An HP PrCurve Netwrking Applicatin Nte Traffic mnitring n PrCurve switches with sflw and InMn Traffic Sentinel Cntents 1. Intrductin... 3 2. Prerequisites... 3 3. Netwrk diagram... 3 4. sflw cnfiguratin n PrCurve switches... 3 4.1 Cnfigure destinatin cllectrs... 3 4.2 View destinatin infrmatin... 4 4.3 Activate sampling and plling... 4 4.4 View sampling and plling statistics... 4
5. Traffic mnitring with InMn Traffic Sentinel... 5 5.1 Cnfigure basic settings... 5 5.2 Set up traffic mnitring... 7 5.3 Traffic views... 9 5.4 Reprting... 11 6. Reference dcuments... 13 HP PrCurve Netwrking 2
1. Intrductin This applicatin nte presents the mnitring and reprting capabilities f InMn Traffic Sentinel n PrCurve netwrk equipment using the sflw prtcl. The applicatin nte fcuses n InMn Traffic Sentinel cnfiguratin. Fr mre infrmatin n the sflw prtcl (histry, prtcl descriptin, and benefits) and its implementatin and cnfiguratin n PrCurve switches, please refer t PrCurve Applicatin Nte AN-S6, Traffic Mnitring with sflw and PrCurve Manager Plus. 2. Prerequisites This prcedure assumes yu have a netwrk cntaining PrCurve switches, with traffic mnitred by InMn Traffic Sentinel. 3. Netwrk diagram Figure 1 details the hardware cnfiguratin referenced in this sectin. Figure 1. Setup fr mnitring traffic flw with InMn Traffic Sentinel The platfrm used t illustrate traffic mnitring cnsists f: One r mre servers with the fllwing services: Active Directry, DHCP, DNS, Certificate Authrity, IAS PrCurve switches: 5406zl, 3500yl, 2610-PWR InMn Traffic Sentinel versin 3_0_22 4. sflw cnfiguratin n PrCurve switches InMn Traffic Sentinel uses the sflw prtcl fr traffic mnitring. This sectin prvides the cmmand syntax fr cnfiguring sflw n a PrCurve switch. 4.1 Cnfigure destinatin cllectrs On each switch, three destinatins (cllectrs) can be cnfigured: 5406zl(cnfig)# sflw <1-3> destinatin <IP-addr> <udp-prt-fr-sflw> Fr example, t cnfigure destinatin 1 t be 10.3.108.36: 5406zl(cnfig)# sflw 1 destinatin 10.3.108.36 The default UDP prt used fr sflw is 6343. HP PrCurve Netwrking 3
4.2 View destinatin infrmatin T view infrmatin abut a destinatin: 5406zl(cnfig)# shw sflw <1-3> destinatin Fr example: 5406zl(cnfig)# shw sflw 1 destinatin Destinatin Instance : 1 sflw : Enabled Datagrams Sent : 557592 Destinatin Address : 10.3.108.36 Receiver Prt : 6343 Owner : 10.3.108.36;prcurve-server.pract... Timeut (secnds) : 415 Max Datagram Size : 1400 Datagram Versin Supprt : 5 4.3 Activate sampling and plling T activate sampling n a set f switch prts, use: 5406zl(cnfig)# sflw <1-3> sampling <prts-list> N Where N is the number f sampled packets. N can vary between 0 (sampling disabled) and 16441700. Fr example: 5406zl(cnfig)# sflw 1 sampling all 500 T activate plling n a set f switch prts: 5406zl(cnfig)# sflw <1-3> sampling <prts-list> P Where P is the interval in secnds between tw plls f cunters. P can vary between 0 (plling disabled) and 16777215. 4.4 View sampling and plling statistics T view sampling and plling statistics: 5406zl(cnfig)# shw sflw 1 sampling Prt Sampling Drpped Plling Enabled Rate Header Samples Enabled Interval ----- + ------- -------- ------ ---------- + ------- -------- A1 Yes(1) 60 128 0 Yes(1) 20 A23 Yes(1) 60 128 0 Yes(1) 20 A24 Yes(1) 60 128 0 Yes(1) 20 B24 Yes(1) 60 128 0 Yes(1) 20 HP PrCurve Netwrking 4
5406zl(cnfig)# shw sflw 1 sampling A1 Prt Sampling Drpped Plling Enabled Rate Header Samples Enabled Interval ----- + ------- -------- ------ ---------- + ------- -------- A1 Yes(1) 60 128 0 Yes(1) 20 5. Traffic mnitring with InMn Traffic Sentinel This sectin uses a data center example t explain hw t set up traffic mnitring using InMn Traffic Sentinel. 5.1 Cnfigure basic settings T cnfigure basic settings fr InMn Traffic sentinel: 1. Access Traffic Sentinel frm its web interface. 2. Brwse t the File Cnfigure menu. There yu have three ptins: The Shw tab shws yu the actual cnfiguratin. The Edit tab allws yu t mdify the cnfiguratin. The XML tab enables yu t imprt r exprt a cnfiguratin in XML frmat. 3. Select the Edit tab. In the Edit tab yu have the fllwing ptins: HP PrCurve Netwrking 5
