<rss version="2.0"
 	 xmlns:dc="http://purl.org/dc/elements/1.1/"
 	 xmlns:atom="http://www.w3.org/2005/Atom">

	<channel>
		<title>Enterprise IT Management, Network performance management, IT Servicedesk, Desktop Management, Datacenter Management,  Server Management, Log Analysis and Security Management, Network Tools, ManageEngine Blogs</title>
		<atom:link href="http://blogs.manageengine.com/netflowanalyzer/feed" rel="self" type="application/rss+xml"/>
		<link>http://blogs.manageengine.com/netflowanalyzer</link>
		<description><![CDATA[Blogs from ManageEngine, written by product experts, on enterprise IT management]]></description>
		<pubDate>Sat, 7 Nov 2009 11:10:23 -0800</pubDate>

		<item>
			<title>Get smart - use NetFlow Analyzer for sFlow from HP ProCurve !</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/11/05/get-smart-use-netflow-analyzer-for-sflow-from-hp-procurve</link>
			<dc:creator>Praveen Kumar V</dc:creator>
			<description><![CDATA[<p><span style="font-weight: bold;"></span><span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span>, though the name says <span style="font-weight: bold;"></span><span><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">NetFlow</a></span>, can work with quite a number of flow formats like <span><a href="http://www.sflow.org/" target="_blank">sFlow</a></span>, jFlow, NetStream, IPFIX etc. This blog will give you a brief idea on sFlow technology and also guide you on how to use NetFlow Analyzer with sFlow from <span><a href="http://www.procurve.com/NR/rdonlyres/D77BE973-F221-40FE-9666-7DEB9F7736CC/0/NetworkVisibilitywithsFlowInMonSolutionBrief_Aug_15_08_WW_Eng_Ltr.pdf" target="_blank">HP Procurve devices</a></span>.<br><br><span style="font-weight: bold;">What is sFlow?</span><br><br><span style="font-weight: bold;"></span><span><a href="http://www.sflow.org/" target="_blank">sFlow</a></span> is a monitoring technology which allows you to capture the traffic data from a switched or routed network to give complete visibility into the use of network bandwidth. This data helps in performance optimization, accounting/billing for usage, defense against security threats, capacity planning and much more.<br><br>sFlow datagrams are exported based on <span><a href="http://www.sflow.org/about/sampling_theory.php">sampling</a></span> due to which impact on the device CPU/Memory and available bandwidth is minimal. Based on a defined sampling rate, 1 out of N packets (where N is the sampling rate) is captured and sent to the NetFlow Analyzer for traffic analysis by the device. Though, this type of sampling does not provide 100% accurate statistics, it does provide a result with quantifiable accuracy.<br><br><span style="font-weight: bold;">sFlow analysis with NetFlow Analyzer:</span><br><br>NetFlow Analyzer can work with any devices which are capable of exporting NetFlow, sFlow and other compatible flow which are completely vendor dependent. You can check out the list of flow formats and devices with which NetFlow Analyzer can work from <span><a href="http://www.manageengine.com/products/netflow/supported-devices.html" target="_blank">here</a></span>.<br><br><span style="font-weight: bold;">HP Procurve and sFlow:</span><br><br>Just like Cisco has NetFlow and other vendors have thier flow formarts, some vendors use a technolgy called sFlow. <span><a href="http://www.procurve.com/NR/rdonlyres/D77BE973-F221-40FE-9666-7DEB9F7736CC/0/NetworkVisibilitywithsFlowInMonSolutionBrief_Aug_15_08_WW_Eng_Ltr.pdf" target="_blank">HP Procurve devices</a></span> are capable of exporting sFlow datagrams which can be used for bandwidth monitoring and traffic analysis. NetFlow Analyzer is capable of analyzing the sFlow datagram exported from the HP Procurve to give you the traffic statiscs on each active ports.<br><br>sFlow export on the HP procuve device can be configured using two different methods, We can enable sFlow on the HP device either by logging in to the router and configuring them for sFlow export. But this is available only in the older device models or OS.<br><br>On the new HP devices, sFlow can be enabled only through SNMP. To make the sFlow configuration on HP device a simple task, NetFlow Analyzer provides scripts to enable and disable the sFlow export. So, lets see how we can use the script and enable sFlow.<br><br><span style="font-weight: bold;">sFlow Enable utility:</span><br><br>The script to enable sFlow, named as <span style="font-weight: bold;">sFlowEnable.bat</span> (for Windows and <span style="font-weight: bold;">.sh</span> for Linux),&nbsp; is present under <span style="font-weight: bold;">&lt;\AdventNet\ME\NetFlow\troubleshooting&gt; </span>directory.<br><br>The usage for the script is as follows:<br><br><span style="background-color: rgb(255, 255, 255); font-weight: bold;">SFlowEnable.bat switchIp snmpPort snmpWriteCommunity collectorIP collectorPort samplingRate</span><br><br><span style="font-weight: bold;">Example:-</span><br><br><span style="font-weight: bold;">C:\AdventNet\ME\NetFlow\troubleshooting&gt;</span><span style="font-weight: bold; background-color: rgb(255, 255, 255);">sFlowEnable.bat 192.168.188.30 161 private 192.168.133.1 9996 4096&nbsp;</span><span style="background-color: rgb(255, 255, 255);">&nbsp;&nbsp;</span>&nbsp;</p><p><br></p><p><span><a href="http://blogs.manageengine.com/image/501000000112166/sflowenable.jpg"><img src="http://blogs.manageengine.com/image/501000000112166/sflowenable.jpg" style="" class="alCenter"></a></span><span></span><br></p><p>Once sFlow is enabled on the HP devices, NetFlow Analyzer server will receive the packets and the product will capture the packets to automatically generate the reports. You also need to ensure that no access control lists (ACLs) or firewalls block the NetFlow packets (on UDP 9996) and that even the software firewalls on the server are allowing the packets to reach the NetFlow Analyzer installation.<br><br>After enabling the sFlow on the HP devices, we need ensure a few points to get the accurate traffic statistics about the device in NetFlow Analyzer.<br><br>The first and foremost is the sampling rate. We suggest setting the sampling rate to 4096. We have observed from various setups and from our existing customers feedback that the sampling rate of 4096 gives the most accurate traffic statistics in NetFlow Analyzer.Most of the other sFlow collectors in the market suggest the sampling rate to 256 which means more number of exported sFlow datagrams. With a sampling rate of 4096, you get the additional benefit that the device is not being overloaded by sampling large number of datagrams and exporting to the NetFlow Analyzer.<br><br>Next point we need verify is the <span style="font-weight: bold;">"sFlow receiver timeout"</span>. This determines how long sFlow remains active on the exporting device. When the value has expired, sFlow also gets disabled on the device forcing you to re-enable sFlow export. Due to this, we recommend setting the sFlow Receiver Timeout to the maximum possible value, which is 2147483647 seconds which is 68 years ! The command to be used on the HP device for setting the sFlow receiver timeout is:<br><br><span style="font-weight: bold; background-color: rgb(255, 255, 255);">setmib sFlowRcvrOwner.1 -D NetFlow Analyzer IP sFlowRcvrTimeout.1 -i 2147483647</span><br><br><span style="font-weight: bold;">sFlow Disable Utility:</span><br><br>Of course. We have thought about that too. Just in case you want to export sFlow to different server or stop the flows for some time or whatever be the reason, NetFlow Analyzer provides you the script to disable sFlow export on the HP device.<br><br>The disable can be done using the script <span style="font-weight: bold;">sFlowDisable.bat</span> (for Windows and <span style="font-weight: bold;">.sh</span> for Linux) and the file is present under &lt;<span style="font-weight: bold;">\AdventNet\ME\NetFlow\troubleshooting &gt;</span> directory. The usage of the script is as below:<br><br><span style="font-weight: bold; background-color: rgb(255, 255, 255);">SFlowDisable.bat switchIp snmpPort snmpWriteCommunity </span><br><br><span style="font-weight: bold;">Example :-</span><br><br><span style="font-weight: bold;">C:\AdventNet\ME\NetFlow\troubleshooting&gt;<span style="background-color: rgb(65, 105, 225);"><span style="background-color: rgb(255, 255, 255);">sFlowDisable.bat 192.168.188.30 161 private </span><br></span></span></p>
