Solved

Network Traffic Flow Capture

Posted on 2009-07-13
10
846 Views
Last Modified: 2013-12-07
Hi Experts !!!
We have just build a Data Centre with 3 external links (WAN, Internet, IPLC) terminating on edge routers.
I have configured routers to send netflow traffic to NetFlow Analyzer and am also seeing captured traffic.

But i'm not able to understand it. Can anyone of you assist me in how to determine howmuch of the external links are bing utilized at any given point of time ?
How do i use this capture to baseline my network ?

Can i configure netflow on Cisco 6500 gig ports, where, DWDM links are getting terminated connecting two redundant data centre ?

Any assistance would be  gr8!!! Thanks:)
0
Comment
Question by:vbongarala
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
10 Comments
 
LVL 1

Expert Comment

by:wsenter
ID: 24842008
If you are using Netflow, a Solarwinds product, just download Orion V9.5 for a 30 day trial.  Netflow integrates with it. Setup SNMP in your 6500 switch and configure the switch in Orion.  You can then view bandwidth utilization and many other measurements on every port on the switch. Very nice product as I use it daily.
0
 

Author Comment

by:vbongarala
ID: 24845734

I'm using ManageEngine's NetFlow Analyzer....have you experience in using this product.. Would appreciate if you tell me..how to measure how much of the bandwidth of external links is being utilized at any given pint of time. ?

Thanks:)
0
 
LVL 57

Expert Comment

by:giltjr
ID: 24868807
To tell the truth most NetFlow analyzers don't show you link utilization.  NetFlow is designed to analyze traffic based on things like source host, destination host, TCP port, UDP port, and COS.  Not "port utilization".

You should be able to get link utilization by using SNMP queiries to for the Interfaces you are interested in.

ManageEngine has a product called OpManager that should be able to do this for you.
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 1

Expert Comment

by:wsenter
ID: 24868843
If you are going to start from scratch,  I would definately check out Solarwinds Orion
0
 

Author Comment

by:vbongarala
ID: 24870026

Thank you for your little but valubale inputs. If its not possible to know link utilization using NetFlow Analyzer, can you plz tell what all things can be done with it.

I have heard a lot can be done. Plz throw some light on this.

Thanks:)
0
 
LVL 57

Expert Comment

by:giltjr
ID: 24870109
From my other post:

"NetFlow is designed to analyze traffic based on things like source host, destination host, TCP port, UDP port, and COS."

Example, say you start monitoring your links and you see that one of the links avg. 10% utilization however everyday between 2-3 PM it goes up to 90% utilization and you don't know of any application/function that should cause this spike in traffic.

Well with NetFlow you will be able to see what layer 4 protocol (UDP vs. TCP) what port (80 vs. 23 vs. 443)  and which host (10.1.1.20 vs. 10.1.23.44) is causing the spike.  This way you can go down and ask "Joe" why he is downloading the entire site content from "www.mypicutures.com" everyday at 2 PM.
0
 

Author Comment

by:vbongarala
ID: 24905031
Sorry..in getting back.

How do i monitor what has been the avg traffic, say on a WAN link ? Which is the peak period during the day ?

Do i have to monitor it hourly to get the above details or i can get the report from the NetFlow Analyzer tool ?

Thanks:)
0
 
LVL 57

Accepted Solution

by:
giltjr earned 300 total points
ID: 24943751
Typically you would use something that would use SNMP to query the bytes sent/received over the WAN link and let it calculate the % utilization.  Most products/programs use 5 minute intervals at there query interval.

You can look at MRTG or PRTG as programs that do this that are free, but ask for donations.
0

Featured Post

MIM Survival Guide for Service Desk Managers

Major incidents can send mastered service desk processes into disorder. Systems and tools produce the data needed to resolve these incidents, but your challenge is getting that information to the right people fast. Check out the Survival Guide and begin bringing order to chaos.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VOIP gateways - feedback 23 118
Layer 3 switch recommendation 15 94
Access-List 15 59
Unable to enable HWIC 2FE 2 24
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question