<rss version="2.0"
 	 xmlns:dc="http://purl.org/dc/elements/1.1/"
 	 xmlns:atom="http://www.w3.org/2005/Atom">

	<channel>
		<title>MangeEngine Blogs , Network Bandwidth Monitoring , Network Traffic Analysis , NetFlow Analysis , Bandwidth Reporting</title>
		<atom:link href="http://blogs.manageengine.com/netflowanalyzer/feed" rel="self" type="application/rss+xml"/>
		<link>http://blogs.manageengine.com/netflowanalyzer</link>
		<description><![CDATA[Manage Engine Product Blogs]]></description>
		<pubDate>Sat, 4 Jul 2009 10:57:00 -0700</pubDate>

		<item>
			<title>Cisco Live @ San Fracisco, IT Management @ booth 219!!</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/06/26/cisco-live</link>
			<dc:creator>Joseph</dc:creator>
			<description><![CDATA[<p>Its San Fran<span style="font-weight: bold;">Cisco </span>this time. If you are there and if you happen to be a 'networker', you are sure to attend <span style="font-weight: bold;"><span><a href="http://www.cisco-live.com/" target="_blank" title="cisco live">Cisco Live</a></span></span>. And if you fulfill all the conditions given in the previous line, you will definitely enjoy one stall. <span style="font-weight: bold;">Stall no. 219. </span>No points for guessing whose stall that will be!! That's where the <span style="font-weight: bold;">IT Management</span> gets 'booth'ed (due to lack of an equivalent word for 'personified'). Its the <span style="font-weight: bold; font-style: italic;"><a href="http://www.manageengine.com" target="_blank" title="manageengine">ManageEngine</a></span> stall!</p><p>ManageEngine will be showcasing its IT Management suite of products. With a suite of close to 25 products, ManageEngine has extensive knowledge &amp; experience in IT Management and when we say "We understand IT Management", we mean it!</p><p>If you are looking for powerful, cost-effective solution (I know its cliched but I'm being really honest!), <span style="font-weight: bold;">Stall no. 219</span> is certainly the place to be!<br></p><p>There are some surprises there, of course! Drop in to IT Management.... I mean ManageEngine!</p><p>See you @ 219<br></p><p>Cheers</p><p>Joe<br></p>]]></description>
			<category>General</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/06/26/cisco-live</guid>
			<pubDate>Fri, 26 Jun 2009 06:14:39 -0700</pubDate>
		</item>

		<item>
			<title>Centralized monitoring - Bringing distributed networks closer</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/06/18/centralized-monitoring-bringing-distributed-networks-closer</link>
			<dc:creator>Don Thomas Jacob</dc:creator>
			<description><![CDATA[<div style="text-align: justify;">When small organizations grow into enterprises, they also grow their
branches..Literally..Well, atleast as remote sites, branch offices and
DR centers. With current scenario defining cost saving as a primary
factor for growth, is it affordable to have IT staff at all the remote
locations? Having IT staff form monitoring the traffic at DR centers
and major branches is justified, but not at the sites having just a
couple of switching and routing devices.<br>
<br>
The best option that comes to the forefront is NetFlow. NetFlow
technology has the ability to give highly granular reports and with
almost all major vendors and a major series of devices supporting
NetFlow or similar flow formats, there is no need to add additional
hardware at extra cost which again leads to cost saving. All you need
is a software that can collect the flow packets and generate the
reports. Here again comes other questions. How can you collect flows
from the devices in various branch offices spread globally? If you
already have a NetFlow tool deployed, will it scale up to handle the
thousands of interfaces and flow rate of 40,000 to 60,000 flows per
second? Along with the need for monitoring remote locations with
detailed reports, there are also needs for features that cater to
specificities for branched networks like time zone based view. Can this
be provided by the existing tool?<br>
<br>
Now, even if your existing application can do all this, questions arise
on the feasibility of sending a large volume of data over valuable
Internet links. The priority is always to save the available Internet
bandwidth for business critical applications. To make the monitoring
easier, enterprises even try deploying different instances of the same
tool at the branches. But this does not help. The job of logging to
separate installations to check the status of multiples links,
generating reports for each interfaces which then have to be
consolidated and etc is a daunting task.<br>
<br>
In such a scenario <span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/" target="_blank">NetFlow Analyzer</a></span> <span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/index.html?nfabdis" target="_blank">Enterprise edition</a></span> with its
distributed flow collector and central server is the best suitable
solution. The Enterprise edition of NetFlow Analyzer has flow
collectors which can be deployed at various branches or geographic
locations. The devices at the branches or a site can send flows to the
collectors. The collectors will then collect the flows, compress them
and then send it over HTTPS (Yes! Security for valuable data) to the
central server. <br>
<br>
The central server is from where all the reporting and analysis takes
place. The central server collects data from the collectors, process
them and stores it to the database from where reports are generated.
