A customer asked me to analyze their network flows, with a solution oriented towards using an nBox that collects NetFlow data from a router located away from the branch office, takes it in for analysis, and then sends it to a NetEye Elastic module, which act as an analysis console for that NetFlow data.
The first step involves choosing how to use the nBox, i.e., whether it should receive traffic on a dedicated socket, and where the correct configuration of the nprobe.conf file would thus have the directive:
[–c=6363]
or whether the nBox should receive traffic through a Span Port or Mirror Port, configured on board a network device such as a switch; in this case the correct configuration of the nprobe.conf file is with the directive:
In the use case under consideration, it was decided to use a Span Port, specifically to configure it as a switch, which physically connected the router port (whose NetFlow is to be analyzed) to the nBox port.
Consider the minimum network needs in terms of the physical layer, looking at the following diagram:
If the router and nBox cannot connect on the same switch, it may be useful configure a remote span port on your Layer2 Network Schema, from the switch where the router is plugged in and the switch where the nBox is plugged in, or it may be more comfortable using a TAP device: the nBox can operate in both cases.
In case you’d like the details and instructions for configuring NetFlow on a Cisco router, I’ve put here the CLI of a Cisco entry level device:
Once the necessary wiring has been completed and the router and switch have been configured, it’s time to configure the nBox to send the NetFlow data received.
Proceed from the nBox Web GUI by selecting the Menu Application > nProbe.
Set the nProbe interface connected to the switch to ON,
Then configure the FQDN and port where Elastic is listening. The default port is 2055, as shown in the following screenshot:
Hi all, my name is Davide and I was born in San Donato Milanese. Since I was a boy I've always been intrigued by PCs, and so I took my first steps with my Commodore VIC-20. Before joining Würth Phoenix as an SI consultant, I worked first as a Network Engineer for several ISPs (Internet Service Providers) in the late 90s, then for the first ASP (Application Service Provider) and next as a head of IT Network and Security. My various ITIL and Vendor certifications have allowed me to be able to cooperate at multiple project levels. I like tennis, music, motorcycles and going on nature walks with my family.
Author
Giovanni Davide Saccá
Hi all, my name is Davide and I was born in San Donato Milanese. Since I was a boy I've always been intrigued by PCs, and so I took my first steps with my Commodore VIC-20. Before joining Würth Phoenix as an SI consultant, I worked first as a Network Engineer for several ISPs (Internet Service Providers) in the late 90s, then for the first ASP (Application Service Provider) and next as a head of IT Network and Security. My various ITIL and Vendor certifications have allowed me to be able to cooperate at multiple project levels. I like tennis, music, motorcycles and going on nature walks with my family.
As you may know, I do ntopng consulting, and support companies in their implementation of ntop solutions. For some time now, ntopng users have noticed a high amount of QUIC traffic in their respective networks. Most people don't really know Read More
Every now and then I like to keep you up to date about news in the ntop environment. This time it's not news about analysis methods or software, but about a new hardware solution. If you're someone looking for a Read More
At the end of June, Luca Deri gave a webinar presenting the new features of the next ntopng release. I'd like to take this opportunity now to present these innovations to all of you. The main enhancements of the new Read More
NagVis is a visualization add-on for NetEye, and can be used to show NetEye monitoring data, over for example, a Network Schema as the use case below will show you. Thanks to NagVis, you can import a previously created network Read More
Ever since version 5.4 of nBoxes with the Enterprise L license it's been possible to use a new feature called Behavior Analysis. Let's see what it is and how to take advantage of it. This ntopng feature enables monitoring of Read More