IP_App on all traffic
The flows seem to be getting to my NetFlow Analyzer ok from our Csico 6509 switch, but all of the traffic shows the source as 0.0.0.0 and the application as IP_App. Is there a config that I am missing as to why it won't tell me exactly what type of traffic it is??
Use with VLAN
Hello, I have a Cisco 6509 switch that runs in Native mode IOS. I am looking to monitor traffic that is coming through this switch (This is a "core" switch). I have 2 seperate vlans set up on this device and have everything set up as shown in the configuring cisco docs. But I only get a small amount of traffic in the netflow analyzer. I suspect that I am only seeing L3 traffic and this switch is switching everything. How can I see all of the other traffic? Thank you!
Layer2 Switched traffic
I have a large switched MAN/LAN with 6509's in the core, trunked to 4500's at the access sites. Is there a way to see the L2 and L3 traffic separately?
Not receiving Netflow Traffic IN
Hi, I'm currently running Netflow Analyzer 4. I have set up Flow monitoring on one of our clients routers in order to analyse a specific interface causing problems. I have a number of the interfaces Managed including the Ethernet, and SNMP has been enabled and is working fine. Most the interfaces that I'm collecting are working fine, but one of them (the one I want to analyse) is only giving me the "Traffic OUT". I'm not receiving anything detailing the traffic IN on that interface. I know that there
Can I use this program for non router interface monitoring?
Hello, I am new around here and I find this monitoring tool very interesting. I would need it for my small network which does not include Cisco or other vendor routers. Can I use this tool for monitoring traffic on usual computer interfaces? Thanks
ifindex0 - Removing from NFA 5.0
Hi, Is there a way to delete an interface and totally remove it from the NFA cache? NFA5.0 has somehow learned/discovered ifindex0 for a router. This interface (I assume is a virtual interface?) is generating many bogus threshold alarms since it is alarming the utilization based on 1.0mbps. I tried unmanaging all interfaces for the router, removing the the netflow configs as per the help but once I recreate/reconfigure, ifindex0 appears again. ifindex0 does not appear in license management or in
Just installed...HTTP Status 500
I just installed the eval and while I can run reports and I get correct looking data whenever I click on an interface in the dashboard I get the following error: HTTP Status 500 - type Exception report message description The server encountered an internal error () that prevented it from fulfilling this request. exception javax.servlet.ServletException org.apache.jasper.runtime.PageContextImpl.doHandlePageException(PageContextImpl.java:825) org.apache.jasper.runtime.PageContextImpl.handlePageException(PageContextImpl.java:758)
custom reports
Hi, It would be good if you can in the next update include in the custom reports an option to group data by source IP or destination IP. This will help reduce the number of displayed records. Also please try to include an option to export to PDF and csv Regards, Ramzi
Traffic graphs not reported at "zero" during downt
In relation to the "mysql crashes" thread, when the collector was down for a period of a couple of hours this afternoon, no updates were received, obviously. The bug is that instead of showing "zero" traffic during this period, the graphs go from the last traffic entry at say 15:48 to the time the server came back up at 17:15. From begin to end, it's just a steady line from one point to the other. Shouldn't it be zero during this time? The "Traffic IN/OUT Details" shows an entry for 15:48 at xMbps
Move to another machine
I want to move netflow analyzer to another machine. How do I do it and keep the data that I have accumulated? Thanks
MySQL Crashes
Am I bugging you yet? I've been evaluating the trial version now for several days and have had MySQL crash twice. I'm an experienced MySQL programmer and know that the program is generally stable if set up correctly, though. The only message that shows up in the Application Event Viewer is "application error" and "the faulting application is mysqld-nt.exe ... faulting module ntdll.dll" Any idea what could be causing this or any settings I could tweak to get this working? The server it's on is a Dual
Changing link speed
I have one router that is showing the link speed as 1500.00Mbps How do I change the link speed so that it is 1.544 like it should be?
Import common application ports from IANA?
Is there a way to import the common ports assigned by IANA to certain applications? I've been adding them one-by-one, manually, as I see them using traffic on the network, but that's a real pain. http://www.iana.org/assignments/port-numbers I could parse that rather easily into SQL queries if you could tell me what table to insert it into. Thanks. ---John Holmes...
