Network Management

NTA Virtual Interface reporting traffic instead of desired interface

You may find a number of unmonitored interfaces reporting data as "NTA Virtual Interface ####" where the #### is a sequential number. This implies that the NTA Collector is receiving flows from a managed node but one that is not responding via SNMP, and thus unable to associate a known interface with the flow conversation data.

First published date

10/20/2018 6:36 PM

Last published date

8/17/2021 6:44 PM

Overview

This article discusses the issue where a number of unmonitored interfaces are reported data as the following:

NTA Interface #### 

*where #### is a sequential number

This implies that the NTA Collector is receiving flows from a managed node but one that is not responding via SNMP, and thus unable to associate a known interface with the flow conversation data.

Product section

Netflow Traffic Analyzer

Cause

Devices configured to export NetFlow are sometimes able to export the NetFlow summarization packets to the NTA Collector with a source address that does not match an existing node.  In addition, this can be caused by using the Null interface to export data.

Resolution

Configure the device to export Netflow using the source address that matches the existing node IP address (which should also respond via SNMP).  Alternatively, please do not use the Null interface to export flow data. The steps for making this configuration change can vary from device to device. SolarWinds recommends searching for vendor documentation as this is can be very different depending on make/model/IOS version.