Application Mapping with IP Networks
VoIP uses a large range of ports. I want to tag those ports coming to/from a specific network range as VoIP from that area. The problem is, the defined ranges talk to each other, natually. An IP in one range talks to an IP in another range during a phone call. For example: Ports 10000 - 20000 IP Network: 10.10.10.0/24 Application: VoIP Main Office Ports 10000 - 20000 IP Network 20.20.20.0/24 Application: VoIP Extension Office Ports 10000 - 20000 Application: VoIP (Generic) How is Netflow Analyzer
Get export of 3 month 1-minute data?
Is there a way to generate a text file export of the 1-minute data for a given device or interface? If not within the program itself, is there an exernal tool I can use? Thanks. ---John Holmes...
Problem with report attachments
Hello. I am receiving the following message regarding scheduled reports: Dear User, "This is an automated mail generated by Netflow Analyzer Report Generation Engine. Problem while sending the report.[ Problem could be of large File size" I wouldn't think the report size would be that big, but maybe I am mistaken. Suggestions would be appreciated. This is the first time I am attempting to use this feature. I am using version 6.1 build 6100 Netflow Analyzer Prof. Edition
application mapping and ip addresses
Pretty sure i've discussed this with support before, but I can't find the response. I'm wondering why if I create an App using a large range of ports and map it to a specific ip address. the tool still displays traffic that doesn't include that ip address For example, exchange, uses a lot of ports. I want to categorize anything to that IP address as exchange traffic. What get though is that App i created contains flows that are not sourced or destined to the IP i specified. Why is this? it seems
Archive old raw data
Hello! Our company used the Crannog NetflowTracker for collect Netflow raw data. And now the think to migrate to the NetflowAnalyzer. And we have question: How we can save or archive old raw data for longer period(more than 1 month)and use it to make the reports in NFA?
Monitor MS exchange traffic
Anyone have a good way to monitor Microsoft Exchange traffic with NFA? The Client ports are random, I haven't found a way to set up an application mapping for it. Thanks!
Supported Linux Versions?
Hello, Okay so we bought this software more than a year ago (we're on our second service contract) and we're finally getting some time to get it in place. We got a decent DL380 with a ton of disk, 4 3GB cores, and 4GB RAM. It's racked and powered and it's time to get the Unix team to give me an OS. They're suggesting we go with RHEL5 x86_64. Will you support that platform? Thanks, Daniel
NBAR support
How do I get Netflow Analyzer to read the NBAR data from a router? I do not have an SNMP write community name for the router. Can I get NBAR enabled on the router without a write community string?
Interfaces not appearing on dashboard
Hi. i downloaded the trial version of netflow analyzer onto a cisco 2610 router. i have confihured it as in the help section. i have enabled the netfloe command on all the interfaces. in the dashboard only the Ethernet interface comes up and none of the serial interfaces. if i do a "show ip cache flow" only the ethernet is sending data and none of the others is there any thing i can do other wise. below are some of the commands on the router interface Serial0/0 description " 512Kb Diginet to Roseville
Moving servers
Hi, I need to change the server that netflow is running on. Whats the best way to transfer all the settings / data / licensing to the new server? thanks
netflow auto-report generation
Hi AdventNet, Just a few suggestions, can you please take a look at the following: 1. Allowing us to change the text that gets sent to the customer in an auto-generated report. 2. Using External E-Mail addresses is a bit hard, we have to create contacts and distribution lists as Netflow scheduled reports sometimes fail with external E-Mail addresses in the destination. Is this a known issue? Regards, BlueFire
Netflow is broadcast?
Helo, I am using netflow im my full transparent network. Today I taked cognizance of netflow comunication betwen server and router is not jus betwen netflow server and router but also everywhre in my network. How is it possible? Or where is the problem?
Configuring interfaces, viewing global device flows
Hi, i'm using Netflow Analyzer in evaluation mode and I wonder how to remove unused interfaces that are not sending sflow anymore, or how to remove whole device ? There is a "Device interface" and I thought it was used to see all the in & out traffic in my device but it seems to be something else (it's not the sum of all other flows). Is there a way to see the global in & out traffic for a particular device ? Thanks a lot, the product seems quite good.
Compare and Contrast with other tools? ISP Market?
