SlideShare una empresa de Scribd logo
1 de 27
Introduction
 A big “Howdy” from SolarWinds
  based in Austin, Texas
   » Josh Stephens, Head Geek, Monster Blogger,
     Constant Tweeter
   » Chris LaPoint – Senior Product Manager, lover of
     island living, beaches, and sand…

 Today’s Topic: Training on the Orion
  NetFlow Traffic Analyzer

 Who is SolarWinds?
   » Dude, if you don’t’ know this
     you’re on the wrong webcast…
Housekeeping

 Can you hear me now?
    If not, use the GoToWebinar chat or Q&A
     panel to let us know.
 How do you win the free stuff?
 How do you ask questions?
 Will this thing be recorded?

 Ask lots of questions, if needed
  we’ll do a part #2…
Agenda
   What is NetFlow and Why Do I Need It?
   NMS Deployment Preparation
   Installing and Configuring NTA
   Enabling Devices for NetFlow
   Maximizing the benefits of NTA
   Optimizing the User Interface
   Best Practices for using NTA data
   Q&A
Basics of Traffic Flow Technologies




 Keeps track of the traffic flowing from place to place
 Traditionally leveraged on to monitor layer 3 (routed)
  traffic flows
 Recent addition of layer 2 (switched) traffic detail
What is a “Flow”
 A flow is identified by   NetFlow v5 Key Fields

  combining a set of key    Source IP Address
                            Destination IP Address
  fields from the network   Source Port Number
  packets                   Destination Port Number
                            Layer 3 Protocol Type
                            ToS byte

 A flow has a set of       Logical Interface Index

  statistical data          NetFlow v5 Flow Statistics
                            System uptime start of flow
                            System uptime end of flow
                            # of packets in flow
                            # of bytes in flow
Shared Technical Details
 Transport Protocol is UDP
    » Some newer versions optionally support TCP and SCTP
    » UDP Port numbers are generally configurable


 Technology included within router/switch software
    » Check your IOS feature set if using Cisco gear
    » Some implementations in software, some on ASIC


 Easy to configure/enable on network gear
    » Usually only a few CLI commands
    » Some devices configurable via SNMP and/or web services interface
Top 5 Reasons to use Flow Technology
      Boss Reasons                        Geek Reasons
#5 Helps meet compliancy needs       #5 Helps you keep hackers out




#4 Enables cost savings on service   #4 Points out the bandwidth hogs
provider costs


#3 Aids with capacity planning       #3 Helps you fine-tune your QoS
                                     implementations


#2 Identify non-essential traffic    #2 Immediately know when a cool
                                     new YouTube video is discovered
Top 5 Reasons to use Flow Technology
   Boss Reason #1              Geek Reason #1
You already own the hardware   It’s just plain cool!!
Possible Downfalls – Rumors and Facts

