Network Management
Application charts showing unmonitored multi-port traffic in Netflow
Application charts showing unmonitored multi-port traffic in Netflow.
First published date
Last published date
Overview
Product section
Cause
The ports used by the unmonotored application traffic are not mapped in NTA. When NTA receives a flow from a device, NTA queries the port number and compares it to what application uses that port.
For example, an application called MyEmailApp uses ports 12345 thru 12350 that NTA sees as unmonitored traffic. Also, a user (workstation) is sending data through your router to some external service using an email application called MyEmailApp on port 12346. If the port to Application mapping does not exist in NTA, then NTA will always show that traffic as unmonitored because it does not know that port 12346 = MyEmailApp.
If you open the Orion Web Console, navigate to Settings > All Settings > NTA Settings > Application and Service Ports, you can view each application and their corresponding mapped ports.
Be aware that not all traffic can or will be identified to a certain ports. Certain applications cannot be mapped because there are so many applications that can or could be used by a user. Also, there are certain applications (such as Skype) that uses different destination ports each time it is enabled, which makes it impossible to map.
Resolution
Create a port to application map.
- Open the Orion Web Console.
- Go to Settings > All Settings > NTA Settings > Application and Service Ports.
- Click Add Application.
- Complete the description, port number(s), source IP address, destination IP address, and protocol fields.
- Click Add Application.
NOTE: Using the example above, adding MyEmailApp as using ports 12345 thru 12350, leaving the remaining fields at the default, will now enable charts to display traffic statistics specifically for MyEmailApp, as opposed to NTA grouping that traffic into an unmonitored traffic pile.