<p><span style="font-weight: bold;"><span style="background-color: rgb(65, 105, 225);"><span></span></span></span><br><span><a href="http://blogs.manageengine.com/image/501000000112174/sflowdisable.jpg"><img src="http://blogs.manageengine.com/image/501000000112174/sflowdisable.jpg" style="" class="alCenter"></a></span></p><p><br></p><p>Go ahead and try our 30 day trial to see for yourself on how well NetFlow Analyzer works with sFlow and HP devices. </p><p>Thanks</p><p>Praveen Kumar<br></p><p><br></p><p><br></p><p><span class="Apple-style-span" style="font-family: verdana; font-size: 12px; color: rgb(51, 51, 51); line-height: 19px; word-spacing: 1px;"><span><a href="http://www.manageengine.com/products/netflow/download-free.html?nfb" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Download</a></span>&nbsp;|&nbsp;<span><a href="http://demo.netflowanalyzer.com/?nfb" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Interactive Demo</a></span>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/nfa_overview/netflow_analyzer_overview.html?nfb" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Product overview video</a>&nbsp;|&nbsp;<span><a href="http://twitter.com/NetFlow_geek" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Twitter</a>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/customers.html" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Customers</a></span></span></span></span></p>]]></description>
			<category><![CDATA[General]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/11/05/get-smart-use-netflow-analyzer-for-sflow-from-hp-procurve</guid>
			<pubDate>Thu, 5 Nov 2009 06:23:17 -0800</pubDate>
		</item>

		<item>
			<title>ManageEngine NetFlow Analyzer : Speed Based Alerts - UI Configuration</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/11/02/manageengine-netflow-analyzer-speed-based-alerts-ui-configuration</link>
			<dc:creator>vraj</dc:creator>
			<description><![CDATA[<p>Couple of days back, we had an interesting conversation going on in our forums. One of our privileged ManageEngine customer wanted to have speed based alerting mechanism and gave us a real good reason to have this feature. Please find the conversation on the below link.&nbsp;</p><p><a href="http://forums.manageengine.com/#Topic/49000003700030">http://forums.manageengine.com/#Topic/49000003700030</a></p><p>I just wanted to check how the UI should look like and input configuration. Please share us your views and inputs to add the speed based alert feature.&nbsp;</p><p>Please write your technical questions to&nbsp;<span class="Apple-style-span" style="font-family: verdana, arial, helvetica, sans-serif; font-size: 12px; border-collapse: collapse; line-height: 15px;">netflowanalyzer-support@manageengine.com.&nbsp;<span class="Apple-style-span" style="border-collapse: separate; font-family: arial; font-size: 13px; line-height: normal;">We are happy to assist you at any moment.</span></span></p><p>Thanks<br>Raj</p><p><span class="Apple-style-span" style="font-family: verdana; font-size: 12px; color: rgb(51, 51, 51); line-height: 19px; word-spacing: 1px;"><span><a href="http://www.manageengine.com/products/netflow/download-free.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline; border-style: initial; border-color: initial; border-style: initial; border-color: initial; border-style: initial; border-color: initial; border-style: initial; border-color: initial;">Download</a></span>&nbsp;|&nbsp;<span><a href="http://demo.netflowanalyzer.com/?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline; border-style: initial; border-color: initial; border-style: initial; border-color: initial; border-style: initial; border-color: initial; border-style: initial; border-color: initial;">Interactive Demo</a></span>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/nfa_overview/netflow_analyzer_overview.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline; border-style: initial; border-color: initial; border-style: initial; border-color: initial; border-style: initial; border-color: initial; border-style: initial; border-color: initial;">Product overview video</a>&nbsp;|&nbsp;<span><a href="http://twitter.com/NetFlow_geek" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Twitter</a>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/customers.html" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Customers</a></span></span></span></span></p><p><br></p><p><br></p><p><br></p>]]></description>
			<category><![CDATA[Technical]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/11/02/manageengine-netflow-analyzer-speed-based-alerts-ui-configuration</guid>
			<pubDate>Mon, 2 Nov 2009 10:17:27 -0800</pubDate>
		</item>

		<item>
			<title>&amp;quot;Free&amp;quot; Vs Free-and-useful</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/29/free-vs-free-and-useful</link>
			<dc:creator>Joseph</dc:creator>
			<description><![CDATA[<p>&nbsp;Some tools claim to be free and some are<span style="font-weight: bold;"> </span><span style="font-weight: bold;"></span><span style="font-weight: bold;">free </span><span style="font-weight: bold;">AND </span><span style="font-weight: bold;">useful</span>. Talking with relation to the so many free network traffic analysis tools available online. The main objective of a traffic monitoring and analysis tool is to be able to see the history of threats, threshold violations, bandwidth utilization and extrapolate it to the future for taking better informed capacity planning decisions. All this analysis is carried out with the data (from NetFlow, sFlow, IPFIX, jfLow <span><a href="http://www.manageengine.com/products/netflow/supported-devices.html" target="_blank" title="supported devices for netflow analyzer">and more</a></span>) available (stored) with the tool. One should be able to compare traffic through a particular device various time periods to see the effectiveness of the policies that have been recently changed / set.</p><div style="text-align: center;">Free tool with no data storage is as needless!