ntop, mirroring ports

Posted on 2007-08-02
Last Modified: 2008-02-01
I've downloaded a program called ntop on my machine. I've gone through a few of the posts and what I'm understanding is that you have to mirror all ports on the switch to one monitor port in order to accurately view all network traffic. The machine I'm running the program is connected to the monitor port.

Is this the recommended way to view network traffic via ntop?
Question by:lyon-it

    Author Comment

    I'm raising the point value to 500.

    Basically I'm experimenting with ntop. I have 1 port mirrored and would like to mirror more. I'm happy with the results so far but I would like to view all network traffic on my switch, and I'm concerned about the impact on network traffic if I mirrored all ports on the switch.
    LVL 57

    Accepted Solution

    What type of switch do you have?  Most switches don't allow you to mirror all ports, ports by ports.  Now some will allow you to mirror by VLAN, which can in the end allow you do mirror all ports.

    Depending on what you want to do, it may be better (if your switch supports it) is to use NetFlow.  This allows the switch to send a 'summary' of the traffic to ntop.
    LVL 25

    Assisted Solution

    agree with giltjr,  use netflow.

    I find it hard to believe any switch can mirror all ports to one port.  even if it was possible via the config, the ports can't support the bandwidth.
    Example, most managed switches are atleast 12 FastE ports.  if you mirror 11 ports to the 12th, you are mirroring 1.1Gbps to one 100mbps port. Even if the 12th port is a 1Gbps port, it's still is short on bandwidth. This is because of all the extra junk you get in the packets you don't need (like the encapsulated data).  This is why netflow is the preferred way for this type of monitoring.
    LVL 25

    Expert Comment


    If you plan on giving a grade less than 'A', you need to give us a reply so we know why the information we gave can't be constituted as  full solution.  No ill-will, just would appreciate a fair chance to get the full grade.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    Large and small networks have one same need, Service monitoring. Service monitoring consists of watch services of the several servers in the network. To monitor means that the administrator will receive an alert when a service is down or it's state …
    This article is in response to a question ( here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
    Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
    In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now