Internet router only shows firewalls publc IP not private IP
Hi, our ISP added the Netflow settings our Cisco 2600 which is our Internet router, it's a 10mb lease line. The Cisco 2600 connects to a VLAN on our Cisco 2950 catalyst where our Cisco Pix's "outside" interface also connects. When I run Netflow and see traffic outbound it shows our Cisco Pix's public outside IP always and not say an internal private IP of a server or a users PC's private IP. I know the firewall PAT's all internet traffic and it's internal IP is Natted to a public IP, but is there
What 2 interfaces to monitor
Hi, I have a Cisco 877 ADSL router. It is based in a remote office setup in VPN mode to my HQ. I am using the free version of Netflow (2 interfaces) on an Windows XP PC at the remote site. What interfaced should I monitor? I ham VLAN 1, Dialer 1 and ATM 0? At first I monitored VLAN 1 and dialer 1 and I copied a 500mb from the HQ to the remote site, it finished after 10 mins, so I looked at Netflow over that period on both interfaces and it only said that PC 1 at the HQ copied 10mb to PC 2 at the
Give friendly names to source & destination IP's
Hi, I use the conversation tab a lot. I know I can click the resolve DNS option but this can take ages, can I give the IP's friendly names so my team know exactly what the IP's are? Thanks
Backing up Netflow?
Hi, I have just realized that I don't backup Netflows data, what do I need to backup? Thanks
Thinking of switching on NBAR monitoring
Hi all I am thinking of enabling NBAR reporting for all our routers. How much would this increase the database size and how much more network traffic would it cause? Thanks
NFA 6.1 and maximum number of IP groups
What is the rule of thumb on how many IP groups can be configured? IS there any relation between this and the number of devices/flows?
No last hour graphs
Hi, There is no graph displayed in Device View - Application/Source/Destination page selecting Last Hour Report. (Traffic graph displayed) Any other report graph in this pages displayed correctly. Selecting Last Hour Report in IP Group View - Application/Source/Destination page displayed correctly. Build Number : 6001 Is this a bug?
NBAR unknown application
Hi, I'm getting high usage of unknown application from NBAR. From Netflow application, the only high bandwidth usage is microsoft-ds, so can I assumed that the unknown reported by NBAR is windows application. If it's correct, why is NBAR not able to identified microsoft applications or it is because Cisco's PDLMs is not able to identify. FYI, I'm running Netflow Analyzer Pro.6.1 and report also attached Many thanks. Regards, Morshidi Saufi
How do I setup the ip flow-cache timeout active to 1?
I am using the Professional Trial version of Netflow Analyzer 6. I need to change the ip flow-cache timeout active to 1. Where do I make the change? :roll:
ETA of SP for upgrade to 6.1
Hello, It has been > a month since the release of 6.1 and I was hoping to upgrade my 6.0 release to this version since it has a lot of benifits that my users have been looking for. Is there an ETA for this release? Thanks, Jeremy
NBAR enabled but not showing in Netflow Analyzer
Quick question- I am evaluating this product, Netflow Analyzer, and would like to check out the NBAR function. Following the guide, I have enabled NBAR on my 2610XM router running "c2600-is-mz.122-16.bin". At the console, I receive an output from "show IP NBAR Protocol-discovery", so I know it is working. However, when I go to Netflow Analyzer I show "NBAR MIB Support: NO" under the device. I click on "set SNMP parameters" and choose update, no luck. I then go to the NBAR configuration page and check
NFA Enterprise Edition 6 released !
We are glad to announce the availability of NetFlow Analyzer Enterprise Edition 6.0 with the following features. 1. Selectable Graph: Drag and drill on the graphs for faster troubleshooting 2. Application Group: Create user-defined application groups by putting together existing applications 3. Interface Group: Create your own logical monitoring entity by grouping together interfaces For more information please visit http://manageengine.adventnet.com/products/netflow/distributed-monitoring/index.html
Need to reset customer's Netflow 6 Admin password
Hello, I am trying to administer a customer's Netflow 6 Installation, but they have forgotten the admin password for the web UI. Could someone please send me the utility that is used to reset the admin password on netflow 6? Thanks so much! Ryan Ticer Quest Media and Supplies
Netflow failed to run
I successfully installed Netflow Analyzer in Fedora Core 6 without a problem but when I run the 'run.sh' script it failed to start and here's the error message I get. The DBPort :: [13310] has been occupied by some other application (or) some other MySQLDB instance. Please free the port. Is there any workaround with this issue? Did I do something wrong during the installation? Please help. I'm evaluating several Netflow Colletors software including this one for our network environment. Nel
Customize usergroups, perhaps user templating?
