Part I: Overview. Core concepts presented:



Similar documents
Network Monitoring and Management Introduction to Networking Monitoring and Management

Network Management & Monitoring Overview

Introduction to Network Monitoring and Management

AfNOG 2010 Network Monitoring and Management Tutorial. Introduction to Networking Monitoring and Management

Network Management & Monitoring Overview

Network Management & Monitoring Overview

Introduction to Network Monitoring and Management

Robust & Reliable DNS Operations Logging & Monitoring

Network Monitoring and Management Introduction to Networking Monitoring and Management

Chapter 6.2: Network Management

Network monitoring systems & tools

Network Monitoring and Management Tutorial: SANOG 2015

The 7 th International Scientific Conference DEFENSE RESOURCES MANAGEMENT IN THE 21st CENTURY Braşov, November 15 th 2012

Details. Some details on the core concepts:

Free Network Monitoring Software for Small Networks

Network Monitoring. Sebastian Büttrich, NSRC / IT University of Copenhagen Last edit: February 2012, ICTP Trieste

CARENET-SE. NOC Tools Review. Communication System Design Summer Project team. Champion Björn Pehrson Coach Hans Eriksson

Monitoring Tools for Network Services and Systems

Network Monitoring. Review of Software

Tk20 Network Infrastructure

CAREN NOC MONITORING AND SECURITY

Empowering the Enterprise Through Unified Communications & Managed Services Solutions

Operations Management Network Monitoring and Management

The Importance of Information Delivery in IT Operations

How To Create A Ticketing System With Rt.Org

Network Management and Monitoring Software

Network Monitoring. Lance Rea. Davis & Gilbert LLP lrea@dglaw.com

Module 1 Study Guide

Work Item C: NOC tools, interworking/interfacing issues, and automation

INASP: Effective Network Management Workshops

Network Monitoring Tools for Monitoring MPLS Links using PRTG Network Monitor Tool

KENET NETWORK INFRASTUCTURE. KENNEDY ASEDA

Operations Management and Open Source Tools

ITOPIA SERVICE LEVEL AGREEMENT

Cisco Unified Computing Remote Management Services

Ticketing Systems with RT

Network Management & Monitoring Ticketing Systems with RT

Best of Breed of an ITIL based IT Monitoring. The System Management strategy of NetEye

WHITE PAPER. Automated IT Asset Management Maximize Organizational Value Using Numara Track-It! p: f:

Fifty Critical Alerts for Monitoring Windows Servers Best practices

G DATA TechPaper #0275. G DATA Network Monitoring

Service Offerings. Ensuring IT Resources are available, reliable, scalable & manageable always.

OpManager MSP Edition

Improving. Summary. gathered from. research, and. Burnout of. Whitepaper

PC Proactive Solutions Technical View

Delivering actionable service knowledge

Network Performance + Security Monitoring

Open Source Network Monitoring Tools

MSP Service Matrix. Servers

APPENDIX 8 TO SCHEDULE 3.3

Edu. Network Management Framework: A Distributed Virtual NOC Architecture. DVNOC Model. Octavian RUSU octavian@iasi.roedu.net

INASP: Effective Network Management Workshops

Automated IT Asset Management Maximize organizational value using BMC Track-It! WHITE PAPER

Aurora365 White Paper. Establishing a Network Operations Centre (NOC) Culture with Aurora365

SERVICE LEVEL AGREEMENT

Operation and Technical Best Practice. IXP Automation and Operational Efficiency

CNE Network Assessment

Ticketing Systems and Documentation

How To Protect A Network From Attack From A Hacker (Hbss)

White Paper. The Ten Features Your Web Application Monitoring Software Must Have. Executive Summary

GRNET NOC network monitoring & visualization tools

Our Server Support. Looking after your servers giving you peace of mind. Document Version Revision Date Feb 2015

Monitoring Microsoft Exchange to Improve Performance and Availability

SPRINT MANAGED NETWORK SERVICES PRODUCT ANNEX ( MNS Terms and Conditions )

AfNOG Monitoring of IP Services. Ayitey Bulley Material generously borrowed from the NSRC NME course

Managed Support Policy

Top 3 Issues and Questions (in Network Monitoring!) Developing a Network Monitoring Architecture! infotex. Dan Hadaway CRISC Managing Partner, infotex

Service Level Agreement and Management By: Harris Kern s Enterprise Computing Institute

Internet Services. Amcom. Support & Troubleshooting Guide

MANAGED SECURITY SERVICES RESPONSIBILITIES GUIDE July 2013

Managed Internet Service

Network Documentation & Netdot

Achieving Service Quality and Availability Using Cisco Unified Communications Management Suite

Operations Manager Comprehensive, secure remote monitoring and management of your entire digital signage network infrastructure

Report of Independent Auditors

Information Services. Standing Service Level Agreement (SLA) Firewall and VPN Services

