Cisco Network Analysis Modules (NAM) Tutorial •• Cisco Cisco Catalyst Catalyst 6500 6500 Series Series and and Cisco Cisco 7600 7600 Series, Series, NAM-1 NAM-1 // NAM-2 NAM-2 •• Cisco Cisco Branch Branch Routers Routers Series, Series, NM-NAM NM-NAM •• Cisco Cisco NAM NAM Traffic Traffic Analyzer Analyzer Software Software v3.5 v3.5 NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
About This Tutorial • Introduce network performance monitoring concepts and the NAM • Highlight the various features within the NAM modules • View various scenarios explaining how to deploy the NAM and use its features • Provide guidelines for system administrators • Provide links to documentation on the NAM NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
How the Tutorial Is Organized Chapter 1 Introduce network monitoring concepts and the various Cisco Network Analysis Modules Introduction to Network Performance Monitoring Chapter 2 Learn about the key features for the NAM-1/2, NMNAM, and the integrated Traffic Analyzer software Product Features Chapter 3 Using several examples, learn how to deploy the NAMs and use the Traffic Analyzer software for viewing the data Scenarios Chapter 4 System Administration Guidelines Review important system requir
Tutorial Contents Chapter 1 – Introduction to Network Performance Monitoring • Network Performance Monitoring - The Need To Manage Network Traffic - Business Metrics, Data to Collect - The Key to Performance Monitoring - Understanding MIBs and RMON • Introducing Cisco’s Network Analysis Modules and Software - Deploying NAMs - Cisco Catalyst 6500 Series and Cisco 7600 Series NAM-1/2 - Cisco Branch Routers Series NM-NAM - Cisco NAM Traffic Analyzer Software • Cisco Complementary Solutions • Summary – Benefi
Chapter 2 – Product Features, continue … • Traffic Analyzer Software -Planning -Getting Started -NAM Hardware Installation -NAM User Interface -NAM Network Configuration -Securing Access to the NAM -Viewing Access Logs -Setting NAM System Time -Configuring -Basic NAM-1, NAM-2 Configuration -Overview of Steps -Configuring Data Sources -Enabling Core Monitoring -Basic NM-NAM Configuration -Overview of Steps -Configuring Data Sources -Enabling Core Monitoring -Types of Statistics Collected -Enabling Traffic Mo
Chapter 3 – Scenarios • Performance/Troubleshooting (NAM-1/2) • Performance/Troubleshooting (NM-NAM) • QoS Monitoring (Using DiffServ and ART) • VoIP Monitoring • Trend Analysis Chapter 4 – System Administration Topics • Requirements - Hosting Hardware and Software - Client (Access to the NAM Using a Web browser) • Administration - NAM-1, NAM-2 - Install and Verification - Initial Configuration - NM-NAM - Install and Verification - Initial Configuration • Maintenance - Resetting the NAM - Image Upgrade -
Introduction Chapter 1 NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Chapter 1 Outline • Network Performance Monitoring - The Need To Manage Network Traffic - Business Metrics, Data to Collect - The Key to Performance Monitoring - Understanding MIBs and RMON • Network Analysis Modules - Deployment - Cisco Catalyst 6500 Series and Cisco 7600 Series NAM-1/2 - Cisco Branch Routers Series NM-NAM • Traffic Analyzer Software • Cisco Complementary Solutions • Summary – Benefits Achieved NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
¾ Network Performance Monitoring ¾ The Need ¾ Business Metrics, Data to Collect ¾ The Keys to Performance Monitoring ¾ Understanding MIBs and RMON • Network Analysis Modules • Traffic Analysis Software • Cisco Complementary Solutions NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Network Performance Monitoring The Importance of Monitoring Network Traffic No longer is it enough … To only react to problems…you must also be proactive To alarm or alert to an outage or service degradation….you must receive information before it occurs …. Intelligent Information Network Cisco’s 3-5 year vision for the evolution of networking from connectivity to intelligent systems To insure traffic flow from one point to another…..
Network Performance Monitoring Business Metrics for Evaluating Performance • Response Time: The elapsed time between the end of a query on one end of a conversation pair and the beginning of a response from the other end of a pair. Latency, a function of response time, is any characteristic of a network or system that increases the response time. • Reliability: A measurement of the consistency of any network, system or application in performing according to its specifications.
Network Performance Monitoring Different Monitoring Points for Application Usage Real-Time Traffic Utilization (Utilization, Errors, Talkers, Conversations, Protocols) Historical Reporting (Statistics over time) Fault Isolation & Troubleshooting (Thresholds, Alarms, Packet Decode) Performance Monitoring (Response Times, Switch/Router Health, Voice, Video, URL, QoS) NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Network Performance Monitoring What Data to Collect • Port level statistics—utilization, collisions, fragments – Basic physical stats good for usage trending and baselining – Useful anywhere in the network – Not necessary for all user ports • Detailed physical, network, and application layer data – Collect layers 2-7 statistics for understanding traffic breakdown – Valuable for WAN aggregation links – Valuable for LAN aggregation links (building to building, distribution to core, server farm to core) • W
Network Performance Monitoring The Key to Performance Monitoring Obtain Obtain “visibility” “visibility” into into the the network at the upper layer network at the upper layer protocols protocols 7 6 RMON-2 Standard OSI Protocol Layers NAM / Traffic Analyzer v3.5 Tutorial RMON-1 Standard Application Presentation 5 Session 4 Transport 3 Network 2 Data Link Data Link (MAC) 1 Physical © 2006 Cisco Systems, Inc. All rights reserved.
Network Performance Monitoring Understanding the Basics telnet CLI SNMP HTTP/S show Commands Web Server Operating System Data Structures SNMP AGENT 09123 COUNTERs GAUGEs TRAPS TABLEs Interfaces TIMERs FILEs Manageable Switch or Router MIBs • MIB II • RMON • ART • HCMON • And more Layer N Forwarding NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Introduction 1-15 Understanding the Basics Let’s now look inside an intelligent switch or router.
Network Performance Monitoring Understanding MIBs - RMON I MIB (Layers 1 & 2) » Real Time Physical and Data Link Layer Statistics 1 statistics 2 history 3 alarm » Predetermined Thresholds Set on Statistics 4 host » Talker Statistics – Data Link Layer 5 hostTopN 6 matrix 7 filter 8 capture 9 event 10 tokenRing » Statistics Over Time » Top N Talkers - Data Link Layer » Conversation Statistics– Data Link Layer » Packet Structure and Content Matching » Packet Capture for later analysis
Network Performance Monitoring Understanding MIBs - RMON II MIB (Layers 3 - 7) 11 protocolDir » Master List of Protocols seen on data source 12 protocolDist » Protocol Statistics 13 addressMap » Host to MAC Address Matching List 14 nlHost 15 nlMatrix 16 alHost 17 alMatrix 18 usrHistory 19 probeConfig NAM / Traffic Analyzer v3.
Network Performance Monitoring Understanding MIBs – Protocol Directory Extensions • Application Response Time (ART) • Voice / Video • Differentiated Services (DSMON) • NBAR-PB MIB Branch Router NM-NAM • Switch Monitoring (SMON) • Usage per Virtual link Catalyst 6500 and 7600 Series NAM Catalyst 6500 and 7600 Series NAM • VLAN • VLAN Priority • VLAN ACL NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Network Performance Monitoring ¾ Network Analysis Modules ¾ Deploying NAMs ¾ Cisco Catalyst 6500 Series and 7600 Series NAM-1/2 ¾ Cisco Branch Routers Series NM-NAM • Traffic Analysis Software • Cisco Complementary Solutions NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Network Analysis Modules Deployment Headquarters 2851 Security Operations NM-NAM 7200 IP L2/L3 Firewall IDS 6K-NAM Branch A IP WAN 3845 NetFlow Data Export to 6K-NAM IDS 6K-NAM NM-NAM NM-NAM Available for Cisco Branch Routers 6K-NAM 6K-NAM Available for Cisco Catalyst 6500 Switches and Cisco 7600 Series Routers Remote Office NAM / Traffic Analyzer v3.5 Tutorial Video Surv. AAA Monitoring remote sites through web based Traffic Analyzer NM-NAM Content © 2006 Cisco Systems, Inc.
Network Analysis Modules Cisco Catalyst 6500 / Cisco 7600 Series NAM-1/2 Catalyst 6500 and Cisco 7600 Series Web Web Server Server Embedded Embedded Traffic Traffic Analyzer Analyzer Software Software HTTP/S RMON RMON IIII NAM-1, NAM-2 Blade DS-MON DS-MON SMON SMON ART ART Voice Voice // Video Video Port Port (mini-RMON) (mini-RMON) statistics statistics are are available available on on each each interface interface NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc.
Network Analysis Modules Cisco Branch Routers Series NM-NAM Cisco ISR 2600XM, 2800, 3660, 3700, and 3800 Series Routers Web Web Server Server Embedded Embedded Traffic Traffic Analyzer Analyzer Software Software HTTP/S RMON RMON IIII DS-MON DS-MON HC-MON HC-MON ART ART Voice Voice // Video Video MIB-II MIB-II statistics statistics are are available available for for each each router router interface interface NAM / Traffic Analyzer v3.
• Network Performance Monitoring • Network Analysis Modules ¾ Traffic Analysis Software • Cisco Complementary Solutions NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Traffic Analyzer Software Overview • Configuration of the NAM – Setup Network Parameters – Selection of traffic to monitor – Define types of statistics to collect • Real-Time and Historical Reports – Switch Port Monitoring (NAM-1/2) – Router Interface Monitoring (NM-NAM) – Application, Hosts, and Conversation Monitoring – Differentiated Services (DiffServ) Monitoring – Voice / Video Quality Monitoring – Application Response Time Monitoring – URL Monitoring – Packet Capture and Decode – IP / MPLS Monitor
Traffic Analyzer Software Switch Port Monitoring Catalyst Catalyst 6500 6500 and and Cisco Cisco 7600 7600 Series Series NAM NAM 1/2 1/2 only only Port Statistics View View traffic traffic and and error error statistics statistics for for all all interfaces interfaces by by selecting selecting an an interface interface and and drill drill down down into into the the interface interface to to obtain obtain more more details details Port-level Port-levelstatistics statistics include: include: Utilization,
Traffic Analyzer Software Router Interface Monitoring Branch Branch Router Router NM-NAM NM-NAM Only Only Interface Statistics Details Detailsavailable availableon oneach eachinterface: interface: –– –– Top TopHosts Hosts Top TopApplications Applications Real-Time & Historical Reports Available –– Top TopConversation ConversationPairs Pairs NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Traffic Analyzer Software Application, Host, and Conversation Monitoring Protocol Distribution Conversation Pair Statistics Real-Time & Historical Reports Available Detailed Host and Conversation Statistics NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Traffic Analyzer Software Differentiated-Services Monitoring (DS-MON) DiffServ DiffServ monitoring monitoring can can be be used used to: to: •• Validate Validate planning planning assumptions assumptions and and QoS QoS allocations allocations •• Detect Detect incorrectly incorrectly marked marked or or unauthorized traffic unauthorized traffic NAM-Embedded Traffic Analyzer Ethernet Header (DSCP0) FTP IP Header (DSCP0)) (DSCP24) SNMP NAM / Traffic Analyzer v3.
Traffic Analyzer Software Voice Monitoring Voice Monitoring Features - Identify call quality degradation o Packet loss statistics report o Jitter statistics report - Track active call attributes o Call Details report - Details for individual phones - Protocols monitored (SCCP, H.
Traffic Analyzer Software Video Monitoring •• Proactively Proactivelymonitors monitors RTP RTP streams streams •• Filter FilterRTP RTPstreams streamsof ofinterest interest by source / destination by source / destination addresses addresses •• Troubleshooting TroubleshootingVideo Video Broadcast Broadcastissues issues Broad cast Video off-air VoD Servers satellite •• Utilize Utilizereal-time real-timevideo videoRTP RTP packet packetcount countand andpacket packetloss loss statistics statistics •• Recei
Traffic Analyzer Software Application Response Time (ART) Monitoring Where’s the latency occurring? The Network or The Application? Application Server Server Latency Total Time The Network NAM Application Clients NAM NAM / Traffic Analyzer v3.5 Tutorial Total Time - Server Latency Network Flight Time © 2006 Cisco Systems, Inc. All rights reserved.
Traffic Analyzer Software URL Monitoring •• Monitor Monitor hits hits on on top top URL URL sites sites •• Collect Collect URL URL host, host, path, path, and and content content •• URL URL can can be be monitored monitored like like an an application application (URL-based (URL-based Application) Application) This This allows allows usage usage statistics statistics to to be be collected collected −− Packet Packet // byte byte rates rates −− Who’s Who’s sending sending packets packets (Host (Host // Conve
Traffic Analyzer Software Packet Capture and Decode Support Support Troubleshooting Troubleshooting Efforts Efforts NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Introduction 1-33 Packet Capture and Decode There may be times when you want to view the contents of packets that traverse the network, perhaps to drill down deeper into the source of a problem or just to do your own analysis.
Traffic Analyzer Software IP / MPLS Monitoring Customer B Customer A VPN 2 VRF NAM-2 VPN 1 VRF Customer A Customer A VPN 1 VRF VPN 2 VRF Customer B Service Provider MPLS Core Customer B Catalyst Catalyst 6500 6500 and and Cisco Cisco 7600 7600 Series Series NAM NAM only only • MPLS provides an elegant solution to overlapping IP address spaces when sharing a core backbone • Packet forwarding is done based on labels, which are assigned when the packet enters the MPLS network • Switching is based on la
Traffic Analyzer Software VLAN Monitoring Catalyst Catalyst 6500 6500 and and Cisco Cisco 7600 Series NAM 7600 Series NAM 1/2 1/2 only only VLAN Traffic Statistics by Individual VLAN Application Monitoring per Spanned VLAN NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Introduction 1-35 VLAN Monitoring The NAM extends RMON capabilities to VLANs by implementing the Switch Monitoring (SMON) standard, a specification for monitoring switched networks.