Values above 100%
Hi, I have MRTG and Netflow Analyzer to monitor internet utilization. Values from Netflow Analyzer show utilization above 100%. I'm using version 5 build 5001. Clocks are in sync and active timeout it's set to 1. This problem began when i upgrade version 4020 to 5001. I trying to convince my client to buy this great software. But with this incorrects values it's dificult to convince them. Hope that someone can help me. Edson.
Number of interfaces using bridged-flow-statistics?
I have a 6509 that has 240 ethernet interfaces on it for my servers. I understand that if I want server-to-server traffic within the same subnet I need to turn on bridged-flow-statistic on the SUP module. If I do that how many interfaces show up in NFA? One per VLAN? One per port? Any info will help I am asking because I want to know which license I need to buy.
Define application mapping by IP address? (Feature request)
I assume this isn't possible right now, so this'll be a feature request. In my network, I know that all traffic between two given IPs is VTC (Video Teleconference) traffic. Is there any way to define this as an application instead of it showing up as UDP_App? I think I've narrowed down that it uses a certain range of ports, but they're not set and could overlap with others. So I have a quick fix that'll probably work on our network, but as an overall feature, it seems like this would be useful. Thanks.
Combine flows from load balanced interfaces?
I have a main layer 3 switch that has two routes out to two separate routers that it load balances between. Those two routers then connect to a main router and then out to the world. Is there a way to see combined graphs for traffic in and out of the interfaces that are load balanced between? I've created some IP groups for known IP addresses that balance between the two connections, so I can see summaries for those regardless of what interface it's using. But I'd like to see all of the summaries
Consolidated Report
Hi, If I generate the Consolidated Report for a month. How this function generate the graph? The figure is per hour. Average or just select a point? Sam.
Will this monitor my traffic correctly?
I'm attaching a rough diagram of what my network looks like. If I'm monitoring "ingress" traffic where each of the arrow heads are at, will that catch all of the traffic on my network? At this point, I'm not concerned with traffic within the clouds and the Layer 3 switch at the bottom (the square) doesn't support Netflow. The most that I can see missing is traffic originating in the top router and destined for the world and traffic originating in the bottom two routers and destined for the LAN. The
Utilization Discrepancy
Hello NFA! I have an evaluation version of NFA v 5. I think I'm experienceing an Id10t error. (jk) Perhaps you can clarify for me. I am running NetFlow on my Gigabit interface 0/0. NFA shows a utilization that is the same as what the router displays. I happened to look at the sh ip flow export command and noticed that the interface was dropping packets due to "IPC rate limiting". So this brings me to two questions. What does this mean exactly? If this does mean that i'm loosing NetFlow Packets on
wrong interface maximum speed of router
hi, i am just wondering why the report of NetFlow Analyzer in the maximum speed of the interface we're monitoring was something funny. the report sez we have a maximum of 4.89 mbps while the real maximum speed we have is 2 mbps. how to fix it? Please help!!!!!
Unable to remove device group
Hello, I'm running NetFlow Analyzer 4 on Windows Server 2003. Whilst setting up the Analyzer, I created a device group, deleted all of the routers out of it (trying to get things all prettied up), but now find that it is listed in "Device Group" but is not deletable in Group Management. If I try to create a group with the same name, I'm told that the group already exists. Thanks in advance for any assistance. -Michael
Real Time View
I am wondering if there is a way to view stats as they are occurring and not just as they are collected over the course of an hour. I deal with users maxing out bandwidth by sending large email attachments, downloading large files or synching large accounting binders. I can see utilization when it jumps up over 100% but when I go in to look at the conversations it is giving me data collected over the period of an hour not the last few minutes.
Monitoring dual interfaces
I read the instructions on how to enable netflow on my cisco 1841 and have done so. The problem I have is that router has two serial interfaces and I cannot set two flow-export sources, or at least I don't know how to. I also see the one interface that I do have exporting netflow stats shows only IN traffic and no out. Any ideas how to fix these?
NetflowAnalyzer ver5 , receives only IN traffic and no OUT
HI AdventNet, great and very nice program. Previously i used NTOP and didnt like it very much. With NetflowAnalyzer there is a problem that I cant see the OUT traffic of the interface.. The IN is counted very good.. I suppose if NTOP showed both the IN and OUT then i dont have to enable anything on the router so N.A. can gt the OUT..Any ideeas?? Thanks a lot!! Oleg R.
