Table Of Contents
Setting Up the Application
Switch Parameters
Viewing the Switch Information
Setting Up NBAR Protocol Discovery
Enabling and Disabling Port Stats (Mini-RMON)
Configuring Switch Login
Router Parameters
Applying Router System Information
Setting Up Data Sources
SPAN Sessions
Creating a SPAN Session
Editing a SPAN Session
Deleting a SPAN Session
Understanding NetFlow Interfaces
Understanding NetFlow Flow Records
Configuring NetFlow on Devices
Configuring VACL on a WAN Interface
Configuring VACL on a LAN VLAN
Managing NetFlow Devices
Creating Devices
Editing Devices
Deleting Devices
Testing Devices
Creating Custom Data Sources
Selecting a NetFlow Device
Selecting the Interfaces
Using the Listening Mode
Testing the Router Community Strings
Setting Up an Interface
MPLS Data Sources
Automatic Discovery of MPLS VPN Labels
Setting Up Layer 3 VRF Data Sources
Setting Up Layer 2 Virtual Circuit Data Sources
Setting Up MPLS Label Data Sources
Creating a VRF/VC Configuration File
Importing a VRF/VC Configuration File
Exporting a VRF/VC Configuration File
Importing Log
Setting Up Monitoring
Monitoring Core Data
Enabling Mini-RMON Collection
Monitoring Voice Data
Monitoring RTP Stream Traffic
Monitoring Response Time Data
Creating Response Time Data Collections
Editing Response Time Data Collections
Deleting Response Time Data Collections
Monitoring DiffServ Data
Setting Up the DiffServ Profile
Creating a DiffServ Profile
Editing a DiffServ Profile
Deleting a DiffServ Profile
Monitoring URL Collection Data
Enabling a URL Collection
Changing a URL Collection
Disabling a URL Collection
Setting Up the Protocol Directory
Individual Applications
Creating a New Protocol
Editing a Protocol
Deleting a Protocol
Setting Up Application Groups
Creating an Application Group
Editing an Application Group
Deleting an Application Group
Setting Up Autolearned Protocols
Setting Up URL-based Applications
Creating a URL-based Application
Editing a URL-based Application
Deleting a URL-based Application
Setting Alarm Thresholds
Setting NAM MIB Thresholds
Selecting NAM MIB Variables
Selecting NAM MIB Parameters
Editing a NAM MIB Threshold
Deleting a NAM MIB Threshold
Setting Voice Thresholds
Setting Up RTP Stream Thresholds
Setting Up the NAM Syslog
Setting Switch Thresholds
Creating Switch Thresholds
Editing Switch Thresholds
Deleting Switch Thresholds
Setting NAM Trap Destinations
Creating a NAM Trap Destination
Editing a NAM Trap Destination
Deleting a NAM Trap Destination
Setting NAM Alarm Mail
Setting Global Preferences
Setting Up the Application
Use the NAM Setup window, Figure 3-1, to set up and configure the NAM application. Set up the NAM application in the sequence shown.
Figure 3-1 Setup Window
This chapter contains the following sections:
•
Switch Parameters
•
Router Parameters
•
Setting Up Data Sources
•
Setting Up Monitoring
•
Setting Up the Protocol Directory
•
Setting Alarm Thresholds
•
Setting Global Preferences
Switch Parameters
From the Switch Parameter window, you can view the switch system information, enable and disable NBAR, enable and disable port stats (mini-Rmon), and configure switch login configuration.
•
Viewing the Switch Information
•
Setting Up NBAR Protocol Discovery
•
Enabling and Disabling Port Stats (Mini-RMON)
•
Configuring Switch Login
Viewing the Switch Information
Note
This section applies to WS-SVC-NAM-1 and WS-SVC-NAM-2 devices only.
To view the Switch Information, Table 3-1, choose Setup > Switch Parameters.
Table 3-1 Switch Information
Field
|
Description
|
SNMP Test information
|
Displays the IP address of the NAM and the switch that the SNMP test occurred on.
|
Name
|
Name of the switch.
|
Hardware
|
Hardware description of the switch.
|
Supervisor Software Version
|
Current software version of the Supervisor.
|
System Uptime
|
Total time the switch has been running.
|
Location
|
Physical location of the switch.
|
Contact
|
Contact name of the network administrator for the switch.
|
SNMP read from switch
|
SNMP read test result.
|
SNMP write to switch
|
SNMP write test result.
|
Mini-RMON on switch
|
For Catalyst OS devices, displays the status if Mini-RMON is enabled (Available) or not (Unavailable)
For Cisco IOS devices, displays the status if there are any ports with Mini-RMON configured (Available) or not (Unavailable).
|
NBAR on switch
|
Displays if NBAR is available on the switch.
|
VLAN Traffic Statistics on Switch
|
Displays if VLAN data is Available or Unavailable.
Note Catalyst 6500 Series switches require a Supervisor 2 or MSFC2 card.
|
NetFlow Status
|
For Catalyst OS devices, if remote NetFlow is configured on the switch, Remote export to <address> on port <number> displays. If local NetFlow is configured on the switch, Local export to module(s) <mod number> displays.
For Catalyst 6500 Series devices running Cisco IOS, if NetFlow is configured on the switch, Remote export to NAM <address> on port <number> displays, otherwise the status will display Configuration unknown.
|
Setting Up NBAR Protocol Discovery
Note
NBAR is supported only on switches with the Catalyst 6500 Supervisor Engine 32 Programmable Intelligent Services Accelerator (PISA) running IOS 12.2(18)ZY (or later).
From the Switch Parameter window, you can view the NBAR Status information and enable or disable NBAR on all interfaces.
To set up NBAR protocol discovery:
Step 1
Choose Setup > Switch Parameters > NBAR Protocol Discovery.
Note
If your switch does not support NBAR, a message displays indicating that NBAR is not supported on your switch.
The NBAR Status window appears with the following options:
•
Details—Click to display the NBAR Interface Details.
•
Save—Click to save the device's running configuration.
•
Enable—Click to enable NBAR on all available interfaces.
•
Disable—Click to disable NBAR on all interfaces.
Note
The Save button is only available on switches running Cisco IOS. Changes occur immediately on switches running Catalyst OS.
The NBAR Interfaces window displays. Figure 3-2 shows an example of the NBAR Interfaces window.
Figure 3-2 NBAR Interfaces Window
The NBAR Interfaces window lists known interfaces by name and type. Check its check box to enable an interface.
You must enable the NBAR Interfaces feature for the NAM to provide information about ethernet ports on the Monitor > NBAR window. Select the ports you want to enable, then click Submit to turn on NBAR for those ports.
The All check box affects only the ports displayed on the current screen. Click the All check box to select all ports displayed on the current window. Clear the All check box to deselect all ports displayed on the current window. The Reset button resets the any changes you might have made to the NBAR window and it reverts to its previous settings.
To view details on an individual Port Stat, click on the Port Name. A Port Statistics detail window displays with the following information:
•
Alias—User defined port name
•
Description—Description of the port
•
Type—Type of port
•
Mtu—Maximum packet size, in bytes, that the port can handle
•
Speed—Speed of the port in bits per second
•
Physical Address—Physical address of the port in the switch
•
Operational Status—Current operational status of the port
•
Admin Status—Current administrative status of the port
Tip
To view data for a specific Interface (NBAR) Details table, enter the port name or port type in the text box, then click Filter.
Note
The Save button is only available on switches running Cisco IOS. Changes occur immediately on switches running Catalyst OS.
Table 3-2 NBAR Interface Details
Field / Operation
|
Description
|
NBAR Enabled
|
Check indicates that NBAR is enabled.
|
Interface
|
Name of the interface.
Depending on the IOS running on the Supervisor, port names are displayed differently. Earlier versions of CatOS displayed port names as 2/1 and 3/1 meaning module 2, port 1 and module 3 port 1.
Newer versions of IOS software display a port name as Gi2/1 to represent a Gigabit port on module 2 port 1.
In the Virtual Switch software (VSS), a port name might be displayed as Gi1/2/1to represent a Gigabit port on switch 1, module2, port 1.
|
Interface Type
|
Description of the interface.
|
Tip
To view data for a specific interface name or interface type in the Interface Details table, enter the interface name or interface type in the text box, then click Filter. To clear the Filter text box, click Clear.
Enabling and Disabling Port Stats (Mini-RMON)
Note
This section applies to WS-SVC-NAM-1 and WS-SVC-NAM-2 devices only.
You must enable the Mini-Rmon switch feature for the NAM to provide information about ethernet ports on the Monitor > Port Stats window. Select the ports you want to enable, then click Submit to turn on Mini-Rmon for those ports. Click the All check box to select or deselect the ports displayed on the current screen.
The Reset button resets the any changes you might have made to the Mini-RMON ports window and it reverts to its previous settings.
Note
Disabling all ports will also affect any reports and alarms that exist for those ports. For devices running Catalyst OS, disabling all ports will also disable other applications that are using Mini-RMON. For devices running Cisco IOS, only the monitor owner ports will be disabled.
To enable and disable interfaces or view Port Stats details:
Step 1
Click Setup > Switch Parameters.
The Switch Information (Table 3-1) displays.
Step 2
From the contents, click Port Stats (Mini-RMON).
The Port Stats (Mini-RMON) window displays listing known ports and their type. Figure 3-3 shows an example of the top portion of the Mini-RMON Port Statistics window.
Figure 3-3 Mini-RMON Port Statistics Window
Port Stats (Mini-RMON) Details
Table 3-3 describes the fields of the Port Stats (Mini-RMON)
Table 3-3 Port Stats (Mini-RMON) Details
Field
|
Description
|
Mini-RMON Enabled
|
Indicates with a check mark if Mini-RMON is enabled on the port.
|
Port Name
|
Name of the port.
Depending on the IOS running on the Supervisor, port names are displayed differently. Earlier versions of CatOS displayed port names as 2/1 and 3/1 meaning module 2, port 1 and module 3 port 1.
Newer versions of IOS software display a port name as Gi2/1 to represent a Gigabit port on module 2 port 1. In the VSS, a port name might be displayed as Gi1/2/1to represent a Gigabit port on switch 1, module2, port 1.
|
Port Type
|
Type of the port.
|
Step 3
Click the Enable checkbox to enable a port, or click a checked checkbox to disable a port, then click Submit.
After you make changes to this window, click Submit to apply the changes, then click Save to save the changes to the start-up configuration.
The Refresh button causes the NAM to update the switch configuration information with the current configuration. The All check box affects only the ports listed on this window. The Reset button resets the any changes you might have made to the Mini-RMON ports window and it reverts to its previous settings.
Step 4
To view details on an individual Port Stat, click on the Port Name.
A Port Statistics detail window displays with the following information:
•
Alias—User defined port name
•
Description—Description of the port
•
Type—Type of port
•
Mtu—Maximum packet size, in bytes, that the port can handle
•
Speed—Speed of the port in bits per second
•
Physical Address—Physical address of the port in the switch
•
Operational Status—Current operational status of the port
•
Admin Status—Current administrative status of the port
Tip
To view data for a specific port name or port type in the Port Stats (Mini-RMON) Details table, enter the port name or port type in the text box, then click Filter.
Configuring Switch Login
The NAM uses switch login information to log in to switches to monitor MPLS. You must provide a user name, password (if required), and login method, either telnet or SSH. Table 3-4 describes the fields and functions of the Switch Login Configuration window.
Note
If you are not using MPLS in your network, switch login configuration is not required.
Table 3-4 Switch Login Configuration
Field
|
Description
|
User Name
|
User name of a switch administrator
|
Password Verify Password
|
Password of the switch administrator (if one is required)
|
Verify Password
|
Verify password of the switch administrator (if one is required)
|
Login Method
|
Choose either telnet or SSH
|
Test Login
|
Performs a test login with current switch login configuration or with newly entered configuration even if not applied
|
Apply
|
Click to set or modify switch login configuration
|
Reset
|
Removes switch login configuration entered but not applied and restores previously saved configuration
|
Clear
|
Removes switch login configuration from the database
|
Router Parameters
From the Router Parameter window you can view the router information and set up NBAR Protocol Discovery.
