Bi-Directional Flows
I am in the process of evaluating your software and I am very impressed. I must have something misconfigured because each interface on the test router only shows packets in or out, not both. Can you tell me what I need to change?
Reports for custom time periods report erroneous data.
If I manually change a 1 hour report to show two hours, then the total traffic for two hours shows less traffic than it did when displaying 1 hour data. Obviously it should be more adding an additional hour. It does not seem to total the information probably when selecting custom periods. Thanks!
6509 Vlan interfaces not showing the proper numbers
Okay; I've been through the manual and Cisco's web site documentation on the following page: http://www.cisco.com/en/US/partner/products/hw/switches/ps708/products_configuration_guide_chapter09186a0080160a2b.html#wp1114378 Here are my traffic stats from netflow analyzer for Vlan 35 over the last day as well as my regular traffic stats from my interface monitoring. On my regular routers (7200s and such) I am getting matching numbers but on these vlan interfaces I am not and I don't know what else
One last question
I apologize for not placing this in my last post, but all source and destination IP numbers are the source interface on our test router. I do get a brekdown of known protocols, but no information on senders or destination IPs. Obviously I am learning, so any help would be appreciated.
Analyzer is working with installed collectors?
hi, the analyzer is working with installed collectors? in our network we have some installed collectors for an other netflow analyzer. now we will test your software, but we have over 250 interfaces to observe and we can not configurate each device for this. have the analyzer an own collector? or we can select our collector? This is very important for us befor we can integrate this software in our network. Sorry for my bad english :) regards gorok
1 hour QuickView incomplete
/scratches head When I click any of the devices or groups QuickView icon the resulting information is missing the first and last 10 minutes of information. I have verified that all devices have the correct time/timezone configured on them. Attached is a copy of one of the reports. This began after I updated the system to the 5002 build. TIA Gordon
no router assigned
Hi All, I'm sure you've seen this post a few times. But I've been through all the support and I've tried to the following using a trial version w/28 days left: First I've confirmed that netflow is configured on my 2821 routers. And I've turned on debugging to ensure that the netflow packets are being exported. I've also looked at the export stats and it says it's exporting packets. On the server I've used tcpdump to ensure that the NFA server is actually receiving the packets and it is. I've confirmed
To many interfaces than i need..
Hallo, our customers are connected like this: Customer Side (VRF-Interfaces) Our MPLS-Network LAN-Interface (1 to 2 * FastEthernet) <= PE-ROUTER => 1 to 4* WAN-Interfaces We are switched on Netflow accounting on the LAN-Interfaces: IP Flow ingres IP Flow engres On the WAN-Interfaces no Netflow ist configured (netflow on MPLS-Interfaces is not supported) Now i see in the NetFlowanalyzer all Interfaces of the Router and i have problems with the performance of the Server (High CPU). (200 Router with
netflow analyzer oracle support
Hello Raghu, Thanks for the quick response on previous questions. Can we run Netflow analyzer with an existing Oracle database? Do you have a schema, where I can create on Oracle? Our Oracle DBA's are curious .... ---Luke---
Disk full!!!!!
I have Netflow Analyzer 4, monitoring about 70 interfaces, in production for about 6 months, and the database has grown to about 3 gigs (just for the file ibdata1). It totally filled the available disk space. Is there a way to limit how much information is stored? If not, if there a formula to estimate the size needed for the database, and how much it will grow over the years? Thanks Sergio
Backup and Restoration
I recently had my paritition that houses NetflowAnalyzer fill up; so I moved the data to another partition. I moved the data that was in the mysql/data/netflow folder to another partition, then symlinked it back to the original location. The app started working again once there was room on the original partition again but all of the previously collected data no longer shows up. Is what I did that bad? But...that leads me to the question how can this tool be backed up and restored reliably?
Summary Report
Is it possible to create a report that shows a summary of network wide application traffic that updates itself regularly and is accessible??? Serge R
Using a radius server f�r authentication
Hallo, i must adminisiter a lot of users (different user / customers). Is it possible to authenticate the login-user with a radius-server? Thanks Tom
Major Inconsistencies between Last hour and last day data
Changing to "Last Day Report" is losing data. Where am I talking about? I click on the interface, then on "Conversation." It defaults to "Last Hour Report" and there are 600 some entries (viewing 100 at a time). Then I change it to "Last Day Report" and there are only 57. Where did all the rest of the data go? (BTW, "Retain Raw Data" is set to "1 Week" I'm finding this a lot the more I look into it. Please identify a fix.
