Netflow of similar without replacing our routers.

Posted on 2013-10-28
Last Modified: 2013-10-29
Perhaps someone can help me find a device that would suite our needs?  We currently have Cisco 3750 switches at each of our sites that are connected to an MPLS network.  Some of the sites have very low speed links and are often saturated.  We wanted to setup NETFLOW on the ports in question so we can easily see where the traffic is coming from but the Cisco 3750 switches do not support it.  Instead of replacing all our switches, we'd like to see if there is some sort of IN-LINE appliance or solution so that we can keep everything as is and just add something within the path of our router and MPLS.  Thanks.
Question by:sthubert
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
LVL 20

Expert Comment

ID: 39606867
Although this isn't inline, PRTG is an application that does all sorts of network monitoring - Netflow, sFlow, SNMP, WMI, etc. It also has the ability to do packet sniffing and reporting based on the sniff. If you were to setup the WAN-facing port on the 3750 as a span source, and the PRTG server as a destination, you would be able to get detailed reports on that info. Performance and historical data will be based on the speed of the machine you configure this on and the disk space available. I believe you can get a free version that allows up to 10 sensors, so you might be able to accomplish this particular task for free, aside from the machine it runs on.

Author Comment

ID: 39607037
Would I simply be able to plug this appliance in the WAN VLAN and capture the data the same way a WireShark would?  Does it provide good reporting and top talkers based on bandwidth?

Author Comment

ID: 39607048
Or perhaps I would setup a port mirror and plug the mirrored port into the appliance?

conf t
monitor session 1 source interface Gigabit 1/0/x
monitor session 1 destination interface Gigabit 1/0/x
Save the day with this special offer from ATEN!

Save 30% on the CV211 using promo code EXPERTS30 now through April 30th. The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

LVL 20

Expert Comment

ID: 39608936
With PRTG, this would be a port mirror. PRTG won't pass traffic through two interfaces, so inline plainly isn't an option. Give it a shot for free, you just need a machine to load it on, and the port mirror to be setup.

Author Comment

ID: 39609273
I just installed PRTG but like I mentioned my Cisco Routers do not support NETFLOW so how do I use PRTG to capture network data?

I'm really looking for a software or device that can either use to create NETFLOW's or to capture and analyze network data.
LVL 20

Accepted Solution

rauenpc earned 500 total points
ID: 39609310
When you install netflow, you have a device called the Probe, which is the server itself. If you go to add a sensor to the probe, you can search for sniffer. One choice will be packet sniffer which will also require you to choose an interface. From there, when viewing the sensor you should be able to see all the types of traffic, as well as the who and where, assuming that your port mirror is setup properly. You will likely need two physical interfaces on the PRTG server to handle this.

Author Comment

ID: 39609336
WOW!  Works like a charm!  Thanks very much for your HELP I will easily be able to deploy this today!

Author Closing Comment

ID: 39609338
Great solution

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Losing network connectivity 8 116
Getting TNS:Connect timeout occurred while opening the application 5 103
null0 7 60
Disabling SNMP Write-Access on Switches 6 54
Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
We recently endured a series of broadcast storms that caused our ISP to shut us down for brief periods of time. After going through a multitude of tests, we determined that the issue was related to Intel NIC drivers on some new HP desktop computers …
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question