4 Replies Latest reply on Mar 13, 2012 8:26 AM by jspanitz

    Can Netflow do this?


      We've had NTA for a pretty long time and I truly understand the concepts but just can't seem to wrap my mind around what I am seeing in the charts and what our execs want to see when there are real or perceived issues with network performance.

      Ideally, we want to capture flow data going out our internet pipes.  We then want to take that data and find the top Endpoints, Apps, etc.  But we want to focus on internal nodes as the point of reference.

      I am most likely not explaining this very well, so bear with me.  When you pull up NTA, you will see Top 10 reports with inside and outside resources listed.  For instance the Top 10 Endpoints you will see inside and outside endpoints.  We just want to see inside or outside endpoints, not both.  Again, I know I am being clear as mud.

      Let me try yet again.  We want to be able to goto netflow, look at the internet flow data and say our traffic rate is high, it is mostly http and https, the biggest INTERNAL users are x,y,z and most of the traffic is going to site a,b,c.

      Ultimately we'd like to have some kind of 3 axis chart showing the relation ship of traffic rate to x.y.z and a,b,c to correlate if the high flow is all going to the same sites from the same users or not.

      So I hope I made some sense.  If anyone can shed some light, it would be great.

        • Re: Can Netflow do this?

          Hi There,
          When you mention users, do you want reports with usernames gathered from Active Directory or do you just want client IP addresses. The second question I have is, do you use proxy servers. The proxy question comes into play as your monitoring will need to take place before it hits the proxies.
          You may need to look at a SPAN port if you don’t have flow options on your core switch

          • Re: Can Netflow do this?

            I think I understand what you're trying to do, and I haven't been able to get it to work either. The closest thing I've found is this: use Flow Navigator to create an interface detail view for an interface near your internet edge, limit it by IP address group, and look at the "Top N Conversations" pane. This doesn't give you what you're asking for, but it is a decent view of who the bandwidth hogs are.

            • Re: Can Netflow do this?

              Hi JSpanitz,

              I understand it can be frustrating sometimes trying to find the bits you really care about among the mountain of data that netflow puts in front of you. 

              The specific challenge of understanding which internal user is responsible for the bulk of a circuit utilization can be particularly tough.

              The answer provided by JSwan touches on the approach we use to solve this with our clients.

              The first and most important step is to design and create the appropriate IP Address Groups for your network.  This could be a series of end-user IP subnets, or specific ranges of IP address within a subnet.  If you have mixed IP ranges that include phones, users and servers for example, this becomes harder still.  The goal though is to come up with a list of valid IP addresses that only include end user workstations and turn that into an IP address group.

              Doing this provides two important capabilities.  The first is you can now see if you have a circuit or interface that is shared by multiple ip address groups, which group is responsible for the largest percentage of utilization.  The second is you can then see, for that IP Address group, what conversations exist and what applications they are using that are generating that network load.

              As you point out, explaining this in the forum can be clear as mud.

              The key to this is really understanding and leveraging IP Address Groups within NTA though, so if you have not had an opportunity to look at them, I would recommend to begin there.

              If you have been working with them, the next step would be to look at creating some custom views, either through flow navigator or just customizing existing views, to remove all the 'distracting' data from the page so you can focus in on just the information you care about.

              I hope that helps!



              Bill Fitzpatrick


              Director of Technical Services

              Loop1 Systems (www.loop1systems.com)