Using the data to bill from
Hi, We would like to bill our customers based on the number of bytes they transferred in a month. What we would need is the monthly total of bytes sent or received for each ip address on our network. Is there a way to get this information in a text file from Manageflow analyzer ? or We could ask for the data using ODBC into the MYSQL Manageflow Data base but we are not sure where to get the transferred byte numbers in Database. any help would be appreciated, Dimitri
Network wide summary report of all traffic
Hi, Is it possible to create a report that shows a summary of network wide application traffic that updates itself regularly and is accessible via a url without needing a username and password to access. We are setting up a system of monitoring that involves a large screen monitor which displays a rotation of the web pages of our different monitoring systems. I would like to be able to include the summary of application traffic as reported by Netflow analyser.
Router sending more than NFA is reporting; does a manual exi
I just fired up NFA to analyze 2 ports on a 3620 router -- one FastEternet interface, one Serial (T1). Seems to be basically working, but I'm not seeing (I don't think) all the traffic that the router is reporting. Right now the router shows: #sho ip flow export Flow export v5 is enabled for main cache Exporting flows to 10.251.12.62 (9996) Exporting using source interface FastEthernet0/0 Version 5 flow records 49792 flows exported in 1664 udp datagrams 0 flows failed due to lack of export packet
alert profile FROM Adresse
Hi, all my alert mail (NFA 5.0) come from the address netflowreport@localdomain.com, unfortunally this is bad because my MTA makes a from check to see if the address is valid. so i actually get no mail. Any point where i can set the from address to netflowreport@mydomain.de regards Martin PS: I would have searched the forum first, but the search function throws a 500 error.
Not seeing any routers
My Netflow was working fine for over a month, but I noticed today it is not reporting any routers, although I have many routers configured t export flow. Can you help please. Thank you
Port not listed for TCP_APP Communication
Source IP Destination IP Application Port Protocol Traffic % of Traffic 10.38.4.20 10.20.4.52 TCP_App * TCP 6682.4 MB 78% I take it the port is not being listed in the above example because the communication between the source & destination IP's are dynamic? Do you have recomendations for monitoring Protocols/Applications such as MAPI or FRS using Netflow Analyzer?
Netflow Version 5 vs Version 7
Could you please advise if version 7 NetFlow exports would give any additional information over version 5 exports within NetFlow Analyzer? My understanding was that version 7 release was to support specific CISCO hardware and did not extend the information contained in NetFlow exports. Maybe I've been misguided...
Authentication with Radius
Hallo, we are using NetFlowanalyzer V5 - a great tool! Is it possible to use an external radiusserver to authenticate the users? Is this feature on the roadmap for V6? Thanks Tom
Maximum Utiliztion is abover 100%
I have a T1 I am monitoring with Neflow and it keeps saying Maximun Utiliztion is abover 100% and tells me to check the interface speed and the timeout. The timeout is set correct, and the bandwidth on the link is set for 1536000. Why is netflow giving me this error.
Netflow through a mapped ip address on a Netscreen firewall
Hello, I have Netflow installed and running on over a hundred router - I love it! But, our Internet router is behind a Netscreen firewall. Internal Address of Netflow is 10.10.10.10 I have mapped the internal address to an external address on the firewall. My internet router points to the mapped IP address of the Netflow server. It works fine for an hour or two then just stops recieving flows. I can get it working again by disabling the rule on the Netscreen firewall that allows the traffic through,
Billing
Hey, I have seen many old (2005) requests for data billing, can I get an update on that? Is it on your roadmap? Maybe NFA 6? Or more generally, is billing expected to be a feature this year? Thanks
question on collectors
In reading the documentation for Cisco it speaks about using netflow to export to collectors. Does this product work as a stand alone collector that you can view all of the information as I did in the demo? thanks, George
Default Admin details on Logon Page
Just have a couple of things: 1. Even after changing the default admin account password the logon page for Netflow Analyser still shows the "For Default User" information. Can this be turned off? 2. Also is there any instructions on customising the logon page and logo's for the application as we would like to give access to some of our premium customers. Thanks for your assistance.
aggregated vs non aggregated
Hi Guys, Back again, question for you this time is. What exactly is the different between the way the two types are stored? So Raw data is used for troubleshooting. Does that mean each flow is saved? please explain as i'm trying to understand what makes the data more accurate. thank you!
