Mikrotik – Traffic Analysis – NetFlow Analyzer

http://2.bp.blogspot.com/_jcpFiiP1rvg/S4dEOOoQnvI/AAAAAAAAAdg/qvxHsFDZLoc/s200/top-bg-graph.png

ManageEngine NetFlow Analyzer.

This web application is written in Java, as an HTTP server supports Apache, for storing data used by MySQL.

Using NetFlow Analyzer may own functional design “dashboards” that are suitable for the monitoring of the most important parts of the network infrastructure. Each panel is created taking into account the specific role of the individual administrator and may consist of multiple elements (widgets), responsible for the extraction of information from various sources.

Thanks to visibility dashboards NetFlow Analyzer can glance to assess the situation, get an idea of ​​the current load on the different parts of the network and examine performance without spending time searching and browsing disparate reports. Supplied NetFlow Analyzer includes over fifty “widgets.”

Let’s start from the beginning, ie installation and setup.

Installing NetFlow Analyzer.

Download the platform for our interest (Windows, Linux), in this case, Windows.

Run.

http://3.bp.blogspot.com/_jcpFiiP1rvg/S4dKEva3kZI/AAAAAAAAAdk/ylb70U6b6sU/s640/nf1.png

All components are placed in one folder on this if you wish, you can choose any.

Just when installation is requested ports on which services will work. Web interface port and the port on which the NetFlow packets will be sent.

http://2.bp.blogspot.com/_jcpFiiP1rvg/S4dKidaE2lI/AAAAAAAAAdo/FpYINCZBZok/s640/nf3.png

Indicate that would run as a service.

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4dMrvCItxI/AAAAAAAAAd0/He3eupy271M/s640/nf4.png

Specify the registration data

http://4.bp.blogspot.com/_jcpFiiP1rvg/S4dK7K2zrRI/AAAAAAAAAds/W0Iy2QvJedc/s640/nf5.png

In general, all as always, “Next”, “Next”, “agree”, “Once More,” “Finish”.

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4dMC_Sa5EI/AAAAAAAAAdw/PkEPy8z0_kE/s640/nf6.png

Upon completion of the installation is started does gets on the login page, the default user admin, and password admin.

http://2.bp.blogspot.com/_jcpFiiP1rvg/S4dNJx5sXGI/AAAAAAAAAd4/ZCV1PyUFopc/s640/nf8.png

Setting Mikrotik.

It’s all ready, now go to the management console Mikrotik and direct the flow of data to our server.

http://3.bp.blogspot.com/_jcpFiiP1rvg/S4dNa-3QI6I/AAAAAAAAAd8/L9AxS7Dz83Q/s640/nf9.png

Or all the same, only from the console:

/ Ip traffic-flow set enabled = yes

/ Ip traffic-flow target add address = 192.168.1.78: 9996 version = 9

The first team activates the service, the second indicates the receiving point, port, and protocol version.

Initial setup NetFlow Analyzer.

Now enter the NetFlow Analyzer and see what we have.

The first place you fall, it’s a list of interfaces being monitored, in this example, the interface named IfIndex * incoming connections on this vpn, interfaces complete * and it crafts * providers, local is the LAN interface.

http://4.bp.blogspot.com/_jcpFiiP1rvg/S4dREPFhmYI/AAAAAAAAAeA/xdMHxwZSpSg/s640/n1.png

If something does not work, then it makes sense to check the appropriate port on which the analyzer and listening port that is specified in Mikrotik.

Go to Admin Operations, Product Settings.

http://2.bp.blogspot.com/_jcpFiiP1rvg/S4dSaPM5mUI/AAAAAAAAAeE/pSvPQbx1rp8/s640/n2.png

Server Settings – Server Settings.

NetFlow / sFlow Listener Port – the port on which flows are taken from the devices.

WebServer Port – the port of the web interface.

Count Of Top Records to Store – the maximum number of rows in the tables with the displayed data.

DNS Settings – set specific dns names.

Resolve only when “Resolve DNS” link is clicked – selected by default, specifies the names by clicking on the “Resolve DNS”.

Resolve DNS names automatically by default- specifies the names automatically (slows down the work)

Resolved DNS count in cache – Size DNS cache.

User defined DNS names – Zdaes can specify static dns entry.

