Bandwidth monitoring and traffic analysis is turning out to be more important than ever with growing advances in networking technologies and advent of Web 2.0. It is no more possible to simply let the organization's traffic network pass through the WAN links, pushing each other for bandwidth. Prioritizing traffic, so that mission-critical applications receive the bandwidth they need, is the key word today.

There is a little feature called NBAR available in many Cisco devices, which lets you do a lot more than it spells and can play a great role in defining the network's traffic policies.

NBAR or Network-Based Application Recognition is a feature available in Cisco IOS that does a deep packet inspection of traffic passing through an interface and can recognize a wide variety of applications, including applications that dynamically assigns TCP or UDP port numbers or even undesired applications that uses well known port numbers to mask itself.

NBAR will show the details of the applications used on an interface basis. The feature can identify even peer to peer applications like Bit Torrent or applications like Skype which uses random port numbers for connectivity and hogs the organizational bandwidth. The results available from NBAR can also be used to define your QoS policies in a much better manner blocking out the unwanted applications.

NetFlow Analyzer, which uses NetFlow data and other similar flow data to give reports on bandwidth usage by host, port, protocol, applications, DiffServ and conversations, can also report on NBAR statistics from the your devices, making reporting an easy task.

NBAR Report

NBAR with its deep packet inspection capability is a great feature for security analysis also. An example is how NBAR helped to identify CODE-RED worm and the related Cisco information can be seen from here. You can even make use of the AutoQoS for the Enterprise feature available in some Cisco devices which can use NBAR data for prioritizing traffic. Do check out how to do this from here.

Since NBAR data help define CBQoS policies, NetFlow Analyzer can also report on the Class Based QoS policies and its pre and post policy traffic usage and drops. Get a first hand experience of the features in NetFlow Analyzer using the 30 day trail.

Download | Interactive Demo | Product overview video | Twitter | Customers

Regards,
Don Thomas Jacob

One year of Professional Plus!

Sep 01 2009 05:41:13 AM Posted By : Joseph
Comments (0)

Celebrating a year of releasing Professional Plus edition of ManageEngine NetFlow Analyzer! As one of the pioneers to leverage on Cisco NetFlow technology to give an in-depth view of the network traffic (for starters) and much more, we also take pride in leveraging other Cisco technologies like CBQoS and NBAR. With time comes stability and user-trust. Hence, we are glad that its been one year. It's around this time, last year, we released Professional Plus edition. For those who don't have an idea about the professional Plus edition, this is the edition that has 3 powerful, highly useful features (users said it, not me!) additional to all the features of professional edition, hence the name "Professional PLUS" (duh!! :)). The three features are

NBAR

  • Cisco technology for deep packet inspection
  • Helps in mapping applications that use dynamic ports, with ease.

CBQoS

  • Leverages on the Cisco CBQoS(class based quality of service) technology. Validate the QoS policies.
  • Reports on per class pre-policy, post-policy, drops and queues
  • More details

 
Billing

  • Useful for chargeback and accounting
  • Automatic bill plans as per schedule
  • Create any number of customized bill plans
  • More details

 

Download (30 day trial) | Interactive Demo | Website


Cheers

Joe

http://www.twitter.com/josephjay