Flow export set as v5 but Netflow reporting incorrect
A customer has configured Netflow on a Cisco 2620XM but Netflow is reporting flows are not v5 or v7. Here is the show ip flow export from his router: ISIMKE2#show ip flow export Flow export v5 is enabled for main cache Exporting flows to 192.168.100.50 (9996) Exporting using source interface FastEthernet0/0 Version 5 flow records 28274 flows exported in 944 udp datagrams 0 flows failed due to lack of export packet 0 export packets were sent up to process level 0 export packets were dropped due to
Migration
I want to move Netflow from my "C" drive to my "D" drive. How would I do this without loosing historical data?
Database back-up
We have had some issues with backing up our Netflow folder that have forced me to not back-up that folder. I would like to set-up the database back-up to create the back-up file in a different folder, but have not been able to alter the BackUpDB.bat file successfully. What changes can I make to the BackUpDB.bat file to save the back-up file in a different folder?
QOS
Hi, How does Netflow calculate the application percentage of total traffic? Is it done before the traffic is passed through quality of service or after? The reason why I am asking is because Netflow most of the times display that we have on our uplink 45% of the total traffic is SMTP and 52% http. We have implemented QOS and reserved 60% of the bandwidth for http but netflow is not showing the changes. We know that http traffic is more than 52% Thank you, Ramzi
NFA 5 support Windows 2003 server?
Greetings, Could you please confirm for me the support status of NFA 5 on Windows 2003 server (std edition). I note that on the System Requirements page for NFA it only refers to XP, 2k and Redhat. My client is procuring server for forthcoming purchase of NFA however they standardise on Windows 2003 Server platform so they would prefer to not deploy a Windows 2000 server for NFA if 2003 will be OK? p.s. Could NFA on Windows 2003 be suseptible to the MySql bug that is mentioned in the Firewall Analyser
Changing the diplay to port numbers
I would like to display reports with the application mapping feature turned off. In other words, I would like reports with the actual port numbers listed rather than the associated application name. How can this be done?
help me
Hello! i'm use Netflow 5 monitor trafic in route cisco 3640 but i can not see sub interface serial use frameRelay. please tell me why? this my config interface Serial0/2 no ip address no ip unreachables encapsulation frame-relay ip route-cache flow interface Serial0/2.1 point-to-point ip unnumbered FastEthernet0/0 no ip mroute-cache no cdp enable frame-relay interface-dlci 1000 frame-relay payload-compression packet-by-packet no ip mroute-cache frame-relay lmi-type ansi ! snmp-server community test
Real traffic
Hello Raghu. Thanks for Netflow. It's very useful tools. Could You please explain me how to get the real Incomming and Outgoung traffic using next configuration of Cisco ETH0-LAN(192.168.1.3)---CISCO---ETH1-WAN(85.x.x.2) Cisco has next setting for flow export: ip flow-export source FastEthernet0/0 I have got Consolidated Report which You can see below. It seems to me that traffic SourceIN and DestinationIN is doubled. Am I right? Thanks, Serge Consolidated Report - [ 192.168.1.3 - Ethernet1] SourceIN
incorrect application mapping
Hello ! Sometimes I see exotic traffic on my router - rmiactivation for example. When I make custom report with Application criteria=rmiactivation, I see simple IRC (1,2) and proxy (3) answers from remote hosts: IN Traffic Details 1. 10.4.0.2 10.8.2.86 rmiactivation 6667 1098 TCP 33.05 KB 341 2. 10.4.0.2 10.8.0.14 rmiactivation 6667 1098 TCP 23.55 KB 250 3. 10.4.0.1 10.8.0.11 rmiactivation 8000 1098 TCP 15.76 KB 19 How I can configure NFA6 to fix this problem ?
RAM & CPU utilization
hi, Netflow was working ok, Suddenly MY SQL like Database & Java process takes more RAM , and CPU utilization Please suggest ???? Thanx
admin account reset itself?
I was in the middle of using NA5 (generating reports) when I started getting errors whenever I click on the consolidated report button. So I logged off and tried logging in again but now its telling me I have the wrong user and password info even though I've been using it all morning. I've cleared browser cache and cookie info but to no avail.
Setting NF interface speeds
I have a router that is connected to a DSL line. The DSL line gets a download of 3mb. The interface connected to this is 100MB. To get accurate output should I set the inteface in Netflow to 3000000 bits/sec ???? Thank you in advance for your suggestion...
Next Page