Hi all, is it possible to create customized usergroups, or perhaps create users using different templates? We are in the process of rolling NFA out and are creating the first operator users. These can have different views, like all devices or just a selected few. Now there is no choice "all", but you must allow the new operator to view all devices by selecting them and adding them to his profile - and thats my problem. Due to the continous addition of new devices (about 10-15 each week) to NFA, right
Problem Installing WiFiManager
I cannot get WiFi Manager to install. Here is the message I get: Install product in current directory? Type Yes (y) or No (n):y expr: non-numeric argument ./ManageEngine_WiFiManager.bin: line 308: [: -ge: unary operator expected Not enough space to install. Quitting installation. Any ideas? I am installing this trial on Red Hat machine for evaluation. Have tried several locations but always same error. Space is NOT and issue on this server I am installing on. If anyone knows what this means and how
Run Netflow Analyzer on Virtual Server instance?
We are currently running Netflow Analyzer on a Windows 2003 Virtual Server with 3Ghz Xeon & 3GB Memory allocated to us. Netflow Analyzer runs painfully slow on this setup. Does anyone have experience with running Netflow Analyzer on a virtual server? Does it work well? Or is this practice not recommended? If we up our virtual server's hardware allocation to what is recommended by AdventNet, should we be fine with that setup? Any thoughts/suggestions would be much appreciated. thank you, Geoff
IPCAD (IP Cisco Accounting Daemon)
I am using IPCAD to create netflow data from a span port that I am monitoring. The software is working well and I am getting data. My question is related to the in/out traffic. They show as both the same, which makes some of the reports and graphs meannigless. In a regular setup, you would have two netflow interfaces. One inbound and one outbound. I only have one, but it has both inbound and outbound traffic in it. Is there anything I can do to make this more usable? John
Run Netflow Analyzer on a Virtual Server?
Currently we're running Netflow Analyzer 5 on a Microsoft 2003 Virtual Server with a 3Ghz Intel Xeon and 2GB of memory. We're trying to monitor 250 interfaces and we find Netflow Analyzer to be VERY slow. Sometimes we login and wait almost 5 minutes for it to even come up. Is the problem the fact we're running it on a virtual server or the hardware spec'd out for it? We're hesitant to upgrade to Netflow Analyzer 6 because that will probably require even more resources to run. Any suggestions to improve
Server full with NetFlow data
How can I free some space on my server? I am running NetFlow Analyzer, but disk is almost full.
About monitoring of IN/OUT data
Dear all, I am use a neflow Analyzer 5.0. I have a problem of IN/OUT data. In My one leased line Delhi 2 Mbps. I am not able to received data of Out traffic. Please provide me a troubleshooting.
Detailed monitoring
Hi, I'd like to know if it is possible to use Netflow Analyzer to monitor my local user's web browsing activities. What i want, is a list of what URLs were accessed by which ip address on my lan. I know netflow can list IP addresses, but thats unfortunately won't tell me what URL was visited. I have a Cisco 876 router and I'm using NAT to provide internet access for my lan users. Currently NBAR is not installed, but if it's needed to accomplish the task, I can upgrade the IOS to include NBAR support.
Open Old netflow data
Hello, I am trying to get some graphs from a IP range that I removed from the IP Group Management, I believe the Data is still on the HDD as we have a 200Gb Drive and Netflow is using around 140Gb. If someone knows a way to view this data for a range of 3 IP's that would be great. Thanks! Jared
Save a custom report?
Hi all, is it possible to save a custom report? Background is that we have loads of interfaces, and want to directly analyze the traffic to and from one specific, central IP in regards to the used ports. The best way seems to generate a custom report, but each time we need to click all the interfaces to poll - altogether something roundabout 100 IF's. So it would be very comfortable to be able to save custom reports and call on them later. It might well be possible that i have missed some other option,
GRE Issues
netflow configured on a router with GRE Tunnel. Data only shows up occasionally even though udp packets are alwasy getting to the collector, although they seem to be fragmented most of the time. Are there any known issues with GRE Tunnels and netflow? Currently MTU size is 1440. Should that be adjusted?
Do more with NetFlow Analyzer
This is a series of articles on how you could derive more value from the NetFlow Analyzer. As the name suggests, these articles/posts are meant to be readily useful to network administrators/managers in their work. If you think you have been able to use NetFlow Analyzer to address a unique requirement in your network, please feel free to share it here. Thanks in advance Raghu
NO TRAFFIC IN AND OUT AT THE SAME TIME
We have a problem here, we cant see in the netflow analyzer console the traffic IN and OUT at the same time in any one of my interfaces, would you help me with this, please? Im attach the command show ip cache flow with the screenshoot of the problem! Thank you!! sh ip cache flow IP packet size distribution (228880310 total packets): 1-32 64 96 128 160 192 224 256 288 320 352 384 416 448 480 .000 .417 .098 .047 .019 .011 .040 .007 .006 .005 .007 .005 .003 .002 .002 512 544 576 1024 1536 2048 2560
All Destination Addresses showing as 0.0.0.0
I have set up a 10720 router to export the following Netflow stats: source-prefix, dest-prefix, source-prefix-tos, dest-prefix-tos and protocol-port-tos. In NetFlow Analyzer, all the flows are showing under the conversations tab, but for some reason ALL the detination addresses are showing as 0.0.0.0. Doing the show ip flow cache command shows that both source and destinationaddresses are there. Any ideas?