•
Applying Router System Information
•
Setting Up NBAR Protocol Discovery
Applying Router System Information
This section describes how to set router parameters.
Note
This section applies only to NM-NAM and NME-NAM devices.
Step 1
Choose Setup > Router Parameters.
The Router System Information displays as shown in Table 3-5.
Table 3-5 Router System Information
Field
|
Description
|
Name
|
Name of the router.
|
Hardware
|
Hardware description of the router.
|
Router Software Version
|
Current software version of the router.
|
System Uptime
|
Total time the switch has been running.
|
Location
|
Physical location of the router.
|
Contact
|
Name of the network administrator for the router.
|
Router IP Address
|
IP address of the router.
|
SNMP Read-Write Community String
|
Name of the SNMP read-write community string configured on the router
|
Verify String
|
Verify the SNMP community string.
|
Netflow Active Timeout
|
Length in minutes (1-60) the router waits before removing active flows.
|
Step 2
Enter the following information:
•
Router IP Address
•
SNMP Read Community String
•
Verify String
Setting Up Data Sources
There are four versions of the NAM:
•
WS-SVC-NAM-1
•
WS-SVC-NAM-2
•
NME-NAM
•
NM-NAM
The NME-NAM device has two Gigabit Ethernet ports—an internal interface and an external interface. The NM-NAM device has two FastEthernet data ports—an internal interface and an external interface. One of the two interfaces must be selected as the NAM management port for IP traffic (such as HTTP and SNMP). The NAM can monitor traffic for analysis on the internal interface, the external interface, or both simultaneously. A typical configuration is to monitor LAN and WAN traffic on the internal interface. However, the external interface can be used to monitor LAN traffic.
Depending on the IOS running on the Supervisor, port names are displayed differently. Earlier versions of CatOS displayed port names as 2/1 and 3/1 meaning module 2, port 1 and module 3 port 1. Newer versions of IOS software display a port name as Gi2/1 to represent a Gigabit port on module 2 port 1. In the VSS, a port name might be displayed as Gi1/2/1to represent a Gigabit port on switch 1, module2, port 1.
The following information describes how to set up NetFlow and SPAN sessions for the WS-SVC-NAM-1 and WS-SVC-NAM 2 devices.
WS-SVC-NAM-1 devices can have only one active SPAN session. You can select a switch port, VLAN, or EtherChannel as the SPAN source; however, you may select only one SPAN type. WS-SVC-NAM-2 devices and switch software support two SPAN destination ports.
Before you can monitor data, you must direct specific traffic flowing through a switch to the NAM for monitoring purposes. Use the methods described in the Methods of Directing Traffic table (Table 3-6).
Table 3-6 Methods of Directing Traffic
Method
|
Usage Notes
|
Switch SPAN
|
You can direct a set of physical ports, a set of VLANs, or a set of EtherChannels to the NAM.
Selecting an EtherChannel as a SPAN source it is the same as selecting all physical ports comprising the EtherChannel as the SPAN source.
There might be limited visibility into MPLS-tagged traffic unless a specific MPLS data source has been defined. For example, when viewing MPLS-tagged traffic in the All SPAN data source, many statistics such as host and conversations will not be available. These statistics are available when viewing the data using the appropriate MPLS data source.
Note This method does not apply to NM-NAM and NME-NAM devices.
|
Switch Remote SPAN (RSPAN)
|
You can monitor packet streams from remote switches, assuming that all traffic from a remote switch arrives at the local switch on a designated RSPAN VLAN. Use the RSPAN VLAN as the SPAN source for the NAM.
There might be limited visibility into MPLS-tagged traffic unless a specific MPLS data source has been defined. For example, when viewing MPLS-tagged traffic in the All SPAN data source, many statistics such as host and conversations will not be available. These statistics are available when viewing the data using the appropriate MPLS data source.
Note This method does not apply to NM-NAM and NME-NAM devices.
|
NetFlow Data Export (NDE)
|
You can monitor NDE records directly from remote switches or routers. You must configure the NDE source to the NAM from a local switch or remote router, using the switch CLI.
SPAN and NDE sources can be in effect simultaneously.
|
SPAN Sessions
Note
This section applies to WS-SVC-NAM-1 and WS-SVC-NAM-2 devices only.
The SPAN Sources (Table 3-7) describes the streams of traffic you can use as SPAN sources.
Table 3-7 SPAN Sources
SPAN Source
|
One of the following:
|
Any set of physical ports
|
• NAM Traffic Analyzer
• Switch CLI
• Supervisor portCopyTable (SNMP)
|
Any EtherChannel
|
• NAM Traffic Analyzer
• Switch CLI
• Supervisor portCopyTable (SNMP)
|
Any set of VLANs configured on the local switch
|
• NAM Traffic Analyzer
• Switch CLI
• Supervisor portCopyTable (SNMP)
|
Packets from a remote switch arriving via RSPAN
Note You can select only one RSPAN VLAN as a SPAN source.
|
• NAM Traffic Analyzer
• Switch CLI
• Supervisor portCopyTable (SNMP)
and
• Configuration on remote switch
|
You can also use locally generated NDE records (the NDE source) as a packet stream to populate NAM collections. You can activate only a subset of the NAM collection types defined in the NDE Collection Types Table, Table 3-8, on the NDE source.
Note
These are the only collection types for which monitoring is supported on the NDE source; NDE records have insufficient information to implement other collection types.
Table 3-8 NDE Collection Types Table
Collection Type
|
Source
|
Protocol
|
RMON2 protocol distribution table.
|
Host
|
RMON2 nlHost and alHost tables.
|
Conversation
|
RMON2 nlMatrix and alMatrix tables.
|
DiffServ stat
|
DSMON statistics table for remote switches and routers.
|
DiffServ apps
|
DSMON applications table for remote switches and routers.
|
DiffServ hosts
|
DSMON host table for remote switches and routers.
|
Creating a SPAN Session
Note
This section applies to WS-SVC-NAM-1 and WS-SVC-NAM-2 devices only.
Creating a SPAN session on a switch running Catalyst OS software and a switch running Cisco IOS software are different. The following procedure applies to switches running both Catalyst OS and Cisco IOS software unless otherwise stated.
Step 1
Choose Setup > Data Sources.
The Active SPAN Sessions Dialog Box(Table 3-9) displays. The SPAN session directed to the NAM is selected by default, otherwise the first radio button is selected.
Table 3-9 Active SPAN Sessions Dialog Box
Column
|
Description
|
Monitor Session
|
Monitor session of the SPAN.
Note For switches running Cisco IOS software only.
|
Type
|
Type of SPAN source.
|
Source - Direction
|
Source of the SPAN session and direction of the SPAN traffic.
For port SPAN types, the source displays the port name and source status after you SPAN it—down, testing, or dormant.
When creating a SPAN session, you can select all ports regardless of their state. See Table 3-10 for a description of the possible SPAN states.
Note For switches running Cisco IOS software only.
|
Dest. Port
|
Destination port of the SPAN session.
|
Dest. Module
|
Destination module of the SPAN session.
|
Status
|
Status of the SPAN session:
Active—Traffic at the SPAN source is being copied to the SPAN destination
Inactive—Traffic at the SPAN source will not be copied to the SPAN destination
Unknown—A mixture of both active and inactive status
|
Table 3-10 lists the possible SPAN states. The SPAN state displays in parenthesis in the Source - Direction column
Table 3-10 Possible SPAN States
State
|
Description
|
Active
|
SPAN source is valid and traffic from the source is being copied to the SPAN destination
|
NotInService
|
SPAN source might be valid, but traffic that appears at the source will not be copied to the SPAN destination
|
NotReady
|
The SPAN source might be valid, but traffic that appears at the source will not be copied to the SPAN destination
|
CreateAndGo
|
The SPAN source might be valid, but the SPAN source is being added to the SPAN session
|
CreateAndWait
|
The SPAN source might be valid, and the SPAN source is being added to the SPAN session
|
Destroy
|
The SPAN source is being removed from the SPAN session.
|
Step 2
Click Create.
The Create SPAN Session Dialog Box (Table 3-11) displays. Switch Port is the default for the SPAN Type.
Step 3
Select the appropriate information.
Table 3-11 Create SPAN Session Dialog Box
Field
|
Description
|
Monitor Session
|
Monitor session of the SPAN.
Note For switches running Cisco IOS or Catalyst OS 8.4 (and later) software only.
|
SPAN Type
|
• SwitchPort
• VLAN
• EtherChannel
• RSPAN VLAN
Note You can have only one RSPAN VLAN source per SPAN session.
|
Switch Module List
|
Lists all modules on the switch other than NAMs and Switch Fabric Modules.
|
SPAN Destination Interface
|
The NAM interface to which you want to send data.
|
SPAN Traffic Direction
|
• Rx
• Tx
• Both
Note Not applicable to RSPAN VLAN SPAN types.
|
Available Sources
|
SPAN sources that are available for the selected SPAN type.
|
Add
|
Adds the selected SPAN source.
|
Remove
|
Removes the selected SPAN source.
|
Remove All
|
Removes all the SPAN sources.
|
Selected Sources
|
SPAN sources selected.
|
Refresh button
|
Causes the NAM to update the switch configuration information with current configuration.
|
Submit button
|
Creates the SPAN configuration.
|
Step 4
To submit the SPAN session, click Submit.
The Active SPAN Sessions window displays and the SPAN session is saved for switches running Catalyst OS software only.
Step 5
To save the current active SPAN session in the running-configuration to the startup-configuration for switches running Cisco IOS software only, click Save in the active SPAN session window.
Note
For switches running Cisco IOS software, all pending running-configuration changes will be saved to the startup-configuration.
Editing a SPAN Session
You can only edit SPAN sessions that have been directed to the NAM.
Note
This section does not apply to NM-NAM and NME-NAM devices.
To edit a SPAN session:
Step 1
Click Setup > Data Sources.
The Active SPAN Sessions dialog box displays.
Step 2
Select the SPAN session to edit, then click Edit.
The Edit SPAN Session Dialog Box, Table 3-12, displays.
Step 3
Make the appropriate changes.
Table 3-12 Edit SPAN Session Dialog Box
Field
|
Description
|
Monitor Session
|
Monitor session of the SPAN.
|
SPAN Type
|
Type of SPAN session.
|
Switch Module List
|
Lists all modules on the switch other than NAMs and Switch Fabric Modules.
|
SPAN Traffic Direction
|
Direction of the SPAN traffic.
Note You cannot edit the SPAN direction on switches running Catalyst OS software. For such switches, all SPAN sources in a SPAN session must be in only one direction.
|
Available Sources
|
SPAN sources available for the selected SPAN type.
|
Add
|
Adds the selected SPAN source
|
Remove
|
Removes the selected SPAN source.
|
Remove All
|
Removes all the SPAN sources.
|
Selected Sources
|
SPAN sources selected.
|
Refresh button
|
Causes the NAM to update the switch configuration information with current configuration.
|
Submit button
|
Saves changes.
|
Reset button
|
Clears all changes.
|
Deleting a SPAN Session
Note
This section does not apply to NM-NAM and NME-NAM devices.
To delete a SPAN session, select it from the Active SPAN Session dialog box, then click Delete.
Understanding NetFlow Interfaces
To use a remote device as an NDE data source for the NAM, you must configure the remote device itself to export NDE packets to UDP port 3000 on the NAM. You might need to configure the device itself on a per-interface basis. An NDE device is identified by its IP address. By default the switch's local supervisor engine is always available as an NDE device.
You can define additional NDE devices by specifying the IP addresses and (optionally) the community strings. Community strings are used to upload convenient text strings for interfaces on the remote devices that are monitored in NetFlow records.
Distinguishing among different interfaces on the remote NDE devices is a feature in this release that allows you to arbitrarily bundle groups of interfaces on each remote NDE device into a conceptual data source instead of simply grouping all flows into the same collections.
If you try to distinguish every interface on every remote device (potentially in both directions separately), this action could result in a large, unmanageable number of data sources. By using conceptual data sources, you have complete flexibility to group all interfaces in all directions into a single conceptual data source.
You could also choose to create a separate conceptual data source for each interface on the device. In general, you can combine any number of "simple flow paths" to form a conceptual data source. Each simple flow path can consist of a single interface in the input direction, the output direction, or both directions.