<span><a href="http://blogs.manageengine.com/image/501000000109077/clock-no-hands.jpg"><img src="http://blogs.manageengine.com/image/501000000109077/clock-no-hands.jpg" alt="Free tool with no data storage is like this clock" style="width: 247px; height: 244px;" class="alCenter"></a></span></div><p> At the end of the day, "relative results" matter. To be able to show that one has made certain changes and how it has affected the network for good, hopefully! All this is possible only if a large amount of data is available for analysis. There are free tools which offer to store data for up to one w<span style="font-weight: bold;">HOLE</span> day. All a user will find the next day is a hole in the previous day data. A clean data base and a blank look on one's face. For analysis, data size is very critical. And it doesn't take a genius to say that one day data does not contribute to any analyzable data. Time and data are somethings that cannot be got back once lost (data can be, if you have fail-over, but, hey! how many free tools have that!). <br></p><p>Even when you are going for a free tool, you have a choice to make. To make the choice between something that is going to cost your time and data or the one that is<span style="font-weight: bold;"> </span>useful-AND-free, which can store the data forever, carry out the necessary analysis. <br></p><p><span><a href="http://www.manageengine.com/products/netflow/download-free.html" target="_blank" title="NetFlow Analyzer - Free and useful">NetFlow Analyzer free edition</a></span> lets you monitor two most critical interfaces in your network and the data can be stored forever - that is absolutely <span style="font-weight: bold;">free AND useful</span>. An useful solution which gives better analysis with the data that can be stored forever. You can see the history of security threats, the trend of bandwidth requirement growth over a period of time, answers questions such as "who are the top talkers?, is the bandwidth used for the business critical applications ?" and much more.</p><p>So you want a "free" tool or a free <span style="font-weight: bold;">AND </span>useful tool?<br> </p><p>Cheers</p><p>Joe</p><p style="font-weight: bold;"><span><a href="http://twitter.com/NetFlow_geek" target="_blank" title="netflow on twitter">Follow NetFlow Analyzer on twitter!</a></span></p>]]></description>
			<category><![CDATA[General]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/29/free-vs-free-and-useful</guid>
			<pubDate>Thu, 29 Oct 2009 07:53:02 -0700</pubDate>
		</item>

		<item>
			<title>NetFlow Analyzer and NBAR – A step closer to better Traffic Management</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/27/netflow-analyzer-and-nbar</link>
			<dc:creator>Don Thomas Jacob</dc:creator>
			<description><![CDATA[<div style="text-align: justify;">Bandwidth monitoring and traffic analysis is turning out to be more important than ever with growing advances in networking technologies and advent of Web 2.0. It is no more possible to simply let the organization's traffic network pass through the WAN links, pushing each other for bandwidth. Prioritizing traffic, so that mission-critical applications receive the bandwidth they need, is the key word today.<br><br>There is a little feature called NBAR available in many Cisco devices, which lets you do a lot more than it spells and can play a great role in defining the network's traffic policies.<br><br>NBAR or <span style="font-style: italic;"><a href="http://www.cisco.com/en/US/products/ps6616/products_ios_protocol_group_home.html" target="_blank">Network-Based Application Recognition</a></span><span style="font-weight: bold;"></span> is a feature available in Cisco IOS that does a deep packet inspection of traffic passing through an interface and can recognize a <span style="font-style: italic;"><a href="http://www.cisco.com/en/US/docs/ios/12_4t/qos/configuration/guide/qsnbar1.html#wp1056828" target="_blank">wide variety of applications</a></span>, including applications that dynamically assigns TCP or UDP port numbers or even undesired applications that uses well known port numbers to mask itself.<br><br>NBAR will show the details of the applications used on an interface basis. The feature can identify even peer to peer applications like Bit Torrent or applications like Skype which uses random port numbers for connectivity and hogs the organizational bandwidth. The results available from NBAR can also be used to <span style="font-style: italic;"><a href="http://blogs.manageengine.com/netflowanalyzer/2009/02/17/netflow-based-application-detection-and-qos-implementation-1-of-4" target="_blank">define your QoS policies</a></span> in a much better manner blocking out the unwanted applications.<br><br><span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span>, which uses <span style="font-style: italic;"><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">NetFlow</a></span> data and other <span style="font-style: italic;"><span><a href="http://www.manageengine.com/products/netflow/supported-devices.html" target="_blank">similar flow data</a></span></span> to give reports on bandwidth usage by host, port, protocol, applications, DiffServ and conversations, can also report on NBAR statistics from the your devices, making reporting an easy task.<br></div><br><span><a href="http://blogs.manageengine.com/image/501000000107901/nbar-report.jpg"><img src="http://blogs.manageengine.com/image/501000000107903/nbar%20report.jpg" alt="NBAR Report" title="NBAR Report" style="width: 484px; height: 303px;" class="alCenter"></a></span><br><div style="text-align: justify;"><br>NBAR with its deep packet inspection capability is a great feature for security analysis also. An example is how NBAR helped to identify CODE-RED worm and the related Cisco information can be seen from <span style="font-style: italic;"><a href="http://www.cisco.com/en/US/products/hw/routers/ps359/products_tech_note09186a00800fc176.shtml" target="_blank">here</a></span>. You can even make use of the AutoQoS for the Enterprise feature available in some Cisco devices which can use NBAR data for prioritizing traffic. Do check out how to do this from <span style="font-style: italic;"><a href="http://www.cisco.com/en/US/docs/ios/12_3t/12_3t11/feature/guide/ft_aqose.html" target="_blank">here</a></span>.<br><br>Since NBAR data help define CBQoS policies, NetFlow Analyzer can also report on the Class Based QoS policies and its pre and post policy traffic usage and drops. Get a first hand experience of the features in NetFlow Analyzer using the 30 day trail.<br></div><p style="font-weight: bold;"><span class="Apple-style-span" style="font-family: verdana; font-size: 12px; color: rgb(51, 51, 51); line-height: 19px; word-spacing: 1px;"><span><a href="http://www.manageengine.com/products/netflow/download-free.html?nfb" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Download</a></span>&nbsp;|&nbsp;<span><a href="http://demo.netflowanalyzer.com/?nfb" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Interactive Demo</a></span>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/nfa_overview/netflow_analyzer_overview.html?nfb" style="border-width: 0px; outline-style: none; color: rgb(20, 78, 137); text-decoration: underline;">Product overview video</a>&nbsp;| <span><a href="http://twitter.com/NetFlow_geek">Twitter</a>&nbsp;| <span><a href="http://www.manageengine.com/products/netflow/customers.html">Customers</a></span></span></span></span></p><p>Regards,<br>Don Thomas Jacob</p>]]></description>
			<category><![CDATA[Technical]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/27/netflow-analyzer-and-nbar</guid>
			<pubDate>Tue, 27 Oct 2009 08:34:29 -0700</pubDate>
		</item>

		<item>
			<title>ManageEngine NetFlow Analyzer : Flexible NetFlow Configuration using Pre-Defined Flow Record</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/23/manageengine-netflow-analyzer-flexible-netflow-configuration-using-pre-defined-flow-record</link>
			<dc:creator>vraj</dc:creator>