        Turning on NetFlow will kill my routers…

        sFlow data isn’t valuable because it doesn’t
         include all of the data…

        Collecting NetFlow data can generate a very
         large database…

        I need to buy a complicated and expensive
         piece of software to leverage the flow data…
Comparison of Flow Analysis Technology
 NetFlow Version 5
   » Developed by Cisco Systems but now in use by several vendors
   » Includes details for all traffic flows
   » Reports data including source and destination interfaces, IP
     addresses, protocol, port numbers, AS numbers, and TOS/DSCP
     information.
 NetFlow Version 7
   » Rarely seen today
   » Specific to Cisco Catalyst Switches
 NetFlow Version 8
   » Rarely seen today
   » Aggregation Technology introduced
 NetFlow Version 9
   » Introduces flexible NetFlow concepts
   » Mainstream availability of aggregation features
Comparison of Flow Analysis Technology
 J-Flow
    » Developed by Juniper Networks
      • Effectively the same as NetFlow Version 5
 sFlow
    » Standards based (RFC 3176)
       • Supported by many vendors including HP,
         Extreme, Foundry, Juniper, Nortel
    » Is based on a statistical sampling of the data flows
    » Implemented primarily for layer 2/3 switches passing very large
      amounts of traffic
 IPFIX
    » Sometimes referred to as NetFlow Version 10
    » Uses NetFlow v9 as a starting point
    » Template based exporting
Comparison of Flow Analysis Technology
 J-Flow
   » Developed by Juniper Networks
   » Effectively the same as NetFlow Version 5
 sFlow
   » Standards based (RFC 3176)
   » Supported by many vendors including HP, Extreme, Foundry, Juniper,
     Nortel
   » Is based on a statistical sampling of the data flows
   » Implemented primarily for layer 2/3 switches passing very large
     amounts of traffic
 IPFIX
   » Sometimes referred to as NetFlow Version 10
   » Uses NetFlow v9 as a starting point
   » Template based exporting
NMS Deployment Preparation
 Step One – Define and document that scope of the
  network you’re managing
 Step Two – Identify the system requirements for Orion
  based upon the managed scope
 Step Three – Assess your current installation
  environment
 Step Four - Evaluate the gap (if any) and make plans for
  deployment
Step One – Scoping the Environment
 Discover/document the network
    »   Number of nodes
    »   Number of interfaces
    »   Number of NetFlow nodes and interfaces
    »   Speed of NetFlow interfaces
 Document and prioritize the best places to analyze traffic
    » Most expensive links
    » Internet connections
    » Junction points between networks
 Document the aggregate bandwidth that you’re trying to
  analyze (or number of flows if you can)
Step Two – Orion’s System Requirements
  Leverage the Orion NPM and NTA Administrator’s
   Guides
    » System requirements are well laid out within these manuals
    » Remember – these are minimum requirements. If you want better performance,
      you need to step up the hardware.


  Leverage your SQL Server admin’s expertise
    » Building high-performance SQL Servers is a form of art…
    » Explain to them the I/O requirements of your NMS
Step Three – Document the current setup
  Document what you have available today
     »   What sort of server is Orion on?
     »   Is SQL on the same machine?
     »   What sort of server is SQL on?
     »   What sort of storage system is in use?


  What do you have that you’re not using?
     » Corporate SQL server implementations…
     » Decommissioned HPOV or Exchange servers?
#5   Add more RAM. It’s almost always a good thing…

#4   Disk controllers – use disk controllers with at least 256MB of battery-
     backed up write back cache enabled. Put the data and log files on
     separate controllers.



#3   RAID – RAID 5 is OK for the OS, but don’t use it for data storage.
     RAID 1,0 offers significantly better I/O.


#2   Use Ramdisk. It significantly speeds up the SQL Server.


#1   Be very wary of SANs… Most aren’t optimized for this sort of use.
Step Four – Evaluate the gap
  Where is your current implementation deficient?
     »   Is the Orion server sized correctly?
     »   Does SQL need to be moved?
     »   Is the SQL server sized correctly?
     »   Do you need additional pollers/collectors?


  Prioritize your deployment
     » Start by enabling NetFlow on a single device/interface
     » Use the best practices for deploying in a “lean” environment
     » Ramp up your deployment as your hardware can support them
Installing and Configuring NTA in a Lean Environment

  Enable NetFlow collection pragmatically
  Go short on data retention
     » How much data can you really look at?
     » You can always increase it later…
  Enable “On Demand DNS Resolution”
  Use “Allow Monitoring of Flows from Unmanaged
   Interfaces”
  Use “Smart Traffic Filtering”
Smart Traffic Filtering

  In most networks, 95% of the traffic traversing the
   network is represented in only 4% of the flows
  Why store the noise?
  Smart Traffic Filtering uses 20x less data storage and
   I/O.
  Doesn’t change the use case for most customers…
  This is how you do it…
Smart Traffic Filtering

 To enable this feature, please follow these steps:
  Find file NetFlowService.exe.config by default located at “C:Program
   FilesSolarwindsOrionNetFlowTrafficAnalysis” and make backup copy of it

  Open this file in notepad

  Also, find the following line in the file and change options as specified below:

  <pduLimiter enabled="true" globalRestriction="1"
   dataPercentageRestriction="95"

  Save this file

  Restart NTA service
Enabling Devices for NetFlow
Step #1 – be sure that the device supports NetFlow, J-
Flow, sFlow, or IPFix.
             For Cisco devices – http://www.cisco.com/go/fn
Step #2 – leverage the hardware manufacturers
documentation for enabling NetFlow on the device. Start
with a single interface on that device.

