NTop plugin
Moderators: Developers, Moderators
NTop plugin
I've just installed cigamit's ntop plugin.
Has anyone ever used this with an installation of Apache on the same machine? How'd you go about it?
Has anyone ever used this with an installation of Apache on the same machine? How'd you go about it?
Well, maybe not so beautifully...
Where is suggested you run ntop from - the cacti server or elsewhere? I was running it on the cacti server until I realized cacti wasn't collecting data any more!
Is this because of the way NTop used the NIC? If so, with a second NIC installed would it be able to run?
Where is suggested you run ntop from - the cacti server or elsewhere? I was running it on the cacti server until I realized cacti wasn't collecting data any more!
Is this because of the way NTop used the NIC? If so, with a second NIC installed would it be able to run?
ntop has an option whether to have the nic placed in promiscuous mode. do a man ntop for the flags on how to toggle it and/or look for it in ntop.conf
I was running ntop & cacti together for a while with no problems, both in ntop 3.1 and then more recently 3.2
I was running ntop & cacti together for a while with no problems, both in ntop 3.1 and then more recently 3.2
Cacti1 OS: CentOS 5.6 | 300+ devices
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
Correct. One of the main points of ntop is to monitor net traffic on the network, not just that computer
Cacti1 OS: CentOS 5.6 | 300+ devices
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
I have ntop running on the same NIC as Cacti as well.
They can peacefully co-exist.
I wrote (and borrowed) some instructions for getting ntop up and running on UNIX:
http://members.netjunkies.net/n3ncy/FreeBSD60/ntop.htm
On any platform, the steps should be similar:
1.) Get ntop installed on your server (ntop is a "Collector" and a web displayer of this collected data)
2.) Make sure you can log into ntop on your server (usually port 3000)
example: http://Yourserver:3000
3.) Configure a pair of items:
- Setup a "Collector" via your ntop web interface (see step 2 above)
- Export a "Flow" from your router to this collector
4.) Test ntop and look at this flow - You should be getting data
5.) Lastly setup the Cacti ntop plug-in to point to your ntop
example: http://Yourserver:3000
They can peacefully co-exist.
I wrote (and borrowed) some instructions for getting ntop up and running on UNIX:
http://members.netjunkies.net/n3ncy/FreeBSD60/ntop.htm
On any platform, the steps should be similar:
1.) Get ntop installed on your server (ntop is a "Collector" and a web displayer of this collected data)
2.) Make sure you can log into ntop on your server (usually port 3000)
example: http://Yourserver:3000
3.) Configure a pair of items:
- Setup a "Collector" via your ntop web interface (see step 2 above)
- Export a "Flow" from your router to this collector
4.) Test ntop and look at this flow - You should be getting data
5.) Lastly setup the Cacti ntop plug-in to point to your ntop
example: http://Yourserver:3000
Thank you,
Ernie
http://www.NMSWorld.com
[b]Dual Zeon Dual Core 2.6Ghz / 8GB RAM / 4x15k RPM SATA RAID5[/b]
[b]Cacti Version[/b] - 0.8.7b
[b]Poller Type[/b] - cactid 0.8.7 with Boost v1.7
[b]Server Info[/b] - FreeBSD 7.0-RELEASE
[b]Web Server[/b] - Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.8g DAV/2 PHP/5.2.5 mod_perl/2.0.3 Perl/v5.8.8
[b]PHP[/b] - 5.2.6
[b]MySQL[/b] - 5.0.51b Mod: poller_output ENGINE = MEMORY
[b]RRDTool[/b] - 1.3.0
[b]SNMP[/b] - 5.4.1
[b]Plugins[/b] - Host Info (hostinfo - v0.2), Update Checker (update - v0.3), Network Tools (tools - v0.2), FlowView (flowview - v0.3), Read-only Devices Tab (devices - v0.4), Network Discovery (discovery - v0.8.3), Syslog Monitoring (syslog - v0.5.2), Thresholds (thold - v0.3.9), Device Monitoring (monitor - v0.8.2), PHP Network Weathermap (weathermap - v0.941), SuperLinks (superlinks - v0.72), Report Creator (reports - v0.1b)
Ernie
http://www.NMSWorld.com
[b]Dual Zeon Dual Core 2.6Ghz / 8GB RAM / 4x15k RPM SATA RAID5[/b]
[b]Cacti Version[/b] - 0.8.7b
[b]Poller Type[/b] - cactid 0.8.7 with Boost v1.7
[b]Server Info[/b] - FreeBSD 7.0-RELEASE
[b]Web Server[/b] - Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.8g DAV/2 PHP/5.2.5 mod_perl/2.0.3 Perl/v5.8.8
[b]PHP[/b] - 5.2.6
[b]MySQL[/b] - 5.0.51b Mod: poller_output ENGINE = MEMORY
[b]RRDTool[/b] - 1.3.0
[b]SNMP[/b] - 5.4.1
[b]Plugins[/b] - Host Info (hostinfo - v0.2), Update Checker (update - v0.3), Network Tools (tools - v0.2), FlowView (flowview - v0.3), Read-only Devices Tab (devices - v0.4), Network Discovery (discovery - v0.8.3), Syslog Monitoring (syslog - v0.5.2), Thresholds (thold - v0.3.9), Device Monitoring (monitor - v0.8.2), PHP Network Weathermap (weathermap - v0.941), SuperLinks (superlinks - v0.72), Report Creator (reports - v0.1b)
- gandalf
- Developer
- Posts: 22383
- Joined: Thu Dec 02, 2004 2:46 am
- Location: Muenster, Germany
- Contact:
Sorry for dropping in ....