The following restrictions apply to creating conceptual data sources and assigning flow paths to them.
•
Any interface that is specified as an input interface for a flow path cannot be specified as an input interface in another conceptual data source for the same device. It also cannot be specified as a bidirectional interface in another flow path for the same conceptual data source.
•
Any interface that is specified as an output interface for a flow path cannot be specified as an output interface in another conceptual data source for the same device. It also cannot be specified as a bidirectional interface in another flow path for the same conceptual data source.
•
Any interface that has been specified as a bidirectional interface for a flow path cannot be specified as a bidirectional interface in another conceptual data source for the same device. It also cannot be specified as an input or output interface in another flow path for the same conceptual data source.
Understanding NetFlow Flow Records
An NDE packet contains multiple flow records. Each flow record has two fields:
•
Input SNMP ifIndex
•
Output SNMP ifIndex
Note
This information might not be available because of NDE feature incompatibility with your Cisco IOS or Catalyst OS version or because of an NDE flow-mask configuration. For more information on flow-mask compatibility, see the "NDE Flow Masks and V8 Aggregation Caches" section on page 4-5.
In most cases, turning on NetFlow on an interface populates the NetFlow cache in the device with flows that are in the input direction of the interface. As a result, the input SNMP ifIndex field in the flow record has the ifIndex of the interface on which NetFlow was turned on. Sample NetFlow Network, Figure 3-4, shows a sample network configuration with a NetFlow router.
Figure 3-4 Sample NetFlow Network
The Reporting Flow Records table (Table 3-13) lists the reported flows if NetFlow is enabled on interface a.
Table 3-13 Reporting Flow Records
Input Interface
|
Output Interface
|
Are Flows Reported?
|
a
|
b
|
Yes
|
a
|
c
|
Yes
|
b
|
c
|
No
|
b
|
a
|
No
|
c
|
a
|
No
|
c
|
b
|
No
|
Configuring NetFlow on Devices
The configuration commands for NetFlow devices to export NDE packets to the NAM are platform and device specific. The example configuration commands provided here are the ones most commonly found for devices running Cisco IOS or Catalyst OS. For more detailed information, see your device documentation.
For Devices Running Cisco IOS
Step 1
Select the interface on which you wish to turn on routed flow cache.
Prompt#configure terminal
Prompt(config)#interface <type slot/port>
Prompt(config-if)#ip route-cache flow
Step 2
Export routed flow cache entries to UDP port 3000 of the NAM.
Prompt(config)#ip flow-export destination <NAM IP address> 3000
For Devices Supporting Multi-Layer Switching Cache Running Cisco IOS
Step 1
Select the version of NDE.
Prompt(config)#mls nde sender version <version-number>
Note
The NAM supports NDE versions 1, 5, 6, 7, 8, and v8 aggregation caches.
Step 2
Select NDE flow mask.
Prompt(config)#mls flow ip full
Step 3
Enable NetFlow export
Prompt(config)#mls nde sender
Step 4
Export NetFlow to UDP port 3000 of the NAM.
Prompt(config)#ip flow-export destination <NAM IP address> 3000
For Devices Supporting NDE v8 Aggregations Running Cisco IOS
Step 1
Select a v8 aggregation.
Prompt(config)#ip flow-aggregation cache <aggregation-type>
Where aggregation-type can be:
•
destination-prefix
•
source-prefix
•
protocol-port
•
prefix
Step 2
Enable the aggregation cache.
Prompt(config-flow-cache)#enable
Step 3
Export the flow entries in the aggregation cache to NAM UDP port 3000.
Prompt(config-flow-cache)#export destination <NAM address> 3000
For Devices Running Catalyst OS
Step 1
Select the version of NDE.
Prompt>(enable) set mls nde version <nde-version-number>
Note
The NAM supports NDE versions 1, 5, 6, 7, 8, and v8 aggregation caches.
Step 2
Select NDE flow mask to be full.
Prompt>(enable) set mls flow full
Step 3
Enable NDE export.
Prompt>(enable) set mls nde enable
Step 4
Export NDE packets to UPD port 3000 of the NAM.
Prompt>(enable) set mls nde <NAM address> 3000
For Devices That Support NDE Export From Bridged-Flows Statistics
Step 1
Enable bridged-flows statistics on the VLANs.
Prompt>(enable) set mls bridged-flow-statistics enable <vlan-list>
Step 2
Export the NDE packets to UPD port 3000 of the NAM
Prompt>(enable) set mls nde <NAM address> 3000
For NAMs Located in a Device Slot
If the NAM is located in one of the device slots, the device can be set up to export NDE packets to the NAM.
Step 1
Select the version of NDE
Prompt>(enable) set mls nde version <nde-version-number>
Step 2
Select NDE flow mask to be full.
Prompt>(enable) sel mls nde full
Step 3
Enable NDE export.
Prompt>(enable) set mls nde enable
Step 4
Export the NDE packets to the NAM.
Prompt>(enable) set snmp extendedrmon netflow enable <NAM-slot>
Configuring VACL on a WAN Interface
Because WAN interfaces do not support the SPAN function, you must use the switch CLI to manually configure a VACL in order to monitor WAN traffic with the NAM. This feature only works for IP traffic over the WAN interface.
VACL can also be used of there is no available SPAN session to direct traffic to the NAM. In this case, a VACL can be set up in place of a SPAN for monitoring VLAN traffic.
The following example shows how to configure a VACL on an ATM WAN interface and forward both ingress and egress traffic to the NAM. These commands are for switches running Cisco IOS version 12.1(13)E1 or higher. For LAN VACLs on Catalyst OS, the security Access Control List (ACL) feature can be used to achieve the same result. For more information on using these features, see your accompanying switch documentation.
Cat6509(config)#access-list 100 permit ip any any
Cat6509(config)#vlan access-map wan 100
Cat6509(config-access-map)#match ip address 100
Cat6509(config-access-map)#action forward capture
Cat6509(config-access-map)#exit
Cat6509(config)#vlan filter wan interface AM6/0/0.1
Cat6509(config)#analysis module 3 data-port 1 capture allowed-vlan 1-4094
Cat6509(config)#analysis module 3 data-port 1 capture
To monitor egress traffic only, get the VLAN ID that is associated with the WAN interface by using the following command:
Cat6509#show cwan vlan
Hidden VLAN swidb->i_number Interface
Once you have the VLAN ID, configure the NAM data port using the following command:
Cat6509(config)#analysis module 3 data-port 1 capture allowed-vlan 1017
To monitor ingress traffic only, replace the VLAN number in the capture configuration with the native VLAN ID that carries the ingress traffic. For example, if VLAN 1 carries the ingress traffic, you would use the following command:
Cat6509(config)#analysis module 3 data-port 1 capture allowed-vlan 1
Configuring VACL on a LAN VLAN
For VLAN Traffic monitoring on a LAN, traffic can be sent to the NAM by using the SPAN feature of the switch. However, in some instances when the traffic being spanned exceeds the monitoring capability of the NAM, you might want to pre-filter the LAN traffic before it is forwarded. This can be done by using VACL.
The following example shows how to configure VACL for LAN VLAN interfaces. In this example, all traffic directed to the server 172.20.122.226 on VLAN 1 is captured and forwarded to the NAM located in slot 3.
Cat6509#(config)#access-list 100 permit ip any any
Cat6509#(config)#access-list 110 permit ip any host 172.20.122.226
Cat6509#(config)#vlan access-map lan 100
Cat6509#(config-access-map)match ip address 110
Cat6509#(config-access-map)#action forward capture
Cat6509#(config-access-map)#exit
Cat6509#(config)#vlan access-map lan 200
Cat6509#(config-access-map)#match ip address 100
Cat6509#(config-access-map)#action forward
Cat6509#(config-access-map)#exit
Cat6509#(config)#vlan filter lan vlan-list 1
Cat6509#(config)#analysis module 3 data-port 1 capture allowed-vlan 1
Cat6509#(config)#analysis module 3 data-port 1 capture
Managing NetFlow Devices
Before you can monitor NetFlow data, you must add the NetFlow devices to be monitored. The remote NDE device must also be configured to export NDE packets to the NAM. For more information on configuring NetFlow on devices, see the "Configuring NetFlow on Devices" section or your accompanying device documentation. The following topics help you set up and manage the devices used for NetFlow monitoring:
•
Creating Devices
•
Editing Devices
•
Deleting Devices
•
Testing Devices
•
Creating Custom Data Sources
•
Using the Listening Mode
Creating Devices
Once you create a NetFlow device, NetFlow data sources are automatically created for that device. You can use the Listening Mode to verify that NDE packets are active on these data sources. For more information on using the Listening Mode, see the "Using the Listening Mode" section.
To create a device:
Step 1
Click Setup > Data Sources.
The Active SPAN Sessions table displays.
Note
For NM-NAM and NME-NAM devices, the Netflow Devices table displays.
Step 2
In the contents, click Devices.
The NetFlow Devices table displays.
Step 3
Click Create.
The New Device dialog box appears.
Step 4
Enter the device name and community string, then do one of the following:
•
To save the changes, click OK.
•
To clear the entries in the dialog box, click Reset,
•
To leave the entries unchanged, click Cancel.
Editing Devices
Note
You cannot edit the local switch.
To edit a device:
Step 1
Click the Setup tab.
Step 2
Click Data Sources.
The Active SPAN Sessions table displays.
Step 3
In the contents, click Devices.
The NetFlow Devices table displays.
Step 4
Select the device you wish to edit from the table and click Edit.
The Edit Device window appears.
Step 5
Make the desired changes and do one of the following:
•
To save the changes, click OK.
•
To restore the original entries, click Reset,
•
To leave the configuration unchanged, click Cancel.
Deleting Devices
To delete a device:
Step 1
Click Setup > Data Sources.
The Active SPAN Sessions table displays.
Step 2
In the contents, click Devices.
The NetFlow Devices table displays.
Step 3
Select the device you wish to delete from the Devices dialog box, then click Delete.
Note
All custom NetFlow data sources that are related to the device will be deleted.
Testing Devices
You can test the SNMP community strings for the devices in the Devices table. To test a device, select it from the Devices table, then click Test. The Device System Information Dialog Box (Table 3-14) displays.
Table 3-14 Device System Information Dialog Box
Field
|
Description
|
Name
|
Name of the device.
|
Hardware
|
Hardware description of the device.
|
Device Software Version
|
The current software version running on the device.
|
System Uptime
|
Total time the device has been running since the last reboot.
|
Location
|
Location of the device.
|
Contact
|
Contact information for the device.
|
SNMP read from device
|
SNMP read test result. For the local device only.
|
If the device is sending NetFlow Version 9 (V9) and the NAM has received the NDE templates, then a V9 Templates button appears below the Device System Information window.
Note
NetFlow V9 templates do not appear in all NDE packets. When there are no templates, the V9 Templates button does not appear.
To view the NetFlow V9 templates, click the V9 Templates button. For more information, see Table 3-17 in Using the Listening Mode.
Creating Custom Data Sources
A NetFlow data sources are automatically learned when you create a device in the Devices section. For more information on creating NetFlow devices, see the "Creating Devices" section. This option allows you to create custom data sources on NetFlow devices with specific interface information.
To create a custom data source:
Step 1
Click Setup > Data Sources.
Step 2
From the contents menu, choose Custom Data Sources.
The NetFlow Data Sources table displays.
Step 3
Click Create.
The following table shows the wizard used to create or edit a NetFlow data source.
Selecting a NetFlow Device
To select a NetFlow device:
Step 1
Select the NetFlow device from the list.
Step 2
Enter the data source name. If none is entered, a default name will be created.
Step 3
Click Next.
Selecting the Interfaces
To select an interface:
Step 1
Select the data flow direction.
Step 2
Select the interfaces you want to add from the Available Interfaces section.
Tip
Use Ctrl+Click to select multiple interfaces.
If no interfaces are listed, manually enter them in the Interface Index text box.
Step 3
Click Add.
The selected interfaces are displayed in the Selected Interfaces section.
•
To remove interfaces, select them from the Selected Interfaces section, then click Remove.
•
To remove all interfaces from the Selected Interfaces section, click Remove All.