Hi, I am scouting for Netflow based tools for use in an ISP environment with about 20+ geographically distributed routers. We would like to do basic network intelligence gathering (top customers, top applications, etc) as well as detect for anomalies (mainly DoS, route misconfigurations, etc). The NetflowAnalyzer online demo looked quite impressive! Do you have any white paper that compares and contrasts NetflowAnalyzer with other Netflow tools, open source and commercial (nfsen, flowtools, Caligare,
DataBase query, generate customized reports
Hi All, We are looking to generate customizable reports after purchasing the netflow analyzer product. Basically, what we are looking for is to extract the (Min, Max, Average) for traffic field out from the consolidated reports for all the available interfaces in a router group, and join all these together in one report summarizing these data. This is needed urgently to generate some high level reports to the management. Now my request is, if possible we need to have the possible queries that will
A lot of usage from unidentified on Destination report
I've got a lot for usage from others (please see the attached file) What does that mean? Do I have any solution for this?
how come this netflow data can not be recognized ?
NetFlow Analyzer 4 can't recognize this netflow data (attached) NetFlow Listener Port::9000 do Someone know about that?
Netflow v9 being discared
Hi. I've just installed NFA v6.1, Professional Edition, Build 6100, but when try to configure my router to Netflow v9, this message appears on NFA: Receiving Non V5 / Non V7 packets from the following devices: Click here for further details. The help indicates V5 is the only version supported, although the message suggests v7 is also supported. On the other hand, the product page says: "The latest version of NetFlow Analyzer supports Netflow version 5, version 7 & version 9 exports." (http://manageengine.adventnet.com/products/netflow/cisco-netflow.html)
Attempting Installation
I have a computer that I use as a sniffer. It has two network cards in it. One that is attached to my network (so I can remote into it), and another that is attached to a mirrored (router) port on a 3Com 4400 switch. I cannot, for the life of me, figure out how to configure the NetFlow Analyzer to read from the network card on the computer. Does anybody else have the same type of setup? If so, how do you configure it? Thank you in advance... ShadowRayz
Installation
Dear sir, I am using 2811 series router for connecting my branch office , i want to view my bandwidth usage, so i downloaded and installed trial version of netflow but i cant able to export settings on a pc. My router is connected to a sonicfirewall PRO2640. site to site vpn is configured in our firewall ..kindly advice me on this thanks in advance. regards Jayakumar System Admin Chennai
Netflow on GRE Tunnel Problem
Are there any issues with Netflow running across a GRE Tunnel? I'm checking out various netflow products - trying out ManageEngine and on a Tunnel there is gap in the data. Could someone explain what the problem could be here? I have included a picture of it along with our router config - all the ips, etc.
Interface doesn't stay deleted
I have a Fastethernet interface with flow enabled I removed the unwanted interface using the License Manage feature It reappears daily. How can I remove this permanently? NOTE: The interface is a sub-interface of the main link i.e. IFIndex1 = main IFIndex15 = sub IFIndex3 = another interface I wish to permanently remove IFIndex15 = sub (NOTE2: there are no flow commands under the sub-interface only the main)
NBAR not working
NBAR MIB Support: Yes IfIndex1 Enabled Nothing shows on NBAR graph Works on 3640 Doesn't work on 3825? Also older IOS uses : ip route-cache flow Newer IOS uses: ip flow ingress ip flow egress NBAR works flawless from CLI
Netflow Analyzer Test Mail Failed
I am not able to successfully send the test mail from the "mail server settings" tab in the netflow settings. I have tried both the name of the mail server and the IP address. Have entered the default email address to send the mail too and the from address and am using port 25. Still continuously receive a "Test Mail Failed". Netflow Anaylzer is version 5.5.0
All group Guest
Hi, can you please add the capability of defining a guest user who gets everything. I have defined a guest user and make this userid/password generally available but every time I add a new group of anything I need to go back into this guest user and specifically add it to this user. What I need is a guest user that gets ALL groups. Or have you added feature this recently?
NFA 6100 on Linux
I am testing the new version. When I display the last hour of statistics for a link and then select the application TAB I see the entry TCP_APP and then after this I see the optioin 'Show Ports'. This is new on this latest version and is very useful. However, when I then select a different period of time for the report this extra option disappears so I cannot see which ports were used. Why is this?
NFA 6100 on Linux and renaming routers
I wish to change the name of the Router displayed in the Device Group display. I try but NFA won't let me. Rather it allows me to change it but completely ignores the change. I have no problem changing the name of the interface on that router. Why is this?
