WhatsUpGold. v14.4. Flow Monitor User Guide



Similar documents
WhatsUpGold. v15.0. Flow Monitor User Guide

Flow Monitor for WhatsUp Gold v16.1 User Guide

Flow Monitor for WhatsUp Gold v16.2 User Guide

WhatsUpGold. v NetFlow Monitor User Guide

CHAPTER 1 WhatsUp Flow Monitor Overview. CHAPTER 2 Configuring WhatsUp Flow Monitor. CHAPTER 3 Navigating WhatsUp Flow Monitor

- QoS Classification and Marking -

Cisco Performance Monitor Commands

Easy Performance Monitor

Easy Performance Monitor

Easy Performance Monitor

How-To Configure NetFlow v5 & v9 on Cisco Routers

- QoS and Queuing - Queuing Overview

Configuring Denial of Service Protection

SolarWinds Technical Reference

SolarWinds Technical Reference

Configuring Flexible NetFlow

Table of Contents. Cisco Blocking Peer to Peer File Sharing Programs with the PIX Firewall

Internetwork Expert s CCNA Security Bootcamp. IOS Firewall Feature Set. Firewall Design Overview

Configuring NetFlow Secure Event Logging (NSEL)

Configuring the Firewall Management Interface

NetFlow Auditor Manual Getting Started

Quality of Service (QoS) for Enterprise Networks. Learn How to Configure QoS on Cisco Routers. Share:

Configuring NetFlow Secure Event Logging (NSEL)

Cisco ASA and NetFlow Using ASA NetFlow with LiveAction Flow Software

QoS: Color-Aware Policer

Lab 8: Confi guring QoS

CISCO IOS FIREWALL DESIGN GUIDE

Lab 3.3 Configuring QoS with SDM

Cisco IOS Flexible NetFlow Technology

Configuring Class Maps and Policy Maps

Configuring NetFlow-lite

Introduction to Cisco IOS Flexible NetFlow

Configuring Control Plane Policing

Configuring SNMP and using the NetFlow MIB to Monitor NetFlow Data

Configuring MPLS QoS

NetFlow-Lite offers network administrators and engineers the following capabilities:

Configuring Server Load Balancing

NetFlow The De Facto Standard for Traffic Analytics

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

Configuring Network Address Translation

Understanding and Configuring NAT Tech Note PAN-OS 4.1

LAB II: Securing The Data Path and Routing Infrastructure

Enabling Remote Access to the ACE

Using The Paessler PRTG Traffic Grapher In a Cisco Wide Area Application Services Proof of Concept

NetFlow/IPFIX Various Thoughts

Fluke Networks NetFlow Tracker

HUNTING ATTACKERS WITH NETWORK AUDIT TRAILS

Configuring NetFlow. Information About NetFlow. Send document comments to CHAPTER

Introduction to Netflow

Network Monitoring and Management NetFlow Overview

Cisco IOS Flexible NetFlow Command Reference

Firewall Defaults and Some Basic Rules

NetFlow Tracker Overview. Mike McGrath x ccie CTO mike@crannog-software.com

NetStream (Integrated) Technology White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date

LogLogic Cisco NetFlow Log Configuration Guide

Configuring NetFlow. Information About NetFlow. NetFlow Overview. Send document comments to CHAPTER

NetFlow v9 Export Format

Configuring NetFlow. Information About NetFlow. NetFlow Overview. Send document comments to CHAPTER

Getting Started with Configuring Cisco IOS NetFlow and NetFlow Data Export

Network Agent Quick Start

Monitoring and analyzing audio, video, and multimedia traffic on the network

Lab Introduction to the Modular QoS Command-Line Interface

NetFlow Subinterface Support

IPv6 Network Management.

Appendix A Remote Network Monitoring

Network Management & Monitoring

Overview. Why use netflow? What is a flow? Deploying Netflow Performance Impact

How To Mirror On An Ipfix On An Rspan Vlan On A Pc Or Mac Or Ipfix (Networking) On A Network On A Pnet (Netnet) On An Uniden (Netlan

Configure Policy-based Routing

Configuring Traffic Policies for Server Load Balancing

Configuring Server Load Balancing

Central America Workshop - Guatemala City Guatemala 30 January - 1 February 07. IPv6 Security

Chapter 3 Security and Firewall Protection

WhatsUpGold. v3.0. WhatsConnected User Guide

Configuring NetFlow Data Export (NDE)

Emerald. Network Collector Version 4.0. Emerald Management Suite IEA Software, Inc.