Step #3 – if you’re having trouble configuring the device,
leverage video support

Step #4 – be sure the device and interfaces are managed
within Orion and that the interface is specified as a
“NetFlow managed interface”
Analyzing traffic thru non-NetFlow devices

 Be sure the device doesn’t support flow analysis
    » Does it support J-Flow, sFlow, or IPFix instead?
    » Is it by chance a Cisco ASA?
 Analyze from an adjacent device
 Consider adding a capable device instream
 Advanced tactic – leverage an open source tool to
  convert packet streams to NetFlow
Optimizing the Orion NTA Website
 For most use cases, drill down vs. using the NetFlow
  tab…
 Decide how important UI performance is to you and
  optimize views accordingly
 Avoid “Network Wide” resources where you can
 Don’t put “heavy” resources on heavily displayed pages

 Let’s go see what I mean…
Using the Information NTA Provides
   What each of the resources mean…
   Using NPM and NTA together
   Using the Traffic View Builder
   Solving problems
Summary and Q&A

Thank you for attending!

To learn more or to download free 30-day trials of
SolarWinds products visit: www.SolarWinds.com



Contact information
Josh Stephens, Head Geek
headgeek@solarwinds.com
twitter: sw_headgeek
Blog: http://thwack.com/blogs/geekspeak/

p.s. Remember to renew your maintenance!!!

Más contenido relacionado

La actualidad más candente

Building a Large Scale SolarWinds Installation
Building a Large Scale SolarWinds InstallationBuilding a Large Scale SolarWinds Installation
Building a Large Scale SolarWinds InstallationSolarWinds
 
PRTG Network Monitor Presentation
PRTG Network Monitor PresentationPRTG Network Monitor Presentation
PRTG Network Monitor PresentationNafaâ TAYACHI
 
How to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco RoutersHow to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco RoutersSolarWinds
 
Wireshark network analysing software
Wireshark network analysing softwareWireshark network analysing software
Wireshark network analysing softwaredharmesh nakum
 
Fortinet Icon Library
Fortinet Icon LibraryFortinet Icon Library
Fortinet Icon LibraryFortinet
 
SolarWinds® Getting Started With NPM and SAM
SolarWinds®  Getting Started With NPM and SAM SolarWinds®  Getting Started With NPM and SAM
SolarWinds® Getting Started With NPM and SAM SolarWinds
 
66 pfsense tutorial
66 pfsense tutorial66 pfsense tutorial
66 pfsense tutorialequinonesr
 
The History and Evolution of SDN
The History and Evolution of SDNThe History and Evolution of SDN
The History and Evolution of SDNNapier University
 
FD.IO Vector Packet Processing
FD.IO Vector Packet ProcessingFD.IO Vector Packet Processing
FD.IO Vector Packet ProcessingKernel TLV
 
Troubleshooting Network and Network Utilities
Troubleshooting Network and Network UtilitiesTroubleshooting Network and Network Utilities
Troubleshooting Network and Network UtilitiesRubal Sagwal
 
SDN Architecture & Ecosystem
SDN Architecture & EcosystemSDN Architecture & Ecosystem
SDN Architecture & EcosystemKingston Smiler
 
Network Troubleshooting - Part 1
Network Troubleshooting - Part 1Network Troubleshooting - Part 1
Network Troubleshooting - Part 1SolarWinds
 
Why sdn
Why sdnWhy sdn
Why sdnlz1dsb
 
MikroTik & RouterOS
MikroTik & RouterOSMikroTik & RouterOS
MikroTik & RouterOSFaelix Ltd
 

La actualidad más candente (20)

Building a Large Scale SolarWinds Installation
Building a Large Scale SolarWinds InstallationBuilding a Large Scale SolarWinds Installation
Building a Large Scale SolarWinds Installation
 
PRTG NETWORK MONITORING
PRTG NETWORK MONITORINGPRTG NETWORK MONITORING
PRTG NETWORK MONITORING
 
PRTG Network Monitor Presentation
PRTG Network Monitor PresentationPRTG Network Monitor Presentation
PRTG Network Monitor Presentation
 
