Cacti (home)ForumsRepositoryDocumentation
Cacti: offical forums and support  

 FAQFAQ   SearchSearch   MemberlistMemberlist    RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in    


NTop plugin
Goto page Previous  1, 2, 3  Next
 
Post new topic   Reply to topic    Cacti Forum Index -> Plugin General
Author Message
N3NCY
Cacti User


Joined: 22 Sep 2005
Posts: 242
Location: Landenberg, PA

PostPosted: Tue Feb 21, 2006 5:32 pm    Post subject: Reply with quote

To get a flow from a Cisco device, that particular device code must support netflow.

You can export flows from multiples devices (even multiple flows from some devices - ie. different vlans and same cisco)

Each flow "export" and "collector" must match up on ports settings.
Use a single port for each export/collector pair.

Example:
telnet 10.0.0.254

config term

ip flow-cache timeout inactive 10
ip flow-cache timeout active 5
ip flow-export version 5
ip flow-export destination 10.0.0.1 9991

interface Vlan 1
ip route-cache flow

end
copy running startup

# Test
show ip flow export
Back to top
knobdy
Cacti User


Joined: 28 Sep 2005
Posts: 495

PostPosted: Wed Feb 22, 2006 11:23 am    Post subject: Reply with quote

and Ntop is just configured to listen for the flow?

How many flows can nTop handle at a time?
Back to top
N3NCY
Cacti User


Joined: 22 Sep 2005
Posts: 242
Location: Landenberg, PA

PostPosted: Wed Feb 22, 2006 6:47 pm    Post subject: Reply with quote

NTop must be configured to receive each flow.

NTop will handle as many flows as you setup.
Your computer running ntop must be more powerful as you add more flows of course.

I don't know exact hardware requirements for a given quantity of flows.
At some point, like any computer program, you may need a more powerful CPU and additional RAM.

But, to answer your question simply:
Each flow must be setup in a pair.
One flow on your Cisco router sending on say port 9991
would need one collector on your NTop box listening on port 9991.

To add more flows, you would setup more pairs.
Your next flow would send on say port 9992
and would need one collector on your NTop box listening on port 9992.

You always setup a sender "the flow export" on your Cisco router
and
a receiver "the collector" on your NTop server.
This makes one functional set or flow.

Please see pevious posts for mor details, example:

I have ntop running on the same NIC as Cacti as well.
They can peacefully co-exist.

I wrote (and borrowed) some instructions for getting ntop up and running on UNIX:
http://members.netjunkies.net/n3ncy/FreeBSD60/ntop.htm

On any platform, the steps should be similar:
1.) Get ntop installed on your server (ntop is a "Collector" and a web displayer of this collected data)
2.) Make sure you can log into ntop on your server (usually port 3000)
example: http://Yourserver:3000
3.) Configure a pair of items:
- Setup a "Collector" via your ntop web interface (see step 2 above)
- Export a "Flow" from your router to this collector
4.) Test ntop and look at this flow - You should be getting data
5.) Lastly setup the Cacti ntop plug-in to point to your ntop
example: http://Yourserver:3000


At a minimum read:
http://www.ntop.org/ to setup NTop
and
http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html to setup your Cisco gear

Very last of all, after you already have NTop working, then consider the NTop plug-in for Cacti, since the Cacti NTop plug-in is only useful if you already have NTop functional.
Back to top
egarnel
Cacti Pro User


Joined: 21 Nov 2002
Posts: 630
Location: Austin, TX

PostPosted: Thu Feb 23, 2006 9:02 am    Post subject: Reply with quote

silly mistake on my part:

I am running a pair of layer 3 switches in an hsrp pair. I opened up the firewall on the box running ntop for the defined ip address and port for netflow. The next day, I got my answer as to why netflow was not appearing in ntop. Lots of firewall logs from the real ip address from the primary l3 switch exporting the netflow. I should have remembered this little gotcha from doing things on the device such as extended pings & traces... Do not use the virtual addr for things like that

Now it appears to be happy.
Back to top
knobdy
Cacti User


Joined: 28 Sep 2005
Posts: 495

PostPosted: Thu Feb 23, 2006 12:27 pm    Post subject: Reply with quote

Cool, I will be trying it within the next week or two.

One more question though, we have some government regs we'll be needing to comply with. One of the requirements for net flows is that they be sent from the loopback interface. Currently we don't do much of anything with the loopback - anyone here got some experience with this on Cisco devices?

