Hi Sean, see my comments inserted.

-----Original Message-----
From: Dunlop, Sean [mailto:[EMAIL PROTECTED] 
Sent: Friday, December 19, 2003 10:48 AM
To: NTOP Mailing List (E-mail)
Subject: [Ntop] A few quick newbie questions


Greetings all,

1) I have recently enabled NTOP as our Netflow collector and reporter.
I have enabled Netflow version 5 transmissions from our 3550 cisco
routers to the Redhat 9 host running the NTOP software. There are 6 x
3550 ciscos distributed between our 3 buildings with fibre campus
links between them all. Each 3550 hosts and/or peers the trunks and
Vlans accessible on our network. Each VLAN has netflow "ip route-cache
flow" enabled adn each 3550 has its netflows directed to the NTOP box.

Netflow config example:
 ip flow-export source Vlan20
 ip flow-export version 5 origin-as
 ip flow-export destination 172.21.254.100 2055
 

[Clinton Hardwick (C)] have you included this under each interface: 
int x/x/x
ip route-cache flow

Now the problem is that although NTOP is recording data sent by the
3550 switches/routers there is traffic not appearing that would expect
to see. For example oracle/unix dbase connections, Outlook -->Exchange
traffic and web traffic from our ISA proxy server (proxy port = 80) is
not recording, even though the data must traverse the same devices
which are only reporting a small range of protocols (ie SNMP, ICMP,
DNS, Telnet, NBios-IP, DHCP-BOOTP, etc do appear in the reports.

My questions are:

- Have I made a common config mistake?, or
- Am I expecting too much from Netflow 5?, or
- Am I confused about how netflow works?, or
- Are my public servant users just not doing anything at all? (even
the slackest employees checks out the web daily)

- Do I need to set the netflow timeouts on the routers to something
other than default?

My understanding is that netflow is transmitted on closure of the
connections, so does this mean days must pass to see the traffic im
missing?

-------------------

2) Heres an easier one hopefully:

In the ntop.conf file there is the setting for local networks

 --local-subnets 172.0.0.0/32

[Clinton Hardwick (C)]  your network has 1 IP address ???? You can
use:
 -m 10.1.0.0/16, 10.2.0.0/16 etc.
This only applies to captured packets not NetFlow - use the whitelist
in the plugin or leave blank for everything.

- My question is how do I configure multiple local networks?

I have about 5 or 6 I would like recognised as local


3) Another config question

In the Netflow Plugin config:

- What is the virtual netflow interface and what relevance does the Ip
and mask have to the way reports are displayed?



Cheers in advance

Sean Dunlop
Network & Security Consultant
Department of Treasury & Finance 
200 St Georges Tce 
Perth WA 6000 
Phone - (08) 9262 1405 
Fax - (08) 9262 1496 
Email - [EMAIL PROTECTED] 
Web - www.dtf.wa.gov.au 



_______________________________________________
Ntop mailing list
[EMAIL PROTECTED]
http://listgateway.unipi.it/mailman/listinfo/ntop
_______________________________________________
Ntop mailing list
[EMAIL PROTECTED]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to