 |
|
 |
 |
InMon Traffic Sentinel uses the sFlow protocol for traffic monitoring. This section provides the command syntax for configuring sFlow on a ProCurve switch.
» Return to top
4.1 Configure destination collectors On each switch, three destinations (collectors) can be configured:
For example, to configure destination 1 to be 10.3.108.36:
The default UDP port used for sFlow is 6343.
» Return to top
4.2 View destination information
To view information about a destination:
For example:
» Return to top

4.3 Activate sampling and polling
To activate sampling on a set of switch ports, use:

Where N is the number of sampled packets. N can vary between 0 (sampling disabled) and 16441700.
For example:
To activate polling on a set of switch ports:

Where P is the interval in seconds between two polls of counters. P can vary between 0 (polling disabled) and
16777215.
» Return to top

4.4 View sampling and polling statistics
To view sampling and polling statistics:

» Return to top
|
 |
 |
|
 |
 |
This section uses a data center example to explain how to set up traffic monitoring using InMon Traffic Sentinel.
5.1 Configure basic settings
To configure basic settings for InMon Traffic sentinel:
- Access Traffic Sentinel from its web interface.
- Browse to the File | Configure menu. There you have three options:
- The Show tab shows you the actual configuration.
- The Edit tab allows you to modify the configuration.
- The XML tab enables you to import or export a configuration in XML format.
- Select the Edit tab. In the Edit tab you have the following options:

- Edit Site enables you to define the name and contact information, and also to input your license key:

- Edit Zones allows you to divide your network into different logical zones, and within these zones to define groups of subnets, agents, interfaces.
For example, a zone can physically correspond to a site, and groups can correspond to different buildings within the site.
- In this data center example, you create one zone, corresponding to the whole data center, and 10 groups (labeled Area 1, Area 2, etc.) corresponding to the different solution areas. You create a distinct group, called BackBone, for the network backbone:

- For each group you can define agent ranges. Then you go to Edit Agents to define the individual agents corresponding to the network equipment:
- Within the File | Configure | Edit view, you can define threshold settings and SNMP parameters.
- Finally, you can go to Edit Sampling Settings to define sampling rates for the different interface speeds:

» Return to top
5.2 Set up traffic monitoring
To set up traffic monitoring:
- 1. Select Traffic | Status to see an overview of status of the different traffic metrics for each zone and group:

- To view more details about a particular metric, click on one of the colored square indicators.
For example, you notice that the BackBone group is experiencing heavy multicast traffic (in red) and you want to determine which machines or applications are causing this multicast. Click on the square red BackBone indicator to display the list of sFlow agents, corresponding to the switches of the group. In this example, the top 10 interfaces with multicast traffic are listed:
- Another way to have a good overview of what is generating traffic on the network is to use the circles function (Traffic | Circles):

This gives a graphical representation of the most important connections between machines on the network.
- You can then click on a particular connection to display a Path Between Hosts screen with information about the corresponding flow:

- To obtain more information about a particular host, in the Path Between Hosts window click on one of the MAC Source or MAC Destination addresses. You then see a Find Host window, where you can choose between different views of the traffic:
» Return to top
5.3 Traffic views
Here are some of the traffic views that are available.
Clicking Connections gives top connections to and from this machine:
Clicking Protocols gives a view of the most used protocols for this MAC address over time:
Factors view gives the proportion of each connection in percent of the flows, total frames and total bytes of the link to this machine:
A Circles view for this machine is also available:
You have a wide variety of traffic types to display in charts:
» Return to top
5.4 Reporting To view the trends for a particular flow over a longer period, the reporting function is useful. To specify the type of
reports:
- On the Traffic Sentinel menu bar click on Reports. You see the available reports arranged by Category:
- Then you can choose a custom report.
For example if you select IP Multicast, you see a report that displays the IP Multicast activity on the network. You see activity reports for the top Multicast Groups, Multicast Sources, and Multicast Trends. This report can be exported as a .PDF or a .HTML file. For example:
- IP Multicast: Shows IP multicast activity on the network.
- Top Multicast Groups: Shows top IP multicast addresses by amount of traffic. For example:

- Top Multicast Sources: Shows Top IP multicast sources by amount of traffic. For example:

- Multicast Trend: Shows trends for total IP multicast activity over time:
» Return to top
|
 |
|