You get real time visibility into the usage statistics about various
links from globally spread branches in a single console.<br></div><p>
<br>
<span><a href="http://blogs.manageengine.com/image/501000000041033/architecture.gif"><img src="http://blogs.manageengine.com/image/501000000041033/architecture.gif" alt="Distributed architecture" style=""></a></span><br>
<br>
</p><p style="text-align: justify;">The distributed flow collection and reporting engine gives the
Enterprise edition capability to monitor up to 20,000 interfaces and
flow rate in the range of even 60,000 flows per second. This rules out
scalability and performance related issues that might have other wise
come up with a integrated application trying to handle a large number
of interfaces and high flow rate. The features available in this
edition are also exactly what a distributed setup needs.<br>
<br>
Tree view for devices helps group devices based on their locations (or
your preferred criteria) for easier selection by users. This way, users
do not have to search through the complete list of devices to find the
one for which bandwidth metrics are needed. <span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/help/admin-operations/timezone.html" target="_blank">Timezone</a></span> based view lets
the users see reports in the time zone the device is at rather than
based on the time where the product is installed. Administrators can
also create multiple user accounts, assign devices or <span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/help/admin-operations/ip-group-mgmt.html" target="_blank">IP Groups</a></span> to them
and also set what timezone the users view the reports in. Do visit <span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/features.html?nfabdis" target="_blank">here</a></span>
to view the complete list of features available in Enterprise edition.<br>
<br>
You can also leave behind your worries about exported NetFlow packets
using a large volume of the Internet bandwidth. The NetFlow data is
compressed using Java technology before being send from the collector
to the central server. This brings down the volume of the exported
NetFlow data to less than 20% of the actual size and helps save your
valuable Internet bandwidth for critical applications. Moreover, since
data is send over HTTPS connection, the NetFlow data is secure and even
the GUI of both the collector and central server have HTTPS enabled by
default.<br>
<br>
Now with the central console, reports from the branches and DR sites
spread geographically are at hand. There is no more need to login into
different installations and have reports generated from each one of
them separately. You also have the option to select the interfaces
displayed in the dashboard and so at a single glance the network team
gets to see the status of highly utilized links or the status of
critical links.<br>
<br>
All enterprises preferred uninterrupted monitoring and reporting of
critical links, applications or servers. But when the need comes to
shut down the central server for maintenance or if the central server
is down inadvertently, what can be done? The <span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/help/Failover/failover.html" target="_blank">failover</a></span> is the
perfect feature for this. The data stored in the central server is replicated to
a secondary central server and any time the primary server goes down,
the secondary is automatically activated after a fixed time. Thus the
fail over gives you a automatic backup and redundancy of data.<br>
<br>
With all these features and its scalability, NetFlow Analyzer
Enterprise edition is the best suitable solution for bandwidth
monitoring and traffic analysis. Do download the Central server and
Collector from <span style="font-style: italic;"><a href="http://www.manageengine.com/products/netflow/distributed-monitoring/download.html?nfabdis" target="_blank">here</a></span> and start your 30 day evaluation with free
technical support from our team.</p><div style="text-align: justify;">Regards,<br>Don Thomas Jacob<br></div><br>]]></description>
			<category>Technical</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/06/18/centralized-monitoring-bringing-distributed-networks-closer</guid>
			<pubDate>Thu, 18 Jun 2009 06:45:53 -0700</pubDate>
		</item>

		<item>
			<title>For better or worse!! Time to Ponder..</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/06/15/for-better-or-worse-time-to-ponder</link>
			<dc:creator>Joseph</dc:creator>
			<description><![CDATA[<p>A <span style="text-decoration: underline;"></span><span style="font-weight: bold; font-style: italic;"><a href="http://www.cisco.com/en/US/solutions/collateral/ns341/ns525/ns537/ns705/ns827/white_paper_c11-481360_ns827_Networking_Solutions_White_Paper.html" target="_blank" title="Cisco study">new study</a></span> by Cisco suggests that "Global IP traffic will quintuple from 2008 to 2013". All the signs point to one question - Is your network bandwidth
utilized for better or worse! . Are the business critical applications getting enough bandwidth?! There comes a time, sooner or later
(preferably sooner), enterprises need to put a limit on their bandwidth
utilization and thus the costs accompanying it.<br><br>Some of the points of "concern" for enterprises would be:<br><br></p><ul><li>Internet video is now approximately one-third of all consumer Internet traffic</li><li>In 2013, the Internet will be nearly four times larger than it is in 2009</li><li>Peer-to-peer (P2P) is growing in volume</li></ul><p>Considering the growth of the internet, the increase in video traffic and P2P volume, its not a surprise that enterprises find it harder to keep a tab on the volume of traffic and the different applications that traversing their network. Of course the task is humongous and difficult, but "<span style="font-weight: bold;">A task is difficult only till the day you find a solution</span>". Today is the day and there is a <span style="font-weight: bold; font-style: italic;"><a href="http://www.netflowanalyzer.com" target="_blank" title="NetFlow Analyzer">solution</a></span> that <span><a href="http://www.manageengine.com/products/netflow/netflow-features.html" target="_blank" title="NetFLow Analyzer feature"><span style="font-weight: bold; font-style: italic;">can do a lot</span>.