Catalyst 6500/6000 Switches NetFlow Configuration and Troubleshooting

Deploying Riverbed Cascade and Steelheads. A Best Practices Whitepaper

Firewall Defaults, Public Server Rule, and Secondary WAN IP Address

NetFlow Aggregation. Feature Overview. Aggregation Cache Schemes

Using WhatsUp IP Address Manager 1.0

This Technical Support Note shows the different options available in the Firewall menu of the ADTRAN OS Web GUI.

LAB THREE STATIC ROUTING

Enabling and Monitoring NetFlow on Subinterfaces

Configuring Denial of Service Protection

Quick Start for Network Agent. 5-Step Quick Start. What is Network Agent?

LogLogic Cisco NetFlow Log Configuration Guide

Netflow Overview. PacNOG 6 Nadi, Fiji

Firewall Technologies. Access Lists Firewalls

WhatsUp Gold v11 Features Overview

NetFlow Analytics for Splunk

Authentication with 802.1x and EAP Across Congested WAN Links

Cisco IOS NetFlow Version 9 Flow-Record Format

CSE331: Introduction to Networks and Security. Lecture 12 Fall 2006

Chapter 2 Quality of Service (QoS)

Firewall Firewall August, 2003

Using IPsec VPN to provide communication between offices

Network security includes the detection and prevention of unauthorized access to both the network elements and those devices attached to the network.

Routing. Static Routing. Fairness. Adaptive Routing. Shortest Path First. Flooding, Flow routing. Distance Vector

The information in this document is based on these software and hardware versions:

Transcription:

WhatsUpGold v14.4 Flow Monitor User Guide

Contents

ingress egress egress ingress

enable configure terminal ip flow-export version <version_number> ip flow-export destination <IP> <port>

interface <interface> ip flow ingress ip flow egress ip flow ingress ip flow egress

Router> enable Router# configure terminal Router(config)# flow monitor application-mon Router(config-flow-monitor)# description app traffic analysis Router(config-flow-monitor)# cache timeout active 60 Router > enable Router# configure terminal Router(config)# flow monitor application-mon Router(config-flow-monitor)# flow record nbar-appmon Router(config-flow-record)# description NBAR Flow Monitor

match Router(config-flow-record)# match ipv4 tos Router(config-flow-record)# match ipv4 protocol Router(config-flow-record)# match ipv4 source address Router(config-flow-record)# match ipv4 destination address Router(config-flow-record)# match transport source-port Router(config-flow-record)# match transport destination-port Router(config-flow-record)# match interface input Router(config-flow-record)# match interface output Router(config-flow-record)# match application name collect Router(config-flow-record)# collect datalink mac source address inpu Router(config-flow-record)# collect datalink mac destination address input Router(config-flow-record)# collect routing destination as Router(config-flow-record)# collect routing next-hop address ipv4 Router(config-flow-record)# collect ipv4 dscp Router(config-flow-record)# collect ipv4 id Router(config-flow-record)# collect ipv4 source prefix Router(config-flow-record)# collect ipv4 source mas Router(config)# flow monitor application-mon Router(config-flow-monitor)# record nbar-appmon Router > enable Router# configure terminal Router(config)# flow exporter export-to-ipswitch-flow-monitor Router(config-flow-exporter)# description Flexible NF v9

Router(config-flow-exporter)# destination 192.168.3.47 Router(config-flow-exporter)# source GigabitEthernet0/0 Router(config-flow-exporter)# transport udp 9996 Router(config-flow-exporter)# template data timeout 120 Router(config-flow-exporter)# option interface-table Router(config-flow-exporter)# option exporter-stats timeout 120 Router(config-flow-exporter)# option application-table timeout 120 Router# configure terminal Router(config)# exporter export-to-ipswitch_flow_monitor

Router> enable Router# configure terminal Router(config)# ip cef Router(config)# interface FastEthernet 0/1 Router(config-if)# ip nbar protocol-discovery Router(config-if)# exit class-map policy-map service-policy

class-map policy-map service-policy Router> enable Router# configure terminal Router(config)# class-map match-any NMclass match-any Router(config-cmap)# match protocol snmp Router(config-cmap)# match protocol icmp Router(config-cmap)# exit

class-map match-any nm match protocol snmp match protocol icmp class-map match-any p2p match protocol kazaa2 match protocol gnutella match protocol edonkey match protocol bittorrent match protocol fasttrack match protocol directconnect match protocol winmx class-map match-all FTP match protocol ftp class-map match-any web match protocol http class-map match-any utube match protocol http s-header-field "*http://www.youtube.com/*" Router> enable Router# configure terminal Router(config)# policy-map newpolicy config config-pmap config-pmap-c Router(config-pmap)# class NMclass