NFA Professional vs NFA Enterprise?
dear admin... im newly about this netflow stuff. i've been tried to login your demo site NFA professional edition, i see the AS number report, well that's one point that i like from it. but.. i dont see any demo site for for enterprise edition, so i used your trial version, but there's no AS number report. and what is the different with two of them? cause, i will recomend this application to my boss at the future. :D. regards anderson
NBAR on Ethernet subinterface
Hi, I created an ethernet subinterface FastEthernet0/1.1 on a Cisco 2811 router and enabled nbar on the interface. From the router the command sh ip nbar protocol-discovery interface fastEthernet 0/1.1 is working fine however NFA does not seem to be collecting any NBAR information. Is there a way to fix this problem. interface FastEthernet0/1.1 description Primary Link bandwidth 6000 encapsulation dot1Q 1 native ip address x.x.x.x x.x.x.x ip access-group traffic-in in ip access-group traffic-out
netflow exp ver to use,how to remove unused int,
Hi, i am testing the Netflow Analyzer EE 6.0.0 I have done the basic netflow configuration, and i am getting the information on the analyzer. I have 2 questions to ask. 1-->Intially i configured a router's (lets say router-X) 2 interfaces for netflow, and then due to some reason, i deleted the config (including export) and then reconfigured the device for 3 different interfaces. But now my dashboard shows the same router in 2 different categories, 1 new one, and 1 old one. How can i delete the old
netflow exp ver to use,how to remove unused int,
Hi, i am testing the Netflow Analyzer EE 6.0.0 I have done the basic netflow configuration, and i am getting the information on the analyzer. I have 2 questions to ask. 1-->Intially i configured a router's (lets say router-X) 2 interfaces for netflow, and then due to some reason, i deleted the config (including export) and then reconfigured the device for 3 different interfaces. But now my dashboard shows the same router in 2 different categories, 1 new one, and 1 old one. How can i delete the old
netflow is showing speed higher then link speed
Hi We are facing problem.Our netflow analyzer 6 shows speed higher then links speed. We have E1 (2Mbps) internet link.Interface is also configured on 2000000bps, but netflow some time shows speed 2.22Mbps, more then link speed.And if i get stats of one month, then it shows maximum speed 3.63Mbps.Which is impossible.Can anybody help me out what is the issue?
NAT and report destination
I have installed Netflow Analyzer 6 to view and account traffic produced by users on my LAN from a router Cisco to and from Internet. But all internal IP addresses are natted on router's outside interface and the destination-out report of inside interface shows only NAT IP address (that is outside interface IP) , and so I am not be able to account how many bytes are forwarded to every internal user. I think that is since NetFlow traffic accounting is ingress by default, only IN traffic across an
ETA on new version?
Just checking to see when the next version of NFA comes out with the billing piece attached to it. Thanks, Steve T.
Monitoring dashboard
Hi all I would like to use the Netflow Analyser graphs in order to build a Monitoring dashboard of our network. We actually use MRTG in order to build some Internet Pages on the response time between two sites, the bandwidth used and so one... Netflow Analyser is much better that what we have ( except for the response time =) ) and I would like to use that tool to generate automatic pages to be displayed in our Monitoring Dashboard. For example, page one will be the response time between two sites,
New function for different management?
Does anybody know in the new Version,Netflow can provide below function or not? Description: Different person has different rights to reach different interface. Means for A person has the admin right to his interface and can do nothing to other interface. Currently the right only has the user and admin. Many thanks for your feedback.
wrong interface speed
I have tested NFA , and netflowed two outbound interfaces of cisco7609 . Some questions : Q1,it seens it's not correct of that it shows the interface utilization is 0% . It captures the interface bandwidth in right snmp property and a community string. And the true speed is above 200Mbps of 10G . The configuration of 7609 : ip flow-cache timeout active 1 mls ip multicast flow-stat-timer 9 mls netflow usage notify 60 120 mls flow ip interface-full no mls flow ipv6 ip flow-export source Loopback1 ip
Custom Reporting
We have two routers that terminate our Internet connections. Each router also has two Ethernet connection -- one towards the corporate environment and one towards the ASP side. I need to be able to report on how much of the Internet bandwidth that the ASP side is using. Note that traffic can go from any interface to any other interface, so measuring the flows on the Ethernet facing the ASP won't give the desired result. Can anyone point to a URL or instruction on how to do that? -- Aaron
About monitoring of IN/OUT data
Dear all, I am use a neflow Analyzer 5.0. I have a problem of IN/OUT data. In My one leased line Delhi 2 Mbps. I am not able to received data of Out traffic. Please provide me a troubleshooting.
wrong interface speed
I have tested the NFA,but that it collected the data seens not correct. The flowed interface is 10GA , and the true speed is above to 200Maps. But the GUI shows just 0% of the interface in . the configuration of 7609: global set: ip flow-cache timeout active 1 mls ip multicast flow-stat-timer 9 mls netflow usage notify 60 120 mls flow ip interface-full no mls flow ipv6 ip flow-export source Loopback1 ip flow-export version 5 ip flow-export destination ******* 9996 ip flow-aggregation cache prefix
Next Page