</a> <br></span></p><p><span>ManageEngine NetFlow Analyzer helps you monitor bandwidth, analyze network traffic and do network forensics. It keeps you informed if the business critical applications are getting enough bandwidth, if not then why. You can view the top talkers, applications, sources and destinations in your network. Reports can be exported, scheduled and threshold violation alerts can be set.&nbsp;</span><span></span></p><p><span>To mention a few of the "lot":</span></p><ul><li><a href="http://www.manageengine.com/products/netflow/bandwidth-monitoring.html">Network Bandwidth Monitoring</a></li><li><a href="http://www.manageengine.com/products/netflow/troubleshoot-faster.html">Faster Network Troubleshooting</a></li><li><a href="http://www.manageengine.com/products/netflow/site-to-site_traffic_monitoring.html">Site to site traffic monitoring</a></li><li><a href="http://www.manageengine.com/products/netflow/optimize-performance.html">Application Performance Optimization</a></li><li><a href="http://www.manageengine.com/products/netflow/Department-wise-bandwidth-monitoring-using-netflow-analyzer.html">Department wise bandwidth monitoring</a></li><li><span><a href="http://www.manageengine.com/products/netflow/cbqos.html" target="_blank" title="cbqos">Validate your QoS policies</a></span></li></ul><span><span></span></span><span>Check out the</span><span> <span></span></span><a href="http://demo.netflowanalyzer.com/" target="_blank" title="NetFlow analyzer demo"><span><span></span></span></a><a href="http://demo.netflowanalyzer.com/" target="_blank" title="NetFlow analyzer demo">interactive demo.</a><br><br><span>To quote an user "</span><span style="font-weight: bold;">ManageEngine NetFlow Analyzer was easy to install, has a very clean interface with good
reporting features, and is a better value than other retail options</span>."<span>(curious to know what others said, click <span style="font-weight: bold; font-style: italic;"><a href="http://www.manageengine.com/products/netflow/nfafans.html" target="_blank" title="NetFlow Analyzer fans">here</a></span>!)</span>
<p>Feel free to <span><a href="http://www.manageengine.com/products/netflow/download.html" target="_blank" title="NetFlow Analyzer">download</a></span> now and evaluate for 30 days with free technical support!<br></p><p>Cheers</p><p>Joe<br><a href='http://twitter.com/josephjay'>http://twitter.com/josephjay</a><br></p>]]></description>
			<category>General</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/06/15/for-better-or-worse-time-to-ponder</guid>
			<pubDate>Mon, 15 Jun 2009 04:10:20 -0700</pubDate>
		</item>

		<item>
			<title>Site to Site traffic with NetFlow Analyzer</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/06/04/site-to-site-traffic-with-netflow-analyzer</link>
			<dc:creator>Don Thomas Jacob</dc:creator>
			<description><![CDATA[<p style="text-align: left">With the branches of an enterprise extending to various locations and connectivity between the branches being a top priority, monitoring traffic between specific sites to ensure uptime and priority for business critical traffic is also very important.</p>
<p>The Site to Site option under IP Groups in <em><a href="www.manageengine.com" target="_blank">ManageEngine</a></em> <em><a href="www.netflowanalyzer.com" target="_blank">NetFlow Analyzer</a> </em>lets you monitor traffic between two specific sites based on IP Address or IP Network. This comes in handy to analyze who contributed to the traffic between the sites, if critical applications are indeed the ones utilizing the bandwidth and if the provided bandwidth does meet the requirement.</p>
<p>To explain how to use this feature and on how to interpret the data shown in the reports pertaining to the IP Group, we will make use of a simple example scenario.</p>
<p>Consider a network where you have a central office whose router is being monitored with NetFlow Analyzer. There are multiple branches, A, B and C, all of which communicate with one another through the main office router. Your requirement is to track the traffic specifically between Site A (192.16.1.82) and Site B (10.15.8.47).</p>
[caption id="attachment_3371" align="alignnone" width="300" caption="Branched network"]<a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/06/nfa-diagram1.gif"><img class="size-medium wp-image-3371" src="/image/501000000026586/nfa-diagram1-300x180.gif" alt="Branched network" width="300" height="180" /></a>[/caption]
<p style="text-align: left">In such a circumstance, you can make use of the Site to Site option under IP Groups.<br />
For this, create an IP Group and select the Between Sites option. Here, add the Site A (192.168.1.82) under the 'From' field and Site B (10.15.8.47) under  the 'To' field. You can add additional filter options like Port/Protocol and/or DSCP fields to this IP Group which would further filter the results based on the added criteria.</p>
<p>In 'Site to Site' IP Groups, for traffic classification purposes, the IP Address under the 'From' field is the primary IP and so all reports will be shown in relation to this IP Address or network. So, in our scenario, the IP Address 192.16.1.82, ie. Site A, is the primary IP Address.</p>
<p>Data Interpretation:</p>
<p>Traffic IN and OUT:<br />
Traffic is shown based on volume, speed, utilization and number of packets for the IP Group and is classified on an IN and OUT basis.<br />
Traffic IN refers to the traffic that came into the IP Group. Site A is considered as the primary IP Address and so any traffic that comes to Site A is classified as the IN traffic for the IP Group. The OUT traffic refers to the traffic that went out of the IP Group and so traffic leaving Site A is accounted as the OUT traffic.</p>
<p>Application:<br />