			<description><![CDATA[<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;This blog may need prior reading of <span><a href="http://blogs.manageengine.com/netflowanalyzer/2009/10/21/manageengine-netflow-analyzer-how-to-configure-cisco-flexible-netflow">my first blog</a></span> about Flexible NetFlow. We have already discussed about the advantages of <span><a href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6555/ps6601/ps6965/white_paper_c11-545581.html">Flexible NetFlow</a></span> and migration from traditional NetFlow versions to FNF. To make this transition smooth <span><a href="http://cisco.com/">Cisco</a></span> provides the option of pre-defined flow records which can be used to configure Flexible NetFlow without investing a lot of time. And as I mentioned earlier it also helps your existing NetFlow V9 collector to parse exported data. However to use Flexible NetFlow to its fullest potential or to monitor a specific network behavior, you should create your own customized records.&nbsp;</p><p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;Let’s see how to configure Flexible NetFlow to export flow statistics. Flexible NetFlow export can be configured in three easy steps.</p><p>1. Configure the exporter</p><p>2. Configure the Flow Monitor with the pre-defined Flow Record and Flow Exporter attached to the monitor.</p><p>3. Add the Flow Monitor to the interface to monitor either ingress (input) or egress (output traffic).</p><p><br></p><p><b>1. Configuring Exporter</b></p><p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Flow exporter can be configured with a unique name. Multiple Flow exporter profiles can be configured. Below is the configuration to configure Flow Exporter.</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>flow exporter &lt;exporter name&gt;</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>destination &lt;ip address of ME NFA&gt;</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>transport udp &lt;port number&gt;</p><p>Example configuration:</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>flow exporter me_nfa_analyzer</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>destination 192.168.1.1</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>transport udp 9996 &nbsp;&nbsp;</p><p><br></p><p><b>2. Flow Monitor and Flow record configuration</b></p><p><span class="Apple-tab-span" style="white-space:pre">	</span>Flow record configuration defines the fields exported via NetFlow protocol. Flexible pre-defined flow records are based on the original NetFlow ingress or egress caches. Cisco provides a unique keyword to identify the pre-defined records and these records can associated with a Flexible NetFlow Flow record configuration. The Flexible NetFlow "netflow-original" and netflow ipv4 original-input are predefined records and these two records can be used interchangeably to export the basic key fields and time stamp fields. Flow monitors can also include packet sampling information if sampling is required.</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>flow monitor &lt;monitor name&gt;</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>record netflow-original</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>exporter &lt;exporter name&gt;</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>cache timeout active &lt;seconds&gt;</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>cache timeout inactive &lt;seconds&gt;</p><p>Example Configuration:</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>flow monitor me_nfa_monitor</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>record netflow-original</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>exporter me_nfa_analyzer</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>cache timeout active 60</p><p><br></p><p><b>3. Adding Flow Monitor to the interface</b></p><p><span class="Apple-tab-span" style="white-space:pre">	</span>Flow Monitor has to be attached to a specific physical or logical interface to export flow statistics for that particular interface. Below is the configuration to attach flow monitor to a specific interface.</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>interface &lt;interface name&gt;</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>ip flow monitor &lt;monitor_name&gt; input</p><p>Example Configuration:</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>interface serial0/0</p><p><span class="Apple-tab-span" style="white-space:pre">	</span>ip flow monitor me_nfa_monitor input</p><p><br></p><p>&nbsp;&nbsp; And the above configuration can be verified by "show flow monitor" command. As I mentioned earlier Flexible NetFlow has numerous advantages and has the power of supporting new performance monitoring statistics as soon as they are available. &nbsp;Flexible NetFlow is an evolving technology available in Cisco devices to help with visibility into how network assets are being used and the network behavior.&nbsp;</p><p>Please find more information on FNF <span><a href="http://www.cisco.com/web/go/fnf">here</a></span>.</p><p>&nbsp;&nbsp; ManageEngine constantly studies the market and user demands to support new technologies. In fact ManageEngine NetFlow Analyzer is the first tool to support multiple bandwidth and performance monitoring technologies like NetFlow, NBAR and CBQoS in the market. And currently ManageEngine NetFlow Analyzer supports Flexible NetFlow without any issues. Please write your questions to netflowanalyzer-support@manageengine.com. We are happy to assist you at any moment.</p><p>Thanks</p><p>Raj&nbsp;</p><p><span class="Apple-style-span" style="font-family: verdana; font-size: 12px; color: rgb(51, 51, 51); line-height: 19px; word-spacing: 1px;"><span><a href="http://www.manageengine.com/products/netflow/download-free.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline; border-style: initial; border-color: initial; border-style: initial; border-color: initial;">Download</a></span>&nbsp;|&nbsp;<span><a href="http://demo.netflowanalyzer.com/?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline; border-style: initial; border-color: initial; border-style: initial; border-color: initial;">Interactive Demo</a></span>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/nfa_overview/netflow_analyzer_overview.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline; border-style: initial; border-color: initial; border-style: initial; border-color: initial;">Product overview video</a>&nbsp;| <span><a href="http://twitter.com/NetFlow_geek">Twitter</a>&nbsp;| <span><a href="http://www.manageengine.com/products/netflow/customers.html">Customers</a></span></span></span></span></p>]]></description>
			<category><![CDATA[Technical]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/23/manageengine-netflow-analyzer-flexible-netflow-configuration-using-pre-defined-flow-record</guid>
			<pubDate>Fri, 23 Oct 2009 12:48:49 -0700</pubDate>
		</item>

		<item>
			<title>NetFlow Analyzer Enterprise Editon 7.0 released!</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/22/netflow-analyzer-enterprise-editon-7-0-released</link>
			<dc:creator>Joseph</dc:creator>
			<description><![CDATA[<p>Released! <br><br>NetFlow Analyzer Enterprise Edition 7.0 is packed with a load of amazing features.  The official PR is available <span style="font-weight: bold;"><a href="http://www.manageengine.com/news/netflow-distributed-monitoring-7-news.html" target="_blank" title="Press release for netflow enterprise edition 7.0">here</a></span>. <br><br>And happy to announce that NetFlow Analyzer Enterprise Edition supports Cisco NetFlow (<span><a href="http://www.manageengine.com/products/netflow/supported-devices.html" target="_blank" title="sFlow, jFlow, IPFIX, NetStream and more">and other flows</a></span>), Cisco NBAR and Cisco CBQoS  out–of–the–box. Download the <span style="font-weight: bold;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/download.html" target="_blank" title="Free trial">30-day free trial</a></span> and try it out in your network setup.<br><br>Following are some of the new features added in 7.0. <br></p><ul><li><strong>Validating QoS policies </strong>with Cisco CBQoS - Enterprise edition now supports <strong>Cisco CBQoS</strong>