Router(config-pmap-c)# drop Router(config-pmap-c)# exit policy-map crtest2 class p2p drop class FTP drop class nm set dscp af43 class web set dscp af12 class utube set dscp af43 Router> enable Router# configure terminal config Router(config)# interface GigabitEthernet0/0 Router(config-if)# service-policy output input newpolicy Router(config-if)# exit

Using WhatsUp Gold Flow Monitor Monitoring traffic on non-standard ports Flow Monitor automatically classifies traffic for most common applications. However, in some cases, you may need to create a custom definition to ensure that Flow Monitor properly classifies some traffic. This need is most common when: Your device routes traffic for applications that use a proprietary protocol. This may be a custom program that uses a protocol developed in-house to send data across the network or a third-party application that uses its own custom protocol to transmit data. Your device routes traffic for standard applications over non-standard ports. Examples include a standard Web server running on a port other than 80 or an FTP client connecting to an FTP server that runs on a port other than 21. Note: In Flow Monitor, for traffic to be considered "unclassified," both the port from which the data is sent, and the receiving port must not be classified in the Flow Ports dialog. If either the sending or receiving port is classified, the traffic is associated with the application of the classified port. To accommodate these cases, you can classify traffic that meets specific rules so that Flow Monitor reports that traffic as belonging to a certain application. Important: You can configure the amount of time unclassified traffic data is kept. For more information, see Configuring data roll-up intervals (on page 26). Tip: If Flow Monitor detects a large amount of traffic to an unmonitored port, the Top Applications workspace report displays a yellow warning flag that explains the situation and guides you in defining the unmonitored port. This can help you to proactively detect emerging non-standard traffic on your network. You can also use the Unclassified Traffic dialog (available from any page in Flow Monitor by selecting GO > Configure > Flow Unclassified Traffic) to view all unclassified traffic since the last hourly rollup. To define rules for classifying traffic that uses non-standard ports: 1 From any workspace view or report in the web interface, select GO. The GO menu appears. 2 If the Flow Monitor section is not visible, click Flow Monitor. The Flow section of the GO menu appears. 3 Select Configure > Applications. The Configure Applications dialog appears. 4 Click New to configure a new application definition. The Map Ports to Applications dialog appears. 5 In Name, enter the name of the application. 6 In Port, enter the port number over which the traffic is sent. 7 In Protocols, select the protocols monitored on the port. 24

Using WhatsUp Gold Flow Monitor 8 If the Port to Application Mapping applies to the entire network, select Global. 9 If the Port to Application Mapping applies to a specific subnet, deselect Global and enter the Subnet address using valid CIDR notation. 10 Click Save to save changes. 11 When the port to application mapping is complete, click OK. The Configure Applications dialog appears. Classifying traffic that is considered unclassified In Flow Monitor, for traffic to be considered "unclassified," both the port from which the data is sent, or the source port, and the receiving, or destination port, must not be classified in the Flow Ports dialog. If either the source or destination port is classified, the traffic is associated with the application of the classified port. You can classify traffic that is considered unclassified by classifying the source and/or destination ports over which the traffic is transmitted via the Flow Unclassified Traffic dialog. To classify a source port: 1 From any workspace view or report in the web interface, select GO. The GO menu appears. 2 If the Flow Monitor section is not visible, click Flow Monitor. The Flow section of the GO menu appears. 3 Select Configure > Flow Unclassified Traffic. The Flow Unclassified Traffic dialog appears. 4 Use the list fields at the top of the dialog to manipulate the port data displayed in this dialog. Select an Interface over which unclassified traffic is transmitting. Select a Traffic direction (Inbound, Outbound, Inbound and Outbound, Bounce) in which the unclassified traffic is traveling. Select a filter (Conversations; Source IP, Port; Source Port; Destination IP, Port; Destination Port) by which to group the unclassified traffic from the Group by field. 5 To begin monitoring a source port, select the port from the list, then click Classify Src Port. To classify a destination port: 1 From any workspace view or report in the web interface, select GO. The GO menu appears. 2 If the Flow Monitor section is not visible, click Flow Monitor. The Flow section of the GO menu appears. 3 Select Configure > Flow Unclassified Traffic. The Flow Unclassified Traffic dialog appears. 25

SQL Server (WHATSUP)

yourcompany.com com

ipswitch.com ipswitch.com