Using Application Response to Monitor Microsoft Outlook

Network and Server Statistics Using Cacti

Radware s AppDirector and AppXcel An Application Delivery solution for applications developed over BEA s Weblogic

Tue Apr 19 11:03:19 PDT 2005 by Andrew Gristina thanks to Luca Deri and the ntop team

Exhibit E - Support & Service Definitions. v1.11 /

Best Practices from Deployments of Oracle Enterprise Operations Monitor

APPENDIX 8 TO SCHEDULE 3.3

OSU INSTITUTE OF TECHNOLOGY POLICY & PROCEDURES

BridgeConnex Statement of Work Managed Network Services (MNS) & Network Monitoring Services (NMS)

USING OPEN SOURCE SOFTWARE IN DAILY ISP OPERATIONS

How To Use Mindarray For Business

Finding Network Security Breaches Using LiveAction Software to detect and analyze security issues in your network

Information Technology Services

Transcription:

Part I: Overview Core concepts presented: What is network monitoring What is network management Getting started Why network management Attack detection Consolidating the data The big picture

What is network monitoring? Anyone have some ideas? Monitoring an active communications network in order to diagnose problems and gather statistics for administration and fine tuning. The term network monitoring describes the use of a system that constantly monitors a computer network for slow or failing components and that notifies the network administrator in case of outages via email, pager or other alarms. It is a subset of the functions involved in network management.

What is network management? Refers to the broad subject of managing computer networks. There exists a wide variety of software and hardware products that help network system administrators manage a network. Network management covers a wide area, including: - Security: Ensuring that the network is protected from unauthorized users. - Performance: Eliminating bottlenecks in the network. - Reliability: Making sure the network is available to users and responding to hardware and software malfunctions.

What is network management? System & Service monitoring Reachability, availability Resource measurement/monitoring Capacity planning, availability Performance monitoring (RTT, throughput) Statistics & Accounting/Metering Fault Management (Intrusion Detection) Fault detection, troubleshooting, and tracking Ticketing systems, help desk Change management and configuration monitoring

Getting started Make sure that the network is up and running. Thus, we need to monitor it: Deliver projected SLAs (Service Level Agreements) Depends on policy What does your management expect? What do your users expect? What do your customers expect? What does the rest of the Internet expect? Is 24x7 good enough? There's no such thing as 100% uptime (as we ll see)

Getting started: Uptime What does it take to deliver 99.9 % uptime? 30.5 x 24 = 762 hours a month (762 (762 x.999)) x 60 = 45 minutes only 45 minutes of downtime a month! Need to shutdown 1 hour / week? (762-4) / 762 x 100 = 99.4 % Remember to take planned maintenance into account in your calculations, and inform your users/customers if they are included/excluded in the SLA How is availability measured? In the core? End-to-end? From the Internet?

Getting started: Baselining What is normal for your network? If you ve never measured or monitored your network you need to know things like: Load on links Jitter between endpoints Percent usage of resources Amount of noise : Network scans Dropped data Reported errors or failures

Why network management? Know when to upgrade Is your bandwidth usage too high? Where is your traffic going? Do you need to get a faster line, or more providers? Is the equipment too old? Keep an audit trace of changes Record all changes Makes it easier to find cause of problems due to upgrades and configuration changes Keep a history of your network operations Using a ticket system let you keep a history of events. Allows you to defend yourself and verify what happened

Why network management? Accounting Track usage of resources Bill customers according to usage Know when you have problems Stay ahead of your users! Makes you look good. Monitoring software can generate tickets and automatically notify staff of issues. Trends All of this information can be used to view trends across your network. This is part of baselining, capacity planning and attack detection.

Attack Detection Trends and automation allow you to know when you are under attack. The tools in use can help you to mitigate attacks: Flows across network interfaces Load on specific servers and/or services Multiple service failures

Consolidating the data The Network Operations Center (NOC) Where it all happens Coordination of tasks Status of network and services Fielding of network-related incidents and complaints Where the tools reside ( NOC server ) Documentation including: Network diagrams database/flat file of each port on each switch Network description Much more as you'll see a bit later.

The big picture - Monitoring - Data collection - Accounting Notifications - Change control & monitoring - Improvements - Upgrades Ticket Ticket - NOC Tools - Ticket system Ticket Ticket Ticket - User complaints - Requests - Capacity planning - Availability (SLAs) - Trends - Detect problems - Fix problems

A few Open Source solutions Performance Change Mgmt Cricket Mercurial IFPFM Rancid (routers) flowc mrtg RCS netflow Subversion NfSen Security/NIDS ntop Nessus pmacct OSSEC rrdtool Prelude SmokePing SNMP/Perl/ping Samhain Ticketing SNORT RT, Trac, Redmine Untangle Net Management Big Brother Big Sister Cacti Hyperic Munin Nagios* Netdisco Netdot OpenNMS Sysmon Zabbix