Monitoring network end user operation with a cisco router
30 pts.
0
Q:
Monitoring network end user operation with a cisco router
Hi


   One of my client requires a solution for monitoring end users traffic  going through a cisco  router.There is a lot of problem with over utilisation of WAN link by end users. The company need a solution for monitoring operation of end users(who & where they are trying to communicate).

  Please suggest an appropriate solution , also mention the software available and configuration needed in the cisco router

 Is there any other method with cisco switches ? , i heard about span configuration but no idea .PLZ help me with a detailed solution.


Software/Hardware used:
cisco 1841
ASKED: Sep 15 2009  5:58 AM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0
26290 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
ntop is an excellent tool for this purpose. However, you will need to properly configure the network for ntop to capture traffic on a switched network. A network switch will only send broadcast traffic to all ports. To "hear" all traffic, a switch port has to be configured as a mirror, span or monitor port. You can then connect your network monitor to this port to listen to all traffic on the network. Another option would be to get a network tap and place it between the edge router & the LAN switch. This will permit you to see all traffic entering and exiting the local network. It would not show you host to host traffic on the local LAN though. Take a look at some of my blog postings on this topic. Start on this page and the first part of the series starts here. The ntop mailing list is a great place to get additional assistance on this excellent application. This video or this one may also give you some education into using ntop. You can find some liveCD's with ntop on it. Check out the Network Security Toolkit.

See this similar question.
Last Answered: Sep 15 2009  11:45 AM GMT by Labnuke99   26290 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

KevinBeaver   7610 pts.  |   Sep 16 2009  5:59PM GMT

This is something that’s easily monitored/solved with a network analyzer. I use OmniPeek given that it can monitor traffic sessions, protocols used, top talkers, etc. all without having to capture packets. CommView is another analyzer worth considering and it’s priced very competitively as well.

 
0