TImeStamps
Hi All, We have been using NFA 4 for a few months now on our WAN link and it's opened our eyes considerably to our traffic and allowed us to manage it alot better. Thanks for great, very usable product. The small query I have relates to the times displayed. We have just changed in the UK to BST and now everything is 1 hour out. The NFA Server is running the correct time (BST), but all reporting appears as GMT. Is there a way to change it over? It is not a problem for me, but a little confusing when
Bandwidth usage for a particular timeframe on one year
Hi, Is there a way to gather the following information with Netflow Analyzer? Graph bandwidth usage between 9am and 17pm on a one year basis? (not a start date on 1/1/2005 and end date on 31/12/2005) Do the same for a particular protocol? Regards,
Real Time
Hello again, I have another question. This one about the real time reporting. The user manual says that NFA provides real time reporting. Does this mean that when i look at a traffic graph I'm seeing what the traffic really looked like at that last 10 minute interval? Or, does this mean that I'm going to see the data as it comes into NFA second by second? My impression of real time is that you see it as it happens, but i just can't seem to figure out how to view it. Thank you again for the help!
Netflow Installation
Hi, Can netflow be installed on the same server as OpManager or it would cause application conflic in terms of database and snmp ports? Thanks Ramzi
2950 Swiches
Can i control flow of the 2950 cisco Series Switches.
Device Group or Ip Group ?
Hi, I've got for my internet access to lines on two different routers. These two routers export netflow to your product. I would like to bundle these two internet lines. --> if i use Device group, i cannot select specific interfaces --> if I use Ip group, i'm able to slect specific interfaces but i need to define an ip range or a port range.... but for the internet, it's not really suitable. 0.0.0.0 mask 0.0.0.0 will work ? Any idea ? regards
SQL-Query MySQL-Database
Hallo, can i directly query the MySQL-Database? How is the structure of the MySQL-Database? Thanks Tom
Netflow analyzer - increase of Pooling interval?
Hi.. I just want to ask how to increase the pooling interval of NFA or is it possible to make it in seconds instead of minutes? pls help us how to do this. Thanks.
interface speed does not match (ver 5)
Hello, I just installed version 5 and exported data from my Cisco routers 3825 and 2821 running ios 12.4.4T1. I only enabled netflow on interface gigabit0/0. I see Two interface index 1 and 12 in netflow analyzer. Does anyone know why? It displays the interface speed is 1Mbps instead of 1000Mbps. How can I fix this? Thanks Phong
One Suggestion for NULL Interface
Hi, In my Cisco router I using rate-limit command on my subinterfaces, for all my clients group. I using MRTG and graphics from MRTG and NFA are identical with 40-50 Kbps differents. I understand where is the loss this 40-50 Kbits. This is the dropped packets (in NetFlow - destination interface is NULL). In MRTG I display traffic that clients received, in NFA I display traffic that router received for this clients. I HAVE ONE SUGGESTION: Added option in IP Group Management include or exclude NULL
traffic 2 IP addresss ( server ip's) how do I do it
I have 2 servers ( IP addresss ) and port numbers and I want track traffic and bandwidth 2 and from ... can I do it from my local pc without installing the software on the servers ?
Traffic flow
I have an issue where the traffic flow in and out options are grayed out. I can no longer monitor the bandwidth from the routers. It was working fine for one day and now I can't track anything. Any suggestions?
support for more than 100 interfaces?
I'd like to know if there are licensing options to support more than 100 interfaces. We have a customer that has been evaluating the trial version of NFA 4 and is very interested in purchasing a license to support more than 50 routers. Thanks in advance Jorge Mora
"Jump to " link in NF5
Hi! I have downloaded an evaluation copy of Netflow 5 and installed on the same server running Opmanager 6. When I use the "Jump To" menu at the top of the screen in Netflow 5 (to go back to OpManager) the link points to http://guma:6081. Can this be modified to use IP address or fqdn instead of localhost (guma:6081)? Jump to Link pointing from Opmanager6 to NF5 can be modifiad and is working fine. Thanks, Guma
Automatic reporting
Hi. Is it possible to have scheduled reports emailed to you as an administrator?
Next Page