I used nTop 2-3 years ago but dropped it then. AFAIK, nTop does not need to gather all network traffic itself. You may configure it as a netflow collector. And e.g. some Cisco Router may be the netflow emitter (or use nProbe on a small and cheap box as an emitter, but then you'll need mirror ports or taps in a switched environment ...). This way, you get the stream info into nTop. But to be honest, my "knowledge" is only theoretical ...
Reinhard
I used nTop 2-3 years ago but dropped it then. AFAIK, nTop does not need to gather all network traffic itself. You may configure it as a netflow collector. And e.g. some Cisco Router may be the netflow emitter (or use nProbe on a small and cheap box as an emitter, but then you'll need mirror ports or taps in a switched environment ...). This way, you get the stream info into nTop. But to be honest, my "knowledge" is only theoretical ...
Reinhard
I'm about to install a second, dual NIC in this machine. I was hoping to tap our network between the ISP and firewalls (our IDS is already on one spanned port, so hopefully this isn't too much of a big deal) as well is in our core network. I would then, if possible, configure these two interfaces in NTop. I do not intend to provide IP addresses for them either - just a question of whether or not its possible to have more than one NIC in use at the same time.
I do have a question about configuring the routers to send flow data - how is it done and how many devices can you configure to do this at the same time, to the same nTop server? Probably a question better asked on an nTop board - but folks here appear to be knowledgable enough (and besides, I'm hoping to get something like this added to the Cacti package - maybe via Argus' xml output files???).
I do have a question about configuring the routers to send flow data - how is it done and how many devices can you configure to do this at the same time, to the same nTop server? Probably a question better asked on an nTop board - but folks here appear to be knowledgable enough (and besides, I'm hoping to get something like this added to the Cacti package - maybe via Argus' xml output files???).
another option would be to implement 8021q kernel module for the network card and add vlan interfaces for each subnet you want to listen to
(assuming linux)
do a 'man vconfig' to see what options are.
a simple setup
vconfig add eth1 <vlan #>
ifconfig 192.168.111.1 netmask 255.255.255.0 eth1.<vlan #> up
(whatever networks you want the box to listen to)
be sure to turn off ip forwarding on the ntop box
I think ntop can only listen up to 20 interfaces
(assuming linux)
do a 'man vconfig' to see what options are.
a simple setup
vconfig add eth1 <vlan #>
ifconfig 192.168.111.1 netmask 255.255.255.0 eth1.<vlan #> up
(whatever networks you want the box to listen to)
be sure to turn off ip forwarding on the ntop box
I think ntop can only listen up to 20 interfaces
Cacti1 OS: CentOS 5.6 | 300+ devices
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
Awesome - I'll certainly look into this! Hopefully I can do it without too much trouble running OpenSuSE 10. Of course, any kernel update is a PIA because of the machine I'm running it on...but I think the payoff here would be worth it.
I'll still need the various NICs, however, since I'll need to get past a firewall or two.
Currently, the second interface is plugged into our alternate Internet access network (a DSL connection for contractors). It's firewalled via SuSEfirewall and configured as being an external NIC. I also have no routes for it configured. I've automated Nessus scans for twice a month which utilizes that connection, the script that kicks it off also creates the route needed and then removes it after the scan is complete. I'm hoping that's enough. That network (the DSL connection) is also firewalled via a PIX.
I'll still need the various NICs, however, since I'll need to get past a firewall or two.
Currently, the second interface is plugged into our alternate Internet access network (a DSL connection for contractors). It's firewalled via SuSEfirewall and configured as being an external NIC. I also have no routes for it configured. I've automated Nessus scans for twice a month which utilizes that connection, the script that kicks it off also creates the route needed and then removes it after the scan is complete. I'm hoping that's enough. That network (the DSL connection) is also firewalled via a PIX.
kernel 2.6.x should have the vlan module (8021q) by default, you may just have to load it (insmod 8021q).
Cacti1 OS: CentOS 5.6 | 300+ devices
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
Cacti2 OS: CentOS 5.6 | 300+ devices
King of the Elves
Local Anarchists Union #427
"Anarchism is founded on the observation that since few men are wise enough to rule themselves, even fewer are wise enough to rule others." -Edward Abbey
Who is online
Users browsing this forum: No registered users and 2 guests