Traffic Analyzer Software Overall System Health Router Hosting NM-NAM Switch Hosting NAM-1/2 Tight Tightintegration integrationwith withthe theswitch/router switch/routerpermits permitsthe theNAM NAMto to monitor and track important infrastructure health diagnostics monitor and track important infrastructure health diagnostics NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Network Performance Monitoring • Network Analysis Modules • Traffic Analysis Software ¾ Cisco Complementary Solutions NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Cisco Complementary Solutions Performance Visibility Manager (PVM) • Centralized configuration and control of data sources PVM Presentation Layer Mediation Layer Reporting, Monitoring, Administration Analysis, Aggregation, Correlation, Baselining, Trending, Alerting Data Store Collection Layer NAM data NM-NAM NAM Adapter NAM-1 Switch/Router Adapter • Aggregated views and reports from multiple data sources • Proactive alerting • Strong reporting • Web-based client NAM-2 • API and integration NetFl
Cisco Complementary Solutions NAPA Solution Utilizing a comprehensive bundled toolset and expertise from Cisco Consulting Engineers, achieve: • Better network performance • Faster identification and resolution of problems • Significantly enhanced network planning capabilities • Reduced risk • Access to Cisco advanced services • Greater efficiency, productivity, and profitability NAM / Traffic Analyzer v3.
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Summary: Benefits Achieved • Using the NAM provides ‘Visibility’ into your network from within your network • Be proactive and make the right decisions – Make accurate business decisions about your IT resources – Identifies traffic with greatest impacts to performance – Pinpoint latencies and isolate problems • “Right-size” the network to reduce network spending $$ NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Thank You! Chapter 1 provided you with a quick overview of the need for network performance monitoring and Cisco’s solution – the NAMs for both the Cisco Catalyst 6500 and Cisco 7600 series routers as well as the Cisco Branch Routers Series. The NAMs provide a wealth of information with the integrated Traffic Analyzer software. Now, continue on to Chapter 2 to discover how to set up and use NAM to provide access to a rich set of traffic statistics collected by the NAM. NAM / Traffic Analyzer v3.
Product Features Chapter 2 •• Cisco Cisco Network Network Analysis Analysis Modules Modules (NAM) (NAM) NAM-1, NAM-1, NAM-2, NAM-2, and and the the NM-NAM NM-NAM •• Cisco Cisco NAM NAM Traffic Traffic Analyzer Analyzer Software Software v3.5 v3.5 NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Chapter 2 Outline • Network Monitoring Using NAMs • NAM Hardware Overview – Cisco Catalyst 6500 Series and Cisco 7600 Series NAM-1, NAM-2 – Cisco Branch Routers Series NM-NAM • Traffic Analyzer Software – Planning – Getting Started – Configuring – Viewing Reports – Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Network Monitoring Using NAMs Overview RMON MIB DSMON MIB SMON MIB ART MIB Voice Analysis NAM-Embedded Traffic Analyzer 0 ms 50ms 100ms 150 ms 200ms 250ms 300ms 350ms 400ms Data Source Ethernet Header FTP IP Header Multicast FTP Data TCP Header BPDU NAM / Traffic Analyzer v3.5 Tutorial FTP HTTP © 2006 Cisco Systems, Inc. All rights reserved.
Network Monitoring Using NAMs NAM Data Sources NAM Embedded Traffic Analyzer Stats per Interface MIB-II Int Stats Data Source Mini RMON Stats per Interface NBAR Stats NetFlow Stats per Total Flow or per individual flow NetFlow Records Stats per Data Source and/or per VLAN/MPLS included in Data Source Stats per Port Mini RMON NetFlow Records Stats per Total Flow or per individual flow NetFlow NBAR MIBMIB-II FTP Cisco Catalyst Switch NAM-1/2 Only HTTP Cisco Router NM-NAM Only Multicast
Network Monitoring Using NAMs NetFlow as a Data Source NAM offers a powerful combination of NetFlow and RMON monitoring NetFlow Data • Use both RMON and NetFlow to provide application-level visibility • Exporting of NetFlow data to the NAM allows monitoring of multi-layer switched traffic (L3) on an aggregate basis • Use the NAM RMON capability for detailed analysis of voice traffic, quality of service, application response time, and packet capture and decode NAM / Traffic Analyzer v3.
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Network Monitoring Using NAMs ¾ NAM Hardware Overview – Catalyst 6500 and Cisco 7600 Series NAM-1, NAM-2 – Cisco Branch Routers Series NM-NAM • Traffic Analyzer Software NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAMs in the Enterprise Headquarters 2851 Security NM-NAM Operations Monitoring remote sites through web based Traffic Analyzer 7200 IP L2/L3 Firewall IDS 6K-NAM Branch A IP WAN NetFlow Data Export to 6K-NAM NM-NAM NM-NAM 6K-NAM Remote Office NAM / Traffic Analyzer v3.5 Tutorial Video Surv. IDS 6K-NAM 3845 Content AAA NM-NAM Available for Cisco Branch Routers 6K-NAM Available for Cisco Catalyst 6500 Switches and Cisco 7600 Series Routers © 2006 Cisco Systems, Inc. All rights reserved.
NAM-1/2 Overview Features • Multiple Data Sources for Analysis • SPAN / RSPAN / ERSPAN / VACL / NetFlow • Supervisor module (mini-RMON, VLAN stats) • MIBs for storing statistics on data sources • Full RMON 2 Capability – Hosts statistics –Network Layer – Conversation statistics –Network Layer – Upper layer protocol distribution • MIB Extensions – ART (Application Response Time) – DS-MON (Differentiated Services) – Voice / Video NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc.
NAM-1/2 Hardware Overview Specifications NAM-1 NAM-2 WS-SVC-NAM-1 WS-SVC-NAM-2 • Fabric and Bus Support Yes Yes • Processor Dual Dual + Accelerator • RAM 512 MB 1 GB • Hard Disk • Capture Buffer 20 GB 125 MB 20 GB 300 MB SPECIFICATIONS • Performance MONITORING APPLICATIONS Sub-gigabit Gigabit Fast Ethernet, Low capacity GE High Capacity GE 1 1 1 2 1 1 Distribution, Access, small core, Branch office Core, Server farm, • No. of SPAN / VACL Sessions • No. of NetFlow Sessions • No.
NAM-1/2 Hardware Overview Architecture Mini RMON per interface SNMP Agent SNMP SNMP Agent Data from ERSPAN Sources Data from NDE Sources (NetFlow Data Export) Web Browser HTTP/S Cisco Catalyst Switch Web Server MIBs Monitor Interface for NDE and ERSPAN Monitor Interface for SPAN/VACL Data from Spanned or VACL Sources NAM / Traffic Analyzer v3.
NAM-1/2 Data Sources Mini-RMON / SPAN / RSPAN Cisco Catalyst 6500 Chassis Mini RMON Use Use SPAN SPAN to to copy copy port, port, VLAN, VLAN, or or Ether Ether Channel Channel traffic traffic to to the the NAM NAM Supervisor Engine EOBC Mini_RMON Mini_RMON traffic traffic collected collected by by internal internal NAM NAM interface interface Data Bus Line Card Traffic Traffic passes passes over over production production links links when when using using RSPAN RSPAN to to monitor monitor traffic tr
NAM-1/2 Data Sources ERSPAN Cisco Catalyst 6500 Chassis Supervisor Engine NDE Line Card NAM ERSPAN ERSPAN traffic traffic collected by collected by NAM NAM Management Management port port ERSPAN Packets RSPANned port NAM / Traffic Analyzer v3.
NAM-1/2 Data Sources VACL •• Multiple Multiple Uses Uses of of VLAN VLAN ACLs ACLs for for Traffic Traffic Analysis Analysis –– Use UseaaVACL VACLto to analyze analyzeWAN WANinterfaces interfacesthat that can cannot notbe bespanned spanned –– Use UseaaVACL VACLififno no more more SPAN SPANsessions sessionsare areavailable availablefor foruse use –– Use UseaaVACL VACLto to pre-filter pre-filter specific specifictypes typesof of traffic traffic for foranalysis analysis •• VACL VACL traffic traffic sent sent
NAM-1/2 Data Sources NetFlow Cisco Catalyst 6500 Chassis Supervisor Engine NDE Line Card EOBC NDE NDEtraffic trafficfrom from local host local hostdevice device can canbe becopied copiedto to the theNAM NAM NetFlow NetFlow Data Data Export Export (NDE) (NDE) traffic traffic collected collected by by aa single single internal internal NAM NAM interface interface NAM NDE Packets RSPANned port NetFlow Enabled Device NetFlow NetFlowsupports supportsmonitoring monitoring of ofApplications, Applications,
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Network Monitoring Using NAMs ¾ NAM Hardware Overview – Catalyst 6500 and 7600 Series NAM-1, NAM-2 – Cisco Branch Routers Series NM-NAM • Traffic Analyzer Software NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Cisco Branch Routers Series NM-NAM Features • Multiple Sources for Analysis – Internal Interface receives interface data streams via CEF – External Interface can be connected to FE LAN segment – NetFlow • Full RMON 2 Capability – Hosts statistics –Network Layer – Conversation statistics –Network Layer – Upper layer protocol distribution • Extended RMON – ART(Application Response Time) – DS-MON (Differentiated Services) – Voice over IP • MIB II support for hosting router interfaces • NBAR-PD MIB NAM / Tr
NM-NAM Hardware Overview Specifications NM-NAM SPECIFICATIONS 500-MHz PIII • Processor • Memory 512MB • Capture Buffer 70 MB • Performance ~10- 45MBs MONITORING APPLICATIONS FE, T1/E1, ATM, T3, DSL DEPLOYMENT SCENARIOS NAM / Traffic Analyzer v3.5 Tutorial BRANCH REMOTE OFFICES © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-19 NM-NAM Specifications Hardware Architecture - Optimized performance single processor architecture with 256 MB of RAM and a 20 GB hard disk drive.
NM-NAM Hardware Overview Architecture Router Console Controlled by IOS Memory Flash Router PCI Bus Interfaces Router CPU Fast Ethernet UART NM Console Fast Ethernet 1 Controlled by NM-NAM application Disk Flash Network Module NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NM-NAM Data Sources Interfaces Branch Router MIB-II / NBAR-PD Interfaces CEF Copied Traffic WAN/LAN WAN/LANtraffic traffic monitoring monitoringusing usingCisco Cisco Express ExpressForwarding Forwarding(CEF) (CEF) to tocopy copypackets packetsto tothe the NAM NAMinternal internalinterface interface Router Internal FE Interface Internal FE Interface NAM External FE Interface OR LAN LANtraffic trafficmonitoring monitoringby by connecting external connecting externalNAM NAM interface interfaceto toa
NM-NAM Data Sources NetFlow & Management Traffic NetFlow Enabled Device NAM NAMManagement Managementtraffic traffic--HTTP(S), HTTP(S), telnet, telnet,SSH, SSH,SNMP, SNMP,NetFlow, NetFlow,etc etc––user’s user’s choice choiceto touse useinternal internalor orexternal externalFE FE Interfaces Interfaces NDE NAM NDE NAM Internal FE Interface External FE Interface Internal InternalInterface Interfacefor for Management Managementtraffic trafficuses usesrouter router CPU, CPU,RAM, RAM,and andbackplane b
• Network Monitoring Using NAMs • NAM Hardware Overview ¾ Traffic Analyzer Software –Planning –Getting Started –Configuring –Viewing Reports –Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Road Map to Using NAMs View View Traffic Traffic Reports Reports Planning Planning Getting Getting Started Started Configure Configure Monitoring Monitoring For For the the most most part part the the use use of of the the Traffic Traffic Analyzer Analyzer software software is is universal universal to to both both types types of of NAM. NAM. However, However, there there are are some some slight slight differences differences in in the the setup setup and and available available reports. reports.
• Network Monitoring Using NAMs • NAM Hardware Overview ¾ Traffic Analyzer Software – – Planning Getting Started – Configuring – Viewing Reports – Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Planning for NAM Deployment Overview Planning Planning Data Requirements for Monitoring and Alarms NAM User Access to NAM Configuration and Traffic Reports Strategic Deployment of NAMs in the Network NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-26 Planning for NAM Deployment The data that the NAM collects, and the reports that it generates, will only be as good as the effort and consideration you put into the planning stages.
Planning for NAM Deployment Defining Data Sources and Reporting Requirements RMON??? Mini-RMON??? SMON??? DSMON??? ART??? QoS? Conversation Pair stats? Host stats? Ports??? VLANs??? Cisco EtherChannel tunnel??? NetFlow??? Switch??? Voice monitoring? VLAN traffic stats? NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Planning for NAM Deployment Application Response-Time Problems Deploy DeployNAMs NAMs closest closestto tothe the application applicationservers servers and andclients. clients. NAM NAMs NAMscould couldbe beeither eitherNAMNAM1/2 1/2or orNM-NAM NM-NAMdepending dependingon on network networkequipment equipment NAM Server Farm Server Response Time Client PC Server and Network Response Time NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Planning for NAM Deployment Voice Monitoring Cisco Data Center CallManager Cluster Access NAM NAM Deploy Deploy NAMs NAMs at at critical critical points points in in your your network network near near the the Cisco Cisco CallManager CallManager as as well well as as near near phones phones and and aggregation aggregation points. points. NAM NAM NAM NAM Distribution Core NetFlow Data Export to remote NAM Internet NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc.
Planning for NAM Deployment Performance Monitoring Access Deploy DeployNAMs NAMsat at critical criticalor or aggregation aggregationpoints pointsin in your network your networkas aswell well as asnear nearserver serverfarms. farms. servers NAM NAM NAM NAM servers NAMs NAMscould couldbe beeither eitherNAMNAM1/2 1/2or orNM-NAM NM-NAMdepending dependingon on network networkequipment equipment NAM / Traffic Analyzer v3.