Step 4
Click Next.
Special (0) Interface
NDE packets sometimes have NetFlow records reporting either (or both) input if-index and output if-index fields as being 0. This could be a result of one or more of the following reasons:
•
Flows are terminated at the device.
•
Configurations of the device.
•
Unsupported NetFlow feature of the platform at the device.
For more information, see the accompanying documentation for your NetFlow device.
Verifying NetFlow Data Source Information
To verify NetFlow data source information:
Step 1
Verify the information is correct.
Step 2
Do one of the following:
•
To save the configuration, click Finish.
•
To cancel any changes and go back to the NetFlow Data Sources table, click Cancel.
Editing a Custom Data Source
To edit a custom data source:
Step 1
Choose Setup > Data Sources.
Step 2
Click Custom Data Sources.
The NetFlow Data Sources table displays.
Step 3
Select the data source you wish to edit, then click Edit.
The wizard used to edit NetFlow data sources displays.
Step 4
Make the desired changes and do one of the following:
•
To accept the changes, click Finish.
•
To cancel the changes, click Cancel.
Deleting a Custom Data Source
To delete a data source, select it from the NetFlow Data Source table, then click Delete.
Note
You cannot delete the default data sources.
Using the Listening Mode
The Listening Mode of the NAM allows you to view the IP addresses of devices sending NDE packets to the NAM, the number of NDE packets, and time that the last NDE packet was received. The NetFlow Listening Mode table only lists devices that the NAM currently receives NDE packets from.
To use listening mode:
Step 1
Choose Setup > Data Sources.
Step 2
In the contents, click Listening Mode.
The NetFlow Listening Mode Table (Table 3-15) displays.
Table 3-15 NetFlow Listening Mode Table
Field
|
Description
|
Start Time
|
The timestamp of when the Start button was clicked.
|
Address
|
IP address of the learned device.
|
# Received NDE Packets
|
Number of NetFlow data export (NDE) packets received.
|
Last Packet Received
|
Time stamp the last NDE packet was received.
|
Step 3
Click Start.
Step 4
To clear the table and stop monitoring, click Stop.
Note
Learning will automatically be disabled after 1 hour.
Viewing Details from the NetFlow Listening Mode Table
Select the device from the table, then click Details.
The Device Details Window (Table 3-16) displays.
Table 3-16 Device Details Window
Field
|
Description
|
Device Added
|
Indicates if the device was added to the NAM device table.
|
Interfaces Reported in NDE Packets
|
Lists the interfaces that NDE packets were seen on.
For example:
Special (0) (Output)
(1) (Input/Output)
(2) (Input/Output
Note Protocol-Prefix NDE packets do not have interfaces information.
|
If the device is sending NetFlow Version 9 (V9) and the NAM has received the NDE templates, then a V9 Templates button appears below the Device Details window. For more information, see:
http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_feature_guide09186a00801b0696.html
Note
NetFlow V9 templates do not appear in all NDE packets. If there are no templates, the V9 Templates button does not appear.
To view the NetFlow V9 templates, click the V9 Templates button.
The V9 Templates Window (Figure 3-5) displays (see example below).
Figure 3-5 V9 Templates Window
The V9 Templates Table (Table 3-17) describes the template data.
Table 3-17 V9 Templates Table
Field
|
Description
|
Type
|
Type of template data.
|
Length (Bytes)
|
Length of template data in bytes.
|
Adding a Device To Monitor
To add a device to monitor:
Step 1
Select the device from the table, then click Add.
The New Device Window displays.
Step 2
Enter the device information and click OK.
The new device is added to the NetFlow Devices table.
Testing the Router Community Strings
For NM-NAM and NME-NAM devices only
Before the router can send information to the NAM using SNMP, the router community strings set in the NAM Traffic Analyzer must match the community strings set on the actual router. The Router Parameters dialog box displays the router name, hardware, Supervisor engine software version, system uptime, location, and contact information.
The local router IP address and the SNMP community string must be configured so that the NAM can communicate with the local router.
To set the community strings on the router, use the router CLI. For information on using the CLI, see the documentation that accompanied your device.
Caution 
The router community string you enter must match the read-write community strings on the router. Otherwise you cannot communicate with the router.
To test router community strings:
Step 1
Choose Setup > Router Parameters.
The Router Parameters dialog box displays.
Step 2
Click Test.
The Router Community String Test dialog box displays.
Setting Up an Interface
Note
This section applies to NM-NAM and NME-NAM devices only.
Before you can view traffic statistics and the TopN traffic for applications, hosts, and conversations, you must first set up the interfaces.
Click in the check box to enable Netflow NDE on the selected interface and all of its sub-interfaces. A NAM NDE datasource will be created for each enabled sub-interface, and hosts, conversations and application NDE data sources will also be created. This action populates the Monitor > Router detail window with the hosts, conversations and application statistics.
In the case of parent interfaces with sub-interfaces, only the leaf child will be enabled. For example, ATM2/0.1-atm-subif has child ATM2/0.1-aal5-layer. Only the aal5-layer will be enabled. NDE will only be seen on this child interface.
Note
Depending on the IOS running on the Supervisor, port names are displayed differently. Earlier versions of CatOS displayed port names as 2/1 and 3/1 meaning module 2, port 1 and module 3 port 1. Newer versions of IOS software display a port name as Gi2/1 to represent a Gigabit port on module 2 port 1. In the VSS, a port name might be displayed as Gi1/2/1to represent a Gigabit port on switch 1, module2, port 1.
To keep the detail screen consistent with data, we recommend that you set the Router Netflow Active Timeout to the same polling interval as the NAM. Go to the Setup > Datasources > Interfaces window or the Setup > Router Parameters window.
To set up interfaces to enable you to view traffic statistics:
Step 1
Choose Setup > Data Sources.
NAM 3.6 supports up to 1,500 datasources.
Step 2
Click Interfaces in the content menu.
The Interfaces window displays.
Router interfaces and SNMP Read/Write Community strings must also be configured. See Router Parameters for more information.
Step 3
Check the Enable check box for each interface you want to enable.
MPLS Data Sources
When data packets containing MPLS labels are spanned to the NAM, the traffic can be monitored by the tag inside the data packets. This feature is especially useful in a network that deploys MPLS/VPN where traffic from each VPN can be uniquely identified by a combination of MPLS labels. When the NAM encounters stacked MPLS labels, only the relevant inner-most label (the bottom tag in the label stack) is used for monitoring.
To enable RMON monitoring for MPLS, you must first configure an MPLS data source. To enable MPLS traffic monitoring, you must create a form of virtual interface that can be tied to a particular MPLS tag. After setting up the custom MPLS data source, you can enable monitoring of the following:
•
Applications per MPLS tag
•
Hosts per MPLS tag
•
Host conversation per MPLS tag
This section contains the following topics:
•
Automatic Discovery of MPLS VPN Labels
•
Setting Up Layer 3 VRF Data Sources
•
Setting Up Layer 2 Virtual Circuit Data Sources
•
Setting Up MPLS Label Data Sources
•
Creating a VRF/VC Configuration File
•
Importing a VRF/VC Configuration File
•
Exporting a VRF/VC Configuration File
•
Importing Log
Automatic Discovery of MPLS VPN Labels
In an MPLS VPN environment, the NAM can monitor traffic using either VPN routing/forwarding (VRF) table name or virtual circuit (VC) ID configured at the switch. This higher level of abstraction hides the underlying label associations.
The VRF and VC information can only be obtained from the switch CLI. This requires you to provide the switch login credentials, username and password, and whether to access the switch CLI through telnet or ssh. Enable mode password is not required.
After the VRF, VC, and the associated labels are discovered, you can reference the VRF or VC using either the VRF name or VC ID directly without any knowledge of the underlying labels using the NAM monitoring functions.
The labels associated with each VRF or VC are allocated dynamically by the switch. As a result, the labels will not be persistent when the switch is rebooted or a supervisor switch-over occurred. The NAM will have to re-discover VRF and VC information from the switch under these situations. A manual refresh feature is also provided for on-demand refresh.
Setting Up Layer 3 VRF Data Sources
To set up layer 3 VPN routing/forwarding (VRF) table (L3 VRF) data sources:
Step 1
Click Setup > Data Sources.
The Active SPAN Sessions table displays.
Step 2
In the contents, click L3 VRF.
The MPLS VRF Data Source Configuration window displays shown in Figure 3-6.
Figure 3-6 MPLS VRF Data Source Configuration Window
Step 3
If VRF information is not displayed or if some VRF information is missing, click Import from Router to refresh the list.
If the list is still empty after clicking Import from Router, the NAM failed to automatically import VRF configuration from the router. In this case, perform Step 4. If the VRF information is available, proceed to Step 5.
If the NAM failed to automatically import VRF configuration from the router, click Import Log. The MPLS Import log contains information that might help you diagnose the problem in the connection. See Importing Log, for more information about the Import Log.
Step 4
If necessary, create a text file containing the VRF information and click Import from File.
After clicking Import from File, the Import VRF/VC Configuration window displays enabling you to specify the location from which to import the VRF/VC configuration file. The VRF/VC configuration file might be on your local machine or at a remote URL.
See Creating a VRF/VC Configuration File, for information about how to create the text VRF/VC configuration file.
Step 5
Choose any VRF data source, then click Create DataSrc.
Creating or deleting a NAM data source does not affect the switch configuration.
Setting Up Layer 2 Virtual Circuit Data Sources
To set up layer 2 (L2) virtual circuit data sources:
Step 1
Choose Setup > Data Sources.
The Active SPAN Sessions table displays.
Step 2
In the contents, click L2 Virtual Circuit.
The MPLS Virtual Circuit Data Source Configuration window displays shown in Figure 3-7.
Figure 3-7 MPLS Virtual Circuit Data Source Configuration Window
Step 3
If VC information is not displayed or if some VC information is missing, click Import from Router to refresh the list.
If the list is still empty after clicking Import from Router, the NAM failed to automatically import VC configuration from the router. In this case, perform Step 4. If the VRF information is available, proceed to Step 5.
If the NAM failed to automatically import VC configuration from the router, click Import Log. The MPLS Import log contains information that might help you diagnose the problem in the connection. See Importing Log, for more information about the Import Log.
Step 4
If necessary, create a text file containing the VC information and click Import from File.
After clicking Import from File, the Import VRF/VC Configuration window displays enabling you to specify the location from which to import the VRF/VC configuration file. The VRF/VC configuration file might be on your local machine or at a remote URL.
See Creating a VRF/VC Configuration File, for information about how to create the text VRF/VC configuration file.
Step 5
Choose any VC data source, then click Create DataSrc.
Creating or deleting a NAM data source does not affect the switch configuration.
Setting Up MPLS Label Data Sources
To set up MPLS Label data sources:
Step 1
Choose Setup > Data Sources.
The Active SPAN Sessions table displays.
Step 2
In the contents, click Label.
The MPLS Label Data Source Configuration window displays shown in Figure 3-8.
Figure 3-8 MPLS Label Data Source Configuration Window
Step 3
Click Create DataSrc.
A dialog box asks you to select a VRF or VC first.
Step 4
Click OK.
The Create MPLS Custom Datasource window displays as shown in Figure 3-9.
Figure 3-9 Create MPLS Custom Datasource Window
Step 5
Enter an MPLS tag number in the MPLS Tag field.
The tag number must match the value in the packets, as only those will be represented in the data-source. You need to know the tag number from the router configuration. The NAM will assign a name based on the MPLS tag number you provide.
Step 6
Accept the name the NAM assigns based on the MPLS tag number, or enter a name you prefer in the Name field.
You can use the name field to identify the MPLS tag value, the VRF tunnel name, or something else (such as VPN-San_Jose-RTP).
Step 7
Click Apply.
Creating a VRF/VC Configuration File
The VRF/VC configuration file contains text information about the VRFs and VCs configured at the router. Each configuration line contains four fields separated by a space. Table 3-18 describes the format of a configuration line.
