Netflow issue Cisco 7206 router
Hi, I am using Netflow V8. I am not able to out stats for Cisco 7206 router on fastthernet interface. I tried using ip flow ingress & ip flow egress options also, no clue. Please help to get the problem solved. Following is my router config. interface FastEthernet1/0 ip address 10.250.4.102 255.255.255.252 no ip redirects no ip proxy-arp ip flow ingress ip flow egress ip pim sparse-mode ip route-cache flow ip igmp join-group 239.1.1.1 duplex full speed 100 no cdp enable no standby redirect
NBAR and bittorrent
HI! We have a router with enabled NBAR. On the router side all works fine - detect and account: sh ip nbar version .... 27 bittorrent Mv: 3, Nv: 2; flash:/bittorrent.pdlm sh ip nbar protocol-discovery .... ------------------------ ------------------------ ------------------------ bittorrent 3563925 2614292 4336629042 765924165 30000
NetFlow Analyzer 8.5 - Advanced Security Analytics Module Available
Folks, We are happy to announce the immediate availability of NetFlow Analyzer 8.5 GA with Advanced Security Analytics Module. We thank all our beta players for their feedbacks. It helped a lot to improve ASAM and re-prioritize our road map. We support both Windows and Linux builds. Below is the link to download NetFlow Analyzer 8.5 with ASAM module. http://www.manageengine.com/products/netflow/download.html Existing customers please fill this form to get the service pack with 30 day free evaluation
Statistics wrong?
Hi, After using Opmanager to monitor bandwidth for a while now, I yesterday activated the netflow plugin and configures our CISCO ASA accordingly. Most things seem to work fine beside that the statistics I get seem to be wrong. We have a 15 MBit line. But the traffic statistics show up to 500 MBit (seen netfow screenshot attached). At the same time, monitoring via SNMP shows the correct information. (see SNMP screenshot). What could be wrong here? Thanks Robert
Fresh Install NetFlow 8 Build 8000 Eval
Have a fresh install of NetFlow Analyzer 8 Build 8000 on CentOS 5. We are exporting the NetFlow packets from an Adtran NetVanta 4305 Firmware 17.05.01.00.E on 3 interfaces, Ethernet 0/1, 0/2 and the WAN PPP (logical port made of 4 T1 for our MPLS WAN connection.) NetFlow Analyzer is reporting that it recieving the packets, but NO data is being shown. I have green status for all of the interfaces. I have confirmed that the Adtran is sending the flows to the correct port. Not sure what to look?
After upgrading from 7600 to 8000 the "Top Devices by Speed Pie Graph" no loger displays
In the HTML, the tag looks like this: <img border="0" usemap="#" src="/netflow/servlet/DisplayChart?filename="> Please let me know your thoughts. Thanks, -Matt
NetFlow Counting Twice the Bandwidth
We are trying to calculate how much bandwidth a particular IP is sending out of our network. We are testing this by downloading a 128MB file off the network. NetFlow Analyzer is however reporting 2+x as much traffic as the actual file being transferred. Is there any reason this could be happening, and if so is there anyway to prevent this? NOTE: I'm currently using the trial license.
Cisco 3845 router with sub-portchannels and sub-serial interfaces
Hello, I am having an issue with seeing outbound traffic on NetFlow Analyzer for my Cisco 3845 router. Below is interface configuration. ip flow-cache timeout active 1 ip flow-export source Port-channel36.1 ip flow-export version 9 ip flow-export template options export-stats ip flow-export destination 10.8.1.10 9996 interface Port-channel36 no ip address hold-queue 150 in ! interface Port-channel36.1 encapsulation dot1Q 1 native ip address XXXXX ip flow ingress ip nat inside ip virtual-reassembly
Traffic Utilization Link Speed
Hi, In Netflow Analyzer 7.5, you choose an index, click Traffic and then Utilization and the report shows Link Speed measured at 1.0Mbps. This isn't an accurate relection of our 40Mbps line. How do we change this to anything other than 1.0Mbps? CHeers
NFA Database fine tuning
Hi, Can you please tell me the exact syntax of fine tunning the NFA 5.0 database. I have dell server with 4 GB RAM and Intel 3.60 Ghz Processor. Please tell me where to apply the commands. Thanks, Ali
Dimensionnement accès
Quelle est la règle qui permet de dimensionner un acces sur lequel est connecter un serveur netflow, il faut savoir que la somme des acces est d'environ 200 Mb/s et qu'il y a 60 routeurs.
Netflow Analyzer showing only Inbound Traffic and No Outbound Traffic on a cisco catalyst 4560
Hello, I'm unable to see any traffic using the latest Netflow Analyzer when connected to my Cisco Catalyst 4560 with the Add-on Netflow Services card. The config I have on my catalyst is as follows for netflow. any ideas would be great. ip flow ingress ip flow-egress input-interface ip flow-cache timeout active 1 ip flow-export source GigabitEthernet1/1 ip flow-export version 5 ip flow-export destination 10.0.0.10 2055 ! ip route-cache flow !
input interface in netflow is coming as zero.
input interface in netflow is coming as zero. when does it happen?