Network monitoring system
Network monitoring systemNetwork monitoring system
Network monitoring system
 
How to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco RoutersHow to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco Routers
 
Wireshark network analysing software
Wireshark network analysing softwareWireshark network analysing software
Wireshark network analysing software
 
Fortinet Icon Library
Fortinet Icon LibraryFortinet Icon Library
Fortinet Icon Library
 
SolarWinds® Getting Started With NPM and SAM
SolarWinds®  Getting Started With NPM and SAM SolarWinds®  Getting Started With NPM and SAM
SolarWinds® Getting Started With NPM and SAM
 
Wireshark
WiresharkWireshark
Wireshark
 
66 pfsense tutorial
66 pfsense tutorial66 pfsense tutorial
66 pfsense tutorial
 
The History and Evolution of SDN
The History and Evolution of SDNThe History and Evolution of SDN
The History and Evolution of SDN
 
MPLS VPN
MPLS VPNMPLS VPN
MPLS VPN
 
Fortinet
FortinetFortinet
Fortinet
 
FD.IO Vector Packet Processing
FD.IO Vector Packet ProcessingFD.IO Vector Packet Processing
FD.IO Vector Packet Processing
 
Troubleshooting Network and Network Utilities
Troubleshooting Network and Network UtilitiesTroubleshooting Network and Network Utilities
Troubleshooting Network and Network Utilities
 
SDN Architecture & Ecosystem
SDN Architecture & EcosystemSDN Architecture & Ecosystem
SDN Architecture & Ecosystem
 
Network Troubleshooting - Part 1
Network Troubleshooting - Part 1Network Troubleshooting - Part 1
Network Troubleshooting - Part 1
 
Why sdn
Why sdnWhy sdn
Why sdn
 
Ip tables
Ip tablesIp tables
Ip tables
 
MikroTik & RouterOS
MikroTik & RouterOSMikroTik & RouterOS
MikroTik & RouterOS
 

Similar a Orion NTA Customer Training

Network Security and Visibility through NetFlow
Network Security and Visibility through NetFlowNetwork Security and Visibility through NetFlow
Network Security and Visibility through NetFlowLancope, Inc.
 
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...SolarWinds
 
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...SolarWinds
 
InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...
InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...
InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...InfluxData
 
WarsawITDays_ ApacheNiFi202
WarsawITDays_ ApacheNiFi202WarsawITDays_ ApacheNiFi202
WarsawITDays_ ApacheNiFi202Timothy Spann
 
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...Christian Esteve Rothenberg
 
Change the Way You Analyze Flow Data
Change the Way You Analyze Flow DataChange the Way You Analyze Flow Data
Change the Way You Analyze Flow DataSolarWinds
 
InfluxEnterprise Architecture Patterns by Tim Hall & Sam Dillard
InfluxEnterprise Architecture Patterns by Tim Hall & Sam DillardInfluxEnterprise Architecture Patterns by Tim Hall & Sam Dillard
InfluxEnterprise Architecture Patterns by Tim Hall & Sam DillardInfluxData
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.pptAssadLeo1
 
Security defined routing_cybergamut_v1_1
Security defined routing_cybergamut_v1_1Security defined routing_cybergamut_v1_1
Security defined routing_cybergamut_v1_1Joel W. King
 
AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101Timothy Spann
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightManageEngine, Zoho Corporation
 
Swisscom Network Analytics
Swisscom Network AnalyticsSwisscom Network Analytics
Swisscom Network Analyticsconfluent
 
NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...
NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...
NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...SolarWinds
 
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...Indonesia Network Operators Group
 
Integração de Dados com Apache NIFI - Marco Garcia Cetax
Integração de Dados com Apache NIFI - Marco Garcia CetaxIntegração de Dados com Apache NIFI - Marco Garcia Cetax
Integração de Dados com Apache NIFI - Marco Garcia CetaxMarco Garcia
 
SDN Demystified, by Dean Pemberton [APNIC 38]
SDN Demystified, by Dean Pemberton [APNIC 38]SDN Demystified, by Dean Pemberton [APNIC 38]
SDN Demystified, by Dean Pemberton [APNIC 38]APNIC
 

Similar a Orion NTA Customer Training (20)

Network Security and Visibility through NetFlow
Network Security and Visibility through NetFlowNetwork Security and Visibility through NetFlow
Network Security and Visibility through NetFlow
 
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
 
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
 
InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...
InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...
InfluxEnterprise Architectural Patterns by Dean Sheehan, Senior Director, Pre...
 