Table 3-18 VRF/VC Configuration Lines
Field
|
Description
|
Comment line
|
Begins with the # character
|
Type
|
VRF or VC
|
Name
|
Name of the VRF or VC ID
|
Local label
|
The local label for the VRF or VC
|
Egress label
|
The out going label stack with the format outer label/inner label. If there is more than one label, each label stack is separated by a comma with no spaces between stack labels.
|
The following is an example of the VRF/VC configuration file:
# MPLS configuration file
# Autogenerated at 2006-04-26 19:43
VRF customer_B 600 204/500,204/308
Importing a VRF/VC Configuration File
If you have a text file that contains the known VRF/VC configuration, you can import the configuration by clicking Import from File. You might have created this file by using the Export to File button. Figure 3-10 shows the Importing VRF/VC Configuration File window.
Click Browse to locate the configuration file you want to import, or enter the URL of a remote file, then click Import.
Figure 3-10 Importing VRF/VC Configuration File Window
Exporting a VRF/VC Configuration File
After you have the desired MPLS configuration on the NAM, you can export the configuration to a file to serve as a backup. Creating a backup file enables you reload the configuration if the configuration is lost or if you want to revert to an earlier configuration. Click Export to File to export your MPLS VRF/VC datasource configuration.
Importing Log
After you import the VRF/VC data source configuration from the router or VRF/VC datasource configuration file, you can view the log of the MPLS import by clicking Import Log. The MPLS Import log contains a listing of occurrences in the connection and can be useful in troubleshooting. The log might show an invalid user name or password, no connection to the switch, command-line parsing errors, or other problems that might have occurred. An MPLS import log should contain the message: VRF/VC update successful.
Setting Up Monitoring
Before you can monitor data, you must set up the data collections in the Monitor option of the Setup tab. For information on data collections, see the "Overview of Data Collection and Data Sources" section on page 4-2. There are options to set up the following:
•
Monitoring Core Data
•
Monitoring Voice Data
•
Monitoring RTP Stream Traffic
•
Monitoring Response Time Data
•
Monitoring DiffServ Data
•
Setting Up the DiffServ Profile
•
Monitoring URL Collection Data
Monitoring Core Data
You can enable or disable individual core data collections on each available data source. The following core collections are available:
•
Application Statistics—Enables the monitoring of application protocols observed on the data source.
•
Host Statistics (Network and Application layers)—Enables the monitoring of network-layer host activity.
•
Host Statistics (MAC layer)—Enables the monitoring of MAC-layer hosts activity. Also enables monitoring of broadcast and multicast counts for host detail windows.
•
Conversation Statistics (Network and Application layers)—Enables the monitoring of pairs of network-layer hosts that are exchanging packets.
•
Conversation Statistics (MAC layer)—Enables the monitoring of pairs of MAC-layer hosts that are exchanging packets.
•
VLAN Traffic Statistics—Enables the monitoring of traffic distribution on different VLANs for the data source.
•
VLAN Priority (CoS) Statistics—Enables the monitoring of traffic distribution using different values of the 802.1p priority field.
•
Network-to-MAC Address Correlation—Enables the monitoring of MAC-level statistics which are shown in host detail windows. Without this collection, a MAC station cannot be associated with a particular network host.
•
TCP/UDP Port Table—Enables the monitoring of server ports on a particular data source such as a VLAN, a physical port on the NAM, or a set of NDE flow records sent to the NAM.
•
Switch engine module (Supervisor) records received by the NAM. You can select any combination of Port statistics, VLAN statistics, and NBAR statistics.
•
Router engine module records (Router) received by the NAM. You can select any combination of Interface statistics and NBAR statistics.
Note
MAC and VLAN collections are not available on NM-NAM and NME-NAM devices.
Note
For better overall system performance, enable only the collections you want to monitor.
Note
You must disable all reports for the collections you want to turn off. If you turn off collections that have reports running on them, the collections will automatically be turned on. For more information on disabling reports, see the "Disabling Reports" section.
To set up core monitoring functions:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions Dialog Box (Figure 3-11) displays.
Figure 3-11 Core Monitoring Functions Dialog Box
Step 2
Select the collection data source from the Data Source drop-down menu.
To turn on core monitoring for the router, select Router from the Data Source drop-down menu. For routers, the following Data Sources are available:
•
Internal
•
External
•
NETFLOW
•
Router
To turn on core monitoring data for the switch, select Supervisor from the drop-down menu. For switches, the following Data Sources are available:
•
ALL SPAN
•
VLANs
•
NETFLOW
•
NDE
•
Supervisor
You can enter a partial name of a data source and click Filter to find data sources that match. Click Clear to return to the entire list of data sources.
Step 3
Select the check boxes to enable any combination of the following specific core monitoring functions:
•
Application Statistics
•
Host Statistics (Network and Application layers)
•
Host Statistics (MAC layer)
•
Conversation Statistics ((Network and Application layers)
•
Conversation Statistics (MAC layer)
•
VLAN Traffic Statistics
•
VLAN Priority (CoS) Statistics
•
Network-to-MAC Address Correlation
•
TCP/UDP Port Table
Step 4
Select the maximum number of entries from the Max Entries lists.
Step 5
Click Apply to save your changes, or click Reset to cancel.
Enabling Mini-RMON Collection
Note
This section does not apply to NM-NAM and NME-NAM devices.
Enabling Mini-RMON on the switch Supervisor allows you to monitor port statistics data from each switch port. You must enable Mini-RMON in privileged mode from the CLI. To enable Mini-RMON, do one of the following:
For Switches Running Catalyst OS
Enter the set snmp rmon enable command.
For Switches Running Cisco IOS Software
You must enable Mini-RMON on each individual interface.
Enter the following commands:
Supervisor name(config) #interface interface-name
Supervisor name(config-if) #rmon collection stats collection-control-index owner monitor
Supervisor name(config-if) #end
where:
•
The interface-name is the name of the interface on which you are enabling Mini-RMON.
•
The collection-control-index is any arbitrary number that has not yet
been used.
Monitoring Voice Data
When you enable monitoring for voice data, the results are exclusively available through the NAM Traffic Analyzer. You can use the Monitor tab to view the collected voice data. For more information on viewing the voice data, see the "Viewing Collected URLs" section on page 4-19.
The voice monitoring option is on by default, however to monitor voice data, you must enable voice monitoring in the NAM Traffic Analyzer application.
Note
Voice monitoring features are supported with Cisco IP telephony devices only.
To set up voice monitoring:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
In the contents, click Voice Monitoring.
The Voice Monitor Setup Window(Table 3-19) displays.
Step 3
Check the Monitoring Enabled check box of the voice protocols you want to monitor, and accept the default values or modify the values as you prefer.
Table 3-19 Voice Monitor Setup Window
Field
|
Description
|
Usage Notes
|
Monitoring Enabled
|
You can enable voice monitoring for the following voice protocols: SCCP, H.323, MGCP, and SIP.
|
Select the check box to monitor the protocol.
|
Number of phone table rows
|
The maximum number of phone records that can be monitored.
|
Enter a number from 10 to 1000.
|
Number of call table rows
|
The maximum number of active calls that can be monitored.
|
Enter a number from 10 to 1000.
|
Number of top packet jitter rows
|
The number of Top N phone calls with the worst jitter.
|
Enter a number from 1 to 20.
|
Number of top packet loss rows
|
The number of Top N phone calls with the worst packet loss.
|
Enter a number from 1 to 20.
|
Debug
|
Allows the application to display calls that are still in the setup state.
|
Click to turn on the debug option.
|

Note
To report jitter and packet loss for the SCCP protocol, you must enable CDR on Cisco Unified CallManager. For more information on Cisco Unified CallManager, see the Cisco Unified CallManager documentation.
http://www.cisco.com/en/US/products/sw/voicesw/ps556/tsd_products_support_series_home.html
Step 4
Click Apply to save your changes, or click Reset to cancel.
Monitoring RTP Stream Traffic
The NAM enables you to identify and monitor all RTP stream traffic among all SPANed traffic without having to know the signalling traffic used in negotiating the RTP channels. When RTP Stream Monitoring is enabled, the NAM identifies all RTP streams among the SPANed traffic, monitors the identified RTP traffic, and sends syslog alarm messages for those RTP streams that violate the packet loss thresholds.
By default, the NAM can monitor up to 30 concurrent RTP streams, but you can set up the NAM to monitor from 1 to 100 streams. See Setting Up RTP Stream Thresholds for more information about how to set up NAM RTP Stream packet loss thresholds for the following:
•
Number of Consecutive Packets Loss threshold
The valid threshold value is 1 to 10 inclusive. Each RTP packet has an RTP header that contains a sequence number. The sequence number is incremented by one for each RTP packet received in the same RTP stream. A gap in the sequence numbers identifies a packet loss. If the gap in sequence numbers jump is more than the threshold, the NAM raises an alarm condition.
•
Packet Loss (10-6) threshold
This value is accumulative per-million packet loss rate from 1 to 100 inclusive. Every time NAM detects a packet loss (sequence gap) event, the NAM calculates the per-million packet loss rate. If the computed per-million packet loss rate crosses this threshold, the NAM raises an alarm condition.
You can set up these thresholds at Setup > Alarms > NAM RTP Stream Thresholds.
You can define filter entries to narrow down to the subset of RTP streams so the NAM monitors only those RTP streams matching the filter criteria. For example, a filter to set up the NAM to monitor RTP streams from the subnet 209.165.201.0 to host 1.1.1.1 would be:
source mask = 255.255.255.0
destination mask = 255.255.255.255
To set up RTP Stream monitoring:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
In the contents, click RTP Stream Monitoring.
The RTP Stream Setup window displays with two distinct areas.
Step 3
In the Filter Table area, click Create to enter filtering data.
The New Filter dialog box appears with fields for you to enter IP address and mask for both the source and destination of the RTP stream.
Step 4
Enter the filter information and click OK, or click Cancel to abort.
Click Reset to clear all fields of the New Filter dialog box.
Step 5
Click the Monitoring Enabled check box, and accept or modify the number of Maximum Source of Destination Entries.
You can set the Maximum Source of Destination Entries to a value from 1 -100.
Step 6
Click Apply to begin monitoring.
Clicking Reset clears the Monitoring Enabled check box and resets the Maximum Source of Destination Entries to the default value (30).
Monitoring Response Time Data
You can monitor response time to collect the response time between a client and a server. You can enable or disable response time monitoring on individual collection data sources. When you enable response time monitoring, the application supplies the default collection parameters.
The response time monitoring option is on by default; however to monitor response time data, you must enable response time monitoring in the NAM Traffic Analyzer application.
These topics help you set up and manage response time monitoring:
•
Creating Response Time Data Collections
•
Editing Response Time Data Collections
•
Deleting Response Time Data Collections
Creating Response Time Data Collections
To set up Response Time data collections:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
In the contents, click Response Time Monitoring.
The Response Time Monitoring Setup table displays.
Step 3
Click Create.
The Response Time Monitoring Setup, Collection Configuration Dialog Box (Table 3-20) displays.
Step 4
Select the appropriate information.
Table 3-20 Response Time Monitoring Setup, Collection Configuration Dialog Box
Field
|
Description
|
Usage Notes
|
Data Source List
|
List of available data sources.
|
Select the data source from the list.
|
Report Interval (sec)
|
Number of seconds between reports.
|
Enter a number in seconds. The default is 1800.
|
RspTime1 (msec)
|
Upper response time limit for the first bucket.
|
Enter a number in milliseconds. The default is 5.
|
RspTime2 (msec)
|
Upper response time limit for the second bucket.
|
Enter a number in milliseconds. The default is 15.
|
RspTime3 (msec)
|
Upper response time limit for the third bucket.
|
Enter a number in milliseconds. The default is 50.
|
RspTime4 (msec)
|
Upper response time limit for the fourth bucket.
|
Enter a number in milliseconds. The default is 100.
|
RspTime5 (msec)
|
Upper response time limit for the fifth bucket.
|
Enter a number in milliseconds. The default is 200.
|
RspTime6 (msec)
|
Upper response time limit for the sixth bucket.
|
Enter a number in milliseconds. The default is 500.
|
RspTimeMax (msec)
|
The maximum interval that the NAM waits for a server response to a client request
|
Enter a number in milliseconds. The default is 3000.
|
Maximum Entries in Tables
|
The maximum number of rows in the report.
|
The default is 500.
|
Step 5
Click Submit to save your changes, or click Reset to cancel.
