Link to home
Start Free TrialLog in
Avatar of netlach
netlach

asked on

Real Time Traffic Monitoring Problem

Hello there:

I need  a  real time  traffic tool that  allows me  to  see  the  traffic  going  in and out  of  the interface.
I already tried SolarWinds. Not good for real time traffic monitoring. Reports at the end of the day do not provide   accurate reports. The  SNMP graphs from  their Engineer  tools  allows  to  see  the  traffic  but  doesn't  work  accurate in 6500's.

I will appreciate any input.

Thank you
Avatar of Pugglewuggle
Pugglewuggle
Flag of United States of America image

I saw you are trying to do this for interfaces in switches... There are few good tools... One thing that is an option is to create a SPAN session on this switch (which will collect specified (rx, tx, or both) traffic from the ports you select to monitor and then mirror it to another port... then connect a PC or server to that port and run a network analysis or packet capture software like Wireshark to monitor the packets. The only limitation to this is that you cannot setup more than 2 SPAN sessions on a 6500 switch (or any smaller ones). However, as I said, you can add more than one interface to the SPAN session. Just make sure the total selected traffic traversing the selected interfaces is NOT more than the total output capacity of the port you mirror to.
Here is documenation on how to setup SPAN and how to mirror the results to another port.
http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a008015c612.shtml 
Also, here's a link to Wireshark - the software I recommend to do a packet capture/analyze the collected traffic.
http://www.wireshark.com
Cheers! Let me know if you have any questions!
Avatar of netlach
netlach

ASKER

Thank you Pugglewuggle:
Actually  what   I need  is  my  traffic  goin  out  to  the internet (for example),  a raltime  soft that  allows me  to  see  how much traffic I  am  sending  to  the internet with  just  one look and  also  at the same  time  keep looking  at  several  interfaces at  the  same  time (like snmp charts). Also  I want to  be  able  to  go  back in time  (2 days  or 3 weeks)  and  see  how much traffic  was  going  through that interface at  any point  during  the day. Spanning  the port  will  allow  to dig in to  the packet level with  wireshark.

Thanks  againg. Let  me  know  any other suggestion.
ASKER CERTIFIED SOLUTION
Avatar of from_exp
from_exp
Flag of Latvia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial