Presentation is loading. Please wait.

Presentation is loading. Please wait.

NetFlow Analyzer Best Practices, Tips, Tricks. Agenda Professional vs Enterprise Edition System Requirements Storage Settings Performance Tuning Configure.

Similar presentations


Presentation on theme: "NetFlow Analyzer Best Practices, Tips, Tricks. Agenda Professional vs Enterprise Edition System Requirements Storage Settings Performance Tuning Configure."— Presentation transcript:

1 NetFlow Analyzer Best Practices, Tips, Tricks

2 Agenda Professional vs Enterprise Edition System Requirements Storage Settings Performance Tuning Configure Flow Exports

3 Agenda.. Application Groups IP Groups Reports ASAM

4 Prof vs EE Professional Edition Up to 600 interfaces Standalone version Enterprise Edition Up to 20,000 interfaces Scalable Central – Collector architecture Distributed networks

5 System Requirments Flow RateProcessorRAMHDD 0 to 30002.4 Ghz Dual2 GB250 GB 3000 to 60003.2 GHz Dual4 GB600 GB 6000 to 90003.2 GHZ Quad8 GB1 TB (High Speed SATA or SAS Drive) Above 90003.2 GHz Quad8 GB1 TB (High Speed S ATA or SAS Drive with RAID 0 or RAID 10 config)

6 Central Server Configuration

7 Storage Settings NetFlow Analyzer classifies data into 2 types namely Aggregated Data and the Raw Data. The amount of hard disk space required to store the aggregated data forever is about 150 MB per interface. You will require a free disk space of 2MB to store one month of one minute traffic data for a single interface.

8 Raw Data Free hard disk space - (150 MB * No. of Managed Interfaces) Raw Data Period (in hours) = ---------------------------------------------------------------------------------------- 60 Bytes * 3600 seconds * Flows Per Second The maximum raw data storage period is 1 month and the minimum is a day.

9 JVM Configuration Admin  Performance Tuning Select the RAM View the Recommended Settings and Update You can also change the Maximum Java Memory and update

10 Configuring Flow Export Make sure the time in the router is correct time Netflow Analyer can handle routers from different time zones automatically, provided the correct time is set. Whenever the time difference between the NetFlow Analyzer Server and the router is above 10 minutes a warning icon will appear in the home page.

11 Application Groups The Application Mapping option lets you configure the applications identified by NetFlow Analyzer. Applications are categorized based on the source address, destination address, source port, destination port and protocol values in the flow record. These values are matched with the list of applications in the Application Mapping.

12 IP Groups Monitor Departmental Traffic Monitor Branch Office Bandwidth usage

13 Reports Schedule Reports Generate Reports based on IP Groups

14 ASAM Generate Security Events – Bad Src –Dst – Suspect Flows – Probe / Scans – Dos / Flash crowd

15 Thanks


Download ppt "NetFlow Analyzer Best Practices, Tips, Tricks. Agenda Professional vs Enterprise Edition System Requirements Storage Settings Performance Tuning Configure."

Similar presentations


Ads by Google