Editing Response Time Data Collections
To edit Response Time data collections:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
In the contents, click Response Time Monitoring.
The Response Time Monitoring Setup table displays.
You can enter a partial name of a data source and click Filter to find data sources that match. Click Clear to return to the entire list of data sources.
Step 3
Select the data source to edit, then click Edit.
The Response Time Monitoring Setup, Collection Configuration Dialog Box (Table 3-20) displays.
Step 4
Make the necessary changes, then click Submit to save your changes, or click Reset to cancel.
Deleting Response Time Data Collections
To delete one or more response time data collections, simply select the data collections from the Response Time Monitoring Setup table, then click Delete.
Monitoring DiffServ Data
Differentiated services monitoring (DSMON or DiffServ) is designed to monitor the network traffic usage of differentiated services code point (DSCP) values.
To monitor DiffServ data, you must configure at least one aggregation profile and one or more aggregation groups associated with each profile. For more information on configuring an aggregation profile, see the "Creating a DiffServ Profile" section.
To set up monitoring of differentiated services:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
In the contents under DiffServ, click Monitoring.
The DiffServ Monitor Setup Dialog Box (Table 3-21) displays.
You can enter a partial name of a data source and click Filter to find data sources that match. Click Clear to return to the entire list of data sources.
Step 3
Select the appropriate information.
Table 3-21 DiffServ Monitor Setup Dialog Box
Element
|
Description
|
Usage Notes
|
Data Source List
|
Lists the data sources available.
|
Select the data source from the list.
|
DiffServ Profile List
|
Lists the user defined DiffServ profiles available.
|
Select the user-defined DiffServ profile from the list.
|
Traffic Statistics
|
Shows basic DSCP traffic distribution.
|
Select to enable or deselect to disable.
|
Application Statistics
|
Shows DSCP traffic distribution by application protocol.
|
Select to enable or deselect to disable. Select the maximum number of entries from the Max Entries list.
|
IP Host Statistics
|
Shows DSCP traffic distribution by host.
|
Select to enable or deselect to disable. Select the maximum number of entries from the Max Entries list.
|
Step 4
Click Apply to save your changes, or click Reset to cancel.
Setting Up the DiffServ Profile
A DiffServ profile is a set of aggregation groups that can be monitored as a whole. After you create the proper profile(s), you can enable DiffServ collection. For more information on setting up DiffServ collections, see the "Monitoring DiffServ Data" section.
These topics help you set up and manage the DiffServ profile:
•
Creating a DiffServ Profile
•
Editing a DiffServ Profile
•
Deleting a DiffServ Profile
Creating a DiffServ Profile
To create a DiffServ profile:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
In the contents under DiffServ, click Profile.
The DiffServ Monitor Profile Dialog Box displays.
Step 3
Click Create.
The DiffServ Profile Setup Dialog Box (Table 3-22) displays.
Step 4
Select the appropriate information.
Table 3-22 DiffServ Profile Setup Dialog Box
Element
|
Description
|
Usage Notes
|
Template List
|
Templates for creating a differentiated services profile.
|
Select the template from the list. Select NONE if you are not using a template.
|
Profile Name text box
|
Name of the profile.
|
Enter the name of the profile you are creating. The maximum is 64 characters.
|
DSCP Value column
|
DSCP numbers from 0 to 63.
|
—
|
Group Description text boxes
|
Name of the aggregation group for each DSCP value.
|
Enter the name of the aggregation group for each DSCP value. The maximum is 64 characters.
|
Step 5
Click Submit to save your changes, or click Reset to cancel.
Editing a DiffServ Profile
To edit a DiffServ profile:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
In the contents under DiffServ, click Profile.
The DiffServ Monitor Profile Table displays.
Step 3
Select the profile to edit, then click Edit.
The DiffServ Profile Setup Dialog Box (Table 3-22) displays.
Step 4
Make the necessary changes, then click Submit to save your changes, or click Reset to cancel.
Deleting a DiffServ Profile
To delete one or more DiffServ profiles, simply select the profiles from the DiffServ Monitor Profile table, then click Delete.
Monitoring URL Collection Data
The URL collection listens to HTTP traffic (TCP port 80) on a selected datasource and collects URLs. Only one collection on a single datasource can be enabled at a time.
A URL, for example: http://host.domain.com/intro?id=123, consists of a host part (host.domain.com), a path part (intro), and an arguments part (?id=123).
The collection can be configured to collect all parts or it can configured to collect only some of the parts and ignore others.
This section contains the following sections:
•
Enabling a URL Collection
•
Changing a URL Collection
•
Disabling a URL Collection
Enabling a URL Collection
To enable a URL collection:
Step 1
Choose Setup > Monitor.
The Core Monitoring Functions table displays.
Step 2
Click URL Collection.
The URL Collection Configuration Dialog Box (Figure 3-12) displays.
Figure 3-12 URL Collection Configuration Dialog Box
Step 3
Click the Enable check box to initiate URL Collection.
Step 4
Provide the information described in the URL Collection Configuration Dialog Box (Table 3-23).
You can enter a partial name of a data source and click Filter to find data sources that match. Click Clear to return to the entire list of data sources.
Note
Depending on which radio button option is collected, the format of the URL varies. For example, the leading http: part is only present if the host part is collected. Keep this variable in mind, when configuring a match only expression.
Table 3-23 URL Collection Configuration Dialog Box
Element
|
Description
|
Usage Notes
|
Datasource
|
Identifies type of traffic incoming from the application.
|
Select one of the options from the drop down box.
|
Max Entries
|
Maximum number of URLS to collect.
|
Select one of the following options from the drop down box:
• 100
• 500
• 1000
|
Match only
|
The application URL to match.
|
Optional parameter to limit collection of URLs that match the regular expression of this field.
|
:
Step 5
Click the Recycle Entries check box to recycle entries.
Step 6
Click the check box for one of the following:
•
Collect complete URL (Host, Path and Arguments)
•
Collect Host only (ignore Path and Arguments)
•
Collect Host and Path (ignore Arguments)
•
Collect Path and Arguments (ignore Host)
•
Collect Path only (ignore Host and Arguments)
Step 7
Click Apply to save your changes, or click Reset to cancel.
Changing a URL Collection
To change a URL collection:
Step 1
Choose Setup > Monitor.
Step 2
Select URL Collection.
The URL Collection Configuration Dialog Box (Figure 3-13) displays.
Figure 3-13 URL Collection Configuration Dialog Box
Step 3
Change the information as described in the URL Collection Configuration Dialog Box (Table 3-23).
Note
Changing any parameters and applying the changes flushes the collected URLs and restarts the collection process.
Step 4
Click Apply to save your changes, or click Reset to cancel.
Disabling a URL Collection
To disable a URL collection:
Step 1
Choose Setup > Monitor.
Step 2
Click URL Collection.
Step 3
Uncheck the Enabled check box.
Step 4
Click Apply.
Setting Up the Protocol Directory
The NAM contains a default set of protocols to be monitored. You can edit and delete protocols from the RMON2 protocol directory table on the NAM.
These topics help you manage the protocol directory:
•
Individual Applications
•
Setting Up Application Groups
•
Setting Up Autolearned Protocols
•
Setting Up URL-based Applications
Individual Applications
The Protocol Directory window (Figure 3-14) lists protocols that have been set up for this NAM. Use this window to view, add proprietary protocols, and to edit the settings for well-known protocols.
Figure 3-14 Protocol Directory Table
This section provides the following sections:
•
Creating a New Protocol
•
Editing a Protocol
•
Deleting a Protocol
Creating a New Protocol
We recommend that users do not make changes to the protocol directory from this screen. The NAM is designed to function with default protocols. Also, modifications that SNMP management applications sometimes make to the protocol directory might conflict with customizations made on this screen.
To create a new protocol:
Step 1
Choose Setup > Protocol Directory.
The Protocol Directory Table (Figure 3-14) displays.
Step 2
Click Create.
The Create New Protocol window (Figure 3-15) displays.
Figure 3-15 New Protocol Parameters Window
Step 3
Choose the new protocol encapsulation method, then click Next.
The New Protocol Parameters window (Figure 3-16) displays. This window varies depending on the protocol type you select.
Figure 3-16 New Protocol Parameters Window
Step 4
Select the appropriate information.
Table 3-24 New Protocol Parameters Dialog Box
Field
|
Description
|
Usage Notes
|
Protocol Identification Value, such as:
• IP Protocol
• TCP Port
• UDP Port
|
Numeric value used to identify the new protocol.
|
Select a number between 1-255.
|
Name
|
Full name of the protocol.
|
—
|
Port Range
|
Port Range for this protocol
|
Select a number between 1-255.
|
Affected Stats
|
• Address Map
• Host
• Conversations
• ART
|
Select the statistics the protocol should collect.
A statistic is grayed out if it is not available for the protocol.
|
Step 5
Click Finish to save your changes, or click Reset to cancel.
Tip
To view the full protocol name, move the cursor over the protocol name in the Protocol column of the Protocol Directory table.
Editing a Protocol
We recommend that you do not change any settings in the NAM protocol directory. Changing the default settings might cause unexpected behavior in SNMP-based management applications such as NetScout nGenius Real-Time Monitor. However, advanced users might want to monitor proprietary protocols or alter the normal settings for well-known protocols.
To edit a protocol:
Step 1
Choose Setup > Protocol Directory.
The Protocol Directory table displays.
Step 2
Select the protocol to edit, then click Edit.
The Edit Protocol Dialog Box(Table 3-25) displays.
Step 3
Make the necessary changes.
Table 3-25 Edit Protocol Dialog Box
Field
|
Description
|
Usage Notes
|
Name
|
The name of the protocol.
|
|
Currently displayed as
|
Protocol name as it appears in the Protocol Directory table.
|
|
Port Range
|
Port Range for this protocol
|
|
Encapsulation
|
Protocol encapsulation type.
|
|
Affected Stats
|
The statistics that can be collected for the protocol:
• Address Map
• Hosts
• Conversations
• ART
|
A statistic is grayed out if it is not available for the protocol.
|
Step 4
Do one of the following:
•
To accept the changes, click Submit.
•
To leave the configuration unchanged, click Cancel.
•
To delete the protocol, click Delete.
Tip
•
You can display the Edit Protocol dialog box for a specific protocol by clicking on the protocol name in the Protocol Directory table.
•
To view the full protocol name, move the cursor over the protocol name in the Protocol column of the Protocol Directory table.
Deleting a Protocol
To delete a protocol, simply select it from the Protocol Directory table, then click Delete.
Tip
You can also delete a protocol from the Edit Protocol Directory dialog box. Select the protocol, then click Delete.
Setting Up Application Groups
An application group is a set of application protocols that can be monitored as a whole. The following topics help you set up and manage the application group:
•
Creating an Application Group
•
Editing an Application Group
•
Deleting an Application Group
Creating an Application Group
To create an application group:
Step 1
Choose Setup > Protocol Directory.
The Protocol Directory table displays.
Step 2
Select Application Groups from the Content menu.
Step 3
Click Create.
The New Application Group Dialog Box (Table 3-26) displays.
Step 4
Enter the application group name.
Step 5
Select the appropriate information.
Table 3-26 New Application Group Dialog Box
Element
|
Description
|
Usage Notes
|
Application Group Name
|
Group Name
|
Enter the group name.
|
Encapsulation
|
Encapsulation of the application.
|
Select the encapsulation from the drop down box.
|
Application Filter
|
Options to filter or clear.
|
Enter the name of the protocol you are filtering. The maximum is 64 characters.
|
Application
|
List of applications
|
Select an application and click Add.
Applications appear in the Selected Applications box.
|
Step 6
Click Submit to save your changes, or click Reset to cancel.
Editing an Application Group
To edit an application group:
Step 1
Choose Setup > Protocol Directory.
The Individual Applications window displays.
Step 2
Select Application Groups from the Content menu.
The Application Groups window displays.
Step 3
Select the application group to edit, then click Edit.
The Application Groups Edit window displays.
Step 4
Make the necessary changes, then click Submit to save your changes, or click Reset to cancel.
