links. • Provide a threshold value. • Set up email/SMS notifications.
  • 42. Thresholds based on multiple conditions Select source Select criteria Define threshold Save alert profile Alerts specific to below violation: • Utilization • Volume • Speed • Packets Alert severity levels: • Critical • Trouble • Attention
  • 43. How do I set up notifications? Types of notifications: • Email • SMS • Trigger SNMP trap • Modify an alarm's description. • Get reports via email. New in v12 Step 1: Configure mail server settings. Step 2: Set threshold. Step 3: Provide an email address or phone number. Step 4: Save alert.
  • 44. Summary Set up flow export #1. Data not available #2. Interfaces not listed Viewing & customizing bandwidth graphs #1. Fetch device/interface name #2. Utilization above 100% #3. Map unknown applications #4. Show DNS name #5. Categorize traffic groups #6. Customize time filter Configuring alerts #1. Set interface overutilized alert #2. Link down Step1 Step 2 Step 3
  • 45. Recent enhancements in NetFlow Analyzer • 'Guest' user privilege has been added for NetFlow installation. • Dashboard loading has been revamped and optimized. • iPhone/Android and iPad application download links available in login. • In the Inventory page, product based tabs have been moved horizontally. • Quick links added for sending support mail, apply license, phone number, SIF, User guide, Videos, Service pack, ThreadDump, DB Query & view Logs with a support icon. • Added an option to export to PDF and mail for individual graph reports. • SFlow flow format for multiple MPLS can be added now. • Added an option to configure billing with base cost as zero.
  • 46. How NetFlow Analyzer scores high over others • Detailed view of applications and QoS traffic • Traffic grouping options (total traffic based on interfaces, IPs, apps, QoS and grouped) • Site to site total traffic view • Alarms for IP groups • Wireless LAN monitoring • Attacks • AS view • and more....
  • 47. Upcoming training on May 22nd Part II: Diagnosing and troubleshooting traffic issues faster • Alarms • Customizing data storage • Troubleshooting with forensics • Reporting and automation • Capacity planning • Traffic shaping • Customizing dashboards • Usage-based billing