Application IN and OUT shows the applications that came in or went out of the IP Group and is classified the same way as Traffic IN and OUT.  Applications which formed the traffic to Site A is shown under Application IN. Those applications which constituted the traffic from Site A is Application OUT as Site A is considered the primary IP Address.</p>
<p>Source:<br />
The Source tab for the IP Group will show the source of traffic originating from the IP Group. When traffic flows from Site A to Site B, the source of the  traffic is 192.16.1.82 and the destination of the traffic is 10.15.8.47. Since the IP under 'From' field is the primary IP Address, 192.16.1.82 will form the addresses shown the source tab.</p>
<p>Destination:<br />
The Destination tab for the IP Group will show the destination of traffic reaching the IP Group. When Site A receives traffic from Site B, the source of the traffic is 10.15.8.47 and the destination of the traffic is 192.16.1.82. Since Site A is the primary IP Address, the IP Address 192.16.1.82 forms the destination address for the IP Group.</p>
<p>For both Source and Destination, you can click on the IP Address and drill down to find the related conversations. Source Address drill down will show the IP Address to which traffic was sent and Destination Address drill down shows the IP Addresses from where traffic originated for the IP Group.</p>
<p>Conversation IN and OUT:</p>
<p>The Conversation IN and OUT is the same as for Traffic IN and OUT. All conversations which came into the IP Group will be classified as Conversation IN and conversations which went out of the IP Group is Conversation OUT. So, Site B to Site A forms the Conversation IN and Site A to Site B forms the Conversation OUT for the IP Group.</p>
<p>Hope this gives you a better understanding on how to monitor traffic between various branches much more effectively and how to interpret the data in Site to Site IP Groups. Do email us at netflowanalyzer-support@manageengine.com  if you have any further queries. You can download the latest version of NetFlow Analyzer from <em><a href="http://www.manageengine.com/products/netflow/download.html?nfabs2s" target="_blank">here</a></em> and see the features available in NetFlow Analyzer from <em><a href="http://www.manageengine.com/products/netflow/7500-features.html/nfabs2s" target="_blank">this</a></em> link.</p>
<p>Regards,<br />
Don Thomas Jacob</p>
]]></description>
			<category>Technical</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/06/04/site-to-site-traffic-with-netflow-analyzer</guid>
			<pubDate>Thu, 4 Jun 2009 09:13:41 -0700</pubDate>
		</item>

		<item>
			<title>NetFlow Analyzer 7.5 - A quick peek!</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/06/02/netflow-analyzer-75-a-quick-peek</link>
			<dc:creator>Joseph</dc:creator>
			<description><![CDATA[<div class="moz-text-html" lang="x-western">
<p>As the team strives to bring better features, faster, with every new release, this release is no different. Lots of new features coming your way! I thought of giving you a peek in to the new features added. I will not be elaborating on it (hence "quick peek"). The detailed blogs will follow later, of course!</p>
<p>Some of the features with this release are:</p>
<ul>
<li><strong>Site to site traffic monitoring </strong></li>
</ul>
<p>Monitor the bandwidth utilized, top talkers, top conversations etc. between any two departments/sites in your enterprise network. Define the site by grouping the IP addresses and you are all set to monitor site to site traffic in your network. <span style="color: #99cc00"><strong><a title="NetFLow analyzer - site to site traffic monitoring" href="http://www.manageengine.com/products/netflow/site-to-site_traffic_monitoring.html" target="_blank">Read more..</a></strong></span></p>
<ul>
<li><strong>Customizable dashboard</strong></li>
</ul>
<p>NetFlow Analyzer provides a whole new user experience with the customizable dashboard. Customizable dashboard allows user to add widgets of their requirement in the dashboard and view the top talkers, host, conversations, applications and more, in one quick glance. Network traffic monitoring was never this easy before! <span style="color: #99cc00"><strong> <a title="NetFlow Analyzer - customizable dashboard" href="http://www.manageengine.com/products/netflow/customizable_dashboard.html" target="_blank">Read more.. </a></strong></span><a href="http://workspace-manageengine/products/netflow/customizable_dashboard.html"> </a></p>
<ul>
<li><strong>Volume based billing </strong></li>
</ul>
<p>Taking bandwidth monitoring to the next level! After the speed based billing, which was released in the previous version, comes "Volume based billing", which allows chargeback with respect to the volume of bandwidth consumed.</p>
<ul>
<li><strong>Email option for sending reports</strong></li>
</ul>
<p>A click is what it takes to send the reports you are seeing to someone else! This new feature lets the user to send the screenshot of the page the user is viewing, through e-mail with just a click.</p>
<ul>
<li><strong>GRE application filter </strong></li>
</ul>
<p>The GRE traffic in a cryptomap tunnel usually gets double counted. To avoid the double counting and thereafter caused errors in the traffic analysis, user has an option to apply GRE application filter in any interface of the user's choice.</p>
<p><strong><span style="color: #99cc00"><a title="NetFlow analyzer download" href="http://www.manageengine.com/products/netflow/download.html" target="_blank">Product download</a></span></strong></p>
<p><strong><span style="color: #99cc00"><a title="Free edition - NetFlow analyzer" href="http://www.manageengine.com/products/netflow/download-free.html" target="_blank">Free Edition</a> </span></strong>- with all features!</div>
<div class="moz-text-html" lang="x-western">Cheers</div>
<div class="moz-text-html" lang="x-western">Joe</div>
]]></description>
			<category>All</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/06/02/netflow-analyzer-75-a-quick-peek</guid>
			<pubDate>Tue, 2 Jun 2009 07:44:16 -0700</pubDate>
		</item>

		<item>
			<title>Enable egress based NetFlow to get the real QoS markings</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/05/26/enable-egress-based-netflow-to-get-the-real-qos-markings</link>