Planning for NAM Deployment NAM Performance Considerations All Allof ofyour your configuration configuration options affect options affectthe the resource resourceutilization utilization and andperformance performanceof of the theNAM. NAM. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-31 NAM Performance Considerations The NAM offers a wealth of data and reports that give you visibility into your network.
Planning for NAM Deployment Users, Security, and NAM Access Which users should have access to which features? Define security policies to protect your data requirements. NAM Define security policies that meet your security needs and NAM users’ functional requirements. NAM / Traffic Analyzer v3.5 Tutorial thirdthird- Party Management Systems Enable third-party management systems to communicate with the NAM via SNMP community strings. © 2006 Cisco Systems, Inc. All rights reserved.
Planning for NAM Deployment Summary 3 Identify the problems or needs you are trying to solve with the NAM. 3 Identify what data collection and monitoring needs will help resolve problems or needs. 3 Determine how many NAMs you will need to deploy and where you need to deploy them. 3 Identify the appropriate SPAN sources – port, VLAN, or Cisco EtherChannel tunnel for each NAM. 3 Define access policies, data collection and reporting, and alarm configuration requirements for each NAM to match needs.
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Network Monitoring Using NAMs • NAM Hardware Overview ¾ Traffic Analyzer Software – Planning – Getting Started – Configuring – Viewing Reports – Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Topics Getting Getting Started Started • NAM Hardware Installation • NAM User Interface • NAM Network Configuration • Securing Access to the NAM – Creating New Users – TACACS+ – SNMP Communication • Viewing Access Logs • Setting NAM System Time NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started NAM Hardware Installation Overview Cisco ISR 2600XM, 2800, 3660, 3700, 3800, 2691 Series Routers Cisco Catalyst 6500 Series or Cisco 7600 Series NAM-1, NAM-2 NAM / Traffic Analyzer v3.5 Tutorial NAM with Integrated Traffic Analyzer Software © 2006 Cisco Systems, Inc. All rights reserved. NM-NAM Product Features 2-37 NAM Hardware Installation Overview NAM-1 and NAM-2 The NAM-1/2 installs into a single slot on the Cisco Catalyst® 6500 series and Cisco 7600 series chassis.
Getting Started NAM User Interface – Traffic Analyzer http:// address> Web WebUsername Username and andPassword Password Logging Logginginto intothe theNAM NAM Web Webinterface interfacewill will bring bringyou youto tothe the opening screen, opening screen, System SystemOverview. Overview. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Traffic Analyzer - Menu Options Options Options for for configuring configuring the the NAM NAM data data collection collection and and report report functions. functions. Options Options for for viewing viewing data. data.
Getting Started Navigation Menu Setup Monitor Configure All Monitoring Options View All Data Collection Reports Switch/Router Parameters: Setup NAM communication with host device View Overview of several statistics Data Source: Configure SPAN and NetFlow sources Monitoring: configure data collection Protocol Directory: Setup application protocols Alarms: Configure alarm parameters Preferences: Configure interface preferences View Application Statistics View Voice Statistics View Host Statistics View
Getting Started NAM Network Configuration 1 2 3 Network Network access access configuration configuration options options that that were were defined defined during during installation installation at at the the command-line interface command-line interface can can be be modified modified in in this this submenu submenu NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Securing Access to the NAM TACACS+ Password Authentication User Account Management SNMP Parameters NAM Access Control Audit Trail NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Creating New Users 1 2 3 This This table table displays displays existing existing user user accounts accounts and and access access privileges. privileges. NAM / Traffic Analyzer v3.5 Tutorial Click Click Create Create to to add add aa new new user. user. Use Use the the New New User User popup box to popup box to configure configure the the user’s user’s password password and and privileges. privileges. © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Using TACACS+ for Authentication 1 2 3 Enable Enable TACACS+ TACACS+ services services by by clicking clicking on on the the Enable Enable box box and and entering entering the the TACACS+ TACACS+ server server IP IP address address and and key key parameters parameters that that you you configured configured on on your your TACACS+ server for TACACS+ server for the the NAM. NAM. NAM / Traffic Analyzer v3.
Getting Started Third Party NMS Access to NAM using SNMP Configure Configure NAM NAM community community strings strings to to allow allow 33rdrd party party NMS NMS to to retrieve retrieve MIB MIB information information from from NAM NAM using using SNMP; SNMP; SNMP SNMP v1/v2 v1/v2 supported. supported.
Getting Started Host Device Parameters - SNMP Setup > Switch Parameters > Switch Information Information Informationabout about the thehost hostswitch switchand and available availabledata data sources sources(VLAN, (VLAN, NetFlow, NetFlow,NBAR) NBAR) NM-NAM NM-NAM Setup > Router Parameters > Router Information NAM-1 NAM-1and andNAM-2 NAM-2 Enter Enterthe thesame sameIP IPaddress addressand and read-write read-writecommunity communitystring stringas aswas was configured configuredon onthe therouter.
Getting Started Host Parameters - NBAR Setup > Switch Parameters > NBAR Protocol Discovery Setup > Router Parameters > NBAR Protocol Discovery Current CurrentNBAR NBARstatus status •• NBAR NBARisisaafeature featurethat thatmust mustbe be enabled for the NAM to enabled for the NAM todisplay display information informationabout aboutprotocols protocols discovered on discovered oneach eachinterface interfaceusing using the themenus: menus: •• Monitor Monitor>>Switch Switch>>NBAR NBARor or •• Monitor Monitor
Getting Started NAM-1, NAM-1, NAM-2 NAM-2 Only Only Host Parameters – Mini RMON Setup > Switch Parameters > Port Stats (Mini-RMON) •• Mini-RMON Mini-RMONisisaaswitch switchfeature featurethat that must be enabled for the must be enabled for theNAM NAMto to provide provideuseful usefulinformation informationabout about Ethernet ports on Ethernet ports onthe theMonitor Monitor>> Switch Switch>>Port PortStats Statsscreen. screen.
Getting Started NAM-1, NAM-1, NAM-2 NAM-2 Only Only Host Parameters – Switch Login The NAM allows you to collect RMON 2 statistics per MPLS VRF, VCID, or Label. To automatically retrieve this information from the switch, you must first provide the NAM with the access credentials for the switch 1 2 3 NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Audit Trail - Enabling 1 2 The TheAudit AuditTrail Trailprovides provides useful usefulinformation informationsuch suchas as which whichuser userlogged loggedin, in,from from what whatIP IPaddress, address,and andwhat what activities activitieswere wereperformed performed during duringthat thatsession. session. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Audit Trail - Viewing 1 2 3 The TheAccess AccessLog Logprovides provides useful usefulinformation informationsuch suchas as which whichuser userlogged loggedin, in,from from what whatIP IPaddress, address,and andwhat what activities activitieswere wereperformed performed during duringthat thatsession. session. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started Audit Trail – Sending as Alerts 1 2 3 Audit AuditTrail Traillog logalerts alerts (System) can (System) canbe besent sentto to local localsystem systemor orto toaaremote remote system system NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-52 Sending Audit Alerts as Syslogs The NAM provides the capability to send audit alerts as Syslog messages to a remote system.
Getting Started Setting NAM System Time Configure Configure the the NAM NAM system system time to either synchronize time to either synchronize with with the the time time set set on on the the host host switch switch or or configure configure the the NAM NAM to to set set its its time time based based on on an an NTP NTP server. server. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Getting Started E-mail Configuration To enable Email support, an external Email server must be configured. This is the POP or exchange mail server for your organization. To validate the mail configuration, a complete email address, such as jdoe@cisco.com, can be entered to receive a test email when NAM completes the configuration. The The NAM NAM can can be be configured configured to to send send e-mail e-mail notification notification of of alarms alarms as as well well as as e-mail e-mail reports.
Getting Started FTP Configuration •• Similar Similar to to email, email, the the NAM NAM can can be be configured configured to to use use FTP FTP to to transfer transfer alarms alarms and and reports reports from from the the NAM NAM to to aa FTP FTP server. server. •• IfIf this this method method is is configured, configured, alarms alarms and and reports reports will will be be exported exported to to the the specified specified FTP FTP server. server. NAM / Traffic Analyzer v3.
Getting Started Web Publishing Configure Configure the the NAM NAM to to allow allow web users to view various web users to view various reports reports without without having having to to establish establish aa login login session session with with the the NAM NAM NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Network Monitoring Using NAMs • NAM Hardware Overview ¾ Traffic Analyzer Software – Planning – Getting Started – Configuring – Viewing Reports – Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Configuring NAM Monitoring Configure Configure Monitoring Monitoring • Basic NAM-1, NAM-2 Configuration – Overview of Steps – Configuring Data Sources – Enabling Core Monitoring • Basic NM-NAM Configuration – Overview of Steps – Configuring Data Sources – Enabling Core Monitoring • Types of Statistics Collected • Enabling Traffic Monitoring • Configuring Alarms • Setting Preferences NAM / Traffic Analyzer v3.5 Tutorial Product Features 2-58 © 2006 Cisco Systems, Inc. All rights reserved.
Basic NAM-1/2 Configuration NAM-1, NAM-1, NAM-2 NAM-2 Only Only Overview of Steps Step 1 – Defining the Data Sources • • • • • • SPAN Session Æ Data Port RSPAN Session Æ Data Port VACL Æ Data Port NetFlow Data Export (NDE) Æ NDE Data Port MPLS (import VRF, VCID, Labels) Supervisor Module (enable Mini-RMON) Step 2 – Enabling Core Monitoring • Turn on various types of statistics for different traffic sources seen by the NAM • Traffic Sources: • • • • • • • ALL SPAN (if multiple span sessions exist) Data
Basic NAM-1/2 Configuration NAM-1, NAM-1, NAM-2 NAM-2 Only Only Step 1: Configuring SPAN / RSPAN Data Sources 1. a. b. c. d. One or more ports from various modules One or more VLANS Single RSPAN VLAN One or more Ether Channels 2. If source is a port, first select switch module where port is located 3. If NAM-2, specify SPAN destination Data Port (1 or 2); One type of SPAN session per Data Port 4. 5.
Basic NAM-1/2 Configuration NAM-2 NAM-2 Only Only Step 1: Utilizing the Second Data Port on NAM-2 •• Must Mustspecify specifywhich whichdata dataport port to tosend sendtraffic traffic(Data (DataPort Port11or or Data DataPort Port2) 2) •• Can Canhave have22 simultaneous simultaneousSPAN SPAN// RSPAN RSPAN// VACL VACLsessions sessions –– Cannot Cannotmix mixtypes typesof ofsessions sessionson onsame samedata dataport port •• Use Use the the 22 ports ports independently independently or or together; togeth
Basic NAM-1/2 Configuration Step 1: Configuring SPAN / RSPAN Data Source Continued •• Shows Shows one one active active SPAN SPAN sessions; sessions; NAM NAM isis in in slot slot 3. 3. DataPort1 is 3/7. DataPort1 is 3/7. •• Click Click Create Create to to define define new new session. session. IfIf there there are are no no available available DataPorts DataPorts then then one one would would need need to to be be deleted deleted first. first.
Basic NAM-1/2 Configuration Step 1: Configuring SPAN / RSPAN Data Source Configuration Configuration screen screen for for creating creating aa SPAN session. Configurable SPAN session.
Basic NAM-1/2 Configuration Step 1: Configuring VACL Data Source VACL VACLare arevaluable valuabledata datasource sourcefor: for: •• Analyzing AnalyzingWAN WANPorts Ports(packets (packetsforwarded forwardedas as Ethernet frames) Ethernet frames) VACL NAM NAMData DataPort Port11 •• Analyzing AnalyzingLAN LANinterfaces interfacesififall allSPAN SPAN sessions are in use sessions are in use •• Pre-filtering Pre-filteringtraffic trafficbefore beforesending sendingitittotothe the NAM NAM 6509(config)#access-l
Basic NAM-1/2 Configuration Step 1: Configuring MPLS Import Import VRF VRF configurations configurations from from the the device device hosting hosting the the NAM NAM NAM / Traffic Analyzer v3.5 Tutorial Import Import VRF VRF configurations configurations from from aa file file © 2006 Cisco Systems, Inc. All rights reserved.
Basic NAM Configuration Step 1: NetFlow Data Sources Same Same for for NAM-1, NAM-1, NAMNAM2, 2, and and NM-NAM NM-NAM 1. Configure NetFlow device to forward to NAM on UDP port 3000 2. Use Listening Mode to see who is sending NAM NDE traffic 3. Add NetFlow Device a. Automatically creates NDE data source for all forwarded traffic b.
Basic NAM Configuration NetFlow Listening Mode Same Same for for NAM-1, NAM-1, NAMNAM2, 2, and and NM-NAM NM-NAM To To create create NDE NDE data data sources, sources, the the NetFlow NetFlow device sending NDE packets to the device sending NDE packets to the NAM NAM must must be be entered entered into into the the NAM NAM NDE NDE device device table. table.
Basic NAM Configuration Defining NetFlow Devices Same Same for for NAM-1, NAM-1, NAMNAM2, 2, and and NM-NAM NM-NAM To Tocreate createan anNDE NDEdata data source, source,the thedevice devicemust mustbe be added addedto tothe theNAM NAMNetFlow NetFlow table table Test Testconnectivity connectivityof ofdevice device NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Basic NAM Configuration NetFlow Custom Data Sources Same Same for for NAM-1, NAM-1, NAMNAM2, 2, and and NM-NAM NM-NAM Adding Addingaadevice deviceto tothe theNAM NAM NetFlow table creates NetFlow table createsaadefault default NDE NDEdata datasource sourcefor forthe the aggregate of all NetFlows aggregate of all NetFlows enabled enabledon onthe thedevice. device.Use Use custom customdata datasources sourcesto tocreate create an anNDE NDEdata datasource sourcefor foraa subset subsetof ofthat thattraffic.
Basic NAM Configuration NetFlow Custom Data Sources, continue … Same Same for for NAM-1, NAM-1, NAMNAM2, 2, and and NM-NAM NM-NAM 33Step Stepwizard wizard––select selectdevice, device, name data source, name data source,select select interfaces, interfaces,and andverify. verify.
