Specifications
© 2006 Cisco Systems, Inc.
All rights reserved.
Introduction 1-20
NAM / Traffic Analyzer v3.5 Tutorial
© 2006 Cisco Systems, Inc. All rights reserved.
Introduction 1-20
NAM / Traffic Analyzer v3.5 Tutorial
Network Analysis Modules
Deployment
Network Analysis Modules
Deployment
Security
IDS
IP L2/L3
AAA
Headquarters
Video Surv.
Operations
Content
IP WAN
Branch A
Remote Office
2851
3845
7200
NM-NAM Available for
Cisco Branch Routers
6K-NAM Available for Cisco
Catalyst 6500 Switches and Cisco
7600 Series Routers
NetFlow Data
Export to
6K-NAM
Monitoring remote sites through
web based Traffic Analyzer
NM-NAM
NM-NAM
NM-NAM
6K-NAM
6K-NAM
6K-NAM
Firewall IDS
Deployment
Collecting the data you need is made easier and flexible by the functionality of the NAM to be placed where it
is needed and gathers data from either local or remote switches and routers.
Cat6500 NAMs
The Catalyst 6500 series switches and the Cisco 7600 series routers can host the NAM-1 or NAM-2. These
NAMs can collect and display per port layer 2 statistics in conjunction with the mini-RMON on every
interface. More in-depth analysis of LAN ports can be achieved by spanning or copying traffic from ports,
VLANs, or Ether Channels to the embedded NAM or by using VLAN Access Lists (VACL) to mirror data to
the NAM if no spanning sessions are available.
Analysis of remote switches can be achieved using the Remote SPAN (RSPAN) and Encapsulated SPAN
(ERSPAN) features of Catalyst switches. (Refer to Chapter 2 for details on RSPAN and ERSPAN.) Detailed
analysis of WAN ports can also be achieved by using VACLs on a local device or by forwarding NetFlow
data from either the local or a remote device.
The Cat6500 NAMs can monitor traffic running at sub gigabit speeds (NAM-1) and gigabit speeds (NAM-2)
and provide enormous value when deployed at the following areas:
• Distribution or core layer trunk ports
• Service points (for example, in data centers, server farms, or Cisco Call Manager clusters in IP
telephony) where performance is critical
• Critical access points
NM-NAM
The Cisco Branch Routers Series NAM, NM-NAM, is an integrated traffic-monitoring network module for
Cisco 2600XM, 2800, 3660, 3700, and 3800 series access routers that enables network managers to gain
application-level visibility into traffic at remote sites or at the WAN edges to improve network performance,
reduce failures, and maximize returns on investments. It expands the NAM solution available for the Cisco
Catalyst 6500 series and Cisco 7600 series by allowing remote troubleshooting and traffic analysis without
having to send personnel to remote sites or hauling large amounts of data to the central site. The NM-NAMs
can collect MIB-II statistics on each interface.