Deleting an Application Group
To delete one or more application groups, simply select the profiles from the Application Groups table, then click Delete.
Setting Up Autolearned Protocols
The Autolearned Protocols Preferences window allows you to configure the NAM to automatically learn application information. You can set the following preferences:
•
Number of protocols to be learned (100 - 500)
•
Number of TCP ports to be learned (0 - 65535)
•
Number of UDP ports to be learned (0 - 65535)
•
Range of TCP ports NOT to be learned (1 - 65535)
•
Range of UDP ports NOT to be learned (1 - 65535)
To set up Autolearned Protocol preferences:
Step 1
Choose Setup > Protocol Directory.
Step 2
Click Autolearned Applications.
The Autolearned Protocols Preferences Dialog Box (Figure 3-17) displays.
Figure 3-17 Autolearned Protocols Preferences Dialog Box
Step 3
Enter or change the information described in the Autolearned Protocols Preferences Dialog Box (Table 3-27).
Table 3-27 Autolearned Protocols Preferences Dialog Box
Field
|
Description
|
Usage Notes
|
Enable Autolearned Protocols
|
Enables the Autolearned Protocols feature.
|
Click checkbox to enable.
|
Maximum Autolearned Protocols
|
The maximum number of protocols that can be autolearned.
|
Enter a number from 100 to 500. The default is 100.
|
Maximum TCP Port
|
The maximum number of TCP ports that can be autolearned.
|
Enter a number from 0 to 65535.
|
Maximum UDP Port
|
The maximum number of UDP ports that can be autolearned.
|
Enter a number from 0 to 65535.
|
TCP Exclusion Port Range
|
Specifies range of TCP ports to be excluded.
|
Enter a number from 0 to 65535. (0 Disables)
|
Start
|
Specifies start of TCP ports to be excluded.
|
|
End
|
Specifies end of TCP ports to be excluded.
|
|
UDP Exclusion Port Range:
|
Specifies range of UDP ports to be excluded.
|
Enter a number from 0 to 65535. (0 Disables)
|
Start
|
Specifies start of UDP ports to be excluded.
|
|
End
|
Specifies start of UDP ports to be excluded.
|
|
Step 4
Click Apply to save your changes, or click Reset to cancel.
Setting Up URL-based Applications
URL-based applications are extensions to the protocol directory. When the URL in an HTTP request (a URL on TCP port 80) matches the criteria of a URL-based application, the traffic is classified as that protocol.
A URL-based application can be used the same way as any other protocol in the protocol directory. For example, a URL-based application can be used in collections, captures, and reports.
An incoming URL is matched against the criteria of the configured URL-based application, in the order of the index, until a match is found. When a match is found, the remaining URL-based applications are not considered.
This section contains the following sections:
•
Creating a URL-based Application
•
Editing a URL-based Application
•
Deleting a URL-based Application
Creating a URL-based Application
A URL consists of the following parts:
•
a host
•
a path
•
an argument
For example, in the URL http://host.domain.com/intro?id=123:
•
the host part is host.domain.com
•
the path part is /intro
•
the argument part is ?id=123
In the configuration of an URL-based application, the path part and the argument path are combined and called the path part.
Note
The match strings of the URL-based applications are POSIX limited regular expressions.
Note
A maximum of 64 URL-based applications can be defined.
To set up URL-based applications:
Step 1
Choose Setup > Protocol Directory.
Step 2
Click URL-Based Applications in the TOC.
The URL Matches Dialog Box (Figure 3-18) displays.
Figure 3-18 URL Matches Dialog Box
Step 3
Click Create.
The Create URL Match Entry Dialog Box (Figure 3-19) displays.
Figure 3-19 Create URL Match Entry Dialog Box
Step 4
Enter the information described in the URL Match Entry Dialog Box (Table 3-28).
RFC 2895 specifies rules for creating a protocol name. In accordance with these rules, only the following characters are allowed:
•
A through Z
•
a through z
•
0 through 9
•
dash (-)
•
underbar (_)
•
asterisk (*)
•
plus (+)
Note
All other characters are changed to a dash (-).
Table 3-28 URL Match Entry Dialog Box
Field
|
Description
|
Usage Notes
|
Index
|
URL Matches are executed in order of the Index
|
Enter a number from 1 to 64.
To change an index, the entry needs to be deleted and recreated with the new index value.
|
Encapsulation Protocol
|
The protocol that encapsulates the URL
|
Select IPv4 or IPv6 from the drop down box.
|
URL Host Part Match
|
POSIX regular expression that the host part is matched against
|
For example: domain.com.
|
URL Path Part Match
|
POSIX regular expression that the path and argument part of a URL is matched against
|
For example: /intro?id.
|
Content Type Match
|
Content-Type in HTTP headers that identify the data type the message; also known as MIME types
|
For example: application/octet-stream, text/html, or image/gif
|
Protocol Description
|
Name of the URL based application
|
For example: url-match-domain-com.
|
Step 5
Click Apply to save your changes, or click Reset to cancel.
Editing a URL-based Application
To edit URL-based applications:
Step 1
Choose Setup > Protocol Directory.
Step 2
Click URL-Based Applications in the TOC.
The URL Matches Dialog Box (Figure 3-20) displays.
Figure 3-20 URL Matches Dialog Box
Step 3
Select a URL and click Edit.
The Edit URL Match Entry Dialog Box (Figure 3-21) displays.
Note
When editing a URL-based application, the index can not be changed. To change the index (to change the order of execution) delete the URL-based application and recreate it.
Figure 3-21 Edit URL Match Entry Dialog Box
Change the information as described in the URL Match Entry Dialog Box (Table 3-28).
Step 4
Click Apply to save your changes, or click Reset to cancel.
Deleting a URL-based Application
To delete a URL-based application:
Step 1
Choose Setup > Protocol Directory.
Step 2
Click URL-Based Applications in the TOC.
The URL Matches Dialog Box (Figure 3-22) displays.
Figure 3-22 URL Matches Dialog Box
Step 3
Choose a URL and click Delete.
Setting Alarm Thresholds
You can set up alarm thresholds on the NAM by defining threshold conditions for the following monitored variables on the NAM:
•
Response times
•
Server-client response times
•
DiffServ host statistics
•
DiffServ traffic statistics
•
DiffServ application statistics
•
Voice protocols
•
Mini-RMON MIB on the switch
•
Network layer statistics
•
MAC layer statistics
•
Application statistics
Note
MAC layer and Mini-RMON statistics do not apply on NM-NAM and NME-NAM devices.
These topics help you set up and manage alarm threshold settings:
•
Setting NAM MIB Thresholds
•
Setting Voice Thresholds
•
Setting Up RTP Stream Thresholds
•
Setting Up the NAM Syslog
•
Setting Switch Thresholds
•
Setting NAM Trap Destinations
•
Setting NAM Alarm Mail
Setting NAM MIB Thresholds
NAM MIB thresholds are values you set that trigger alarms. Thresholds can be set on network hosts, MAC-layer hosts, network conversations, and MAC-layer conversations.
Note
MAC-layer hosts and conversations are not available on NM-NAM and NME-NAM devices.
Selecting NAM MIB Variables
To select NAM MIB variables:
Step 1
Choose Setup > Alarms.
Step 2
The Thresholds Table displays.
Step 3
Click Create.
Step 4
The Alarms wizard displays. The following table shows the steps used to create NAM MIB thresholds.
Selecting NAM MIB Parameters
To select NAM MIB parameters:
Step 1
Select the alarm variables from the Variable list. The Variable list displays the MIB variables for which thresholds can be configured.
Step 2
Select the network protocol from the Network Protocol list, then click Next.
The New Alarm Dialog Box (Table 3-29) displays.
Step 3
Select the appropriate information.
Table 3-29 New Alarm Dialog Box
Field
|
Description
|
Usage Notes
|
Data Source
|
Available data sources on the NAM.
|
Select the data source from the list.
|
Aggregate Group
|
Aggregate group of the selected DiffServ profile.
|
For DiffServ variables only.
|
Network Protocol
|
Selected protocol to be monitored.
|
This variable comes from Step 1 of the wizard.
|
Application Protocol
|
Application protocol to be monitored.
|
Select the application protocol from the list. For server and server-client response time variables only.
|
Variable
|
Selected variable to be monitored.
|
This variable comes from Step 1 of the wizard.
|
Server Address
|
Network address of the server.
|
For server and server-client response time variables only.
|
Client Address
|
Network address of the client.
|
For server-client response time variables only.
|
Network Address
|
Network address of host.
|
For network-layer host variables only.
|
MAC Address
|
MAC address of host.
|
For MAC-layer host variables only.
Note MAC variables are not available on NM-NAM and NME-NAM devices.
|
Dst Address
|
Destination IP or MAC address of the host.
|
For MAC- or network-layer conversation variables only.
Note MAC variables are not available on NM-NAM and NME-NAM devices.
|
Src Address
|
Source IP or MAC address of the host.
|
For MAC- or network-layer conversation variables only.
Note MAC variables are not available on NM-NAM and NME-NAM devices.
|
Interval
|
Interval in seconds for the sampling period to last.
|
Enter a decimal value.
|
Description
|
Description of the alarm.
|
Must not exceed 128 characters.
|
Sample Type
|
Type of sampling to be done.
|
• Click Absolute for an alarm to be triggered by an absolute value that is reached.
• Click the Delta for an alarm to be triggered by a change in the data rate.
|
Rising Threshold
|
Number of packets/octets that triggers the alarm. For response time alarms, it is the number of msec.
|
Enter a decimal number.
|
Falling Threshold
|
Number of packets/octets that triggers the alarm. For response time alarms, it is the number of msec.
|
Enter a decimal number.
|
Alarm Action
|
Action to be taken when the alarm is triggered.
|
• Click Log to log the event and display it in the Alarms tab.
• Click Trap to send the event to traps.
• Click Log and Trap to log the event and send it to traps.
|
Community
|
SNMP community to which traps are sent.
|
This community string must match the traps community string set in NAM traps.
|
Capture Trigger
|
Starts or stops the capture when the alarm threshold is triggered.
|
• Click None to disable Capture Triggers.
• Click Start to start the capture when the alarm threshold is triggered.
• Click Stop to stop the capture when the alarm threshold is triggered.
|
Step 4
Click Finish to accept your changes, or click Cancel to cancel.
Viewing Alarm Details from the NAM MIB Thresholds Table
To view details of a specific alarm from the NAM MIB Thresholds table, select the radio button, then click Details. The Alarms Details Table(Table 3-30) displays.
Table 3-30 Alarm Details Table
Field
|
Description
|
Variable
|
Monitored variable.
|
Data Source
|
Data source being monitored.
|
Address
|
Destination and source address of the hose.
|
Interval (seconds)
|
Interval of the sampling period.
|
Description
|
Description of the alarm.
|
Sample Type
|
Sample type of the alarm—absolute or delta.
|
Rising Threshold
|
The number of rising packets or octets that triggers the alarm.
|
Falling Threshold
|
The number of falling packets or octets that triggers the alarm.
|
Alarm Action
|
Action to be taken when the alarm is triggered.
|
Community
|
SNMP community where traps are sent.
|
Trigger Set
|
None, Start or Stop. Start indicates a capture process would start when this alarm is triggered. Stop means a capture process would stop when this alarm is triggered. None means no capture trigger is set for this alarm.
See Working with Automatic Capture (Alarm-Triggered Capture) for information about how to use the alarm-triggered capture feature.
|
Editing a NAM MIB Threshold
To edit a NAM MIB threshold:
Step 1
Choose Setup > Alarms.
The Thresholds table displays.
Step 2
Select the alarm to edit, then click Edit.
The Edit Alarm dialog box displays.
Step 3
Make the necessary changes.
Step 4
Click Submit to save your changes, or click Reset to cancel.
Deleting a NAM MIB Threshold
To delete a NAM MIB threshold, simply select it from the Alarms table, then
click Delete.
Setting Voice Thresholds
Voice threshold events can be logged locally on the NAM or sent to remote syslog hosts. For information on setting up syslogs, see the "Setting Up the NAM Syslog" section.
To set voice thresholds:
Step 1
Choose Setup > Alarms.
The NAM MIB Thresholds table displays.