Basic NAM-1/2 Configuration Step 2: Enabling Core Monitoring Step Step2: 2:Enable Enablemonitoring monitoringtype type by bydata datasource source Step Step1: 1: Configure ConfigureData Data Sources Sources ALL SPAN App, host, conv, voice, ART, DiffServ, VLAN,URL DATAPORT 1 SPAN source 2/1 (Trunk) VLAN 1 and 99 NAM NAMDATAPORT DATAPORT11 App, host, conv, voice, ART, DiffServ, VLAN, URL VLAN 1 App, host, conv, DiffServ, URL MPLS VRF Cust1 NDE Device 192.168.79.
Enabling Core Monitoring (NAM-1/2) Configuring Monitoring Parameters This Thistable tablelists listsall all the available the available monitoring monitoringoptions. options. ItItenables enablesyou youtoto choose choosehow howyou you want wantthe thedata datatotobe be analyzed. analyzed. This Thisoption optionenables enables you youtotodefine definethe the data datasource sourcethat thatwill will populate populatethe the monitoring monitoringfunctions functions you youchoose. choose.
Enabling Core Monitoring (NAM-1/2) Selecting Data Sources to Configure •• The The ALLSPAN ALLSPAN data data source source aggregates aggregates all all of of the the Spanned Spanned and and VACL VACL statistics statistics into into aa single single data data source. source. •• DATAPORT DATAPORT provides provides statistics statistics for for all all traffic traffic forwarded forwarded to to the the specified specified data data port. port.
Enabling Core Monitoring (NAM-1/2) Selecting Statistics to Collect •• Enable Enable RMON RMON and and VLAN VLAN statistics statistics to to be be collected collected and and reported reported on on per per data data source source •• ALL ALL SPAN, SPAN, Data Data Port, Port, ERSPAN, ERSPAN, and and VLAN VLAN data data sources sources all all have have the the same same enabling enabling functions functions (Class of Service) IfIf you you want want individual individual VLAN VLAN monitoring, monitoring, yo
Enabling Core Monitoring (NAM-1/2) Selecting Statistics to Collect, continue … •• Enable Enableapplication application protocol, protocol,hosts, hosts,and and conversation conversationstatistics statisticsfor for each eachNetFlow, NetFlow,NDE, NDE,and and MPLS MPLSdata datasource sourcetotobe be monitored monitored •• VLAN VLANand andAddress Address Correlation Correlationstatistics statisticsnot not available availableon onNetFlow NetFlowand and MPLS MPLSdata datasources sources Enabling Enablingcollectio
Enabling Core Monitoring (NAM-1/2) Example Step1: Create a SPAN session that uses the ports 1/1 and 1/2 as your SPAN source and view your configuration settings via the Active Sessions Menu. Step 3: View Network Host Statistics Report by choosing the VLAN you configured in Step 2. Ports Ports 1/1 1/1 and and 1/2 1/2 are are members members of of VLAN VLAN 904. 904.
Basic NM-NAM Configuration See See earlier earlier slides slides for for NetFlow NetFlow setup setup Overview of Steps Step 1 Step 2 • Turn on types of monitoring (Application, host, conversation, …) for data streams - Internal - External - ALL NDE Traffic from device Router (config)# ip cef - Subset of NDE traffic from a device Router (config)# interface type slot|wic-slot|port • Configure CEF using Router CLI to forward interface packets to the NM-NAM internal interface Router (config-if)# analysis-m
Basic NM-NAM Configuration Host Interface When When local local Interfaces Interfaces are are enabled enabled to to be be monitored, monitored, the the NM-NAM NM-NAM will will automatically automatically interact interact with with the the router router to: to: •• Enable Enable NetFlow NetFlow Data Data Export Export (NDE) (NDE) on on the the router router Interfaces Interfaces •• Set Set itself itself as as the the destination destination for for NDE NDE Provides Provides App, App, Host, Host, and and Con
Basic NM-NAM Configuration Step 2: Enabling Core Monitoring Step Step2: 2:Enable Enablemonitoring monitoringtype type by bydata datasource source Step Step1: 1: Configure ConfigureData Data Sources Sources Local Router Interfaces (Se0/0, Se0/1) NM-NAM NM-NAMInternal Internal Fast-Ethernet Source NM-NAM NM-NAMExternal External (Configured (Configuredas as Management ManagementInterface) Interface) NDE Device 192.168.79.
Enabling Core Monitoring (NM-NAM) Selecting Data Sources to Configure Internal Internaldata datasource source includes all includes allinterfaces interfaceson on the therouter routerconfigured configuredtoto forward forwardpackets packetstotothe the NM-NAM. NM-NAM.
Types of Statistics Collected 3 3 3 3 Application Statistics Enables the monitoring of application protocols observed on the data source Host Statistics (network and application layers) NDE NDEand andNM-NAM NM-NAM data sources provide data sources provide Enables the monitoring of network-layer host activity monitoring monitoringfor forthese these 33groups groupsof ofstatistics statistics Conversation Statistics (network and application layers) Enables the monitoring of pairs of network layer hosts
Types of Statistics Collected Application 3 Application Statistics Enables the monitoring of application protocols observed on the data source Current Rates for Application Statistics Choosing ChoosingApplication ApplicationStatistics Statistics from the Setup from the Setup>>Monitoring Monitoring>> Core CoreMonitoring Monitoringmenu menuenables enables the illustrated statistics the illustrated statisticsby by application applicationprotocol. protocol.
Types of Statistics Collected Hosts 3 Host Statistics (Network and Application layers) Enables the monitoring of network layer host activity Current Rates for Network & Application Layer Statistics Choosing ChoosingHosts HostsStatistics Statisticsfrom fromthe the Setup > Monitoring > Core Setup > Monitoring > Core Monitoring Monitoringmenu menuenables enablesthe the following statistics by following statistics bynetwork networkand and application. application.
Types of Statistics Collected Conversations 3 Conversation Statistics (Network and Application layers) Enables the monitoring of pairs of network layer hosts that are exchanging packets Cumulative Data for Network and Application conversation statistics •• Choosing ChoosingConversation Conversation Statistics Statistics(Network (Networkand and Application Applicationlayers) layers)from fromthe the Setup Setup>>Monitoring Monitoring>>Core Core Monitoring Monitoringmenu menuenables enables traffic rates pe
Types of Statistics Collected VLAN Traffic 3 VLAN Traffic Statistics NAM-1/2 NAM-1/2 Only Only Enables the monitoring of traffic on different VLANs for the data source Choosing ChoosingVLAN VLANTraffic TrafficStatistics Statisticsfrom fromthe the Setup > Monitoring > Core Monitoring Setup > Monitoring > Core Monitoring menu menuenables enablesthe thestatistics statisticsillustrated illustratedininthe the table and chart. table and chart.
Types of Statistics Collected VLAN Priority 3 VLAN Priority (CoS) Statistics NAM-1/2 NAM-1/2 Only Only Enables the monitoring of traffic using different values of the 802.1p priority field Choosing ChoosingVLAN VLANPriority PriorityStatistics Statisticsfrom fromthe the Setup Setup>>Monitoring Monitoring>>Core CoreMonitoring Monitoringmenu menu enables, enables,as asan anexample, example,the thestatistics statisticsby byVLAN VLAN priorities. priorities.
Types of Statistics Collected (NAM-1/2) Supervisor Data Source Setup > Monitor > Core Monitoring Enable Enablestatistics statistics collection collectionfrom from Supervisor Supervisor Monitor > VLAN > Traffic Statistics Current Currentstatistics statistics for forall allVLANs VLANs configured configuredon on Switch Switch NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Types of Statistics Collected (NAM-1/2) Supervisor Data Source – Port Stats Monitor > Switch > Port Stats Current Current Rates Rates for for Port Port Layer Layer 22 Statistics Statistics Details Details for for selected selected port port Real-Time Real-Time stats stats for for selected selected port port NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Types of Statistics Collected (NM-NAM) Router Data Source Setup > Monitor > Core Monitoring Enable Enablestatistics statistics collection collectionfor forhost host Router RouterInterfaces Interfaces Monitor > Router > NBAR Current Currentrates ratesfor for NBAR discovered NBAR discovered protocols protocolsfor for selected selectedinterface interface NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Types of Statistics Collected (NM-NAM) Router Data Source – Interface Stats Monitor > Router > Interface Stats Current CurrentRates Rates for forRouter Router Interfaces Interfaces NAM / Traffic Analyzer v3.5 Tutorial Select Select interface interface and andclick clickDetails Details for forApp, App,Host, Host, and andConv Convdata data © 2006 Cisco Systems, Inc. All rights reserved.
Types of Statistics Collected (NM-NAM) Router Data Source – Interface Stats Details NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-91 Core Monitoring: Router Data Source – Interface Stats Details Is so enabled, you can see application, host, and conversation detail for the selected interface from the Monitor > Router Interface > Stats report. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring (NAM-1/2) MPLS – Enable Monitoring Setup > Monitor > Core Monitoring Enable Enableapplication applicationprotocol, protocol,host, host,and and conversation conversationstatistics statisticsfor foreach eachMPLS MPLS data datasource sourceto tobe bemonitored monitored Monitor > MPLS > VRF Statistics View Viewtraffic trafficstatistics statistics(packets, (packets, bytes) bytes)by byMPLS MPLSData DataSource Source MPLS MPLS traffic traffic must must be be present present in in the
Enabling Traffic Monitoring (NAM-1/2) MPLS – RMON-2 Stats Apps, Apps,Hosts, Hosts,and andConv Convstats statsavailable available for forMPLS MPLSdata datasources sourcesjust justlike likeALL ALL SPAN SPANand andVLANs, VLANs,simply simplyselect selectMPLS MPLS from Data Source from Data Source NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring Voice Setup > Monitor > Voice Monitoring IfIfyou youenable enablevoice voicemonitoring, monitoring,the theTraffic Traffic Analyzer software generates the Aggregate Analyzer software generates the Aggregate Statistics Statisticstable tableas aswell wellas asthe thedetailed detailedreports reports illustrated on the next illustrated on the nextpage. page. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring Example: Voice Overview Monitor > Voice/Video >Voice Overview Aggregate Statistics for Voice Calls Detailed Reports for SCCP Packet Loss Statistics NAM / Traffic Analyzer v3.5 Tutorial Details for selected call © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-95 Voice Overview Use the Monitor > Voice/Video > Voice Overview report to see packet loss and jitter statistics gathered for each enabled protocol.
Enabling Traffic Monitoring RTP Stream Monitoring Setup > Monitor > RTP Stream Monitoring • Monitor RTP streams • View real-time video packet loss statistics • Apply src/dest address filters to monitor key RTP streams of interest • Obtain key data on RTP packet count, packet loss, and packet loss rate • Set alarm thresholds on packet loss variables • View RTP packet loss events as syslogs NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring Example: RTP Stream Monitoring RTP RTP Packet PacketLoss: Loss: •• Number Numberof of packets packetsexpected expected vs. vs.Number Numberof of packets packets received received RTP RTP Packet PacketLoss Loss Rate: Rate: •• [Number [Numberof of packet packet lost/(number lost/(numberof of packet packetlost lost++ number numberof of packets packets received)] received)] **1,000,000 1,000,000 Selected Selected stream stream details details NAM / Traffic Analyzer v3.
Enabling Traffic Monitoring Response Time Setup > Monitor > Response Time Monitoring NAM-1/2 NAM-1/2 NM-NAM NM-NAM The Thefirst firstscreen screenlists liststhe thedata datasources sources currently currentlyenabled enabledfor forResponse ResponseTime Time Monitoring Monitoringdata datasource. source.
Enabling Traffic Monitoring Example: Response Time Statistics Response Time All Data Table Monitor > Response Time This Thischart chartshows showsdetailed detailed server serverresponse-time response-timestatistics. statistics. Select Selectaaserver serverand andclick clickon onthe the Show ShowDetails Detailsbutton buttonto toview view detailed detailedstatistics statisticsfor forthe the selected selectedserver. server. NAM / Traffic Analyzer v3.
Enabling Traffic Monitoring DiffServ Overview DSMON DSMON MIB MIB NAM-Embedded Traffic Analyzer Ethernet Header (DSCP0) FTP IP Header (DSCP0)) (DSCP24) SNMP FTP Data TCP Header (DSCP40) (DSCP26) FTP http NAM / Traffic Analyzer v3.5 Tutorial ICMP © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring DiffServ Overview – Aggregation Groups User-Defined Profile Aggregation Group 1 DSCP0 DSCP1 DSCP2 Aggregation Group 2 DSCP3 DSCP4 DSCP9 NAM / Traffic Analyzer v3.5 Tutorial DSCP10 DSCP6 DSCP7 Aggregation Group 4 Aggregation Group 3 DSCP8 DSCP5 DSCP11 DSCP12 DSCP13 DSCP14 © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring DiffServ Configuration Step 1: Define profile by assigning DSCPs to groups and giving the profile a name. Templates provide starting point.
Enabling Traffic Monitoring Example: DiffServ Statistics DiffServ DiffServapplication application statistics statisticsprovide provideapplication application protocol protocolstatistics statisticsby bydata data source and profile you source and profile you created createdunder underSetup Setup>> Monitoring > DiffServ Monitoring > DiffServ Monitoring. Monitoring.
Enabling Traffic Monitoring URL Setup > Monitor > URL Collection Enable EnableURL URLcollection, collection, only onlyone onecollection collectionon onaa single singledata datasource sourcecan canbe be enabled enabledatataatime. time. Monitor > Apps > URLs URLs URLsseen seenon onselected selected data datasource source •• AA URL, URL, for for example: example: http://host.domain.com/intro?id=123 http://host.domain.com/intro?id=123 consists consists of of aa host host part part (host.domain.com), (host.
Enabling Traffic Monitoring Monitored Protocols Setup > Protocol Directory > Individual Applications •• The The Protocol Protocol Directory Directory shows shows you the protocols that are you the protocols that are configured configured by by default default for for collection collection and and reporting. reporting. (Support (Support available available in in v3.5 v3.