I'd love to find someone who's brain I can pick...
Back to top
egarnel
Cacti Pro User


Joined: 21 Nov 2002
Posts: 630
Location: Austin, TX

PostPosted: Thu Feb 23, 2006 12:29 pm    Post subject: Reply with quote

ip flow-export source Loopback < number>
Back to top
knobdy
Cacti User


Joined: 28 Sep 2005
Posts: 495

PostPosted: Thu Feb 23, 2006 1:33 pm    Post subject: Reply with quote

egarnel wrote:
ip flow-export source Loopback < number>


Sending you a private message...
Back to top
qwertz
Cacti User


Joined: 16 Feb 2006
Posts: 98

PostPosted: Thu Mar 09, 2006 9:58 am    Post subject: Reply with quote

I just installed netflow with ntop and everything is working fine.
I used Cacti and ntop plugin with success

I noticed in the netflow mode of ntop that the stat of all the remote routers are mixed in the same tables.
Is it possible to separate the tables per remote netflow router ?

Thanks

Qwertz
Back to top
N3NCY
Cacti User


Joined: 22 Sep 2005
Posts: 242
Location: Landenberg, PA

PostPosted: Sat Mar 11, 2006 10:22 am    Post subject: Reply with quote

Did you setup mulitple flows and collectors on different ports?
Under the Admin menu click Switch NIC
Do you have multiple choices for sources you want to look at?
I setup different flows from my routers for each vlan I want to look at.
I get a "per vlan" view, not everything in one view.
Back to top
qwertz
Cacti User


Joined: 16 Feb 2006
Posts: 98

PostPosted: Sat Mar 11, 2006 5:18 pm    Post subject: Reply with quote

Thanks i will do it. (ie i will use a different port per remote host).

By the way i have a other question.
I wanted to keep my data when i stop ntop. Do you know how to set ntop to save the data in log files instead of only put them in the swap?

Strangly, i did not find any clear answer on the web

Thanks again

Qwertz
Back to top
flavour



Joined: 28 Sep 2005
Posts: 15

PostPosted: Sat Mar 11, 2006 5:41 pm    Post subject: Reply with quote

Quote:
I wanted to keep my data when i stop ntop. Do you know how to set ntop to save the data in log files instead of only put them in the swap?


rrd plugin

F


Last edited by flavour on Tue Mar 14, 2006 5:10 pm; edited 1 time in total
Back to top
qwertz
Cacti User


Joined: 16 Feb 2006
Posts: 98

PostPosted: Sun Mar 12, 2006 4:34 am    Post subject: Reply with quote

Sorry, i don't understand
Back to top
N3NCY
Cacti User


Joined: 22 Sep 2005
Posts: 242
Location: Landenberg, PA

PostPosted: Sun Mar 12, 2006 10:59 am    Post subject: Reply with quote

Somebody would need to create the RRDTool Cacti plugin?

Currently my nTop does not save data between restarts either.
(Although I don't need it to do so)

Your question is really more for the nTop people:
http://www.ntop.org/documentation.html

Unless the Cacti crew already created a plguin for long term storage?
Back to top
flavour



Joined: 28 Sep 2005
Posts: 15

PostPosted: Mon Mar 13, 2006 7:10 am    Post subject: Reply with quote

RRDPlugin is part of the normal NTop distribution - just needs enabling.
- Check Plugins off the Admin menu.

F
Back to top
qwertz
Cacti User


Joined: 16 Feb 2006
Posts: 98

PostPosted: Wed Mar 15, 2006 5:19 am    Post subject: Reply with quote

Thanks for your help.

For N3NCY:
On admin -> Plugins -> Netflow -> on Flow Collection -> Local Collecor UDP Port
I can set only one port. So i will have on admin -> Switch NIC: my ethernet interface and only one netflow interface and i will still see all my remote netflow hosts in one table


For flavour:
I went on admin -> Plugins -> rrdplugins -> i enabled everything in "data to Dump"
I noticed that the only things that are kept after a ntop restart is the data in the graphs in Summary -> Traffic

Thank you again

QWertz
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Cacti Forum Index -> Plugin General All times are GMT - 5 Hours
Goto page Previous  1, 2, 3  Next
Page 2 of 3

 



Powered by phpBB © 2001, 2005 phpBB Group