Real Time Traffic  Monitoring Problem

Posted on 2008-10-07
Medium Priority
Last Modified: 2013-12-07
Hello there:

I need  a  real time  traffic tool that  allows me  to  see  the  traffic  going  in and out  of  the interface.
I already tried SolarWinds. Not good for real time traffic monitoring. Reports at the end of the day do not provide   accurate reports. The  SNMP graphs from  their Engineer  tools  allows  to  see  the  traffic  but  doesn't  work  accurate in 6500's.

I will appreciate any input.

Thank you
Question by:netlach
LVL 12

Expert Comment

ID: 22666290
I saw you are trying to do this for interfaces in switches... There are few good tools... One thing that is an option is to create a SPAN session on this switch (which will collect specified (rx, tx, or both) traffic from the ports you select to monitor and then mirror it to another port... then connect a PC or server to that port and run a network analysis or packet capture software like Wireshark to monitor the packets. The only limitation to this is that you cannot setup more than 2 SPAN sessions on a 6500 switch (or any smaller ones). However, as I said, you can add more than one interface to the SPAN session. Just make sure the total selected traffic traversing the selected interfaces is NOT more than the total output capacity of the port you mirror to.
Here is documenation on how to setup SPAN and how to mirror the results to another port.
Also, here's a link to Wireshark - the software I recommend to do a packet capture/analyze the collected traffic.
Cheers! Let me know if you have any questions!

Author Comment

ID: 22666500
Thank you Pugglewuggle:
Actually  what   I need  is  my  traffic  goin  out  to  the internet (for example),  a raltime  soft that  allows me  to  see  how much traffic I  am  sending  to  the internet with  just  one look and  also  at the same  time  keep looking  at  several  interfaces at  the  same  time (like snmp charts). Also  I want to  be  able  to  go  back in time  (2 days  or 3 weeks)  and  see  how much traffic  was  going  through that interface at  any point  during  the day. Spanning  the port  will  allow  to dig in to  the packet level with  wireshark.

Thanks  againg. Let  me  know  any other suggestion.
LVL 21

Accepted Solution

from_exp earned 500 total points
ID: 22666704
please check cisco network assistant - for realtime and cacti.net for snmp graphs
WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

LVL 32

Assisted Solution

by:Kamran Arshad
Kamran Arshad earned 500 total points
ID: 22669272

For real time traffic you need any of the below applications;


Accurate Network Monitor

Bandwidth Monitor

Netstat Live

For whole NMS , you may pick any one from the below;


Smarts      www.smarts.com      Propriety
Adventnet OP Manager      www.adventnet.com      Propriety
WhatsupGold      www.whatsupgold.com      Propriety
SNMPc      www.castlerock.com      Propriety
ServerAlive      www.woodstone.nu      Propriety
NetXMS      www.netxms.org      Propriety
CommView      www.tamos.com      Propriety
AirMagnet      www.airmagnet.com      Propriety
MonitorMagic      www.tools4ever.com      Propriety
Observer      www.netinst.com      Propriety

Vendor Specific-NMS            

IronView      www,foundrynetworks.com      Propriety
Procurve Manager Plus      www.hp.com      Propriety
Dell Remote Monitoring      www.silverbacktech.com      Propriety
Microsoft Operation Manager      www.microsoft.com      Propriety
CiscoWorks      www.cisco.com      Propriety


Watch4Net      www.watch4net.com      Propriety
Nimsoft      www.nimsoft.com      Propriety
ResponseWatch      www.flukenetworks.com      Propriety
Perspective      www.packettrap.com      Propriety
NPM Analyst      www.prolan.ru      Propriety
APG Suite      www.watch4net.com      Propriety
InfoVista      www.infovista.com      Propriety
nGenius      www.netscout.com      Propriety

Flow Analyzers            

SolarWinds NetFlow Analyzer      www.solarwinds.com      NetFlow/SFlow
Scrutinizer NetFlow/Sflow Analyzer      www.plixer.com      NetFlow/SFlow
Caligare Flow Inspector      www.caligare.com      NetFlow/SFlow
PRTG      www.paessler.com/prtg      NetFlow/RRDTool
Adventnet Netflow Analyzer      www.adventnet.com      NetFlow
StealthWatch® Xe       www.lancope.com      SFlow
Traffic Sentinel      www.inmon.com      SFlow
Splunk      www.splunk.com      Propriety

Open-Source NMS            

Ntop      www.ntop.org      LAMP based NMS
Bandwidthd      bandwidthd.sourceforge.net      LAMP based NMS
ZenOSS      www.zenoss.com      LAMP based NMS
Nagios      www.nagios.org      LAMP based NMS
JFFNMS      www.jffnms.org      LAMP based NMS
OpenNMS      www.opennms.org      LAMP based NMS
Zabbix      www.zabbix.com      LAMP based NMS
Hyperic HQ      www.hyperic.com      LAMP based NMS
Etherape      etherape.sourceforge.net      LAMP based NMS
GroundWork      www.groundworkopensource.com      LAMP based NMS
NAV      metanav.uninett.no      LAMP based NMS
Netdisco      netdisco.org      LAMP based NMS
MRTG      oss.oetiker.ch/mrtg      RRDTool
Cacti      www.cacti.net      RRDTool
LVL 12

Assisted Solution

Pugglewuggle earned 500 total points
ID: 22671784
That's got to be the biggest pasted list I've ever seen on here! Wow!
As far as monitoring ports on the 6500 switches goes, SolarWindos NPM (Orion) is the best thing I've found. Your right that it's screwy and doesn't display accurate info all the time, but unless you have a Cisco NAM module in your 6509 there is really no easy way to do this.
I've setup and used a NAM before and it was VERY good for monitoring traffic on the switch... it can monitor any ports you want and break up traffic by protocols and by bits and bytes. It can get much more granular... source and destination addresses... MAC addressess, etc. You might request a demo unit from your Cisco sales rep to try it out.
The only problem with the NAM is that it is $30,000+ USD.
I hope this helps - let me know.

Assisted Solution

wulfhere earned 500 total points
ID: 22683889
We are using a mix of Intermapper (www.intermapper.com) and Cacti (www.cacti.net) to monitor several 6500 series switches.

Intermapper is nice because it is easily configurable, multi-platform, and gives both real-time utilization (and also does graphing).

Cacti is also relatively easy to set up, and provides nice web-based historical reporting.

Good luck!

Featured Post

WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Introduction Many times we come across a slowness or instability between two hosts, and almost always we blame the poor networking guys, just because they're an easy target.  Sometimes we forget that other factors including disk bottlenecks, CPU …
Network ports are the threads that hold network communication together. They are an essential part of networking that can be easily ignore or misunderstood, my goals is to show those who don't have a strong network foundation how network ports opera…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question