Enabling Traffic Monitoring Monitored Protocols – Create New Then Thenchoose choosefrom fromthe thelist listthe theprotocol protocol that thatthe thenew newprotocol protocolisisencapsulated encapsulated within. within.InInour ourcase, case,we wechose choseTCP. TCP. Then Thenenter enterthe theTCP TCPport port that is assigned that is assignedto tothe the protocol. protocol.
Enabling Traffic Monitoring Monitored Protocols – Auto Learned Applications Setup > Protocol Directory > Auto-learned Applications Monitor > Apps > Individual Applications The TheNAM NAMwill willalso alsodetect detectnew newprotocols protocolsand andadd add them thembased basedon onport portnumber number(i.e. (i.e.TCP-1098 TCP-1098or or IP-33). IP-33). Auto-learned Auto-learnedapplication application NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring Monitored Protocols – URL Applications Setup > Protocol Directory > URL-Based Applications Monitor > Apps > Individual Applications URL-based URL-basedapplication application Collect Collect and and present present statistics statistics on a URL as on a URL asan anapplication. application. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Enabling Traffic Monitoring Monitored Protocols – Application Groups Setup > Protocol Directory > Application Groups Add Addprotocols protocolsto toan an application applicationgroup. group. Monitor > Apps > Applications Groups Group Groupapplications applicationstogether togetherfor for reporting purposes. reporting purposes. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Configuring Alarms Overview Do I measure the condition by delta or absolute values? What is an alarm and how do I use thresholds to define an alarm? NAM / Traffic Analyzer v3.5 Tutorial How do I let others know about failures on my network? © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-110 Configuring Alarms Overview Configuring alarms is serious business.
Configuring Alarms Types of Alarms 3 3 3 NAM MIB Thresholds NAM Voice Thresholds NAM RTP Stream Thresholds 3 NAM Syslog 3 Switch Thresholds 3 NAM Trap Destinations 3 NAM Alarm Mail NAM / Traffic Analyzer v3.5 Tutorial Enables you to define thresholds/alarms based on byte or packet counts by protocol for network and MAC layer hosts and conversations Enables you to define thresholds/alarms for packet loss and jitter for SCCP, H.
Configuring Alarms NAM MIB Thresholds Alarm Configuration Choose Choosethe the analysis analysis type type Choose Choosewhat whatMIB MIB variable variableyou youwant want to tomonitor monitoron. on. MAC MACbased basedalarms alarmsnot notavailable available on onNM-NAM NM-NAM NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Configuring Alarms NAM MIB Thresholds Alarm Configuration, continue … Choose Choosethe thedata datasource sourcetotomonitor monitorfor forthis this threshold condition. threshold condition. Various Variousalarm alarmtypes typeswill willallow allowyou youtotoselect select the theapplication applicationtotoconfigure configurethe thealarm alarmagainst. against.
Configuring Alarms Voice Alarms Choose Choosethe thejitter jitterand and packet-loss packet-lossthreshold thresholdfor for any anyor orall all(SCCP, (SCCP,H.323, H.323, MGCP, MGCP,and andSIP) SIP) NAM / Traffic Analyzer v3.
Configuring Alarms RTP Stream Alarms Set Setconsecutive consecutive packet-loss packet-lossvalue valueand and packet-loss packet-lossthreshold threshold NAM / Traffic Analyzer v3.
Configuring Alarms Syslog for the NAM These Theseoptions optionsenable enable you youtotoforward forwardMIB, MIB, voice, voice,and andRTP RTPStream Stream threshold thresholdmessages messages and andsystem systemalerts alertsas as syslog messages syslog messagestoto either eitherthe thelocal localsyslog syslog server or to server or toaaremote remote syslog syslogserver. server.
Configuring Alarms Switch Thresholds Alarms NAM-1/2 NAM-1/2 Only Only Configuring Configuring aa switch switch alarm alarm is is similar similar to to configuring configuring aa NAM NAM threshold threshold alarm. alarm. The The basic basic differences differences are are the the data data source source and and the the variable variable options. options. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Configuring Alarms Trap Destinations Enter Entermultiple multiple destinations destinationstotoreceive receive traps trapsgenerated generatedby byNAM NAM alarms. alarms. To Toconfigure configuretrap trapdestinations, destinations, enter enterthe thecommunity communitystring stringfor for the management console the management consolethat thatwill will receive receivethe thetraps, traps,its itsIP IPaddress, address, and andthe theUDP UDPport portthat thatlistens listenstoto for arriving traps.
Configuring Alarms Alarm Mail Enter Entermultiple multiplee-mail e-mail addresses addressestotoreceive receivean an e-mail e-mailnotification notificationfor for NAM NAMalarms alarms NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-119 Configuring Alarm E-mail Alternative to notification via syslog or trap, the NAM can be configured to send an e-mail to a list of recipients when an alarm occurs.
Setting Software Preferences Use Use this this field field to to customize customize the the default default number number of of rows rows in in aa table. table. Use Use this this field field to to customize customize how how often often the the NAM NAM refreshes refreshes the the data data that that you you view. view. Use Use this this field field to to enable enable IP IP host host name name resolution resolution for for use use of of host host names names in in tables tables and and graphs. graphs.
• Network Monitoring Using NAMs • NAM Hardware Overview ¾ Traffic Analyzer Software –Planning –Getting Started –Configuring –Viewing Reports –Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Viewing Traffic Reports • Viewing Real-Time Reports – Types – Layout – Selecting Data Source – Common Error Messages – Standard Reports – Real-Time Trending – Drill-Down – Health • Creating and Viewing Historical Reports • Viewing Alarm Logs NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports NAM-1, NAM-2 Report Types Overview: Combination of several statistics, including most active applications, most active hosts, protocol suites, and server response times Apps: Traffic statistics per application protocol (groups and URL) Voice/Video: VoIP (SCCP, H.
Viewing Traffic Reports NM-NAM Report Types Overview: Combination of several statistics, including most active applications, most active hosts, protocol suites, and server response times Apps: Traffic statistics per application protocol (groups and URL) Voice/Video: VoIP (SCCP, H.
Viewing Traffic Reports Monitor Report Layout Select Select monitor monitor report report type. type. Use Use the the radio radio buttons buttons to to select select report report display display view. view. Some Some reports reports have have contextcontextsensitive sensitive submenus submenus ifif they they have have more more viewing viewing options. options. Print Print and and data data export export options. options.
Viewing Traffic Reports Monitor Report Layout (Continued) Bottom portion of monitor report Rows Rows to to display display per per monitor monitor report report page page Use Use to to display display more more pages pages of of data. data. To To use use any any of of these these options, options, first first select select aa entry entry from from the the data data table table Details Details of of selected selected item item depend depend on on monitor monitor report. report. (i.e. (i.e.
Viewing Traffic Reports Selecting Data Sources Real-time Real-timemonitoring monitoring reports reportsfound foundunder under Monitor Monitortab. tab. The The Data Data Source Source pull-down pull-down list list shows shows you you only only the the data data sources sources that that have have been been enabled enabled for this for this collection collection using using the the Setup Setup >> Monitor Monitor task. task.
Viewing Traffic Reports Common Error Messages Another Anotherreason reasonwhy whyyou you may have no data may have no data available availableisisthat, that,even even though you configured though you configuredthe the report, report,you youchose choseaadata data source sourcethat thatisisnot notpart partofof the theconfigured configureddata data source. source. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Standard Report Options Current Rate Reports show data that has been collected during the most recent refresh interval only. These Thesethree threereports reportsare areavailable availablefor forapplication, application, hosts, conversations, VLANs, DiffServ, hosts, conversations, VLANs, DiffServ,and andport port statistics. statistics. NAM / Traffic Analyzer v3.5 Tutorial Cumulative Data Reports show all data since the NAM started collecting.
Viewing Traffic Reports Real Time Statistic Tracking Monitor > Apps > Individual Apps How does the SNMP traffic on VLAN99 change over the short term? Select Select statistic statisticto to track track Select Selecttable tableentry entrytototrack, track,and and click the Real-Time click the Real-Timereport report option. option. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Application Drill-Down Monitor > Apps > Individual Applications Which Whichhosts hostsare are generating generatingspecific specific application applicationtraffic traffic Drill Drilldown downby byapplication applicationtotosee see all hosts transmitting all hosts transmittingor or receiving receivingusing usingthat thatapplication. application. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Application Group Drill-Down Monitor > Apps > Application Groups Drill Drilldown downby byapplication applicationgroup group totosee seeall allhosts hoststransmitting transmittingor or receiving receivingusing usingapplications applications within withinthe thegroup. group. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Host Drill-Down From FromHost Hostor orConversation Conversationreport reportclick clickon onhost hostor or select selectrow rowof oftable tableand andclick clickDetails Detailsbutton button Details Details of of network network host activity host activity and and conversations conversations by by application application NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports DiffServ Drill-Down Monitor Monitor>>DiffServ DiffServ>> Application ApplicationStats Stats Drill Drilldown downon onan an application listed application listedfor foraa specific aggregation specific aggregationgroup group totosee seethe theconversations conversations for forthat thatapplication application Monitor Monitor>>DiffServ DiffServ>> Host HostStats Stats Drill Drilldown downon onaa host host listed for a listed for aspecific specific aggregation aggregationgroup grouptoto
Viewing Traffic Reports Voice Drill-Down Monitor > Voice/Video > Voice Overview Packet PacketLoss Lossand and Jitter Jitterfor forthe the55 “worst” “worst”calls. calls. •• Voice Voice Overview Overview report report provides an overview provides an overview of of packet packet loss lossand and jitter jitter statistics statistics by by protocol. protocol.
Viewing Traffic Reports Voice Drill-Down (Continued) Per Percall calldetails details Page 2 Page 1 NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-136 Voice Drill Down (Continued) The illustration above is a drill down for a particular call displayed in the “worst” packet lost report. This report can also be displayed by selecting individual calls from the Known Phones drill down report or the Active Calls report. NAM / Traffic Analyzer v3.
Viewing Traffic Reports RTP Stream Drill-Down Monitor > Voice/Video > RTP Stream Traffic •• RTP RTPStream Stream Report Report report report provides an overview provides an overviewof ofpacket packet loss statistics to help assure loss statistics to help assureaa high highrate rate of ofpacket packetdelivery. delivery. •• Select SelectDetails Details to to view viewpacket packetloss loss by bystream. stream. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Server Response Time Drill-Down Monitor > Response Time > Server Detailed Detailedreports reportsshow showthe thebuckets buckets you created during configuration you created during configurationtoto report reporton onthe theindividual individualresponseresponsetime samples (for time samples (forall allclient clientrequests). requests). NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Client/Server Response Time Drill-Down Detailed Detailed reports reports show show the the buckets buckets you you created created during during configuration configuration to to highlight highlight the the individual individual client/server client/server response-time response-time samples. samples. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Viewing Traffic Reports Port Drill-Down NAM-1, NAM-1, NAM-2 NAM-2 Only Only Monitor > Switch > Port Stats Drill Drill down down to to view view packet packet size size distribution distribution for for selected selected port port NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-140 Port Drill-Down On the NAM-1/2 the mini-RMON statistics pulled from the host switch provide utilization and error statistics for each active port.
Viewing Traffic Reports Interface Drill-Down NM-NAM NM-NAM Only Only Monitor > Router > Interface Stats Drill Drill down down to to see see App, App, Host, Host, and and Conv Conv details details for for selected selected interface interface NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-141 Interface Drill Down On the NM-NAM interface statistics are pulled from MIB-II on the router.
Viewing Traffic Reports Router/Switch Health Monitor > Router > Health Monitor > Switch > Health NAM-1/2 NAM-1/2 NM-NAM NM-NAM NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-142 Router/Switch Health As with all critical network devices, monitoring the overall health (CPU utilization, memory utilization, temperature, etc.
Basic Historical Reports Creating Report Existing ExistingReports Reports Historical HistoricalReports ReportsControls Controls Applications Continued NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-143 Historical Reports Earlier we looked at how to use the Real-Time graphs to do short term trending. Using the Historical reports we can extend this trending capability to up to 100 days from the creation of the report.
Basic Historical Reports Creating Report, Continue … Select Select Report Report Parameters Parameters Report Report by by Application Application or or Top Top N N Applications Applications Available Available TopN TopN Reports: Reports: •• Protocols Protocols •• Hosts Hosts •• Conversations Conversations •• MPLS MPLS Tags Tags Title Title auto-selected auto-selected or or can can be be created created by by user user NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Basic Historical Report Quick Create Monitor > Apps > Individual Applications Select Selecttable tableentry entry and click and clickreport reportto to create a basic create a basic historical historicalreport report Entry EntryisisPending Pending until untilfirst firstdata datapoll poll NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Basic Historical Reports Viewing Report Launch by selecting one or more basic reports from Reports > Basic Reports Export Export as as CSV CSV or or PDF PDF on on demand demand Change Changeday dayand and time timeof ofdisplayed displayed data data Change Change report report period, period, granularity, granularity, and and display display style style List List of of all all defined defined basic basic reports. reports.
Basic Historical Reports Viewing Report – Top N •• Use Use to to troubleshoot troubleshoot aa problem problem by by going going back-in-time back-in-time •• Maximum Maximum number number of of TopN TopN entries entries per per interval: interval: 50 50 (protocols), (protocols), 100 100 (hosts), (hosts), 200 200 (conversations) (conversations) NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Basic Historical Reports Create Custom Report Reports > Custom Reports Can Can create create folders folders to organize to organize custom custom reports reports Used to group together basic reports NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-148 Creating Custom Historical Reports The second option available under the Reports tab is Custom reports. A Custom Historical report is simply a collection of basic reports displayed together.
Basic Historical Reports View Custom Report Launch Launch by by selecting selecting aa report report from from Reports Reports >> Custom Custom Reports Reports System System events events that that may may affect affect reporting reporting include include changing changing of of data data sources sources and and enabling enabling of of monitoring monitoring options options NAM / Traffic Analyzer v3.