			<dc:creator>vraj</dc:creator>
			<description><![CDATA[<p>One of the common problems Network Administrators face while using ingress based NetFlow configuration is reporting of incorrect DSCP markings for the traffic going out from the WAN interfaces. This is absolutely due to the behavior of the ingress based NetFlow export configuration and this can be fixed by enabling egress based NetFlow data export.</p>
<p>Most of the enterprises deploy ISP provisioned circuits to its branch offices and configure output QoS markings on WAN interfaces for traffic prioritization. This ensures that business critical applications are given high priority for optimum performance. The following picture depicts a typical enterprise way of connecting branch offices and datacenters.</p>
<p><a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/05/diagram-3.gif"><img class="alignnone size-medium wp-image-3081" src="/image/501000000026572/diagram-3-300x197.gif" alt="" width="300" height="197" /></a></p>
<p>An Enterprise headquarters is connected to its branch offices and datacenter using an ISP circuit. The edge router in HQ is enabled with ingress based NetFlow data export. Let’s see how NetFlow Analyzer interprets QoS markings using the flow record.</p>
<p>As I mentioned earlier NetFlow data export is ingress based. Whenever a host with IP address 1.1.1.1 inside the LAN network starts sending data to server B in the branch office, the HQ router creates a NetFlow record in the cache with the following entries.</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Field</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Src IP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Dst IP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Port</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Protocol</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">DSCP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Src Inf</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Dst Inf</td>
</tr>
<tr>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Data</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">192.168.1.2</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">10.1.10.1</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">2113</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">TCP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top"><strong>Default</strong></td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">LAN –   Fa0/0</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">WAN-Serial0/0/0</td>
</tr>
</tbody>
</table>
<p>In the meanwhile due to the output QoS policy configuration in the WAN interface, the DSCP code of the traffic is altered to a high priority value and routed. And this priority change is not captured in the ingress based NetFlow traffic exported to Analyzer server since the flow cache was populated before the QoS policy action. Due to this NetFlow Analyzer reports the right DSCP value for the incoming traffic on the LAN interface and since the same flow record is used to calculate the out traffic for the WAN, WAN interface does not report the prioritized DSCP value on the outgoing traffic.</p>
<p>This issue can be fixed by enabling egress based NetFlow data export on the routers. The NetFlow Egress Support feature allows NetFlow accounting to be implemented for egress (outgoing) traffic on an interface or sub interface. Once the egress configuration is applied, NetFlow cache is populated with the information pertaining to outgoing traffic from any particular interface. For the same example which we have discussed above, the flow record will look like</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="border: 1pt solid black;padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Field</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Src IP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Dst IP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Port</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Protocol</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">DSCP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Src Inf</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Dst Inf</td>
</tr>
<tr>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">Data</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">192.168.1.2</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">10.1.10.1</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">2113</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">TCP</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top"><strong>AF1</strong></td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">LAN –   Fa0/0</td>
<td style="padding: 0in 5.4pt;width: 59.85pt" width="80" valign="top">WAN-Serial0/0/0</td>
</tr>
</tbody>
</table>
<p>As you see in the DSCP field now egress configuration reports the prioritized DSCP value since the NetFlow cache population happens after the promotion of DSCP value.</p>
<p>Additionally this egress based exports are also helpful to see the internal LAN IP addresses in the conversation reports, while NATing is in place on the router. Egress flows holds the local LAN IP addresses instead of the NATed IP address.</p>
<p>Please click <a href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124cg/hnf_c/ch05/nfb_bega.htm#wp1069461">here </a>for information on configuring egress based NetFlow export. This will give you more information on pre-requisites and configuration commands. Kindly write to support@netflowanalyzer.com for your questions.</p>
<p>Thanks</p>
<p>Raj</p>
]]></description>
			<category>All</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/05/26/enable-egress-based-netflow-to-get-the-real-qos-markings</guid>
			<pubDate>Tue, 26 May 2009 06:21:00 -0700</pubDate>
		</item>

		<item>
			<title>Either clean up or cough up $$!!</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/05/21/either-clean-up-or-cough-up</link>
			<dc:creator>Joseph</dc:creator>