Netflow analyzer reporting double interface speed
Cisco 1841 Config (Note, FastEthernet0/1 is connected to a T-1 router via a crossover cable) interface FastEthernet0/1 description >> To Internet T-1 << bandwidth 1536 ip address w.x.y.z 255.255.255.240 ip access-group FW-List in ip nbar protocol-discovery ip flow ingress ip flow egress ip inspect Stateful out ip nat outside ip virtual-reassembly ip ospf priority 128 speed 100 full-duplex crypto map EasyVPN-Map service-policy output SDM-Pol-Fa0/1 ip flow-cache timeout active 1
Database dump interval
Is possible to decrease the dump interval to the database? I get the data in the database after 15min, can it be reduced to 5min?
how to manage users
how to manage users. How to create it.
Problems with Netflow backups
Good Night. Yesterday was a problem with the application and tried to climb several backups but it was not possible because all these generated error and indicated that they were corrupt, because of this and the urgency of having the service we had to reinstall the application again. Then we started to review the information and found that when performing the backup should not have the service up and that it corrupts the database. (Http://forums.manageengine.com/ # topic/49000002655437) Because of
Exclude option for port/Protocol
I would like to have an exclude option for the ports selection when making IP groups. For example, I would like to make an IP group which includes a certain subnet say 192.168.1.0-192.168.1.255 which shows all traffic except for the traffic that is on port 25,80 and 443. I already look at the traffic on these ports separately in diffrent IP groups and would like to see the traffic that remains when these ports are filtered out.
Problems With account
Good morning. We forget the administrator profile password, it is possible to recover this password?. My version is 7.5 professional. Note: I attach the file after running the file "LogZiputil.bat" Cordially. Andrés Osorio M.
Links in emailed reports not working
For example if I view a graph from the web interface it launches a new window with a URL of: http://x.x.x.x:8080/netflow/jspui/indivitualGraph.jsp?app=DestinationIN...etc If I launch the same graph from an emailed report it tries to load: http://www.indivitualgraph.jsp/?app=DestinationIN...etc If I manually sub in http://x.x.x.x:8080/netflow/jspui/ for http://www. and change graph.jsp/? to Graph.jsp? I get the correct graph. Have I missed something or configured something incorrectly within the
unaccounted
why unaccounted data is showing in source list
Fortigate IfIndex and SNMP issue
Hi, Fortinet has done some strange things with sFlow and SNMP, check out this document. The article states - Most of the third party sflow applications display incorrect interface statistics based on sflow information received. This is because interface index reported by a FortiGate in sflow packets is different to the ifIndex value of the port numbers. The application assumes that the sflow source index reported should match the SNMP ifIndex value, will poll the FortiGate, if configured, for additional
Netflow and its interface to other applications or other analyzers
Can netflow analyzer forward data to another collector? I have NFA currently configured with the network, but I would like to forward the data from NFA to another collector for further analysis. Does it do that? Thanks, Rom
Netflow disk space
Hi, I am receiving emails from netflow indicating that Available free hard disk space is less than 50%. What sort of maintenance should I do to clean-up old entries and claim back some space. Thank you Ramzi
How to best implement a netflow probe?
I have questions around using a netflow probe with Netflow Analyzer. How would NFA display data that has missing or incorrect ifIndex fields? What is the best way to setup and use a netflow probe with NFA? e.g. sourced from a data tap. Any recommendations for a probe that works well with NFA? Or specific features to look for. Thanks for any advice
Why am I not seeing flexible neflow traffic with v8 of the Analyzer when according to my configuration and capture I should be.
flow exporter pcd-1 destination 192.168.4.225 transport udp 9996 ! ! flow monitor pcd description 555Wireless_R record netflow ipv4 original-input exporter pcd-1 ! ip cef ! no ipv6 cef ! interface GigabitEthernet0/1 no ip address duplex full speed 100 ! interface GigabitEthernet0/1.2 encapsulation dot1Q 2 ip address 192.168.2.52 255.255.255.0 ip helper-address 192.168.4.220 ip flow monitor pcd input ! interface GigabitEthernet0/1.3 encapsulation dot1Q 3 ip address 192.168.3.52 255.255.255.0
Facebook IP Group with IP address range exclusion
Hello, I'm attempting to build an IP group for Facebook, which works fine. However, when I attempt to add an 'exclude' IP address range, then data collection for the group stops altogether. Below is an example of what I'm trying to do. My expectation is the following IP group would capture all traffic to/from the the 'included' IPs (Facebook) except in those cases where the excluded IP addresses are either a source or destination associated with the Facebook IPs. What am missing? Thank you- Ron
Cisco 1811 + NetFlow Analyzer + NAT
Good Morning, We have a Cisco 1811 router, setup to report internally to Netflow Analyzer. Right now, we are getting duplicate flows for all entries that go through NAT. For example, if someone goes to google, you would see 2 conversations in the internal interface, one from the internal of the computer requesting to the website as well as a entry for the external ip to the website. Is this intended behaviour? Is there a way to stop this? Right now, I am using: ip flow egress ip flow ingress on
Running NetFlow Analyzer through Apache's mod_proxy
Hi, I'm currently trying to get NetFlow Analyzer running through mod_proxy so I can remove port 8080 from my firewall. I've got the proxy part working, but the problem is all the URLs constructed by NetFlow are all /jsp/<blah> when I need them to be /netflow/jsp/<blah> Is there a setting somewhere in the app that I can set a new base url/directory from? Regards, Sage.