WarsawITDays_ ApacheNiFi202
WarsawITDays_ ApacheNiFi202WarsawITDays_ ApacheNiFi202
WarsawITDays_ ApacheNiFi202
 
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
IEEE HPSR 2017 Keynote: Softwarized Dataplanes and the P^3 trade-offs: Progra...
 
Change the Way You Analyze Flow Data
Change the Way You Analyze Flow DataChange the Way You Analyze Flow Data
Change the Way You Analyze Flow Data
 
InfluxEnterprise Architecture Patterns by Tim Hall & Sam Dillard
InfluxEnterprise Architecture Patterns by Tim Hall & Sam DillardInfluxEnterprise Architecture Patterns by Tim Hall & Sam Dillard
InfluxEnterprise Architecture Patterns by Tim Hall & Sam Dillard
 
network-management Web base.ppt
network-management Web base.pptnetwork-management Web base.ppt
network-management Web base.ppt
 
Security defined routing_cybergamut_v1_1
Security defined routing_cybergamut_v1_1Security defined routing_cybergamut_v1_1
Security defined routing_cybergamut_v1_1
 
AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings right
 
OpenFlow Tutorial
OpenFlow TutorialOpenFlow Tutorial
OpenFlow Tutorial
 
Swisscom Network Analytics
Swisscom Network AnalyticsSwisscom Network Analytics
Swisscom Network Analytics
 
NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...
NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...
NetFlow Deep Dive: NetFlow Tips and Tricks to get the Most Out of Your Networ...
 
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...
 
Integração de Dados com Apache NIFI - Marco Garcia Cetax
Integração de Dados com Apache NIFI - Marco Garcia CetaxIntegração de Dados com Apache NIFI - Marco Garcia Cetax
Integração de Dados com Apache NIFI - Marco Garcia Cetax
 
Introduction to Software Defined Networking (SDN)
Introduction to Software Defined Networking (SDN)Introduction to Software Defined Networking (SDN)
Introduction to Software Defined Networking (SDN)
 
Introductionto SDN
Introductionto SDN Introductionto SDN
Introductionto SDN
 
SDN Demystified, by Dean Pemberton [APNIC 38]
SDN Demystified, by Dean Pemberton [APNIC 38]SDN Demystified, by Dean Pemberton [APNIC 38]
SDN Demystified, by Dean Pemberton [APNIC 38]
 

Más de SolarWinds

SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds
 
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds
 
Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilitySolarWinds
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilitySolarWinds
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...SolarWinds
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsSolarWinds
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsSolarWinds
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...SolarWinds
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...SolarWinds
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsSolarWinds
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceSolarWinds
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceSolarWinds
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...SolarWinds
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion SolarWinds
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...SolarWinds
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning SolarWinds
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkSolarWinds
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...SolarWinds
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges SolarWinds
 

Más de SolarWinds (20)

SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
 
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
 
Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of Observability
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack Observability
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT Operations
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application Performance
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid Workforce
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your Network
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges
 

Último

Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 

Último (20)

Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 

Orion NTA Customer Training

  • 1.
  • 2. Introduction  A big “Howdy” from SolarWinds based in Austin, Texas » Josh Stephens, Head Geek, Monster Blogger, Constant Tweeter » Chris LaPoint – Senior Product Manager, lover of island living, beaches, and sand…  Today’s Topic: Training on the Orion NetFlow Traffic Analyzer  Who is SolarWinds? » Dude, if you don’t’ know this you’re on the wrong webcast…
  • 3. Housekeeping  Can you hear me now?  If not, use the GoToWebinar chat or Q&A panel to let us know.  How do you win the free stuff?  How do you ask questions?  Will this thing be recorded?  Ask lots of questions, if needed we’ll do a part #2…
  • 4. Agenda  What is NetFlow and Why Do I Need It?  NMS Deployment Preparation  Installing and Configuring NTA  Enabling Devices for NetFlow  Maximizing the benefits of NTA  Optimizing the User Interface  Best Practices for using NTA data  Q&A
  • 5. Basics of Traffic Flow Technologies  Keeps track of the traffic flowing from place to place  Traditionally leveraged on to monitor layer 3 (routed) traffic flows  Recent addition of layer 2 (switched) traffic detail
  • 6. What is a “Flow”  A flow is identified by NetFlow v5 Key Fields combining a set of key Source IP Address Destination IP Address fields from the network Source Port Number packets Destination Port Number Layer 3 Protocol Type ToS byte  A flow has a set of Logical Interface Index statistical data NetFlow v5 Flow Statistics System uptime start of flow System uptime end of flow # of packets in flow # of bytes in flow
  • 7. Shared Technical Details  Transport Protocol is UDP » Some newer versions optionally support TCP and SCTP » UDP Port numbers are generally configurable  Technology included within router/switch software » Check your IOS feature set if using Cisco gear » Some implementations in software, some on ASIC  Easy to configure/enable on network gear » Usually only a few CLI commands » Some devices configurable via SNMP and/or web services interface
  • 8. Top 5 Reasons to use Flow Technology Boss Reasons Geek Reasons #5 Helps meet compliancy needs #5 Helps you keep hackers out #4 Enables cost savings on service #4 Points out the bandwidth hogs provider costs #3 Aids with capacity planning #3 Helps you fine-tune your QoS implementations #2 Identify non-essential traffic #2 Immediately know when a cool new YouTube video is discovered
  • 9. Top 5 Reasons to use Flow Technology Boss Reason #1 Geek Reason #1 You already own the hardware It’s just plain cool!!
  • 10. Possible Downfalls – Rumors and Facts  Turning on NetFlow will kill my routers…  sFlow data isn’t valuable because it doesn’t include all of the data…  Collecting NetFlow data can generate a very large database…  I need to buy a complicated and expensive piece of software to leverage the flow data…
  • 11. Comparison of Flow Analysis Technology  NetFlow Version 5 » Developed by Cisco Systems but now in use by several vendors » Includes details for all traffic flows » Reports data including source and destination interfaces, IP addresses, protocol, port numbers, AS numbers, and TOS/DSCP information.  NetFlow Version 7 » Rarely seen today » Specific to Cisco Catalyst Switches  NetFlow Version 8 » Rarely seen today » Aggregation Technology introduced  NetFlow Version 9 » Introduces flexible NetFlow concepts » Mainstream availability of aggregation features
  • 12. Comparison of Flow Analysis Technology  J-Flow » Developed by Juniper Networks • Effectively the same as NetFlow Version 5  sFlow » Standards based (RFC 3176) • Supported by many vendors including HP, Extreme, Foundry, Juniper, Nortel » Is based on a statistical sampling of the data flows » Implemented primarily for layer 2/3 switches passing very large amounts of traffic  IPFIX » Sometimes referred to as NetFlow Version 10 » Uses NetFlow v9 as a starting point » Template based exporting
  • 13. Comparison of Flow Analysis Technology  J-Flow » Developed by Juniper Networks » Effectively the same as NetFlow Version 5  sFlow » Standards based (RFC 3176) » Supported by many vendors including HP, Extreme, Foundry, Juniper, Nortel » Is based on a statistical sampling of the data flows » Implemented primarily for layer 2/3 switches passing very large amounts of traffic  IPFIX » Sometimes referred to as NetFlow Version 10 » Uses NetFlow v9 as a starting point » Template based exporting
  • 14. NMS Deployment Preparation  Step One – Define and document that scope of the network you’re managing  Step Two – Identify the system requirements for Orion based upon the managed scope  Step Three – Assess your current installation environment  Step Four - Evaluate the gap (if any) and make plans for deployment
