Solved

Monitoring bandwidth usage on a cisco router with netflow analyzer

Posted on 2010-09-10
6
746 Views
Last Modified: 2012-05-10
I have a cisco router connected to a T1 with some users behind it. Every now and then someone is downloading something during an inconvenient time and using up all the bandwidth. I am trying to use netflow analyzer to determine which IP address is requesting the download.

However its giving me inconsistent data (see picture). This picture is the OUTBOUND traffic of our INTERNAL interface fa0/1. It clearly says in the lower right the outbound traffic is 1.44mbps, however when you look at the top 4 "endpoints" in the traffic column it says they have only downloaded 69.7KB, 63.6KB, 26.7KB, and 26.3KB respectively. This was after the monitor had been running for close to a minute. During that time the person downloading should have been able to get up to 60mb of data, clearly not reflected in the chart.

Furthermore when I test this with myself as the downloader and I KNOW I am the only person using up the 99% of the T1 pipe, it fails to register on this chart, even though it does say the corrrect traffic utilization in the lower right.

Can anyone help with this?

 netflow output
0
Comment
Question by:steiner470
6 Comments
 
LVL 27

Expert Comment

by:davorin
ID: 33649074
If they (you) are downloading shouldn't check INBOUND traffic?
0
 

Author Comment

by:steiner470
ID: 33649229
As I explained, the chart is outbound traffic for the internal interface. Both interfaces fa0/0 (external) and fa0/1 (internal) have inbound and outbound data.

Since the download stream is flowing from the internet to the LAN, it should register as inbound traffic on fa0/0 and outbound traffic on fa0/1.
0
 
LVL 27

Expert Comment

by:davorin
ID: 33649551
Sorry, I was a little bit distracted. I'm not really familiar with netflow analyzer and yours like quite different from this online demo (http://demo.netflowanalyzer.com)
On this you have option to select from trafic/application/source/destination/... table view in and time windows (15 min, 30min, 1h,...) when you are on certain interface.
Do some other views offer some more logical data? Maybe you have set too small time window -e.g 1 second?
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 36

Accepted Solution

by:
ArneLovius earned 250 total points
ID: 33650147
or run ntop on a linux box connected to a span port...

you might find it gives you quite a bit more information :-)
0
 
LVL 10

Assisted Solution

by:cstosgale
cstosgale earned 250 total points
ID: 33654828
Netflow top talkers might be the easiest way of getting the answer to who is doing the large download:-

http://www.cisco.com/en/US/docs/ios/netflow/configuration/guide/cfg_nflow_top_talk.html
0
 

Author Closing Comment

by:steiner470
ID: 33664516
Never did get netflow analyzer to show what I needed. But ntop and netflow top talkers are good alternatives.
0

Featured Post

Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Transparency shows that a company is the kind of business that it wants people to think it is.
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now