and provides report on the per-class pre policy, post policy drops and
queues. This new feature complements the already existing support for
Cisco's Network based application recognition (<strong>NBAR</strong>), helping in application  mapping and providing better quality of service. <span><a href="http://blogs.manageengine.com/netflowanalyzer/2009/10/19/manageengine-netflow-analyzer-enterprise-edition-distributed-netflow-collection-and-reporting-solution-with-nbar-and-cbqos" target="_blank" title="CBQoS and NBAR in distributed monitoring">Read more...</a></span><br></li><br><li><strong>User based dashboard</strong>
page for guests / Operators - Each user can have their own dashboard,
only viewing devices that need to be monitored by them, which can be
sorted based on utilization, speed etc.</li><br><li><strong>Business hour alerts</strong>
- makes sure that the users do not have to worry about the alerts that
might be generated during non-business hours. With the new version of
NetFlow Analyzer, business hours can be preset as per the enterprise's
need and the alerts can be activated only during that period.</li><br><li><strong>Exclude IP address</strong>(es)
option in IP groups - During creations of IP groups, the exclude option
makes it much easier to exclude only particular addresses from a
network as the requirement may be. </li><br><li><strong>Radius authentication</strong>
- Radius Server is useful in centralised management of user credential
details. Once the user roles are defined in the User Management feature
of NetFlow Analyzer, subsequent authentication of the user profiles can
be done from the Radius Server.</li><br><li><strong>Exclude encrypted applications </strong>
- Enabling NetFlow on cryptomap tunnel interfaces double counts the ESP
/ GRE traffic. That can be prevented by applying this filter on
cryptomap tunnel interfaces.</li><br><li><strong> Output interface suppression</strong> - <strong>WAN optimizers</strong>
compress the packets and therefore the flow size varies. The size of
the packet going in and coming out is not the same, and the readings
can be misleading and confusing, to say the least. To avoid this, "<strong>Output Interface Suppression</strong>" can be used. The interface in which the compression takes place (destination/output interface) can be suppressed. </li><br><li><strong> ACL related drops</strong>
- Access control filter drops the flow information which contains data
pertaining to dropped traffic due to Access Control List. </li></ul><br><span style="font-weight: bold;">Existing users</span> can download the <span style="font-weight: bold;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/service-packs.html" target="_blank" title="NetFlow Analyzer service pack">service pack</a></span>. <span style="font-weight: bold;">New evaluators</span> can download the product from <span style="font-weight: bold;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/download.html" target="_blank" title="NetFlow Analyzer download">here</a></span>. <br><br>And catchup with  <span><a href="http://twitter.com/NetFlow_geek" target="_blank" title="netflow analyzer on twitter">NetFlow Analyzer on twitter.</a></span><br><br>Cheers <br>Joe<br><span></span><br><br><br><p></p>]]></description>
			<category><![CDATA[General]]></category>
			<category><![CDATA[Product Release Announcements]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/22/netflow-analyzer-enterprise-editon-7-0-released</guid>
			<pubDate>Thu, 22 Oct 2009 06:15:22 -0700</pubDate>
		</item>

		<item>
			<title>ManageEngine NetFlow Analyzer : Juniper Firewalls supports policy based JFlow/NetFlow export</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/22/manageengine-netflow-analyzer-juniper-firewalls-supports-policy-based-jflow-netflow-export</link>
			<dc:creator>vraj</dc:creator>
			<description><![CDATA[<span class="Apple-style-span" style="font-family: arial, helvetica, sans-serif; line-height: 20px;"><p>Hello,</p><p>&nbsp;&nbsp;Some of our community folks using <span><a href="http://www.manageengine.com/products/netflow/">ME NetFlow Analyzer</a></span> to monitor their Juniper firewalls SSG 500 series. It supports policy based netflow/JFlow export.&nbsp;</p><p>&nbsp;&nbsp;Can you share us the netflow/JFlow configuration to enable NetFlow/JFlow on these firewalls?</p><p>Thanks<br></p><p>Raj</p><p><span class="Apple-style-span" style="font-family: verdana; font-size: 12px; line-height: 19px; color: rgb(51, 51, 51); word-spacing: 1px;"><span><a href="http://www.manageengine.com/products/netflow/download-free.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Download</a></span>&nbsp;|&nbsp;<span><a href="http://demo.netflowanalyzer.com/?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Interactive Demo</a></span>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/nfa_overview/netflow_analyzer_overview.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Product overview video</a></span></span></p></span>]]></description>
			<category><![CDATA[Technical]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/22/manageengine-netflow-analyzer-juniper-firewalls-supports-policy-based-jflow-netflow-export</guid>
			<pubDate>Thu, 22 Oct 2009 03:33:57 -0700</pubDate>
		</item>

		<item>
			<title>ManageEngine NetFlow Analyzer : How to configure Cisco Flexible NetFlow</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/21/manageengine-netflow-analyzer-how-to-configure-cisco-flexible-netflow</link>
			<dc:creator>vraj</dc:creator>
			<description><![CDATA[<p style="text-align: justify;">&nbsp;<span><a href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6555/ps6601/ps6965/prod_white_paper0900aecd804be1cc.html">Flexible NetFlow</a></span> is the next generation flow export technique promoted by <span><a href="http://www.cisco.com">Cisco Systems</a></span>. As the word depicts it is highly flexible based on user requirements and to monitor specific network behaviour. Traditional NetFlow used a fixed seven tupple of IP information to identify a flow most of the time. Advantages of Flexible NetFlow&nbsp;</p><p>1. Flexibility to choose the desired export fields.&nbsp;</p><p>2. Reduce the number of flows and allows CPU to perform efficient routing and switching</p><p>3. Convergence of multiple accounting technologies into one accounting mechanism</p><p><b>Flexible NetFlow and NetFlow V9</b></p><p style="text-align: justify;">&nbsp;&nbsp;The export protocol of choice for Flexible NetFlow is the NetFlow Version 9 export protocol, but unfortunately and to date, NetFlow Version 5 has been a much more widely used protocol because of the legacy Cisco IOS® Software images that are still around that supported the NetFlow v5 export protocol only and worked very well. However Cisco claims the future is going to be Flexible NetFlow. And believe it this migration is going to very smooth since Flexible NetFlow can also be configured to export some predefined flow records using the NetFlow Version 5 protocol format for backward compatibility. This helps your existing collectors can work with Flexible NetFlow until you find a real requirement to use additional fields offered by Flexible NetFlow.