Basic Historical Reports Scheduled Export Reports > Scheduled Export > Create Schedule Schedule report report daily, daily, weekly, weekly, or or monthly monthly Select Select report report format format Configure Configure server server using using Admin Admin >> System System >> E-mail E-mail Configuration Configuration and and FTP FTP location location using using Admin Admin >> System System >> FTP FTP Configuration Configuration Select Select from from existing existing reports reports NAM / Traffi
Viewing Alarm Logs NAM Thresholds Display Displayalarms alarms generated generatedby bythe theNAM NAM NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-151 Viewing NAM Threshold Alarms Under the Traffic Analyzer Alarm tab, you can view all the alarms that both the NAM and the Cisco Catalyst® Switch have generated. Remember, however, that alarms will appear only if you have first configured them under Setup > Alarms.
Viewing Alarm Logs Switch Thresholds NAM-1/2 NAM-1/2 Only Only Display Displayalarms alarmsdetected detected on the Catalyst on the Catalystswitch switch AAgood gooddescription description entered enteredduring duringsetup setupcan can help pinpoint the help pinpoint theexact exact nature natureofofthe thealarm alarm NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Network Monitoring Using NAMs • NAM Hardware Overview ¾ Traffic Analyzer Software –Planning –Getting Started –Configuring –Viewing Reports –Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Packet Capture and Decode Packet Capture • Overview • Buffers (NAM RAM) • Capture Settings • Quick Capture • Decoding Captures • Saving Buffers NAM Hard Disk • Additional Remote Disk Storage • Managing Capture Files NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-154 Packet Capture Overview Previous sections discussed the NAM monitoring features that provide application visibility.
Packet Capture and Decode Navigation Menu •• Perform Perform multiple multiple captures captures and and decode decode within within the the same same browser browser session session –– even even while while the the NAM NAM is is performing performing RMON2 RMON2 analysis! analysis! •• You You can can even even save save capture capture sessions sessions to to your your local local NAM NAM hard hard disk disk or or aa remote remote disk. disk. NAM / Traffic Analyzer v3.
Packet Capture and Decode Buffers Capture > Buffers Capture Capture Buffers Buffers dialog dialog shows shows all all capture capture buffers buffers (NAM (NAM RAM) RAM) and and their their current current status status Create Create new new capture capture NAM / Traffic Analyzer v3.
Packet Capture and Decode Capture Settings Status Status of of capture capture Select Select data data source source Define Define how how much much NAM NAM memory will be memory will be allocated allocated to to packet packet capture, capture, or or which which disk disk (local (local or or remote) remote) to to store store data data Setup Setup&&use useof ofremote remote storage storagediscussed discussedlater later Define Define how how the the NAM NAM handles handles new packets when new packets when t
Packet Capture and Decode Quick Capture Monitor > Conversations Auto-name Auto-name •• From Fromaamonitor monitorreport, report,selecting selectingaatable tableentry entry and andthe theCapture Capturebutton buttonautomatically automaticallysets setsup up aadata datacapture captureusing usingthe thetable tableentry entrytotofill fillinin the thecapture capturesettings. settings. •• Note: Note:Capture Captureisisimmediately immediatelystarted startedand and decode results are displayed.
Packet Capture and Decode Custom Capture Filters Capture > Custom Filters > Capture Filters Select Select protocol protocol encapsulation encapsulation and and protocol protocol to to base base filter filter on. on. Leave Leave blank blank ifif filter filter is is protocol protocol independent. independent. Enter Enter your your data data string string here. here.
Packet Capture and Decode Decoding Packets From Fromthe theCapture Capture>>Buffer Bufferor or Capture > Files dialogs, Capture > Files dialogs,select select aabuffer/File buffer/Filethen thenDecode Decode Apply Applyfilter filterto tolimit limit packets displayed packets displayed This Thispane panegives givessummary summary information for information foreach eachpacket. packet.
Packet Capture and Decode Custom Display Filters Capture > Custom Filters > Display Filters IfIf you you do do not not want want to to filter filter by by protocol, protocol, choose choose ALL ALL from from the the protocol protocol pull-down pull-down list. list. IfIf desired, desired, enter enter addresses addresses as as part part of of the the filter filter definition. definition. Enter Enter the the data data string string or or pattern pattern that that you you want want to to filter filter on. on.
Packet Capture and Decode Decoding Packets – TCP Stream NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Product Features 2-162 Decoding Packets – TCP Stream Packet analysis is very beneficial for troubleshooting packet level problems. The NAM offers an additional analysis tool to enhance this process, the TCP Stream tool. To launch, select a TCP packet from the packet decode window, and click the TCP Stream button.
Packet Capture and Decode Analyzing Packets Capture > Files Presents Presents detailed detailed statistical statistical analysis analysis of of captured captured data data •• Traffic Traffic Rate Rate over over selected selected time time period period •• List List of of host host and and associated associated traffic traffic •• List List of of protocols protocols and and associated associated traffic traffic View View more more details details about about aa specific specific time time frame, frame, proto
Packet Capture and Decode Save to NAM Hard Disk (Local Disk) Two TwoMethods Methods Selecting Selecting“Capture “Captureto toDisk Disk>> Local LocalDisk” Disk”option optionas asthe thestorage storage option optionininthe theCapture CaptureSettings Settings Capture Settings Selecting Selecting“No. “No.
Packet Capture and Decode Additional Remote Data Storage (Optional) Extend Extend the the NAM’s NAM’s data data capture capture storage storage capability, capability, by by defining defining remote remote storage storage locations locations Before Before using using aa remote remote disk to disk to store store data data captures, captures, use use the the Admin Admin >> System> System> Capture Capture Data Data Storage Storage task task to to first first define define itit AA remote remote data data stor
Packet Capture and Decode Defining Remote Data Storage (NFS) Name Name to to define define the the remote remote data storage. Name data storage.
Packet Capture and Decode Defining Remote Data Storage (iSCSI) Name Name to to define define the the remote remote data storage. Name data storage.
Packet Capture and Decode Managing Capture Files Capture > Files Select Selectcapture capture files fileson onNAM NAM hard harddisk disk(Local) (Local) or orRemote RemoteDisk Disk Download Downloadselected selected file fileto toyour yourcomputer computer ininSniffer Sniffer.enc .encfile file format format Merge Mergefiles filesinto intoone one(From (From “Number “Numberof ofFiles” Files”option option NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Product Features - Summary • Flexible Monitoring – LAN/WAN – SPAN/RSPAN/VACL – NDE • Comprehensive Visibility – – – – – – – Application Host Conversation Voice DiffServ VLANs MPLS Tags • Historical Trend Reports • Packet Capture and Decode NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Thank You! Continue on to Chapter 3 to learn how to use the NAMs through a series of scenarios. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM Usage Scenarios Chapter 3 •• Cisco Cisco Network Network Analysis Analysis Modules Modules (NAM) (NAM) NAM-1, NAM-1, NAM-2, NAM-2, and and the the NM-NAM NM-NAM •• Cisco Cisco NAM NAM Traffic Traffic Analyzer Analyzer Software Software v3.5 v3.5 NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Chapter 3 Outline NAM Scenarios • Performance/Troubleshooting (NAM-1/2) • Performance/Troubleshooting (NM-NAM) • QoS Monitoring (Using DiffServ and ART) • VoIP Monitoring • Trend Analysis WAN NAM-1/2 NM-NAM NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-2 Chapter 3 Outline This chapter explores several scenarios to illustrate how you can use the various Network Analysis Modules (NAM) to gain visibility into your network.
Network Overview Q-Bits International WAN (connections to other sites) HQ-Core-1 BR-Core-1 NM-NAM NAM-1/2 HQ-Dist-MSFC-1 BR-Dist-MSFC-1 HQ-Dist-1 Gi1/2 HQ-Access-1 HQ-Access-2 Use UseNM-NAM NM-NAMexternal external interface interfaceto tomonitor monitorSPAN SPAN port on access port on accessswitch switch HQ-Access-3 BR-Dist-1 BR-Access-1 BR-Access-2 Cisco CallManager Server Farm NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Performance/Troubleshooting (NAM-1/2) • Performance/Troubleshooting (NM-NAM) • QoS Monitoring • VoIP Monitoring • Trend Analysis NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 1 Performance/Troubleshooting (NAM-1/2) • NAM Access • Port Utilization • Port Spanning • Traffic Overview • Unwanted Traffic Users NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-6 Scenario 1 - Performance/Troubleshooting NAM-1/2 After Dean installs and configures the Catalyst 6500 series NAM module, he is ready to see if the new network is performing as expected.
Scenario 1 Accessing the NAM Enter Enteruser useraccount account information informationcreated createdduring during the theinstallation installationof ofthe theNAM NAM NAM NAMPerformance Performance Metrics Metrics NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 1 Setting Switch Parameters Setup > Switch Parameters > Switch Information The TheNAM NAMSNMP SNMPto toretrieve retrieve Mini-RMON stats. Verify Mini-RMON stats. VerifyNAM NAM SNMP SNMPconnectivity connectivityto toswitch. switch. SNMP MINI-RMON MINI-RMON Setup > Switch Parameters > Port Stats Enable/Verify Enable/VerifyMini-RMON Mini-RMONisis enabled on enabled onSwitch Switch NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 1 Switch Port Utilization Monitor > Switch > Port Stats Check Checkport portstatus statusfor forany anyindication indicationof ofproblems. problems. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-9 Switch Port Utilization Dean can now look at the utilization of each of the Cisco Catalyst® Switch ports that host the NAM card. Step 1. Click Monitor > Switch > Port Stats. The Port Stats data screen is displayed.
Scenario 1 SPAN Traffic To/From Server Farm Setup > Data Sources > SPAN HQ-Dist-1 Gi1/2 HQ-Access-1 1. 1. Select SelectSPAN SPANType. Type. 2. 2. Select SelectSwitch SwitchModule Moduleififport portSPAN. SPAN. 3. 3. Select SelectSPAN SPANdirection. direction. 4. 4. Select SelectSource. Source. 5. 5. Click ClickAdd. Add. 6. 6. Repeat Repeatsteps steps44and and55ififnecessary. necessary. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 1 Configure Core Monitoring (ALLSPAN) First the packet is counted here ... PHY PHYPort Port (ALLSPAN) (ALLSPAN) SPAN source (1/2) is a trunk port. VLAN VLANXX VLAN VLANYY VLAN VLANZZ …then the packet is counted again on the proper VLAN data source for all enabled monitoring categories. Setup > Monitor > Core Monitoring Enable Enable Collections Collections NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 1 VLAN Traffic Statistics Monitor > VLAN > Traffic Statistics Unexpected UnexpectedHigh High Traffic TrafficLevel. Level. Who Whoisisusing usingthis this bandwidth? bandwidth? NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-12 VLAN Traffic Statistics Dean now wants to see which VLANs are passing traffic to and from the server farm and how much. Step 1. Click Monitor > VLAN > Traffic Statistics. The VLAN Traffic Statistics report is displayed.
Scenario 1 Configure Core Monitoring for VLAN 130 VLAN VLAN100 100 PHY PHYPort Port (ALLSPAN) (ALLSPAN) SPAN source (2/1) is a trunk port. .. . VLAN VLAN130 130 VLAN VLANZZ Setup > Monitor > Core Monitoring Enable Enablestatistics statisticscollection collection for fortraffic trafficin inVLAN VLAN130. 130. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 1 Traffic Overview VLAN 130 High Highpercentage percentage hosts, hosts,suspects suspectsof of game gameplaying playing Who Whoisisplaying playing games gamesacross acrossthe the link? link? NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-14 Traffic Overview VLAN 130 Dean uses the traffic overview feature of the NAM to get a quick look at what is happening on VLAN 130. Step 1. Click Monitor > Overview. The Overview data screen is displayed.
Scenario 1 Apps and App Consumers on VLAN 130 Monitor > Apps > Individual Applications Simply Simplyclick click on onan an application application to tosee seeall allusers users of ofthat thatapplication. application. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-15 Apps and App Consumers on VLAN130 Now that Dean knows that there is some suspect application traffic on VLAN 130, he uses NAM monitor reports to quickly find the consumers.
Scenario 1 Host View VLAN 130 Zoom Zoom in inon on one oneof of the the reported hosts to reported hosts to view view details detailsabout aboutapplication application usage and usage andconversations conversations See next page NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-16 Host View VLAN 130 Now that Dean knows which hosts are playing Doom, he wants to determine what other network activities they are involved in.
Scenario 1 Host Zoom NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-17 Host Zoom Dean drills down on one of the hosts reported as playing Doom and is presented with a wealth of information about its activities. Looking at the Application Protocol Usage chart, Dean quickly sees all applications this host is using, and a listing of conversations to and from for each application.
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Performance/Troubleshooting (NAM-1/2) • Performance/Troubleshooting (NM-NAM) • QoS Monitoring • VoIP Monitoring • Trend Analysis NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 2 Performance/Troubleshooting (NM-NAM) • NAM Access • Interface Utilization • WAN Interface Monitoring • Host Monitor • Packet Capture to Classify Traffic • Create New Protocol for Monitoring NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-20 Scenario 2 - Performance/Troubleshooting NM-NAM The branch office was recently opened and is expected to send lots of proprietary application traffic back to headquarters.
Scenario 2 Accessing the NM-NAM NM-NAM NM-NAMsoftware softwareis isthe the same sameas asthe theNAM-1/2 NAM-1/2 software softwarewith withaafew fewminor minor differences, differences,hence, hence, access accessis isthe thesame. same. NAM NAMPerformance Performance Metrics Metrics NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 2 Setting Router Parameters Setup > Router Parameters > Router Information Enter Enterthe thesame sameIP IPaddress address (internal (internalanalysis analysisint) int)and andreadreadwrite community string write community stringas aswas was configured configuredon onthe therouter. router. The TheNM-NAM NM-NAMneeds needsto toknow know the therouter’s router’scommunity community strings stringsin inorder orderto toretrieve retrieve interface interfacestatistics. statistics.
