Network Management
Netflow Local Network Probe
An Evaluation User wants to be able to quickly evaluate NTA product without any configuration needed. A few minutes after the installation he wants to automatically see charts and be able to use all standard NTA features like navigation, drill-downs, filtering, search, reports, etc in the same way as with standard flows. He wants to see data from the local network interface that can be easily found and distinguish from other interfaces. Traffic on this interface reflects real traffic sourced and destined to main poller.
First published date
Last published date
Overview
Product section
Resolution
- Local Network Probe works only on the main poller
- Probe captures only TCP and UDP traffic
- Probe captures only traffic sourced and destined to the main poller. Source or destination IP address of the packet has to be the same as is some of the IP addresses that main poller has in the time when is the packet captured. Otherwise is packet dropped.
- Traffic on the loopback interface is not captured and collected
- Traffic from all physical interfaces is collected under single one virtual Local Netflow Source
- After installation or upgrade is approximately 5-8 minutes time delay until is local traffic visible on the web
- For the upgrades is probe installed only when Orion node for the main poller exists and match these criteria:
- ObjectSubType = Agent
- DNS name or one of his IP addresses needs to match with current values for the main poller
- When network configuration change, and main poller physical interface gets completely new IP address that is not known by Orion, there could be a delay up to 30 minutes until these changes are reflected in Orion. In such case packets going from or to this interface are not collected during all this time window. Data from other physical interfaces are collected without a change.
- Example 1: User unplugged Ethernet cable and connects to WiFi for the first time. Assigned IP address is not known by Orion. First change cause the delay, second and next changes probably do not (IP addresses will be already known in Orion)
- Example 2: Crossing between different WiFi networks. Assigned IP address is not known by Orion. First change cause the delay, second and next changes probably do not (IP addresses will be already known in Orion)