</p><p></p><p><b>Flexible NetFlow Configuration</b></p><p style="text-align: justify;">&nbsp;&nbsp; &nbsp;Traditional NetFlow configuration is pretty much straight forward. Flexible NetFlow consists of components that can be used together in several variations to perform traffic analysis and data export, and the new command-line interface (CLI) configuration follows the same traditional logic.In this user-defined flow records and the component structure of Flexible NetFlow make it easy to create various configurations for traffic analysis and data export on a networking device with a minimum number of configuration commands.&nbsp;</p><p>&nbsp;&nbsp; &nbsp;Flexible NetFlow consists of components that can be used together in several variations to perform traffic analysis and data export, and the new command-line interface configuration follows the same traditional logic.</p><p>&nbsp;Let's see this components in detail</p><p><i>Flow Monitor:</i></p><p style="text-align: justify;">&nbsp;&nbsp; &nbsp;A Flexible NetFlow Flow Monitor describes the NetFlow cache or information stored in the cache. The Flow Monitor contains the Flow Records or key and non-key fields within the cache. Also, part of the Flow Monitor is the Flow Exporter which contains information about the export of NetFlow information including the destination address of the NetFlow collector. The Flow Monitor includes various cache characteristics including the timers for exporting, the size of the cache and if required, the packet sampling rate.</p><p><i>Flow Record:</i></p><p style="text-align: justify;">&nbsp;&nbsp; &nbsp;A Flow Record is a set of key and non-key NetFlow field values used to characterize flows in the NetFlow cache. Flow Records may be pre-defined for ease of use or customized and user defined. A typical pre-defined record will aggregate flow data and allow users to target common applications for NetFlow. User defined records will allow selection of specific key or non-key fields in the Flow Record. The user defined field is the key to Flexible NetFlow allowing a wide range of information to be characterized and exported by NetFlow. It is expected that different network management applications will support specific user defined and pre-defined Flow Records based on what they are monitoring (ie: security detection, traffic analysis, capacity planning).</p><p><i>Flow Exporter:</i></p><p style="text-align: justify;">&nbsp;&nbsp; &nbsp;The Flexible NetFlow Exporter allows the user to define where the export can be sent, the type of transport for the export and properties for the export. Multiple exporters can be configured per Flow Monitor or the same exporter can be used by multiple monitors.</p><p>The following figure shows the flow monitor and it components.</p><p><span><a href="http://blogs.manageengine.com/image/501000000107537/flex-net-flow-mon.jpg"><img src="http://blogs.manageengine.com/image/501000000107537/flex-net-flow-mon.jpg" alt="Flexible NetFlow Flow Monitor" title="Flexible NetFlow Flow Monitor" class="alCenter" style=""></a></span><br></p><p style="text-align: justify;">&nbsp;In our <span><a href="http://blogs.manageengine.com/netflowanalyzer/2009/10/23/manageengine-netflow-analyzer-flexible-netflow-configuration-using-pre-defined-flow-record">next blog</a></span> we are going to use a pre-defined (defined in IOS itself) flow record to export netflow records using Flexible Netflow. In the meanwhile if you have any queries. please write to netflowanalyzer-eesupport@manageengine.com</p><p>Thanks</p><p>Raj</p><p><span class="Apple-style-span" style="font-family: verdana; font-size: 12px; color: rgb(51, 51, 51); line-height: 19px; word-spacing: 1px;"><span><a href="http://www.manageengine.com/products/netflow/download-free.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Download</a></span>&nbsp;|&nbsp;<span><a href="http://demo.netflowanalyzer.com/?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Interactive Demo</a></span>&nbsp;|&nbsp;<span><a href="http://www.manageengine.com/products/netflow/nfa_overview/netflow_analyzer_overview.html?nfb" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; outline-style: none; outline-width: initial; outline-color: initial; border-style: initial; border-color: initial; color: rgb(20, 78, 137); text-decoration: underline;">Product overview video</a></span></span></p><p><br></p><p></p>]]></description>
			<category><![CDATA[Technical]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/21/manageengine-netflow-analyzer-how-to-configure-cisco-flexible-netflow</guid>
			<pubDate>Wed, 21 Oct 2009 11:55:24 -0700</pubDate>
		</item>

		<item>
			<title>Erratic spikes in bandwidth utilization graphs? Resolve it  in 4 quick steps !</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/20/incorrect-utilization-in-netflow-analyzer-resolve-it-in-4-quick-steps</link>
			<dc:creator>Praveen Kumar V</dc:creator>
			<description><![CDATA[<p>We have posted a number of blogs to share information on how to use
<span><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">NetFlow</a></span> technology and <span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span> to manage your network better.
Those blogs will definitely continue to give you more ideas to put the
product to better usage but we will also discuss about some of the
common issues that you may have come across in the product and how they
can be resolved.<br clear="none"><br clear="none"><span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span>
generates traffic reports based on the <span><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">NetFlow</a></span> packets exported from
the router. Based on the information in the <span><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">NetFlow</a></span> packets, the
product displays the traffic passing through the interfaces of the
exporting device. <br clear="none"><br clear="none">One issue that is frequently reported is that the traffic utilization shown in <span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span> is more than the actual traffic on the interface. Reports
showing more than actual utilization or more than 100 % utilization can
be resolved quickly by checking a few points on the exporting device
and the product.<br clear="none"><br><span style="font-weight: bold;">Incorrect active timeout:</span><br><br clear="none">The
traffic reports in <span><a href="http://www.manageengine.com/products/netflow/">NetFlow Analyzer</a></span> is shown with a 1 minute
granularity, ie. <span><a href="http://www.manageengine.com/products/netflow/">NetFlow Analyzer</a></span> shows details of the traffic for each
minute. By default, the active timeout on the <span><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html">NetFlow</a></span> exporting devices
is 30 minutes, which means that the information about the traffic that
passed through the interface in the previous 30 minutes is exported at
the 30th minute.<br><br clear="none">Since <span><a href="http://www.manageengine.com/products/netflow/"></a></span><span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span> reports traffic
every minute, the export of 30 minutes information all at once leads to
the product's reports showing a spike every 30 minutes. The incorrect
traffic details for that minute leads to showing incorrect speed which
thus leads to worng utilization calculation. To avoid this, simply
check if the active timeout on the router is set to 1 minute using the
command <span><a href="http://www.manageengine.com/products/netflow/help/cisco-netflow/cisco-ios-netflow.html">"ip flow-cache timeout active 1"</a></span><span style="background-color: rgb(65, 105, 225);"></span>"<br clear="none"><br clear="none"><span style="font-weight: bold;">Multiple NetFlow commands:</span><br><br clear="none">NetFlow can be enabled on the router using any one of the three commands:<br clear="none"><br style="background-color: rgb(123, 104, 238);" clear="none"><span style="background-color: rgb(123, 104, 238); font-weight: bold;">ip