Scenario 2 Configuring Interfaces as Data Sources When When local local Interfaces Interfaces are are enabled enabled as as aa data data source, source, the the NM-NAM NM-NAM will will automatically automatically interact interact with with the the router router to: to: •• Enable Enable NetFlow NetFlow Data Data Export Export (NDE) (NDE) on on the the router router Interfaces Interfaces •• Set Set itself itself as as the the destination destination for for NDE NDE Provides Provides Application, Applicatio
Scenario 2 Interface Utilization Monitor > Router > Interface Stats Check Checkinterface interfaceusage usagefor forany anyindication indicationof ofproblems. problems. Select Selectinterface interfaceand andclick click Details Detailsfor forapplication, application,host, host, and andconversation conversationstatistics statistics See next page NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 2 Interface Details View Viewtop topapplications, applications,hosts, hosts,and and conversations for selected conversations for selectedinterface interface For Formore moreapplications, applications,hosts, hosts,and and conversations conversationsdetails detailsfor foraaselected selectedinterface, interface, use useCEF CEFto toforward forwardtraffic trafficto tothe theNAM NAM NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 2 Interface NBAR Monitor > Router > NBAR Use UseNBAR NBARto tofind findout outapplication applicationdetails detailsper perinterface interfacefor forany anyindication indicationof ofproblems. problems. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-26 Interface NBAR Before configuring the NM-NAM for more in-depth monitoring of the WAN link, Dean decides to also view what applications NBAR has discovered on the WAN link. Step 1.
Scenario 2 Configure Data Source and Monitoring Step 1: Select NAM Data Source Telnet WAN Router > configure terminal Router (config)# ip cef Se0/0 Router (config)# interface Se0/0 Router (config-if)# analysis-module monitoring 1. 1. Enable EnableCisco CiscoExpress ExpressForwarding. Forwarding. 2. 2. Select Selectinterface. interface. 3. Forward packets to NAM. 3. Forward packets to NAM.
Scenario 2 Top Hosts Monitor > Hosts > Network Hosts Select SelectHost Hostfor forCapture Capture Host HostDrill DrillDown Down •• Use Usedata datacapture captureto todetermine determinewhat whatis isthe the “tcp-unknown” “tcp-unknown”traffic traffic •• Traffic TrafficAnalyzer Analyzercan canautomatically automaticallydiscover discover up to 100 unknown protocols. up to 100 unknown protocols.
Scenario 2 Quick Capture Settings Review Capture > Buffers Available Availablebuffer bufferspace space Automatically Automaticallycreated createdbuffer buffer Buffer BufferStatus Status Buffer Buffer Parameters Parameters Settings Settings automatically automatically filled filledin inby byQuick Quick Capture Capture Filter Filterby byAddress Address Buffer BufferControls Controls NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 2 Decoding the Packets Summary Summary Data Data Header Header Decode Decode AAlot lotof ofdata dataseen seenon on TCP TCPport port2020 2020 Raw Raw Data Data NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 2 Adding a New Protocol Setup > Protocol Directory > Individual Applications Select Select Encapsulation Encapsulation Enter Enterport portnumber number and andname name Enter Enternumber numberof ofcontinuous continuousports ports used by application used by application NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 2 New Application View Monitor > Apps > Individual Applications Previously Previously“tcp“tcpunknown” unknown”traffic trafficis isnow now reclassified reclassifiedproviding providingaa more moredetailed detailedpicture pictureof of applications applicationson onthe the network network NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Performance/Troubleshooting (NAM-1/2) • Performance/Troubleshooting (NM-NAM) • QoS Monitoring • VoIP Monitoring • Trend Analysis NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 3 QoS Monitoring (Using DiffServ and ART) Differentiated Services Monitoring DST MAC xx-xx-xx-xx-xx-xx SRC MAC yy-yy-yy-yy-yy-yy ----------------------------------------IP Header DiffServ Field XXXXXX . . . 0 DSCP0 1 2 3 4 AZT1 . . .
Scenario 3 Create DiffServ Profile Setup > Monitor > DiffServ > Profile Select SelectTemplate Template and andEdit Editfield field names namesififdesired desired (named (namedfields fields create createcollection collection buckets). buckets). Create Createaageneric genericprofile profileto to determine determinewhat whatDSCP DSCPvalues values are arecurrently currentlyset. set. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 3 Enable DiffServ Monitoring Setup > Monitor > DiffServ > Monitoring Enable EnableDiffServ DiffServstatistics statisticsfor for the thecreated createdprofile profileon onVLAN VLAN100 100 (main (mainVLAN VLANfor forserver serverfarm). farm). Enable Enable Collection Collection Statistics Statistics NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 3 DiffServ Traffic Statistics (VLAN 100) Monitor > DiffServ > Traffic Stats All Alltraffic trafficto toand andfrom fromthe the server serverfarm farmon onVLAN VLAN100 100has has one oneof offour fourDSCP DSCPvalues valuesset. set. Next Nextstep stepis isto tosee seeififthe theexpected expectedapplications applicationsand and hosts hostsusing usingaaparticular particularDSCP DSCPvalue. value. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 3 DiffServ Application Statistics (VLAN 100) Monitor > DiffServ > Application Stats Verify Verifythat thatthe thelisted listed protocols protocolsare arethe theonly onlyones ones you configured to you configured touse usethe the selected selectedDSCP DSCPvalue. value. Verify Verifythat thatonly onlythe the expected expectedservers serversare are using a protocol with using a protocol withthis this DSCP value DSCP value NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc.
Scenario 3 DiffServ Host Statistics (VLAN 100) Monitor > DiffServ > Host Stats Verify Verifythat thattraffic trafficfrom fromthese these hosts hostsare areeligible eligibleto to send/receive send/receiveapplication application traffic trafficusing usingDSCP DSCP26. 26. Verify Verifythat thatthe thelisted listed hosts hostsare areusing usingexpected expected protocols protocolsand andconversing conversing with withexpected expectedservers. servers. NAM / Traffic Analyzer v3.
Scenario 3 Enable ART Monitoring (VLAN 100) Setup > Monitor > Response Time Monitoring Select Selectdata datasource sourceto to enable enableART ARTon onand and configure configurethe thereport report interval intervaland andresponse response buckets buckets NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 3 ART Server Data (VLAN 100) Zoom Zoomin infor for more moredetails details NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-41 ART Server Data Dean is ready to view how the Cisco CallManager application is performing. Based on the placement of the NAM in the distribution switch, the times reported will be from the distribution switch, to the server farm workgroup access switch, to the Cisco CallManager, and back.
Scenario 3 ART Server Detail Data (VLAN 100) Too TooSlow? Slow? Need Needmore more information… information… single singleclient client slow slowor orall? all? NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-42 ART Server Detail Data The ART Server Details report opens in a new window. Dean uses this report to see the number of responses and their time grouping.
Scenario 3 ART Client Server Data (VLAN 100) Monitor > Response Time > Client/Server Zoom ZoomIn Infor for More MoreDetails Details Response Response times timesare are consistent consistent for forall all clients clients You Youcan canview viewresponse responsetime timeby byclient clientserver serverpairs pairsto tosee seeififany any QoS QoSor orother othermodifications modificationsneed needto tobe bemade. made. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 3 ART Client/Server Detail Data (VLAN 100) NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-44 ART Client/Server Detail Data The ART Client/Server Details report opens in a new window. Dean uses this report to see the number of responses and their time grouping. In this case, some of the response pairs fall into the 200-500 ms time bucket, indicating that response time is a little high for this Cisco Call Manager / IP phone pair.
• Performance/Troubleshooting (NAM-1/2) • Performance/Troubleshooting (NM-NAM) • QoS Monitoring • VoIP Monitoring • Trend Analysis NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 4 VoIP Monitoring • Enable Voice Monitoring Voice Gateway • Control Protocol Statistics • Phone Statistics – All Calls – Individual Call • Active Call Statistics CallManager NAM NAMgathers gathersstatistics statisticsbased based on onSCCP, SCCP,H.323, H.323,MGCP, MGCP,and andSIP SIP messages. messages. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 4 Enable VoIP Monitoring Enable Enable Setup > Monitor > Voice Monitoring VoIP VoIPmonitoring monitoringis is enabled enabledfor forall alltraffic trafficand and not notby byindividual individualVLANs VLANs NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-47 Enable VoIP Monitoring Like all other NAM monitoring features, voice monitoring must be enabled before any data collection will take place.
Scenario 4 Voice Overview Monitor > Voice/Video > Voice Overview To ToView ViewCalls Calls with with“Worst” “Worst” Packet PacketLoss Loss and andJitter Jitter NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-48 Voice Overview Dean first chooses to view the Voice Overview report that shows him the overall health of the voice network.
Scenario 4 List of “Worst” Calls To Toview viewcall calldetails details Calls Callswith with“Worst” “Worst” Packet PacketLoss Lossand and Jitter Jitter NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-49 List of “Worst” Calls A separate window is opened containing two tables: the first shows the five calls with the worst packet loss and the second contains the five calls with the worst jitter.
Scenario 4 Individual Call Statistics Details Details for for selected selected call call NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-50 Individual Call Statistics The Individual Call Statistics report also opens in a new browser window. Dean now has all known details about a particular call.
Scenario 4 Overview of All Phones Click Clickto toView View all allCalls Calls to/from to/fromThis This Number Number NAM / Traffic Analyzer v3.5 Tutorial List Listof ofAll All Phones PhonesSeen Seen © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-51 Overview of All Phones The NAM voice monitoring features give Dean the ability to view statistics of each phone and, if necessary, drill down into each call to or from a phone and review quality statistics on a per-call basis.
Scenario 4 Listing of All Calls for Individual Phone Last LastFive FiveCalls Callsto to or orfrom fromThis This Number Number To ToView ViewCall CallDetails Details NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-52 Listing of All Calls for Individual Phone A new window opens with call-quality statistics for the selected phone and the last five calls to or from this number.
Scenario 4 Listing of Active Calls Click Clickto toview view call calldetails details NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 4 Individual Active Call Details Details Details for for Selected Selected Active Active Call Call NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-54 Individual Active Call Details Again, many of the details about a call will not be available until after the call has been completed. However, some of the information on this screen provides Dean with clues as to where to begin troubleshooting.
• Performance/Troubleshooting (NAM-1/2) • Performance/Troubleshooting (NM-NAM) • QoS Monitoring • VoIP Monitoring • Trend Analysis NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 5 Trend Analysis Retrieve save data from database and view historical report On-board Database Periodically save collected data to database • Real-Time Trend • Configure Basic Reports – Port Statistics HTTP – Application Statistics • View Basic Reports View Real-Time or Historical Data NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 5 Real-Time Trend Report Monitor > Switch > Port Stats Short-term Short-termtrend trendreport report (real-time (real-timeupdate) update)available available from frommost mostmonitor monitorreports reports NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-57 Real-Time Trend Report Dean can always use basic monitoring reports to view a snapshot of the current application, host, and conversation traffic rates per port.
Scenario 5 Create Basic Report – Port Statistics Reports > Basic Reports Use Usethe theReports Reports tab tabto tocreate create long-term long-term(100 (100 days) days)historical historical trend trendreports reports Bytes/sec NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-58 Create Basic Report – Port Statistics Dean uses the following steps to create a basic historical report to help him trend the byte rate of port Gi1/2: Step 1.
Scenario 5 Quick Create Basic Report – Application Monitor > Apps > Individual Applications Quickly Quicklycreate create historical historical reports reportsfrom from most mostmonitor monitor reports reports Waiting Waitingfor forfirst first data datacollection collection based basedon onset set polling pollinginterval interval Clicking ClickingReports Reports takes takesyou youto tothe the Reports > Reports >Basic Basic Reports screen Reports screen NAM / Traffic Analyzer v3.
Scenario 5 View Basic Reports NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-60 View Basic Reports The data for the reports generated are being logged every 15 minutes. Some time later Dean uses the following steps to view the three values together to determine how much of the link is being consumed by these two protocols: Step 1. Select Reports > Basic Reports. The list of Basic Reports is displayed. Step 2.
Scenario 5 Create Top N Reports Reports > Basic Reports Top Top NN Reports: Reports: •• Applications Applications •• Hosts Hosts •• Conversations Conversations •• Ports Ports(NAM-1/2) (NAM-1/2) •• Interfaces Interfaces(NM-NAM) (NM-NAM) •• MPLS (NAM-1/2) MPLS (NAM-1/2) Default Default Name Name Choose Choosethe the appropriate appropriateData Data Source Source NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Scenario 5 View Top N Reports Narrow Narrow the thetypes types of of reports reportsdisplayed displayed Top Top10 10applications applications for foreach each hour hourfor for one one day day NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Scenarios 3-62 View Top N Reports The data for the report are being logged every 15 minutes. Some time later Dean uses the following steps to view the top applications on the WAN link: Step 1. Select Reports > Basic Reports.
Thank You! Continue on to Chapter 4 to learn about some of the administrative tasks not yet discussed. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM System Administration Chapter 4 •• Cisco Cisco Network Network Analysis Analysis Modules Modules (NAM) (NAM) NAM-1, NAM-1, NAM-2, NAM-2, and and the the NM-NAM NM-NAM •• Cisco Cisco NAM NAM Traffic Traffic Analyzer Analyzer Software Software v3.5 v3.5 NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Chapter 4 Outline • Requirements – Hosting Hardware and Software – Client (Access to the NAM) • Administration – Install – Initial Configuration • Maintenance • Diagnostics & Troubleshooting Tips NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
¾ Requirements • Administration • Maintenance • Diagnostics & Troubleshooting Tips NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Requirements NAM Specifications NAM-1 Supported Platforms Operating System NAM-2 Fabric Enabled Cat 6000/6500 Cat 6000/6500 Switches, Cisco Switches, Cisco 7600 Router 7600 Router NM-NAM 2600XM, 2800, 3660, 3700, 3800 Series Routers IOS 12.3(7)T or later or IOS 12.
