Menu

monitoring network from cisco switch

NST
2012-12-26
2013-01-03
  • Noritaka Sawamura

    hi,
    i just install NST, anyone can help me to monitoring source/destination/protocole/bandwith from 3 spécifique port of my 2960G cisco Switch.

    NST look like a nice tool, but a simple howto for basic use will good things.

    Thx.

     
  • Noritaka Sawamura

    Thanks for your Answer RWH, but I made a mistake in my explanation, i have 3 ports traffic to specificly monitoring (Internet Routeur, DSL routeur, switch uplink).
    On NST system, i have 3 NICS (1 management, 1 dedicated monitoring, 1 backup). all (management and monitoring(Gi0/24), Internet Routeur(Gi0/1), DSL routeur(Gi0/2), switch uplink(Gi0/3)) are connecting to the same switch.
    when i add cisco SPAN command :
    monitor session 1 source interface gigabitethernet0/1
    monitor session 1 source interface gigabitethernet0/2
    monitor session 1 source interface gigabitethernet0/3
    monitor session 1 destination interface gigabitethernet0/24 encapsulation replicate

    thanks for everyone can help me.

     
  • Ronald W. Henderson

    Noritaka:

    I am a little confused with your question now:

    1) Are you connecting the NST dedicated monitoring NIC to the Cisco 2960G port: gigabitethernet0/24?

    2) Which NST monitoring tool are you using?

    3) Have you put the NST dedicated monitoring NIC in promiscuous mode?

    ---RWH

     
  • Noritaka Sawamura

    1 yes the dedicated monitoring is connecting to 2960G port gigabitethernet0/24.
    2 i use ntop.
    3 in promiscious mode in ntop config. is there location to define the nic in promiscuous mode

     
  • Noritaka Sawamura

    i think i solved my problem.
    all interface was inaccessible du to SPAN configuration Why ??? i don't know.
    but from the NST machine console, it's slow but i can see live data analysis in ntop.
    I also activate promiscuous on the nic interface parameter in WUI interface, i don't remember where exactly.

     
  • Ronald W. Henderson

    Noritaka:

    1) If you are using the NST WUI ntop management page to start ntop then you do not have to worry about configuring promiscuous mode on the NIC. This is done automatically by ntop.

    2) To manually set promiscuous mode via the NST WUI, just click on a NIC icon (Many NST WUI pages provide NIC icons) and use the "Promisc On" action button. View the "Promiscuous" flag setting for the NIC to see if it is enabled or not.

    3) You can use the "Network Packet Capture" page to quickly do a capture to see if you are seeing any data from the SPAN port.

    See this NST Wiki page for additional help on NST and ntop usage:

    http://wiki.networksecuritytoolkit.org/nstwiki/index.php/HowTo_Geolocate_ntop_Data

    ---RWH

     
  • Noritaka Sawamura

    hi Ronald,
    I have an other issue in Ntop, when i click on a host, i don't have detailed of ip traffic like protocole and port number, i have the screen in attachment below.

    Thanks for your help.

     

Log in to post a comment.