Professional Documents
Culture Documents
Notes: Introduction To Networking Monitoring and Management
Notes: Introduction To Networking Monitoring and Management
Introduction to Networking
Monitoring and Management
Part I: Overview
Core concepts presented:
– What is network monitoring
– What is network management
– Getting started
– Why network management
– The big three
– Attack detection
– Documentation
– Consolidating the data
– The big picture
Network Management Details
We Monitor
• System & Services
– Available, reachable
• Resources
– Expansion planning, maintain availability
• Performance
– Round-trip-time, throughput
• Changes and configurations
– Documentation, revision control, logging
Network Management Details
We Keep Track Of
• Statistics
– For purposes of accounting and metering
• Faults (Intrusion Detection)
– Detection of issues,
– Troubleshooting issues and tracking their history
Availability
– Nagios Services, servers, routers,
switches
Reliability
– Smokeping Connection health, rtt, service
response time, latency
Performance
– Cacti Total traffic, port usage, CPU
RAM, Disk, processes
Functional overlap exists between these programs!
Attack Detection
• Trends and automation allow you to know
when you are under attack.
• The tools in use can help you to mitigate
attacks:
– Flows across network interfaces
– Load on specific servers and/or services
– Multiple service failures
Network Operations Center (NOC)
- Monitoring Notifications
- Data collection
- Accounting
Ticket
- Change control &
monitoring
- Capacity planning
Ticket
- NOC Tools - Availability
- Ticket system - Trends
- Detect problems
Ticket
Ticket
- Improvements
- Upgrades
Ticket - User complaints
- Requests
- Fix problems
A few Open Source solutions…
Performance Change Mgmt Net Management
l Cricket l Mercurial l Big Brother
l IFPFM l Rancid* (routers) l Cacti*
l flowc l CVS* l Hyperic
l mrtg* l Subversion* l Munin
l NetFlow* l git* l Nagios*
l NfSen* Security/NIDS l OpenNMS*
l ntop l Nessus l Observium*
l perfSONAR l OSSEC l Sysmon
l pmacct l Prelude l Zabbix
l RRDtool* l Samhain Documentation
l SmokePing* l SNORT • IPplan
Ticketing l Untangle • Netdisco
l RT* Logging • Netdot*
• swatch* • Rack Table
l Trac*
• syslog-ng/rsyslog* Protocols/Utilities
l Redmine
• tenshi* • SNMP*, Perl, ping