Specifications

© 2006 Cisco Systems, Inc.
All rights reserved.
Scenarios 3-27
NAM / Traffic Analyzer v3.5 Tutorial
© 2006 Cisco Systems, Inc. All rights reserved.
Scenarios 3-27
NAM / Traffic Analyzer v3.5 Tutorial
Scenario 2
Configure Data Source and Monitoring
Scenario 2
Configure Data Source and Monitoring
Se0/0
WAN
Telnet <NAM Host Router IP Address>
Router > configure terminal
Router (config)# ip cef
Router (config)# interface Se0/0
Router (config-if)# analysis-module monitoring
1. Enable Cisco Express Forwarding.
2. Select interface.
3. Forward packets to NAM.
1. Enable Cisco Express Forwarding.
2. Select interface.
3. Forward packets to NAM.
Step 1: Select NAM Data Source
Step 2: Configure Core Monitoring (
Setup > Monitor > Core Monitoring)
Enable Application, Host, and
Conversation monitoring for the
Internal NM-NAM interface
Enable Application, Host, and
Conversation monitoring for the
Internal NM-NAM interface
NM-NAM Data Source and Collection Configuration
To analyze all traffic on the WAN link, Dean uses the following steps:
Step 1. From a Command window on his desktop machine, Dean telnets to the router that hosts the NM-
NAM and enters configuration mode.
Step 2. First, he enables Cisco Express Forwarding on the router by entering the command ip cef.
Step 3. Next he enters the interface configuration mode for the WAN link using the command int Se0/0.
Step 4. Next he configures the router to forward a copy of all packets coming to or from Se0/0 to the
NAM with the command analysis-module monitoring. He could forward packets from other
interfaces in the same way. When configuration is complete he exits the router.
Step 5. Next Dean must enable monitoring for the traffic being sent by CEF to the internal interface of
the NAM. Click Setup > Monitor > Core Monitoring. The Core Monitoring Functions dialog is
displayed.
Step 6. The pull-down Data Sources list displays the two interfaces for the NM-NAM and any configured
NDE data sources. Select Internal from this menu to enable monitoring.
Step 7. Enable desired monitoring functions (application, network host, network conversations) and click
Apply.
All packets to/from Se0/0 are now being copied to the Internal NM-NAM interface and are being analyzed.