Cisco 831 misses sending OUTBOUND flow?
Hi, I am using NFA v8 (build 8000) and monitoring 10 interfaces. Strangely I have a Cisco 831 router (provided by service provider) which always send only INBOUND flows without the OUTBOUND. I can confirm this from my ME NFA console as well as from Solarwinds realtime NFA. Can you pls advise if there is known issues with this Cisco 831? FYI, IOS is: c831-k9o3sy6-mz.123-11.T.bin Regards, Chin
CBQOS MIBS needed
What are the minimum SNMP MIBS needed for Netflow Analyzer to query and capture CBQOS stats
Incorrect Bandwidth setting
We are trialing you netflow analyzer and have setup netflow with all of the recommended settings on two of our edge routers that have gigabit connections to the internet. Even though these routers are moving on average over 100MB to 660MB of traffic the analyzer is reporting average speeds of 40 and 20 Kbps respectively. I have followed every one of your online docs about bandwidth reporting and can't seem to get it to report correctly.
Packets/flow
It occasionally happens that I have connections on my network that don't transmit a lot of volume, but they transmit a huge amount of tiny packets, chewing up CPU on my routers. It would be nice if Netflow Analyzer had a report that could show source/destination information for IN/OUT flows sorted by number of packets, not just volume. As it stands when I have an issue, I have to configure flow top-talkers on the affected router(s) and sort by packets to find these, but this doesn't show me anything
Flows Rcvd:?
What does "Flows Rcvd:" means in Netflow Analyzer? Is it flows rcvd in last 10 mins, last hour etc.? This value gets reset to zero after sometime on the central server but its not zero on the collectors, is it a bug?
MPLS Aware Netflow - traffic stats are too high.
Hello, I am running a trial of prof edition v8.0. I have enabled flow caching and export on a Cisco 7206 PE router. My config is below. My traffic stats are as much as x10 too great on the analyser. Any suggestions? There are no esp or gre tunnels terminating on the device. The analyser has correctly identifdied the interfaces as Fast Ethernet. Could the issue relate to the fact that mpls aware netflow has been enabled? ip flow-cache timeout active 1 ip flow-cache mpls label-positions 1 2 ip flow
Netflow v8 + Patch ( Seeing src / dst IP as 0.0.0.0 )
I have just installed Netflow v8 with the patch. Now I see my top talker is as per the attachment. Everything else seems to be fine. I am running an MPLS based network This is my router config for netflow ip flow-export source FastEthernet0/0.2 ip flow-export version 9 ip flow-export template options export-stats ip flow-export template options timeout-rate 120 ip flow-export template options refresh-rate 25 ip flow-export template timeout-rate 90 ip flow-export template refresh-rate 15 ip flow-export
Netflow Analyzer 8 Problem - Operator has no network snapshot or widgets
Hey, I have created a couple of users with operator privileges however the accounts get no network snapshot or ability to create dashboards. There are also no widgets available. The admin accounts seem to work fine. Am I missing something here but should all users get at least the network snapshot dashboard? Thanks
Netflow Upgrade and Migration (huge db) v6 --> v7
Hello, In my company are planning move from Netflow 6.0 to 7.6.... I'm just start working with Netflow, so I hope someone can help me with these Issues. 1. Is the version 7.6 the latests stable one in the v7 family ?? Can I install the v8 version with my current license ? 2. We are planning some minor-tests preparing for the big upgrade, the main issue is if we can migrate all the database from version 6 to 7 without problem, I read some post where talks about migration between same build version,
Support for Cisco IPSLA - VOIP Performance Monitoring
Hello All, Now NetFlow Analyzer supports Cisco IPSLA based VOIP performance monitoring. Please send a mail to netflowanalyzer-support@manageengine.com to try this feature. Thanks Raj
NetFlow Analyzer 8 and Upgrade status
Hello NFA users, Thank you so much for overwhelming response to NetFlow Analyzer 8. We wish to acknowledge and extend our sincere thanks to Matt Goli from American Foods Group for sharing his views on NetFlow Analyzer 8 in our press release. Our support team witnessed more than 1000 upgrades last week without any issues. We have seen a lot of customers interested to evaluate our VOIP add-on and some of them shared a couple of feature requests after looking at it. Couple of issues has been reported
Next Page