route-cache flow&nbsp;</span>&nbsp; <span style="font-weight: bold;">: -</span>&nbsp; This command can be applied on all main
interfaces and will automatically enable NetFlow on the sub interfaces
too. This command accounts for the IN traffic across an interface.<br><br clear="none"><span style="background-color: rgb(123, 104, 238); font-weight: bold;">ip
flow ingress&nbsp;</span><span style="font-weight: bold;">&nbsp;</span>&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;<span style="font-weight: bold;">&nbsp;&nbsp; :-&nbsp;</span> Some of the newer IOS supports this command
which also accounts for the IN traffic across an interface. The
difference is that this command needs to be applied on a sub-interface
level<br><br style="background-color: rgb(123, 104, 238);" clear="none"><span style="background-color: rgb(123, 104, 238); font-weight: bold;">ip flow egress</span><span style="font-weight: bold;">&nbsp;&nbsp;&nbsp;</span> &nbsp;&nbsp;&nbsp; <span style="font-weight: bold;">&nbsp;&nbsp;&nbsp; :-</span>&nbsp; The same as 'ip flow ingress' but this command accounts for the OUT traffic across an interface.<br clear="none"><br clear="none"><span><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">NetFlow</a></span>
can be enabled on the interfaces of the router by applying any one of
the above mentioned command, but most of the netwrok admin&nbsp; enable
either "ip flow ingress" or "ip route-cache flow" on the interfaces for
traffic accounting. When all these commands are applied on the
interfaces, it causes the same traffic to be counted multiple times
again causing the product to show incorrect traffic stats and thus
incorrect utilization reports.<br clear="none"><br clear="none"><span style="font-weight: bold;">Incorrect link speed in NetFlow Analyzer: </span><br><br clear="none"><span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span> calculates the utilization based on the link speed. For
example, if the link has capability to handle 1 Mbps and the actual
traffic passing through an interface is about 512 Kbps, the utilization graph in <span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span> displays the traffic percentage as 50 %. Here
is the&nbsp; formula which explains the utilization calculation on NetFlow
Analyzer.<br clear="none"><br style="font-weight: bold;" clear="none"><span style="background-color: rgb(100, 149, 237); font-weight: bold;">Utilization = Actual Speed/Link Speed * 100</span><br clear="none"><br clear="none">So,
if the link speed is not updated properly in NetFlow Analyzer, the
utilization shown in <span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span> will be different than the
actual. NetFlow&nbsp; Analyzer can determine the interface speed if you set
the appropriate SNMP Port and Community for the router on <span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span>. This can be&nbsp; done from the 'Set SNMP Parameters' icon on the
'Interface View' right next to the router name or you can set the
interface speed&nbsp; manually for each interface on NetFlow Analyzer (from
the Edit Settings icon on the 'Interface View' next to the interface
name). You can refer to this <span><a href="http://blogs.manageengine.com/netflowanalyzer/2009/09/17/interface-link-speed-vs-interface-bandwidth-command-what-netflow-analyzer-reports" target="_blank">blog</a></span> for more details.<br><br><span style="font-weight: bold;">Non dedicated burstable bandwidth:</span><br><br clear="none">Certain ISPs allows
you to use over the allocated bandwidth depending on the other
customers sharing that link. So, even though the max bandwidth is
2Mbps, the ISP may allow you to use even more based on availability.
This also affects the accurate reporting on NetFlow Analyzer causing
incorrect bandwidth utilization values and even more than 100%.<br><br><span style="font-weight: bold;">ESP and GRE traffic:</span><br clear="none"><br>This is another reason for traffic
to get double counted in <span><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span>. With <span><a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">NetFlow</a></span> data, the
tunnel traffic will be accounted as the normal traffic before
encryption and again as the encrypted traffic. NetFlow Analyzer have an
option to filter this kind of encrypted&nbsp; tunnel traffic from the
reports. This option is availble under Product Settings - Advance
Settings - ESP or GRE Filter.<br clear="none"><br clear="none">To know more about the about ESP and GRE traffic double count, check this <span><a href="http://blogs.manageengine.com/netflowanalyzer/2009/01/27/problem-traffic-double-counts-with-ipsec-tunnels-use-the-esp-filter-in-netflow-analyzer">link</a></span>.<br clear="none"><br clear="none">If none of the above resolves the issue, please find the technical explanation on what could still be causing this:<br clear="none"><br>Any
analyzer tools calculates the OUT traffic of an interface based on the
IN traffic of the interface that sends traffic to it. When traffic is
passing from higher speed interface to lower speed interface, the
calculation of OUT traffic from a higher speed IN traffic causes
incorrect traffic utilization to be shown on the OUT traffic.<br clear="none"><br>The
above reason for more than 100 % utilization on OUT traffic can be
resolved by enabling only "ip flow egress" on all the interfaces.<br><br>If you have any further queries on this, kindly send us a email at <span><a href="http://netflowanalyzer-support@manageengine.com" target="_blank">netflowanalyzer-support@manageengine.com</a></span>. <br><br>Thanks<br>Praveen<br><span><br><a href="http://www.manageengine.com/products/netflow/download-free.html?nfb">Download</a></span>&nbsp;| <span><a href="http://demo.netflowanalyzer.com/?nfb">Interactive Demo</a></span> | <span><a href="http://www.manageengine.com/products/netflow/nfa_overview/netflow_analyzer_overview.html?nfb">Product overview video</a></span><br><br clear="none"></p>]]></description>
			<category><![CDATA[General]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/20/incorrect-utilization-in-netflow-analyzer-resolve-it-in-4-quick-steps</guid>
			<pubDate>Tue, 20 Oct 2009 10:43:23 -0700</pubDate>
		</item>

		<item>
			<title>ManageEngine NetFlow Analyzer Enterprise Edition : Distributed NetFlow Collection and Reporting Solution with NBAR and CBQoS</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/10/19/manageengine-netflow-analyzer-enterprise-edition-distributed-netflow-collection-and-reporting-solution-with-nbar-and-cbqos</link>
			<dc:creator>vraj</dc:creator>
			<description><![CDATA[<p></p><p style="text-align: justify;">&nbsp;Being a niche player in the SAAS market, <span><a href="http://www.zoho.com/">Zoho</a></span> brings an<span style="font-weight: bold;"> </span>amazing level of<span style="font-weight: bold;"> </span>engineering
expertise to <span><a href="http://www.manageengine.com/">ManageEngine</a></span> in building highly secure and scalable
distributed applications. And hopefully you know, Adventnet has
recently changed its name to <span><a href="http://www.zohocorp.com/">Zoho Corp</a></span> and formed three divisions
namely <span><a href="http://www.manageengine.com">ManageEngine</a></span>, <span><a href="http://www.zoho.com/">Zoho</a></span>, and <span><a href="http://www.webnms.com/">WebNMS</a></span>.</p><div style="text-align: justify;">&nbsp;ManageEngine NetFlow Analyzer Enterprise Edition is a truly<span style="font-weight: bold;"> </span>distributed