Manage Engine Netflow Analyzer v.4 Database Structure
Hi, I am in desperate need of the structure of the database(database schema), as my all work is on a hault because of the same, please is there anybody who can help me out.......PLZZZZZZZZZZZZZZZZZZZZZZZZZZ
Problem with Reports - File to large
I get the error below when I try to send a report. I have sent reports in the past while testing out NetFlow with no issues, but recently I get an error message sent. This error happen when set to send zipped or as a pdf. ====================== EMAIL ====================== Dear User, This is an automated mail generated by Netflow Analyzer Report Generation Engine. Problem while sending the report.[ Problem could be of large File size Report details:Report Type :Consolidated Report Report Generation
No out traffic record
anyone help please.. I installed netflow6 to monitor branches and head office traffic...... by using PFSense (www.pfsense.org) as the GW. It has the internal package called pfflowd that forward all out and in package through port 9996 to NF. I enabled netflow both interfaces but it only detected and showed only one interface named: IfIndex-1 but.......no out traffic recorded Any idea on this problem Thanks
Interface groups?
is it possible to, or are there any plans to create "Interface groups"? I want to have the ability to create groups of interfaces in the same fashion that we can create groups of devices in order to assign users rights to see statistics from only select interfaces on select devices. I see that there is an interface group feature that allows you to group multiple interfaces into one monitoring entity, but this is not what I want. Thanks...
NFA 6.0 and Riverbed Steelhead WAN Optimization Appliance
We have WAN optimization appliances called Riverbed Steelhead among our Data Center and 2 of our biggest remote sites. NFA are getting Netflow data from our Cisco Routers but the problem is the bulk of the traffic being seen are those optimized data to and from the Riverbed appliances. In the top Application Report, NFA just sees them as TCP_App. We found out that you can enable Netflow on the Riverbed Appliance. Do you support Netflow traffic coming from Riverbed Steelhead appliance? If yes, how
No Out traffic, and also tiny traffic rates being displayed
I am using a J4350 and exporting version5 netflow data to the Netflow Analyzer. This router has 4 Ge interfaces and we have netflow sampling configured inbound on all 4 interfaces. The sampling rate we are using is 1 in 200 packets and a run-rate of 4, so that we should be sampling 5 out of 200 packets. 1) do we need to make modifications to the Netflow Analyzer to take this into account. 2) how do we get outbound traffic to be showing up in the GUI. Thanks
Netflow Configuration for VLANs on 3550 Switch
I enabled netflow on 3550 switch and was able to see the interfaces but there was no OUT traffic, only the IN traffic. I enabled ip route-cache flow on all VLANs but i am only getting the IN traffic and no OUT. Any help is appreciated.
Problems enterprise collector 5410
hello! i installed the collector (everything works with netflow analyzer PROF 6.0 though!) on the same machine with the reporting server. -> i see flows in the collector (green marks) but NO traffic whatssoever! its say... netflows received (increasing number) but the log says: [11:44:18:827]|[11-25-2007]|[SYSOUT]|[INFO]|[24]|: Request timed out for router with request id:3:for router:1| [11:44:19:228]|[11-25-2007]|[SYSOUT]|[INFO]|[22]|: if count from db = 11| [11:44:19:759]|[11-25-2007]|[SYSOUT]|[INFO]|[22]|:
Extreme networks alpine switch, not getting outbound trafic
Hello I�m running demo version Netflow analyzer 6.1 collecting sflow data from Extreme networks Alpine switches. Analyzer only shows me the inbound not the outbound traffic of any interface. Tried to put in 1, 2� 10 and all interfaces... But it was all the same. Configured ports and sflow several times but without results.. In each and every instruction you are concentrating on Cisco gear. Can you send me proper configuration for Extreme xos and extremeware switches. I have to mention that my company
Extreme networks switches- no output on interfaces, problem
I'we seen lot's of posts with same problems not geting output on ports. Each and every time youve suggested to have flow export on all ports. Since i'we enabled sflow on all ports on switch and geting same result, question is what to do.. I tryed on several diferent switches with same results.. If you could good enough to specify exact sflow configuration on extreme xos or extremeware switches...
IP group traffic double counting
Hi, I am trying NFA version 6. I have a site and a central location. Both routers, at the site and the centre are reporting to the NFA. When I look at the IP group for the site, I can see double of traffic. The graphs of the routers' interfaces are showing normal status. For example, I have 1 MB link between the centre and the site. It is fully utilized by sending data from centre to the site. Outgoing interface on centre shows 1MB speed; inbound interface on the site shows 1 MB speed. The IP group
DNS / NSLookup Server tables
Can you please add/include a tool which will allow the users to add to the DNS lookup tables to include local servers as well as external sources such a RIPE, ARIN, etc. We have a spread of incoming traffic over MPLS and what to add the local country DNS and also global DNS resolution so we can get the complete picture in one go. Regards
Next Page