			<description><![CDATA[<p>There are many solutions to a problem, be it cleaning up your house or tidying up your network. Ok!, not <strong>all</strong> problems have many solutions!!, but almost all of them do and I'm gonna tell you two such problems now.</p>
<p><em><strong>Note</strong>: While reading this, you might even wonder what this has got to do with your network. Read on..<br />
</em></p>
<p><strong>Problem 1</strong></p>
<p>You go home and find the house very dirty, clothes lying all around, many boxes of pizzas (many days old!), networking magazines, CD's out of the rack, coffee stains on the cushions... yada yada.. (You get the picture!). You come to the same place everyday but today you realize that it’s dirty because today there is not even enough place to rest your head.</p>
<p>You have two ways to solve the problem:</p>
<p>1. "<strong>Let the lying dirt lie</strong>" - You can move to a bigger house. On a short term, yes, this solution would be useful. But on a long run, No. It’s still going to get dirty again and eventually you'll have to move to a much bigger place. This $olution is obviously expen$ive and not a reliable one on a long run.</p>
<p>OR</p>
<p>2. <strong>Clean the house</strong> – Yea! You might even hire a maid if the idea of you cleaning the house sounds very strange to you. It is a cost effective solution and useful on the long run. You will get a space to sleep and monitor it periodically so that it never gets so dirty again.<strong><br />
</strong></p>
<p><strong>Problem 2</strong><br />
You are a network administrator (no, that's not the problem!). One day you realize that there is not enough bandwidth for your business critical application on your network. The network traffic is chaotic and you wonder how it happened. There is no point pondering "how it happened" but what you should be doing is looking for a solution.</p>
<p><strong>Solutions:</strong></p>
<p>1. You can commission extra bandwidth pipe, say from T1 to T3. Of course, this will solve the problem for a short period. But eventually you will have the same problem and many more sequels which will cost you lots of $$.</p>
<p>OR</p>
<p>2. You can invest on a <a title="NetFlow analyzer features" href="http://www.manageengine.com/products/netflow/netflow-features.html?bltdy" target="_blank"><strong></strong></a><strong><a title="NetFLow Analyzer features" href="http://www.manageengine.com/products/netflow/netflow-features.html" target="_blank">tool (highly affordable)</a></strong> that will help you find the "trash" applications, top talkers, etc on your network, help you get an in-depth visibility into your network traffic, gives you alerts, generates scheduled reports and the list goes on.</p>
<p>Make the <em><strong><a title="NetFlow Analyzer" href="http://www.netflowanalyzer.com" target="_blank">smart choice</a></strong></em>. And start tidying up your network (and your house, if necessary)!</p>
<p>And if you are at the <span style="color: #99cc00"><strong>Interop</strong></span>, visit us at <span style="color: #99cc00"><strong>booth 1169</strong>!</span></p>
<p>Cheers<br />
Joe</p>
]]></description>
			<category>All</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/05/21/either-clean-up-or-cough-up</guid>
			<pubDate>Thu, 21 May 2009 04:12:33 -0700</pubDate>
		</item>

		<item>
			<title>From the user's heart... for NetFlow Analyzer!</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/05/13/from-the-users-heart-for-netflow-analyzer</link>
			<dc:creator>Joseph</dc:creator>
			<description><![CDATA[<p>Given the fact that ManageEngine NetFlow analyzer has grown to be a well known and a very useful traffic analysis and network forensics tool, it comes as no surprise to find ourselves helping more than<em><strong> 3500 organizations </strong></em>worldwide see through their network deficiencies and fix it.</p>
<p>For all those who want to let it show, we have dedicated a page just for you. You can <strong><em><a title="NetFlow Analyzer feedback" href="http://www.manageengine.com/products/netflow/customer-feedback.html" target="_blank">jot in the reason</a></em></strong> for being a fan,  how NetFlow Analyzer has helped you save the day! It can be as short as, like Kevin Anderson puts it, "It works!", to as elaborate as ( to quote Nick Rieber) "It has helped identify our biggest bandwidth abusers, malicious applications running on the network, and an easy interface to see the network stats on our different locations."</p>
<p>Go on and let it show!</p>
<p>And if you are new to NetFlow Analyzer, you can check out what <strong><em><a title="NetFlow Analyzer Fans" href="http://www.manageengine.com/products/netflow/nfafans.html" target="_blank">users ("fans") have said</a></em></strong> and check out the<strong> <a title="Demo" href="http://demo.netflowanalyzer.com/" target="_blank"><em>interactive demo</em></a> </strong>or even <strong><em><a title="NetFlow Analyzer" href="http://www.manageengine.com/products/netflow/index.html?bfan" target="_blank">test drive the solution</a></em></strong>!</p>
<p>Cheers</p>
<p>Joe</p>
]]></description>
			<category>All</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/05/13/from-the-users-heart-for-netflow-analyzer</guid>
			<pubDate>Wed, 13 May 2009 09:27:07 -0700</pubDate>
		</item>

		<item>
			<title>Monitoring Remote Locations with NetFlow, NetFlow Analyzer and IP Groups</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/05/07/monitoring-remote-locations-with-netflow-netflow-analyzer-and-ip-groups</link>
			<dc:creator>Don Thomas Jacob</dc:creator>
			<description><![CDATA[<div style="text-align: justify;">
Enterprises, who serve a large customer base spread geographically, need a distributed setup of branch offices and head quarters. This helps organizations grow their business through better reach and customer interaction. Connectivity between the various office branches and head office is also a major requirement for faster data and information transfer. With such a distributed setup also comes the requirement for monitoring the traffic from the branches to the Internet and to other sites to ensure connectivity which can otherwise affect business continuity.