NetFlow collection and reporting application, purpose-built for large
organizations managing hundreds and thousands of networking devices and
links across their geographically distributed business locations. When
we started building NetFlow Analyzer Enterprise Edition, one of the
biggest challenges we faced was improving the flow handling capacity
and building a unified view of geographically separated networks. After experiments, the engineering team concluded that offloading flow collection from the reporting center drastically improved the flow handling capacity.</div><br clear="none"><div style="text-align: justify;">&nbsp;Below is the architecture of our <span><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/index.html">distributed edition</a></span>. You can see the collectors are
deployed at every major business locations and data centers for flow
collection. These collectors compresses the exported flow data and
sends it via HTTPS connection to the central server for reporting
purposes. Here<span style="font-weight: bold;">,</span> most of the
flow processing functionalities were offloaded to collectors which
helps the central server to generate reports within seconds for any
particular device.</div><div style="text-align: justify;"><br></div><div style="text-align: center;"><span><a href="http://blogs.manageengine.com/image/501000000105597/netflow_analyzer_enterprise_architecture.gif"><img src="http://blogs.manageengine.com/image/501000000105599/netflow_analyzer_enterprise_architecture.gif" alt="NetFlow Analyzer EE Architecture" title="Distributed NetFlow Collection Architecture" style=""></a></span></div><div style="text-align: left;"><div style="text-align: left;">Many of the NetFlow Analyzers available in the market are not truely distributed in nature. They parse and store the flow records in the same collector and cannot give you the unified view of all the collection points. And there is no automatic crash recovery of data is possible. Unlike in ManageEngine, it involves individual backup and upgrade procedures which requires lot of maintenance activities. All these procedures are automated in ManageEngine NetFlow Analyzer Enterprise Engine via <span><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/failover.html">failover</a></span> and smart upgrade manager technologies. And this is why we call ManageEngine NetFlow Analyzer is a Enterprise class distributed NetFlow collection and reporting engine suitable for any large organisations. And when we say distributed we mean it.</div><div style="text-align: left;"><br></div><div style="text-align: left;">Before you start evaluating a distributed and scalable netflow monitoring solution, please ensure that you have the following Enterprise class features are available.</div><div style="text-align: left;"><br></div><div style="text-align: left;"><b>1. Distributed flow collection capability and optimized bandwidth usage between collectors and central reporting server.</b></div><div style="text-align: left;"><b>2. Scales upto 20000 interface with 15000 flows per second. Any number of collectors can be added without any additional license.</b></div><div style="text-align: left;"><b>3. Support for NetFlow V5,V7,V9 /sFlow, JFlow, NetStream, IPFIX.</b></div><div style="text-align: left;"><b>4. Support for Cisco NBAR and correlate NBAR data with NetFlow data.</b></div><div style="text-align: left;"><b>5. Support for CB-QoS (Class Based - Quality of Service) monitoring. Identify Pre and Post policy metrics and fine tune your QoS configurations.</b></div><div style="text-align: left;"><b>6. Failover support - automatic crash recovery and data replication. Please visit <span><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/failover.html">this link</a></span> for more information.</b></div><div style="text-align: left;"><b>7. Ability to use your existing SAN (Storage Area Network).</b></div><div style="text-align: left;"><b>8. Compatible with VM ware.</b></div><div style="text-align: left;"><b>9. No data loss even after a link failure between Collectors and Central Server.</b></div><div style="text-align: left;"><b>10. Ensure separate 64 bit binaries are available for increased flow handling and reporting performance.</b></div><div style="text-align: left;"><b>11. Secure data transfer - https mode between collector and central server</b></div><div style="text-align: left;"><b>12. Smart upgrade manager. Upgrade patchs are pushed automatically from the central console to collectors.&nbsp;</b></div><div style="text-align: left;"><b>12. User defined dashboards and views.</b></div><div style="text-align: left;"><b>13. Group devices based on their location and build tree view for easy access and troubleshooting.</b></div><div style="text-align: left;"><b>14. Ability to work in multiple time zones</b></div><div style="text-align: left;"><b>15. Network Forensics using raw data</b></div><div style="text-align: left;"><br></div><div style="text-align: left;">Sample screen shot from <span><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/new-features.html?temp">ManageEngine NetFlow Analyzer Enterprise Edition</a></span>:</div><div style="text-align: left;"><br></div><div style="text-align: left;"><span><a href="http://blogs.manageengine.com/image/501000000106003/netflow-analyzer-ee-view.jpg"><img src="http://blogs.manageengine.com/image/501000000106005/netflow_analyzer_ee_view.jpg" alt="NetFlow Analyzer EE View" title="NetFlow Analyzer EE View" class="alCenter" style=""></a></span><br></div><div style="text-align: left;"><br></div><div style="text-align: left;"><br></div><div style="text-align: left;">&nbsp;And remember thousands of users like <span><a href="http://www.cisco.com">Cisco</a></span>,<span><a href="http://www.adobe.com">Adobe</a></span>, <span><a href="http://www.ferrari.com/">Ferrari</a></span> and many <span><a href="http://www.manageengine.com/products/netflow/customers.html">fortune companies</a>&nbsp;</span>cannot be wrong.</div><div style="text-align: left;"><br></div><div style="text-align: left;">&nbsp;Please download and try our 30 day full featured trial edition in the following link</div><div style="text-align: left;"><br></div><div style="text-align: left;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/download.html">http://www.manageengine.com/products/netflow/distributed-monitoring/download.html</a></div><div style="text-align: left;"><br></div><div style="text-align: left;">Full Feature List is available in the following link</div><div style="text-align: left;"><br></div><div style="text-align: left;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/new-features.html?temp">http://www.manageengine.com/products/netflow/distributed-monitoring/new-features.html?temp</a></div><div style="text-align: left;"><br></div><div style="text-align: left;">&nbsp;&nbsp;Kindly write your questions to&nbsp;netflowanalyzer-eesupport@manageengine.com. We are happy to assist you at any moment.&nbsp;</div><div style="text-align: left;"><br></div><div style="text-align: left;">Thanks</div><div style="text-align: left;">Raj</div><div style="text-align: left;"><br></div></div><p></p>]]></description>
			<category><![CDATA[General]]></category>
			<category><![CDATA[Technical]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/10/19/manageengine-netflow-analyzer-enterprise-edition-distributed-netflow-collection-and-reporting-solution-with-nbar-and-cbqos</guid>
			<pubDate>Mon, 19 Oct 2009 03:47:10 -0700</pubDate>
		</item>
	</channel>
</rss>
