Understanding nprobe
Andreas Brück <[email protected]> Fri, 28 Jun 2019 10:50:38 +0200
| Newsgroups | gmane.linux.ntop.general |
|---|---|
| Message-ID | <[email protected]> |
--===============3199190100136087891==
Content-Type: multipart/alternative;
boundary="------------763E3629BDB5248C6C6210F3"
Content-Language: en-US
--------------763E3629BDB5248C6C6210F3
Content-Type: text/plain; charset="utf-8"; format=flowed
Content-Transfer-Encoding: 7bit
Hello everybody,
i have build up a virtual test environment to get familiar with flow
monitoring. I installed ntop on a server and nprobe on a gateway
(provides access to the internet). I hoped that nprobe is collecting all
the traffic/flows and send it to the ntop server. But it does not work
work me. I don't see any flows if i check it on the ntop web gui. Both
machines could ping each other and no firewall is between them.
I used the following configuration:
Ntop-server (ip-address: 194.95.66.100, interface: enp0s8):
- ntopng -i enp0s8 -i tcp://8.8.8.1:5556
Gateway (ip-address: 8.8.8.1, interface: enp0s8):
- nprobe --zmq tcp://8.8.8.1:5556 -i enp0s8 -n none -T @NTOPNG@
If i check the sockets with "ss" there is a established zmq connection
listed between this to server. I also can choose the interface
"tcp://8.8.8.1:5556" in the ntop web gui. But no traffic will be
reported to ntop. I generated traffic with iperf, which comes from a
third server. This traffic transited the gateway interface enp0s8 with
the ip address 8.8.8.1.
It is possible that i missundertood the function of nprobe? Can i use
only nprobe instead of sflow to collect flows or it is necessary to
combine them? I hope anyone could help me. Thank you very much in advance.
Regard,
Andreas
<https://dict.leo.org/german-english/misunderstood>
--------------763E3629BDB5248C6C6210F3
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: 7bit
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p><tt>Hello everybody,</tt></p>
<p><tt>i have build up a virtual test environment to get familiar
with flow monitoring. I installed ntop on a server and nprobe on
a gateway (provides access to the internet). I hoped that nprobe
is collecting all the traffic/flows and send it to the ntop
server. But it does not work work me. I don't see any flows if i
check it on the ntop web gui. Both machines could ping each
other and no firewall is between them.<br>
</tt></p>
<p><tt>I used the following configuration:</tt></p>
<p><tt>Ntop-server (ip-address: 194.95.66.100, interface: enp0s8):</tt></p>
<p><tt>- ntopng -i enp0s8 -i tcp://8.8.8.1:5556</tt></p>
<p><tt>Gateway (ip-address: 8.8.8.1, interface: enp0s8):</tt></p>
<p><tt>- nprobe --zmq tcp://8.8.8.1:5556 -i enp0s8 -n none -T
@NTOPNG@</tt></p>
<p><tt>If i check the sockets with "ss" there is a established zmq
connection listed between this to server. I also can choose the
interface "tcp://8.8.8.1:5556" in the ntop web gui. But no
traffic will be reported to ntop. I generated traffic with
iperf, which comes from a third server. This traffic transited
the gateway interface enp0s8 with the ip address 8.8.8.1.</tt></p>
<p><tt>It is possible that i missundertood the function of nprobe?
Can i use only nprobe instead of sflow to collect flows or it is
necessary to combine them? I hope anyone could help me. Thank
you very much in advance.</tt></p>
<p><tt>Regard,</tt></p>
<p><tt>Andreas</tt><br>
<tt></tt><tt><a
href="https://dict.leo.org/german-english/misunderstood"><mark></mark></a></tt>
</p>
<p><br>
</p>
</body>
</html>
--------------763E3629BDB5248C6C6210F3--
--===============3199190100136087891==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
--===============3199190100136087891==--