Fluke Computer Accessories Protocol, Source port, Dest port, Src/dest port, Source application

Page 33

User’s Guide – version 3.5

NetFlow Tracker

Protocol

You can restrict the set of IP protocols considered. For example, you may want to consider only UDP or ICMP traffic while investigating a denial-of-service attack.

Source port

The source port filter restricts the source application port number; it should be used in conjunction with the protocol filter.

Dest port

This restricts the destination application port number.

Src/dest port

This filter will consider traffic with the given port number as either the source or destination.

Source application

The source application filter restricts the IP protocol and source application port number. You can enter a port number and protocol manually or you can select from the configured in the IP Application Names settings page.

Dest application

This restricts the protocol and destination application port, selectable by name.

Src/dest application

This filter considers traffic using the given application as either the source or destination.

Recognised application

This filter selects traffic with the given source or destination application. Whether the source or destination application is considered depends on whether it has a name defined in the IP Application Names settings page, or if both or neither have names, whichever has the lower port number.

Identified application

This filter selects traffic with the given identified application. In order for applications to be identified the NetFlow device must support the functionality and its identified application mapping must be configured in Device Settings.

ToS

You can report only on traffic bearing any one of a set of type-of-service byte values. You build the ToS byte value by picking the priority and the minimize delay (D), maximise throughput (T), maximise reliability (R) and minimise monetary cost (M) flags. If you leave the priority or any of the flags empty then only the fields you supplied a value for are considered. Thus you can match traffic of a given priority with any flags, or with particular flags set or unset but any priority and any values for the other flags.

33

Image 33
Contents NetFlow Tracker Contents LONG-TERM Reports Appendix 2 CSV File Format Grant of Licence and Payment of Fees Software License AgreementCopyright Customer Remedies Confidential Information and Security User’s Guide version NetFlow Tracker Definitions Support Charges Support ServicesUndertakings by You Supplier’s UndertakingsLimitation of Liability and indemnity Intellectual Property RightsTermination Miscellaneous Confidential Information and SecurityExceptions to Support Services Support HoursResponse Times What is NetFlow Tracker? What is NetFlow?Features and Benefits IntroductionUser’s Guide version NetFlow Tracker Pre-installation Checks InstallationMinimum System Requirements Operating System SupportInstallation on Microsoft Windows Installation on Linux Post-installation Tasks Set up web front-end security Set up Snmp community stringsConfigure your routers and switches Add listener portsUsing NetFlow Tracker Interfaces Device traffic metersChanging the displayed chart Working with ChartsChart legend Per-AS dataView a standard chart as a tabular report View a standard chart as a pie chartZooming Zooming outExport a chart to another application Alter the filter applied to a standard chartPrint the chart Open the chart in a new windowWorking with Tabular Reports Working with Pie ChartsExamine a single row Sort a tabular reportReport Templates Address ReportsSession Reports Network Reports QoS ReportsInterface Reports Creating Filtered ReportsTraffic Identification Reports Other ReportsSample size Report templateSource data Start timeSource device Time zoneInterface Out interfaceSource port ProtocolDest port Src/dest portTraffic class DiffServSource AS Dest ASDevices and Interfaces Long-term ReportsPer-device and Per-interface Long-term Reports Filter EditorUser’s Guide version NetFlow Tracker Reports Report URL Format General FormReport Format Parameters 0024 00230025 0026Pie ChartNumber TrueSections Features128 256Time Range Parameters Hour MillisDay WeekCalendar-based advanced Time range will extend for this number of unitsHHmm Applying a time-of-day mask to the time rangeDay1-day2/time1-time2 105 110100 113120 115140 125300 285Minute DailyFilter Parameters Name Addr1-addr2Port1-port2 Port/number Port/namePort1-port2/name Port1-port2/numberTos PrecPrec%20tos CodeMask Addr/maskPassword Security ParametersUsername Management Portal Access Control Parameters SecretNull VPN Out VPN Chart selection headers Chart scrollbarFilter Editor button, if applicable Refresh and Resolve All buttons, if applicableDatabase Server Settings Performance TuningDisk Speed Query SizeSnmp Settings Configuration GuideLicensing Listener PortsDevice Settings Device SettingsDevice List Sampled Data Scaling VPNs Security SettingsHttp//proxy/tracker1/report1 Management Portal SettingsHttp//tracker1/report.jsp?portalsecret=secret&aclif= Http//proxy/tracker1/report.jsp?portalacl=RewriteEngine On Using Apache as a Portal ServerRewriteRule /tracker1/.*$ http//1.2.3.4/$1 P,L,QSA ProxyPassReverse /tracker1/ http//1.2.3.4Report Settings General SettingsReal-time Reports Scheduled Reports Saved FiltersLong-term Reports Executive Reports Span class=repdesctextTest/span Nelements=5 and chartWidth=400 ContentSub-reports User’s Guide version NetFlow Tracker Hostname Resolution Settings IP Application NamesDiffServ Names Database Settings AS NamesSubnet Names Backup Memory Settings ArchivingPerformance Counters Traffic Described NetFlow Data ReceivedIgnored Flows Unprocessed FlowsetsNo In Interface AboutEnabling Netflow Export on an IOS Device Appendix 1 Device ConfigurationIp cef Ip flow-export destination addressIp flow-cache timeout inactive Ip flow-cache timeout activeShow ip flow export Show ip cache flow Show ip cache verbose flowMls netflow Ip route-cache flow infer-fieldsMls nde sender version Mls aging longUser’s Guide version NetFlow Tracker Set mls nde enable Set mls bridged-flow-statistics enable vlanlistSet system name name Set mls nde addressEnabling Flow Detail Records on a Packeteer Device Flow-sampler-map allflows mode random one-out-of 1 exitEnabling NetFlow on an Enterasys Device Pie chart CSV format Chart CSV formatAppendix 2 CSV File Format Tabular report CSV formatPie chart XML format Chart XML formatAppendix 3 XML Format Tabular report XML formatAppendix 4 Third Party Software Components JspSmartUpload Quartz