Skip to main content

NetFlow Configuration Wizard

NetFlow Configuration Wizard pulls together various configuration options into one place.

  1. Used to configure most common settings for NetFlow
  2. Use SNMP to resolve router names, interface names, and speeds
  3. Enable Interface Tracking
  4. Email Alerts
  5. Create Trackers
  6. Create utilization alerts

Using the Wizard

To use the NetFlow Wizard, Login as admin and,

navigation

👉 Go to Context: Default → profile0 → NetFlow Wizard

Figure: Showing NetFlow Wizard for the Default Context

You will see a Check mark against each option that is configured correctly

Notice that the NetFlow Configuration Wizard has 6 Tabs.

  1. Basics: Essential setup for NetFlow
  2. Routers: Helps discover router names using SNMP (Optional)
  3. Interfaces: Enable or Disable “Interface Tracking” analytics
  4. Email Alerting: Alerts via Email
  5. Trackers: Enable this to provide drilldowns from router interfaces to metrics
  6. Utilization Alert: Generate alerts when any interface utilization crosses specific level of thresholds

Basic Configuration

Here you can configure the most common items related to NetFlow.

The current setting is shown just below the form items.

Configurations requiredDescription
Network Interface to listen onIf you are receiving NetFlow on an interface other than eth - click on Set Adapter and enter the new interface name.
Specify IP ranges in Home Network for calculating External and Internal trafficEnter IP ranges other than the default Private IP space that constitute your home network. This is used for calculating various metrics.
Select NetFlow/SFlow portsEnter the UDP ports that are mapped to NetFlow. If you want to enter a new port click on Set NetFlow Ports then enter a Port Number and select “NetFlow” from the drop down list.
Select counter groups typically used in NetFlow environments- In NetFlow mode many packet based counter groups such as HTTP Hosts, DNS Counters, SSL/TLS certificate metrics are not available. - Select Choose Counters then scroll to the bottom for Advanced Options then select - Typical enterprise NetFlow counter configuration
Switch Trisul Probes to NetFlow_TAPThe Probe nodes have to be in NetFlow_TAP mode. Click the button and ensure that the Packets or NetFlow parameter is changed to NetFlow_TAP from TAP
EdgesEnables the database containing the streaming graph of relationship between different entities
RingEnable to capture raw packets

Routers

After Trisul has collected NetFlow for a while, it automatically builds a map of Routers and their attached Interfaces. This page allows you to perform the following tasks on the discovered routers.

NOTE: Skip this step if you have just started collecting NetFlow. You can come back here after Trisul has been running for a few hours in NetFlow mode.

Select routers and then :

Configurations RequiredDescription
SNMP SettingsRead community string for discovery
Resolve Router and Interface NamesUsing SNMP resolve all sysName and interface name
SNMP Port MapMap netstream ifindex with snmp ifindex

Interfaces

This tab allows you to enable the “Interface Tracking” features for discovered interfaces.

NOTE
This step needs to have discovered NetFlow entities. Skip this step if you have just started collecting NetFlow a few minutes ago. You can come back here after Trisul has been running for a 15-20 minutes.

Select interfaces by clicking on the checkboxes and then :

Configurations RequiredDescription
Enable Interface Tracking for Top 100Enables the Interface Tracking feature for the busiest 100 interfaces
Enable Interface TrackingEnables Interface Tracking on the selected intefaces
Disable Interface TrackingDisables the feature
Create TCACreate TCA for selected interfaces
Delete TCADelete TCA for selected interfaces
AttributesClear attributes resets the configuration fields

Configure Email Alerts

This page allows you to configure real time E-Mail alerts for various conditions.

Configurations RequiredDescription
Email Account settingsOutgoing SMTP email account
Configure Email Alerts RecipientsEmail IDs of those who want to receive the alerts
Start/StopMust be started and running
Alerts go to syslogSelect which alert types go to SYSLOG. Trisul sends out Emails only for those alerts that are sent to SYSLOG. To send an alert type to SYSLOG, click on the button and select any SYSLOG alert level in the next screen.
Syslog readableChecks if syslog files on the hub node are readable

Once you go through the items in this wizard you will have a robust NetFlow based monitoring system.

Trackers

Trackers are Streaming algorithms that convert flow or packet metrics into sub metrics for hosts per interface, apps per interface, NBAR-APPID per interface and so on. Internally the trackers use the “Cross Key” counter groups for this purpose.

For Enterprises

Enable these to provide drilldowns from router interfaces to these metrics.These appear as Tabs in the Router and Interface Drilldown pages.

Configurations requiredDescription
Track ASN Per InterfaceOutgoing SMTP email account
Track Protocol Per InterfaceFor each interface track IP protocol usage for TCP, UDP, etc.
Track AppID / NBAR per interfaceFor each interface track which NBAR/AppID applications are using it. Automatically tags flow with NBAR/AppID
Track Interfaces Per InterfaceFor each interface track other interfaces. This will enable the Interface Matrix in Interfaces Drilldown.
Track Hosts per interfaceHost traffic per interface
Track Apps per interfaceApplication traffic per interface
Track User-ID per InterfaceFor each interface track User-ID from devices like Palo Alto firewalls
Track App- ID per InterfaceFor each interface track App-ID from devices like Palo Alto firewalls

For ISP (Internet Service Provider)

Configurations RequiredDescription
Track ASN for SubnetsAllows ISP to define IP subnets and assign them to customers, then track AS wise usage of those subnets.
Track ASN for LocationsAllows ISP to define Locations as a group of routers then track AS wise traffic for the entire location
Mixed BandwidthAllows ISP to define peering vs internet traffic
Track Mixed Bandwidth Per InterfaceFor each interface track mixed bandwidth(peerig vs internet)
Track Mixed Bandwidth for SubnetsFor each interface track mixed bandwidth(peerig vs internet)

Utilization Alert

Generate alerts when any interface utilization crosses these thresholds

Configurations requriedDescription
HighIf interfaces crossed 90% it will give high level alerts
MediumIf interfaces crossed 80% it will give medium level alerts
LowIf interfaces crossed 70% it will give low level alerts