Edit Site enables yu t define the name and cntact infrmatin, and als t input yur license key: Edit Znes allws yu t divide yur netwrk int different lgical znes, and within these znes t define grups f subnets, agents, interfaces. Fr example, a zne can physically crrespnd t a site, and grups can crrespnd t different buildings within the site. 4. In this data center example, yu create ne zne, crrespnding t the whle data center, and 10 grups (labeled Area 1, Area 2, etc.) crrespnding t the different slutin areas. Yu create a distinct grup, called BackBne, fr the netwrk backbne: 5. Fr each grup yu can define agent ranges. Then yu g t Edit Agents t define the individual agents crrespnding t the netwrk equipment: 6. Within the File Cnfigure Edit view, yu can define threshld settings and SNMP parameters. HP PrCurve Netwrking 6
7. Finally, yu can g t Edit Sampling Settings t define sampling rates fr the different interface speeds: 5.2 Set up traffic mnitring T set up traffic mnitring: 1. Select Traffic Status t see an verview f status f the different traffic metrics fr each zne and grup: HP PrCurve Netwrking 7
2. T view mre details abut a particular metric, click n ne f the clred square indicatrs. Fr example, yu ntice that the BackBne grup is experiencing heavy multicast traffic (in red) and yu want t determine which machines r applicatins are causing this multicast. Click n the square red BackBne indicatr t display the list f sflw agents, crrespnding t the switches f the grup. In this example, the tp 10 interfaces with multicast traffic are listed: 3. Anther way t have a gd verview f what is generating traffic n the netwrk is t use the circles functin (Traffic Circles): This gives a graphical representatin f the mst imprtant cnnectins between machines n the netwrk. HP PrCurve Netwrking 8
4. Yu can then click n a particular cnnectin t display a Path Between Hsts screen with infrmatin abut the crrespnding flw: 5. T btain mre infrmatin abut a particular hst, in the Path Between Hsts windw click n ne f the MAC Surce r MAC Destinatin addresses. Yu then see a Find Hst windw, where yu can chse between different views f the traffic: 5.3 Traffic views Here are sme f the traffic views that are available. Clicking Cnnectins gives tp cnnectins t and frm this machine: HP PrCurve Netwrking 9
Clicking Prtcls gives a view f the mst used prtcls fr this MAC address ver time: Factrs view gives the prprtin f each cnnectin in percent f the flws, ttal frames and ttal bytes f the link t this machine: A Circles view fr this machine is als available: HP PrCurve Netwrking 10
Yu have a wide variety f traffic types t display in charts: 5.4 Reprting T view the trends fr a particular flw ver a lnger perid, the reprting functin is useful. T specify the type f reprts: 1. On the Traffic Sentinel menu bar click n Reprts. Yu see the available reprts arranged by Categry: 2. Then yu can chse a custm reprt. Fr example if yu select IP Multicast, yu see a reprt that displays the IP Multicast activity n the netwrk. Yu see activity reprts fr the tp Multicast Grups, Multicast Surces, and Multicast Trends. This reprt can be exprted as a.pdf r a.html file. Fr example: IP Multicast: Shws IP multicast activity n the netwrk. HP PrCurve Netwrking 11
Tp Multicast Grups: Shws tp IP multicast addresses by amunt f traffic. Fr example: Tp Multicast Surces: Shws Tp IP multicast surces by amunt f traffic. Fr example: HP PrCurve Netwrking 12
Multicast Trend: Shws trends fr ttal IP multicast activity ver time: 6. Reference dcuments This cncludes the prcedure fr traffic flw mnitring n PrCurve switches using InMn Traffic Sentinel and sflw. Fr further infrmatin abut hw t cnfigure PrCurve switches t supprt security, please refer t the fllwing links: Fr PCM+ and IDM manuals: http://www.hp.cm/rnd/supprt/manuals/prcurve-manager.htm http://www.hp.cm/rnd/supprt/manuals/idm.htm Fr user manuals fr PrCurve 3500yl-5400zl-8212zl switches: http://www.hp.cm/rnd/supprt/manuals/3500-6200-5400-chapterfiles.htm Fr PrCurve Switch 2610 series manuals: http://www.hp.cm/rnd/supprt/manuals/2610.htm Fr infrmatin, abut InMn Traffic Sentinel, including dcuments and tutrials, see: http://www.inmn.cm/prducts/trafficsentinel.php Fr further infrmatin, please visit www.prcurve.eu 2008 Hewlett-Packard Develpment Cmpany, L.P. The infrmatin cntained herein is subject t change withut ntice. The nly warranties fr HP prducts and services are set frth in the express warranty statements accmpanying such prducts and services. Nthing herein shuld be cnstrued as cnstituting an additinal warranty. HP shall nt be liable fr technical r editrial errrs r missins cntained herein. sflw is a registered trademark f InMn Crp. HP PrCurve Netwrking 4AA2-1719EEE, July 2008 13