Probably the second place where you should look in the settings, and configure it to send mail.

http://3.bp.blogspot.com/_jcpFiiP1rvg/S4dYhd2ZGKI/AAAAAAAAAeM/D6IKhEw_L6w/s640/n4.png

Press the Test Mail.

http://3.bp.blogspot.com/_jcpFiiP1rvg/S4dZN_yX4fI/AAAAAAAAAeQ/GAap0fEypJM/s640/n5.png

Dashboard.

As mentioned at the outset is an interesting chip DashBoard, which exists in a certain initial state.

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4dbPpMzrXI/AAAAAAAAAeU/Rp8_GR9jshI/s640/n6.png

But the administrator can make the panel with widgets “for themselves.” For example, do something like this (it is not necessary to delve into much sense:-) I just pulled out the maximum potential widgets)

http://4.bp.blogspot.com/_jcpFiiP1rvg/S4deXmx90BI/AAAAAAAAAeY/mPlG3YYeCeY/s640/n7.png

They’re – here or who goes where and what shakes.

Let us return to the Interface tab and look at the statistics for one particular.

http://2.bp.blogspot.com/_jcpFiiP1rvg/S4dfAH-nhlI/AAAAAAAAAec/4uiWEdubyLo/s640/n8.png

The application tab displays information on the type of traffic.

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4dfhuKI3lI/AAAAAAAAAeg/0gwdWYunrjY/s640/n9.png

Click on a specific line, and we get detailed information. For example information on the HTTP traffic.

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4dggWIE8kI/AAAAAAAAAek/5oupyjPcSxE/s640/n10.png

You can reduce the results to the output (for example) 10 and do the conversion in the names ip (helps very not always).

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4djU1yLYoI/AAAAAAAAAeo/A3nEWvP44Oo/s640/n11.png

You can also request a detailed timetable for each compound.

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4dkTTfD3II/AAAAAAAAAes/BGgWmfy9Wcc/s640/n12.png

In the Source tab to receive reports on sources of traffic, and just select the specific element we get the details on it.

http://1.bp.blogspot.com/_jcpFiiP1rvg/S4dojSY_5FI/AAAAAAAAAew/DTSNEamd3q0/s640/n13.png

Group addresses.

Sometimes it is interesting to consider the traffic for multiple users simultaneously, for example servers that perform the exact same role.

Under Admin Operations have Subpart IP Grouups, where you can combine multiple addresses in a group to create a group of entire subnets, etc.

http://3.bp.blogspot.com/_jcpFiiP1rvg/S4dsvPy7VzI/AAAAAAAAAe0/emPk--1Qclw/s640/n14.png

Further it is already possible to obtain all of the same reports, but in the context of addresses, combined in this group.

http://3.bp.blogspot.com/_jcpFiiP1rvg/S4duoCsNI4I/AAAAAAAAAe4/BFJy4u3eN7s/s640/n15.png

For the lazy – reports by mail.

Probably the most enjoyable thing that I liked is the ability to generate reports and get out in the mail, it was not necessary to climb every morning in this interface and to order them, they just came with the morning mail.

Go to section Admin Operations, in subsection Schedule Reports.

http://3.bp.blogspot.com/_jcpFiiP1rvg/S4dxJGWrYBI/AAAAAAAAAfA/yGQ7v4DT6m0/s640/n16.png

As a result, the morning will receive a letter about this content.

http://4.bp.blogspot.com/_jcpFiiP1rvg/S4dy0GqBcYI/AAAAAAAAAfE/TWRKEdcaxyQ/s640/n17.png

Where will lie on the pdf-have for every interface about this content.

http://4.bp.blogspot.com/_jcpFiiP1rvg/S4dz6E_1gCI/AAAAAAAAAfI/5Kc-lRjkpfo/s640/n18.png

By Rayhan

My name is Rayhan and I'm an IT professional with over 10 years of experience in the field. I'm passionate about all things tech, and I love helping people solve their IT problems. In my free time, I enjoy tinkering with new gadgets and software, and I'm always on the lookout for the latest tech trends. I believe that technology has the power to make our lives easier and more enjoyable, and I'm excited to be a part of this ever-evolving field. Thank you for taking the time to visit my page.

Leave a Reply

Your email address will not be published. Required fields are marked *