Requirements NAM-1, NAM-2 Host Platform Hardware/Software Details Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers Cisco IOS Software Version Hardware Release 12.1(13)E or later Supervisor Engine 2 with an MSFC2 Release 12.2(14)SX1 or later WS-SUP720 Release 12.2(18)SXF or later WS-SUP32 * Refer to notes for specific IOS requirements for the Virtual SPAN and ERSPAN features Catalyst OS Software Version NAM / Traffic Analyzer v3.5 Tutorial Hardware Release 7.
Requirements Client (Access to the NAM’s Web Server) Browser Version Platform Java Plug-in Support Internet Explorer (recommended) 6.0 (or later) Windows, XP Prof. JRE Version 5.0 Update 6 Mozilla 1.7 Windows, XP Prof. Solaris Firefox 1.5 Windows, XP Prof.
• Requirements ¾ Administration – NAM-1, NAM-2 – NM-NAM • Maintenance • Diagnostics & Troubleshooting Tips NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM-1, NAM-2 Administration Install NAM Module NAM NAM module module can can occupy occupy any any slot, slot, except Supervisor slot except Supervisor slot NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Sys tem Admin 4-8 Installing the NAM-1, NAM-2 When deployed properly, the capabilities of the NAM provide a wide array of benefits for analyzing data and voice streams.
NAM-1, NAM-2 Administration Verify the NAM Installation Status LED Shutdown/Reset NAM-1 / NAM-2 Green Green--Operational Operational Red Red --Failure Failure Orange Orange--Disabled/Shutdown/Running Disabled/Shutdown/RunningTests Tests Check CheckNAM NAMStatus StatusLED LED Verify VerifyNAM NAMdetected detectedby bySupervisor Supervisor (show (showmodule) module) NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM-1, NAM-2 Administration Initial Configuration – IP Settings Telnet LAN / WAN Console Port • Access CLI of hosting device (Telnet or Console Port) • Establish console session to NAM module • Login to NAM (default login: root, password: root) • Enter IP configuration • IP Address, Subnet Mask , Broadcast Address • IP Hostname, Domain Name • Default Gateway • DNS Name Server (if applicable) • Verify IP configuration NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM-1, NAM-2 Administration Initial Configuration – IP Settings Console> (enable) session mod_num --- CatOS Console> (enable) session slot slot_num processor 1 --- IOS Root@localhost# ip address ip-address subnet-mask ip broadcast broadcast-address ip host name ip gateway default-gateway ip domain domain-name ip nameserver ip-address [ip-address] NAM / Traffic Analyzer v3.5 Tutorial Sys tem Admin 4-11 © 2006 Cisco Systems, Inc. All rights reserved.
NAM-1, NAM-2 Administration Initial Configuration – Enabling the Web Server HTTP/HTTPS NAM NAM Before Beforeusing usingNAM NAMTraffic Traffic Analyzer Analyzer software, software, first first enable enablethe the web webserver server on onthe the NAM: NAM: Root@localhost# ip Root@localhost# ip http http server server enable enable Enter Enter aa web web username: username: Enter Enter aa password: password: NAM / Traffic Analyzer v3.
NAM-1, NAM-2 Administration Initial Configuration – SNMP Settings (Optional) SNMP Get / Set NAM NAM SNMP Response IfIf you you want want to to use use an an external external network network management management application application to to communicate with NAM, first enable SNMP attributes: communicate with NAM, first enable SNMP attributes: •• SNMP SNMP MIB MIB variables variables (sysLocation, (sysLocation,sysContact, sysContact,sysName) sysName) •• Community Communitystrings strings (read-only, (r
NAM-1, NAM-2 Administration Initial Configuration – SNMP Settings (Optional) Example shows how to configure a NAM running Catalyst OS Root@localhost# snmp location Location-string snmp contact Contact-string snmp name SysName-MIB-string snmp community ro snmp community rw show snmp NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM-1, NAM-2 Administration Initial Configuration – Management VLAN (Cisco IOS Only) Note: Note: Devices Devicesrunning runningCatalyst CatalystOS OSdo donot notneed needto toconfigure configureaaVLAN VLAN as the NAM management port. The port is automatically as the NAM management port. The port is automaticallysynchronized synchronized to tothe theVLAN VLANassigned assignedto tointerface interfacesc0 sc0on onthe theSupervisor Supervisorengine. engine.
This page intentionally left blank. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
• Requirements ¾ Administration – NAM-1, NAM-2 – NM-NAM • Maintenance • Diagnostics & Troubleshooting Tips NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NM-NAM Administration Install NAM Module Host Router NMNM- NAM NAM occupies occupies the the analysis module slot analysis module slot NM-NAM Interface Interface type Location Configure and manage from 1 Internal NAM interface Fast Ethernet NM-NAM internal NAM CLI 2 Analysis-Module interface Fast Ethernet Router internal Cisco IOS CLI 3 External NAM interface Fast Ethernet NM-NAM faceplate NAM CLI NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NM-NAM Administration Verify Installation Disk Power Enable When Whenthe theEnable EnableLED LEDisison, on, the NM-NAM has passed the NM-NAM has passedselfselftest testand andisisavailable availableto tothe the router. router. NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Sys tem Admin 4-19 Verifying the Installation (NM-NAM) Before proceeding with any configuration, you should verify that the NAM hardware is functioning properly.
NM-NAM Administration NM-NAM Management Interface Management Management Interface Interface is is used used to to communicate communicate with with Traffic Traffic Analyzer Analyzer software software (HTTP, (HTTP, SNMP). SNMP). Which Which one one you you use, use, determines determines how how to to configure configure NAM NAM IP. IP. Interfaces NAM Interfaces NAM Internal FE Interface Internal FE Interface Traffic Analyzer v3.5 Traffic Analyzer v3.
NM-NAM Administration Router Analysis Module Interface Configuration Configure Configure Analysis-Module Analysis-Module Interface Interface Router (config)# interface analysis-module slot/port Set Set Analysis-Module Analysis-Module Interface Interface IP IP Address Address /* If you use the ip unnumbered command, requires static requires static route if Internal NAM interface is the Management Interface */ Router (config-if)# ip unnumbered FastEthernet slot/port /* If you use a routable IP address and su
NM-NAM Administration Initial Configuration – IP Settings Session Session to to NM-NAM NM-NAM Router# service-module analysis-module slot/0 session Select Select Management Management Interface Interface Root@localhost# ip interface {internal | external} Enable Enable Packet Packet Monitoring Monitoring on on Interface Interface Root@localhost# analysis-module monitoring IP IP Settings Settings Root@localhost# ip address ip-address subnet-mask ip broadcast broadcast-address ip host name ip gateway def
NM-NAM Administration Initial Configuration – Enabling the Web Server HTTP/HTTPS NAM NAM Before Before using using NAM NAM Traffic Traffic Analyzer Analyzer Software, Software, first first enable enable the the web web server server on on the the NAM: NAM: Root@localhost# ip Root@localhost# ip http http server server enable enable Enter Enter aa web web username: username: Enter Enter aa password: password: NAM / Traffic Analyzer v3.
NM-NAM Administration Initial Configuration – SNMP Configuration (Optional) SNMP Get / Set NAM NAM SNMP Response IfIf you you want want to to use use an an external external network network management management application application to to communicate with NAM, first enable SNMP attributes: communicate with NAM, first enable SNMP attributes: •• SNMP SNMP MIB MIB variables variables (sysLocation, (sysLocation,sysContact, sysContact,sysName) sysName) •• Community Communitystrings strings (read-only, (re
• Requirements • Administration ¾ Maintenance • Diagnostics & Troubleshooting Tips NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM Maintenance Resetting the NAM NAM NAM NAM CLI Unreachable NAM-1, NAM-1, NAM-2 NAM-2 •• •• Native NativeIOS IOS-CatOS CatOS - device# device#hw-mod hw-modmod mod reset reset reset reset NM-NAM NM-NAM •• Router# Router#service-module service-moduleanalysis-module analysis-moduleslot/0 slot/0reset reset NAM CLI Reachable NAM NAM Root@localhost# Root@localhost#reboot reboot NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM Maintenance NAM-1, NAM-2 Image Upgrade Application Image Maintenance Image hdd:1 1. 2. 3. 4. 5. 6. NAM-1/NAM-2 = cf:1 Reset NAM using the maintenance image (cf:1) Log in to NAM CLI with root Retrieve image from FTP site and upgrade Follow prompts Exit NAM CLI Reset NAM using the application image (hdd:1) NAM / Traffic Analyzer v3.5 Tutorial 1. 2. 3. 4. 5. 6.
NAM Maintenance NM-NAM Image Upgrade The The NM-NAM NM-NAM contains contains three three NAM NAM software software images: images: •• NAM NAM application application image image on on the the hard hard drive drive -- Source Source of of the the NAM NAM Traffic Traffic Analyzer Analyzer and and NAM NAM CLI CLI •• Helper Used Helper image image in in flash flash memory memory -Used to to recover recover or or upgrade upgrade NAM NAM software software images images •• Bootloader Used Bootloader image image in
NAM Maintenance Patch Installation Patch Installation From the NAM CLI Root@localhost# patch ftp://user:password@host/full-path/filename NAM-1, NAM-2 NM-NAM Patches Patches -- Incremental Incremental updates updates to to software software releases releases that that are are installed installed with with the the patch patch NAM NAM CLI CLI command. command. Patches Patches are are available available only only for for the the NAM NAM application application image image NAM / Traffic Analyzer v3.
NAM Maintenance Shutdown NAM-1, NAM-2 Option 1 - Issue shutdown command from NAM CLI. Option 2 - Issue module shutdown command from supervisor CLI. Option 3 - If above two options fail, then press the shutdown button on NAM.
• Requirements • Administration • Maintenance ¾ Diagnostics & Troubleshooting Tips NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
Diagnostics Check System Alerts View Viewfailures failuresor orproblems problemsthat that have occurred have occurred NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Sys tem Admin 4-32 Check System Alerts You can view any failures or problems that the NAM Traffic Analyzer has detected during normal operations. This information can be viewed by going to the Admin > Diagnostics > System Alerts screen in the NAM Traffic Analyzer software.
Diagnostics Check Audit Trail View Viewactivities activitiesthat that have haveoccurred occurred NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Sys tem Admin 4-33 Check Audit Trail You can view a listing of recent critical activities that have been recorded in an internal syslog log file. Syslog messages can also be sent to an external log.
Diagnostics Check Monitor & Capture Configuration Verify Verifyhow howthe theNAM NAMisis configured configured for forcollecting collectingvarious various statistics statistics NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Sys tem Admin 4-34 Check Monitor & Capture Configuration If reports and statistics are not being displayed as you thought they should, check how the NAM is configured for monitoring and capturing.
Diagnostics Check Messages Logged Check Check further further down down for for messages messages with with the the words words ... ••Error Error ••Failed Failed ••Incorrect Incorrect ••Warning Warning NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved. Sys tem Admin 4-35 Check Messages Logged The NAM also has a “tech-support” option that gathers diagnostic information from the NAM hardware and operating system.
Troubleshooting Tips Verify Configuration NAM NAMand andCisco CiscoCatalyst CatalystSwitch Switchmust must be bein insame samesubnet/VLAN. subnet/VLAN. Slow SlowDNS DNSmay mayresult resultin inslow slowWeb Webpages. pages. Web Webserver serverenabled enabledand andclient clientusing usingcorrect correctport. port. Third-party Third-partyapplications applicationsneeds needsto touse usesame same community communitystrings stringsas asset seton onthe theNAM. NAM. NAM / Traffic Analyzer v3.
Troubleshooting Tips Configuration Guide Refer to the following Catalyst 6500 and 7600 Series Router NAM Configuration Note for additional information on the following topics: • Netflow Data Export • • • • Error Messages Web Username and Password Guidelines Supported MIB Objects Local Interfaces in the NAM ifTable http://www.cisco.com/en/US/products/hw/switches/ps708/pro ducts_configuration_guide_chapter09186a00805e351a.html NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc.
Thank You! We hope that you have found the NAM features to be an important part of your network-management toolkit. Cisco Systems NAM / Traffic Analyzer v3.5 Tutorial © 2006 Cisco Systems, Inc. All rights reserved.
NAM References Chapter 5 • Cisco Network Analysis Modules (NAM) NAM-1, NAM-2, and the NM-NAM • Cisco NAM Traffic Analyzer Software v3.
Reference Materials Many Cisco reference documents have been created to help users understand the use of Network Analysis Modules (for the Cisco Catalyst 6500 series and Cisco 7600 series NAM-1 and NAM-2 and the Cisco Branch Routers series NM-NAM) and its integrated Traffic Analyzer software. However, finding help and documentation can often be a challenge. This reference chapter has been created to assist you in your pursuit of additional product information.
• Other Related References ♦ Cisco Performance Visibility Manager (URL) Cisco Performance Visibility Manager (PVM) is a new proactive network- and application-performance monitoring, reporting, and troubleshooting application for maximizing network availability. http://www.cisco.com/en/US/products/ps6768/index.html ♦ Differentiated Services – White Paper (URL) Different applications have varying needs for delay, delay variation (jitter), bandwidth, packet loss, and availability.
♦ Configuring NetFlow Data Export – Catalyst 6500 Series (URL) This chapter describes how to configure NetFlow statistics collection and NetFlow Data Export (NDE) on the Catalyst 6500 series switches. http://www.cisco.com/en/US/products/hw/switches/ps708/produ cts_configuration_guide_chapter09186a0080160a2b.
• Online Bug Tracker Search for known problems on the Cisco bug tracking system tool, called Bug Toolkit. To access Bug Toolkit, perform the following steps: o Click on the link above (www.cisco.com/cgi-bin/Support/Bugtool/launch_bugtool.pl) o Login to Cisco.com o Click Launch Bug Toolkit. o Enter the keyword NAM in the field to search a list of Cisco Software Products o Then click Next. NAM / Traffic Analyzer v3.