Step 2
In the contents menu, click NAM Voice Thresholds.
The Voice Alarms Dialog Box(Table 3-31) displays.
Step 3
Select the appropriate information.
Table 3-31 Voice Alarms Dialog Box
Protocol
|
Condition
|
Threshold
|
SCCP
|
Jitter Threshold—Select to monitor jitter
|
Enter the threshold in milliseconds.
|
Pkt Loss Threshold—Select to monitor the number of packets lost
|
Enter the threshold as a percentage of total packets lost per call.
|
H.323
|
Jitter Threshold—Select to monitor jitter
|
Enter the threshold in milliseconds.
|
Pkt Loss Threshold—Select to monitor the number of packets lost
|
Enter the threshold as a percentage of total packets lost per call.
|
MGCP
|
Jitter Threshold—Select to monitor jitter
|
Enter the threshold in milliseconds.
|
Pkt Loss Threshold—Select to monitor the number of packets lost
|
Enter the threshold as a percentage of total packets lost per call.
|
SIP
|
Jitter Threshold—Select to monitor jitter
|
Enter the threshold in milliseconds.
|
Pkt Loss Threshold—Select to monitor the number of packets lost
|
Enter the threshold as a percentage of total packets lost per call.
|
Step 4
Click Apply to save your changes, or click Reset to leave the configuration unchanged.
Setting Up RTP Stream Thresholds
You can set up the NAM to monitor RTP streams to display packet loss statistics based on the RTP sequence number. When you set up the RTP stream thresholds and enable alarms, an EMail alarm message is sent to those configured under Admin > System > EMail Configuration. See E-Mail Configuration for information about how to configure EMail.
Step 1
Choose Setup > Alarms.
The NAM MIB Thresholds table displays.
Step 2
In the content menu, click NAM RTP Stream Thresholds.
The NAM RTP Steam Thresholds window displays. Table 3-32 describes the fields of the NAM RTP Steam Thresholds window.
Table 3-32 NAM RTP Steam Thresholds
Field
|
Description
|
Enable Alarm
|
Check to enable NAM RTP Stream Threshold alarms.
|
Number of Consecutive Packets Loss (1-10)
|
The number of consecutive packets lost; streams that lose more consecutive packets than the number entered here generate an alarm message.
|
Packet Loss Threshold (10-6)
|
The packet loss rate (1-100); streams that have a packet loss rate greater than the value entered here generate an alarm message.
|
Step 3
Enter a value (from 1-10) in the Number of Consecutive Packets Loss field.
Step 4
Enter a value (from 1-100) in the Packet Loss Threshold field.
Step 5
Check Enable Alarm, then click Apply to activate NAM RTP Stream Thresholds.
Setting Up the NAM Syslog
NAM syslogs are created for MIB threshold events, voice threshold events, or system alerts. The NAM maintains two syslog files, one for logging RMON threshold events (for MIB and voice threshold events) and one for logging local NAM system alerts.
You can specify whether syslog messages should be logged locally on the NAM, on a remote host, or both. You can use the NAM Traffic Analyzer to view the local NAM syslogs.
For information on viewing the syslogs, see "Viewing Alarms." You can use a standard text editor to view syslogs on remote hosts.
To set up the NAM syslog:
Step 1
Choose Setup > Alarms.
The NAM MIB Thresholds table displays.
Step 2
In the content menu, click NAM Syslog.
The NAM Alarms Syslog Dialog Box (Table 3-33) displays.
Step 3
Make the necessary changes.
Table 3-33 NAM Alarms Syslog Dialog Box
Field
|
Usage Notes
|
MIB Thresholds
|
• Select Local to log messages on your local system.
• Select Remote to log messages on a remote system.
|
Voice
|
• Select Local to log voice threshold syslogs on your local system.
• Select Remote to log voice threshold syslogs on a remote system.
|
RTP Stream
|
• Select Local to log RTP Stream threshold syslogs on your local system.
• Select Remote to log RTP Stream threshold syslogs on a remote system.
|
System
|
• Select Local to log system alert syslogs on your local system.
• Select Remote to log system alert syslogs on a remote system.
• Select Debug to log debug messages from the application to the syslog.
|
Remote Server Names
|
Enter the IP address or DNS name of up to 5 remote systems where syslog messages are logged. Each address you enter receives syslog messages from all three alarms (MIBs, Voice, and System).
|
Step 4
Click Apply to save your changes, or click Reset to cancel.
Setting Switch Thresholds
Note
This section does not apply to NM-NAM and NME-NAM devices.
You can configure RMON thresholds in the switch Mini-RMON MIB. You can specify only variables from the etherStatsTable in the Mini-RMON MIB to monitor for threshold-crossing conditions.
These topics help you set up and manage switch thresholds:
•
Creating Switch Thresholds
•
Editing Switch Thresholds
•
Deleting Switch Thresholds
Creating Switch Thresholds
Note
This section does not apply to NM-NAM and NME-NAM devices.
To create switch thresholds:
Step 1
Choose Setup > Alarms.
The Thresholds table displays.
Step 2
In the contents, click Switch Thresholds.
The Switch Threshold Alarms dialog box displays.
Step 3
Click Create.
The New Switch Alarm Dialog Box (Table 3-34) displays.
Table 3-34 New Switch Alarm Dialog Box
Field
|
Description
|
Usage Notes
|
Data Source List
|
Data source from the switch.
|
—
|
Variable
|
The following variables are available:
• Broadcast Pkts
• Collisions
• CRC Align Errors
• Drop Events
• Fragments
• Jabbers
• Multicast Pkts
• Bytes
• Oversize Pkts
• Packets
• Pkts size 64 Bytes
• Pkts 65 to 127 Bytes
• Pkts 128 to 255 Bytes
• Pkts 256 to 511 Bytes
• Pkts 512 to 1023 Bytes
• Pkts 1024 to 1518 Bytes
• Undersize Pkts
|
—
|
Interval (seconds)
|
Length of time, in seconds, for the sampling period to last.
|
Enter a decimal number.
|
Description
|
Description of the alarm.
|
Must not exceed 128 characters.
|
Sample Type
|
Type of sampling to be done.
|
• Click Absolute for an alarm to be triggered by an absolute value that is reached.
• Click Delta for an alarm to be triggered by a change in the data rate.
|
Rising Threshold
|
Number of packets/octets that trigger the alarm.
|
Enter a decimal number.
|
Falling Threshold
|
Number of packets/octets that trigger the alarm.
|
Enter a decimal number.
|
Alarm Action
|
Action to be taken when the alarm is triggered.
|
• Click Log to log the event and display it in the Alarms tab.
• Click Trap to send the event to traps.
• Click Log and Trap to log the event and send it to traps.
|
Community
|
SNMP community where traps are sent.
|
This community string must match the traps community string set on the switch.
|
Step 4
Click Apply to save your changes, or click Reset to cancel.
Note
If the switch is running a Catalyst operating system image, the switch alarm configuration is automatically stored. If the switch is running a Cisco IOS image, you can save the alarm configuration to NVRAM.
Editing Switch Thresholds
Note
This section does not apply to NM-NAM and NME-NAM devices.
To edit switch thresholds:
Step 1
Choose Setup > Alarms.
The Thresholds table displays.
Step 2
In the content menu, click Switch Thresholds.
The Switch Threshold Alarms dialog box displays.
Step 3
Select the alarm to edit, then click Edit.
The Edit Alarm dialog box displays.
Step 4
Make the necessary changes, then click Submit to save your changes, or click Reset to cancel and leave the configuration unchanged.
Deleting Switch Thresholds
Note
This section does not apply to NM-NAM and NME-NAM devices.
To delete an existing switch threshold alarm, simply select it from the Switch Threshold Alarms table, then click Delete.
Setting NAM Trap Destinations
Traps are used to store alarms triggered by threshold crossing events. When an alarm is triggered, you can trap the event and send it to a separate host.
These topics help you set up and manage NAM traps:
•
Creating a NAM Trap Destination
•
Editing a NAM Trap Destination
•
Deleting a NAM Trap Destination
Creating a NAM Trap Destination
To create a NAM trap destination:
Step 1
Choose Setup > Alarms.
The NAM MIB Thresholds table displays.
Step 2
In the content, click NAM Trap Destinations.
The Traps dialog box displays.
Step 3
Click Create.
The Create Trap Dialog Box (Table 3-35) displays.
Step 4
Enter the appropriate information.
Table 3-35 Create Trap Dialog Box
Field
|
Description
|
Community
|
The community string of the alarm community string set in the NAM MIB Thresholds.
|
Address
|
The IP address to which the trap is sent if the alarm and trap community strings match.
|
UDP Port
|
The UDP port number.
|
Step 5
Click Submit to save your changes, or click Reset to cancel and leave the configuration unchanged.
Editing a NAM Trap Destination
To edit a NAM trap destination:
Step 1
Choose Setup > Alarms.
The Thresholds table displays
Step 2
In the contents, click NAM Traps.
The Traps dialog box displays.
Step 3
Select the trap to edit, then click Edit.
The Edit Trap dialog box displays.
Step 4
Make the necessary changes.
Step 5
Click Submit to save your changes, or click Reset to cancel and leave the configuration unchanged.
Deleting a NAM Trap Destination
To delete an existing trap, simply select it from the Traps table, then click Delete.
Setting NAM Alarm Mail
Note
NAM alarm mail is sent as a result of NAM alarms, not router or switch alarms.
You can configure the NAM to send email to one or more addresses in the case of a NAM alarm. To configure EMail alarms:
Step 1
Choose Setup > Alarms.
Step 2
From the content menu, click NAM Alarm Mail.
The Alarm Mail Configuration dialog box displays.
Step 3
In the Mail Alarm to field, enter one or more EMail addresses to receive the NAM alarm mail.
Use an EMail address such as jdoe@cisco.com. Use a space to separate multiple EMail addresses.
Setting Global Preferences
Global preferences settings apply to all users of the NAM and determine how data displays are formatted. To set up global preferences.
Step 1
Choose Setup > Preferences.
The Preferences Dialog Box (Figure 3-23) displays.
Figure 3-23 Preferences Dialog Box
Step 2
Enter or change the information described in the Preferences Dialog Box (Table 3-36).
Table 3-36 Preferences Dialog Box
Field
|
Description
|
Usage Notes
|
Entries Per Screen
|
The number of rows to display in tabular screens.
|
Enter a number from 1 to 100. The default is 15.
|
Refresh Interval
|
The number of seconds between monitor display refreshes.
|
Enter a number from 15 to 3600. The default is 60.
|
Number Graph Bars
|
The number of graph bars to display in TopN displays and charts.
|
Enter a number from 1 to 15. The default is 10.
|
Perform IP Host Name Resolution
|
Display DNS names, if available.
|
Select to enable or deselect to disable. Enabled by default.
Note Enabling IP host name resolution without configuring nameservers might result in slow response times.
|
Data Displayed in
|
Option to display data in bits or bytes.
|
Select Bytes or Bits. Default is bytes.
|
Format Large Numbers
|
Display large integer values in appropriate units with prefixes such as Kilo (K), Mega (M), Giga (G) and Tera (T.)
|
Check box to format large numbers. If this box is unchecked, large numbers are not formatted. The default is unchecked.
|
International Notation
|
You have the option to print numbers in the following format:
1,025.72
1.025,72
1 025,72
|
Default is 1,025.72
|
CSV Export Monitor Entries
|
Provides the option to CSVexport all entries in a particular monitor table or just the current entries displayed on a particular window.
|
Default is Current Window Only.
|
Audit Trail
|
Check box to enable or disable the audit trail.
|
Enables the recording of critical user activities to an internal log file. By default, the audit trail is enabled.
See also:
• Viewing the Audit Trail, for information about audit trail entries
• Setting Up the NAM Syslog, for information about setting up remote file storage
|
ESP-Null Heuristic
|
Enables NAM to detect ESP-null encryption and parse content as described in Internet RFC 2410.
|
Enabling ESP-Null Heuristic forces the NAM to check all packets with an ESP header to see if it could be using Null encryption. The ESP-Null Heuristic feature adds processing overhead, so it is disabled by default.
|
Step 3
Click Apply to save your changes, or click Reset to cancel.