  • 15. Step One – Scoping the Environment  Discover/document the network » Number of nodes » Number of interfaces » Number of NetFlow nodes and interfaces » Speed of NetFlow interfaces  Document and prioritize the best places to analyze traffic » Most expensive links » Internet connections » Junction points between networks  Document the aggregate bandwidth that you’re trying to analyze (or number of flows if you can)
  • 16. Step Two – Orion’s System Requirements  Leverage the Orion NPM and NTA Administrator’s Guides » System requirements are well laid out within these manuals » Remember – these are minimum requirements. If you want better performance, you need to step up the hardware.  Leverage your SQL Server admin’s expertise » Building high-performance SQL Servers is a form of art… » Explain to them the I/O requirements of your NMS
  • 17. Step Three – Document the current setup  Document what you have available today » What sort of server is Orion on? » Is SQL on the same machine? » What sort of server is SQL on? » What sort of storage system is in use?  What do you have that you’re not using? » Corporate SQL server implementations… » Decommissioned HPOV or Exchange servers?
  • 18. #5 Add more RAM. It’s almost always a good thing… #4 Disk controllers – use disk controllers with at least 256MB of battery- backed up write back cache enabled. Put the data and log files on separate controllers. #3 RAID – RAID 5 is OK for the OS, but don’t use it for data storage. RAID 1,0 offers significantly better I/O. #2 Use Ramdisk. It significantly speeds up the SQL Server. #1 Be very wary of SANs… Most aren’t optimized for this sort of use.
  • 19. Step Four – Evaluate the gap  Where is your current implementation deficient? » Is the Orion server sized correctly? » Does SQL need to be moved? » Is the SQL server sized correctly? » Do you need additional pollers/collectors?  Prioritize your deployment » Start by enabling NetFlow on a single device/interface » Use the best practices for deploying in a “lean” environment » Ramp up your deployment as your hardware can support them
  • 20. Installing and Configuring NTA in a Lean Environment  Enable NetFlow collection pragmatically  Go short on data retention » How much data can you really look at? » You can always increase it later…  Enable “On Demand DNS Resolution”  Use “Allow Monitoring of Flows from Unmanaged Interfaces”  Use “Smart Traffic Filtering”
  • 21. Smart Traffic Filtering  In most networks, 95% of the traffic traversing the network is represented in only 4% of the flows  Why store the noise?  Smart Traffic Filtering uses 20x less data storage and I/O.  Doesn’t change the use case for most customers…  This is how you do it…
  • 22. Smart Traffic Filtering To enable this feature, please follow these steps:  Find file NetFlowService.exe.config by default located at “C:Program FilesSolarwindsOrionNetFlowTrafficAnalysis” and make backup copy of it  Open this file in notepad  Also, find the following line in the file and change options as specified below:  <pduLimiter enabled="true" globalRestriction="1" dataPercentageRestriction="95"  Save this file  Restart NTA service
  • 23. Enabling Devices for NetFlow Step #1 – be sure that the device supports NetFlow, J- Flow, sFlow, or IPFix. For Cisco devices – http://www.cisco.com/go/fn Step #2 – leverage the hardware manufacturers documentation for enabling NetFlow on the device. Start with a single interface on that device. Step #3 – if you’re having trouble configuring the device, leverage video support Step #4 – be sure the device and interfaces are managed within Orion and that the interface is specified as a “NetFlow managed interface”
  • 24. Analyzing traffic thru non-NetFlow devices  Be sure the device doesn’t support flow analysis » Does it support J-Flow, sFlow, or IPFix instead? » Is it by chance a Cisco ASA?  Analyze from an adjacent device  Consider adding a capable device instream  Advanced tactic – leverage an open source tool to convert packet streams to NetFlow
  • 25. Optimizing the Orion NTA Website  For most use cases, drill down vs. using the NetFlow tab…  Decide how important UI performance is to you and optimize views accordingly  Avoid “Network Wide” resources where you can  Don’t put “heavy” resources on heavily displayed pages  Let’s go see what I mean…
  • 26. Using the Information NTA Provides  What each of the resources mean…  Using NPM and NTA together  Using the Traffic View Builder  Solving problems
  • 27. Summary and Q&A Thank you for attending! To learn more or to download free 30-day trials of SolarWinds products visit: www.SolarWinds.com Contact information Josh Stephens, Head Geek headgeek@solarwinds.com twitter: sw_headgeek Blog: http://thwack.com/blogs/geekspeak/ p.s. Remember to renew your maintenance!!!