<p>Trying to diagnose and troubleshoot network problems at the remote locations can be a tough task as your router cannot show who is consuming the bandwidth, what application is used, the hosts involved, when spikes or choke in bandwidth occurred and due to what this happened. Deploying technical staffs at all branches for monitoring purposes is not a feasible solution too.</p>
<p>This is where NetFlow and <a href="http://www.netflowanalyzer.com" target="_blank"><em>NetFlow Analyzer</em></a> comes into the picture. Most of the Cisco devices supports NetFlow feature by default and other major vendors like HP, Riverbed, Juniper, Enterasys and so on also have a similar flow technology. NetFlow Analyzer <a href="http://www.manageengine.com/products/netflow/supported-devices.html?nfbbrn" target="_blank"><em>supports</em></a> not only NetFlow but most of the major flow formats. All you need to do is enable NetFlow on the devices and have them exported to your server running NetFlow Analyzer. And yes, you do not have to worry about the bandwidth taken up by NetFlow export as NetFlow itself does not utilize more than 2% to 3% of the link capacity.</p></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Using NetFlow Analyzer you can see traffic statistics for the whole branch office, who used what applications and how much of it and so on. As a network administrator you may also want to specifically see the traffic to the Internet and not to the main office. Now, how can this be achieved?</div>
<div style="text-align: justify;">For this purpose, the <a href="http://www.manageengine.com/products/netflow/help/admin-operations/ip-group-mgmt.html" target="_blank"><em>IP Group</em></a> feature available in NetFlow Analyzer can be used. Using IP Groups, you can monitor a specific 'IP' entity and make use of include and exclude options. To monitor traffic from the branches to the Internet and not the main office, create an IP Group and include the IP Network of the branch and exclude the IP Network of your main office. Also set the speed of the IP Group which is used for utilization calculation and can be set based on the associated interface speed or on the bandwidth allocated to the branch for Internet traffic.<br><br></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;"><a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/05/creating-ip-group-for-branch-office1.jpg"><img class="size-medium wp-image-2671" src="/image/501000000026544/for-branch-office1-300x225.jpg" alt="Creating IP Group for branch office monitoring" height="225" width="300"></a></div>
<div style="text-align: justify;">
<div class="mceTemp">
<dl>
<dd>Creating IP Group for branch office monitoring</dd>
</dl>
</div>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Once the IP Group is created, the traffic will be categorized based on the added criteria. In this IP Group, all traffic from the branch, but excluding the traffic to the main office, will be accounted for. You can see the traffic utilization to the Internet by the branches, the speed at which traffic is traversing, the applications going to the Internet, the hosts involved with the traffic and etc. When there is a bandwidth choke, you can check the traffic report and drill down to see the hosts involved, the destination to which they send traffic and what application was used.<br><br></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;"><a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/05/branch-office-link-utilization.jpg"><img class="size-medium wp-image-2681" src="/image/501000000026546/e-link-utilization-300x225.jpg" alt="Branch office Link utilization" height="225" width="300"></a></div>
<div style="text-align: justify;">
<div class="mceTemp">
<dl>
<dd>Branch office Link utilization</dd><dt><br></dt>
</dl>
</div>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/05/applications-to-the-internet-from-the-branch.jpg"><img class="size-medium wp-image-2691" src="/image/501000000026548/et-from-the-branch-300x225.jpg" alt="Applications to Internet from branch" height="225" width="300"></a></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;"><br>Applications to Internet from branch<br><br>So, sitting at the main office, you can monitor the branch office traffic to the Internet, if the links provided are being utilized or if there is unwanted traffic. This data helps make capacity planning decisions, find who misused the WAN connection and you can also get reports to your email using <a href="http://www.manageengine.com/products/netflow/help/admin-operations/Scheduler-Configuration.html" target="_blank"><em>Schedule Reports</em></a> and also have <a href="http://www.manageengine.com/products/netflow/help/admin-operations/alert-profiles.html" target="_blank"><em>Alerts</em></a> generated when the utilization exceeds a certain percentage. With NetFlow Analyzer and these <a href="http://www.manageengine.com/products/netflow/netflow-features.html?nfbbrn" target="_blank"><em>features</em></a>, remote management is taken to the next level.
<p>You can view a live demo of the product from <a href="http://demo.netflowanalyzer.com" target="_blank"><em>here</em></a>. Do post your suggestions and <a href="http://www.manageengine.com/products/netflow/download.html?nfbbrn" target="_blank"><em>download</em></a> NetFlow Analyzer trail edition to see what more you can do with the product.</p>
<p>Regards,<br>
Don Thomas Jacob</p></div>]]></description>
			<category>Technical</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/05/07/monitoring-remote-locations-with-netflow-netflow-analyzer-and-ip-groups</guid>
			<pubDate>Thu, 7 May 2009 03:28:03 -0700</pubDate>
		</item>

		<item>
			<title>Monitoring business critical servers with NetFlow Analyzer</title>
			<link>http://blogs.manageengine.com/netflowanalyzer/2009/05/04/monitoring-business-critical-servers-with-netflow-analyzer</link>
			<dc:creator>Don Thomas Jacob</dc:creator>
			<description><![CDATA[<div class="entrybody">
<p style="text-align: justify">Emails are an important aspect in every organization’s business needs. Email fetching issues or delay in mail delivery triggers many questions and raising of incident tickets by almost every employee ranging from the managers to CTO’s. Ensuring the up-time of the servers running <em><a href="http://blogs.manageengine.com/netflowanalyzer/2009/04/24/application-specific-traffic-monitoring-with-netflow-analyzer/" target="_blank">business critical applications</a></em> and links that connect to these servers are a big priority for a Network Administrator.</p>
<p style="text-align: justify">As a Network Administrator, you would definitely look forward to monitoring your organization’s email server to know if there is any unwanted traffic originating from it or to it, if the link connected to the server has the right capacity to carry the traffic, if the provided bandwidth is being choked and which hosts are the main contributors of the traffic.</p>
<p style="text-align: justify">But which is the&nbsp; <a href="http://www.manageengine.com/" target="_blank"><em>cost effective solution</em></a>? That is the “million-dollar”(pun intended!) question. The answer lies in&nbsp; <a href="http://www.netflowanalyzer.com" target="_blank"><em>NetFlow Analyzer</em></a> and its <a href="http://www.manageengine.com/products/netflow/help/admin-operations/ip-group-mgmt.html" target="_blank"><em>IP Group</em></a> feature. NetFlow Analyzer, an all software bandwidth monitoring solution, can monitor your network bandwidth and report on traffic usage across the links. By using the IP Group feature, you can monitor specific server or even a numbers of servers and get network reports on the traffic utilization, applications contributing to the traffic, hosts involved with the traffic and etc. This helps to find if only those applications that are actually supposed to contribute traffic to server are doing so, if any unwanted applications are running on the server, which specific host is sending high volumes of traffic, if the bandwidth provided is indeed right or if there is any bandwidth choke and at what time it happens.</p>
<p style="text-align: justify">You can create the IP Group by including the IP Address of your mail server and associate it with the interface that carries traffic to the mail server. You can also set the IP Group speed based on the speed of the interface carrying traffic to the server or based on the maximum speed to be taken by the traffic to the server. This speed is used for calculating the utilization percentage of traffic to the server.</p>
<div id="attachment_2561" class="wp-caption alignnone" style="width: 310px"><a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/05/creating-ip-group-for-mail-server.jpg"><img class="size-medium wp-image-2561" src="/image/501000000026530/up-for-mail-server-300x225.jpg" alt="Creating the IP Group" height="225" width="300"></a>
<p class="wp-caption-text">Creating the IP Group</p>
</div>
<p style="text-align: justify">The IP Group created will show the traffic based on volume, speed, utilization and packets. You can thus find if the link has the right speed to handle all the traffic to the server or if the provided speed is much higher than needed (This might not be an issue when considering the LAN traffic).<br><br />
The application tab shows you what applications contributed to the traffic to or from the server. You can see if the majority of traffic that came to or went out of the server is indeed SMTP or if there are applications like maybe FTP which should never have happened or an unexpected large volume of HTTP traffic. The advantages does not stop there. You can even drill down on an application to find what hosts were using these applications and volume of traffic they contributed.</p>
<div id="attachment_2571" class="wp-caption alignnone" style="width: 310px"><a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/05/applications-to-mail-server.jpg"><img class="size-medium wp-image-2571" src="/image/501000000026532/ons-to-mail-server-300x225.jpg" alt="Unwanted traffic to the mail server" height="225" width="300"></a>
<p class="wp-caption-text">Unwanted traffic to the mail server</p>
</div>
<div id="attachment_2581" class="wp-caption alignnone" style="width: 310px"><a href="http://blogs.manageengine.com/netflowanalyzer/files/2009/05/source-of-ftp-traffic-to-mail-server.jpg"><img class="size-medium wp-image-2581" src="/image/501000000026534/fic-to-mail-server-300x225.jpg" alt="Who was FTPing to the mail server" height="225" width="300"></a>
<p class="wp-caption-text">Who was FTPing to the mail server</p>
</div>
<div style="text-align: justify">You can also create alerts using <a href="http://www.manageengine.com/products/netflow/help/admin-operations/alert-profiles.html" target="_blank"><em>Alert Profiles</em></a> to let you know if the traffic to the server exceeds an expected percentage and have the alerts emailed to you or send as SNMP traps to management applications like <a href="http://www.manageengine.com/products/opmanager/" target="_blank"><em>OpManager</em></a>. The <a href="http://www.manageengine.com/products/netflow/help/admin-operations/Scheduler-Configuration.html" target="_blank"><em>Schedule Reports</em></a> option in NetFlow Analyzer lets you create the reports you need to be emailed to you on a daily weekly or monthly basis. So, while you check on other important tasks, you get reports about how well your mail server is in your email !</div>
<div style="text-align: left">Download the trail version from <a href="http://www.manageengine.com/products/netflow/download.html?nfabser" target="_blank"><em>here</em></a> and feel free to post your suggestions or email your queries to the product experts at netflowanalyzer-support@manageengine.com</p>
<p>Thanks and Regards,<br><br />
Don Thomas Jacob</p>
</div>
</div>
]]></description>
			<category>Technical</category>
			<guid isPermaLink="true">http://blogs.manageengine.com/netflowanalyzer/2009/05/04/monitoring-business-critical-servers-with-netflow-analyzer</guid>
			<pubDate>Mon, 4 May 2009 01:11:14 -0700</pubDate>
		</item>
	</channel>
</rss>
