Podcast
Questions and Answers
What responsibility does an organization have when incorporating third-party content?
What responsibility does an organization have when incorporating third-party content?
What should an organization do before integrating custom scripts or recommendations?
What should an organization do before integrating custom scripts or recommendations?
What type of products does SolarWinds offer for free trials?
What type of products does SolarWinds offer for free trials?
Which aspect of SolarWinds products is emphasized in their development?
Which aspect of SolarWinds products is emphasized in their development?
Signup and view all the answers
What should an organization consider when choosing to use third-party scripts?
What should an organization consider when choosing to use third-party scripts?
Signup and view all the answers
Which field represents the source autonomous system number in BGP?
Which field represents the source autonomous system number in BGP?
Signup and view all the answers
Which of the following fields must be included in the template for the packets group to avoid showing 0 in the packets column?
Which of the following fields must be included in the template for the packets group to avoid showing 0 in the packets column?
Signup and view all the answers
What does the ApplicationID field signify in the context provided?
What does the ApplicationID field signify in the context provided?
Signup and view all the answers
If you want to specify the destination TCP port, which field should you refer to?
If you want to specify the destination TCP port, which field should you refer to?
Signup and view all the answers
In the context of BGP, what does the field PeerSrcAS represent?
In the context of BGP, what does the field PeerSrcAS represent?
Signup and view all the answers
Which of the following fields indicates the destination TCP/UDP port?
Which of the following fields indicates the destination TCP/UDP port?
Signup and view all the answers
Which type of service is indicated by the ToS field?
Which type of service is indicated by the ToS field?
Signup and view all the answers
What is the minimum requirement for including source ports in the template?
What is the minimum requirement for including source ports in the template?
Signup and view all the answers
What is the first step to enable NetFlow monitoring for selected nodes?
What is the first step to enable NetFlow monitoring for selected nodes?
Signup and view all the answers
How often does the SolarWinds NPM polling engine collect network information for nodes after the initial data collection?
How often does the SolarWinds NPM polling engine collect network information for nodes after the initial data collection?
Signup and view all the answers
What occurs after SolarWinds NTA is installed and devices are added?
What occurs after SolarWinds NTA is installed and devices are added?
Signup and view all the answers
What should you verify before leaving SolarWinds NTA to gather data?
What should you verify before leaving SolarWinds NTA to gather data?
Signup and view all the answers
What is the purpose of enabling NetFlow and CBQoS monitoring?
What is the purpose of enabling NetFlow and CBQoS monitoring?
Signup and view all the answers
How does SolarWinds NTA detect and analyze flow data after a device is added?
How does SolarWinds NTA detect and analyze flow data after a device is added?
Signup and view all the answers
Which setting path is correct to disable flow sources in SolarWinds?
Which setting path is correct to disable flow sources in SolarWinds?
Signup and view all the answers
What signifies an increase in CPU usage after adding a device to the SolarWinds Platform database?
What signifies an increase in CPU usage after adding a device to the SolarWinds Platform database?
Signup and view all the answers
What is the first step to filter network traffic by IP address groups?
What is the first step to filter network traffic by IP address groups?
Signup and view all the answers
What action should you take to view network traffic using specific protocols?
What action should you take to view network traffic using specific protocols?
Signup and view all the answers
Which option allows you to add more filtering criteria for IP address groups?
Which option allows you to add more filtering criteria for IP address groups?
Signup and view all the answers
What does the Local NetFlow Source provide information about?
What does the Local NetFlow Source provide information about?
Signup and view all the answers
Which feature is enabled by default when installing NTA version 4.6 and later?
Which feature is enabled by default when installing NTA version 4.6 and later?
Signup and view all the answers
What is necessary to save your custom filtered view in the Flow Navigator?
What is necessary to save your custom filtered view in the Flow Navigator?
Signup and view all the answers
What are the available functions provided by the Local NetFlow Source?
What are the available functions provided by the Local NetFlow Source?
Signup and view all the answers
What happens when you expand the Types of Service section?
What happens when you expand the Types of Service section?
Signup and view all the answers
What is the correct method to add multiple domains in the Flow Navigator?
What is the correct method to add multiple domains in the Flow Navigator?
Signup and view all the answers
Which notation can be used to specify a range of IP addresses when including or excluding traffic from a subnet?
Which notation can be used to specify a range of IP addresses when including or excluding traffic from a subnet?
Signup and view all the answers
When entering an IP address group in Flow Navigator, what indicates that the group is inactive?
When entering an IP address group in Flow Navigator, what indicates that the group is inactive?
Signup and view all the answers
What happens if a domain name is not resolved in NTA when trying to filter traffic?
What happens if a domain name is not resolved in NTA when trying to filter traffic?
Signup and view all the answers
Which of the following is NOT a step for including or excluding traffic related to specific endpoints?
Which of the following is NOT a step for including or excluding traffic related to specific endpoints?
Signup and view all the answers
Which action must be taken to exclude traffic from a specified subnet?
Which action must be taken to exclude traffic from a specified subnet?
Signup and view all the answers
What should you do if you want to include additional endpoints after your first entry?
What should you do if you want to include additional endpoints after your first entry?
Signup and view all the answers
To filter out specific IP address groups in Flow Navigator, which of the following is required?
To filter out specific IP address groups in Flow Navigator, which of the following is required?
Signup and view all the answers
What could cause the 'Last Received Netflow' to show 'Never' or a past date?
What could cause the 'Last Received Netflow' to show 'Never' or a past date?
Signup and view all the answers
Which of the following best describes a likely situation where Netflow data might not be received?
Which of the following best describes a likely situation where Netflow data might not be received?
Signup and view all the answers
What aspect of Netflow Sources does the issue primarily affect?
What aspect of Netflow Sources does the issue primarily affect?
Signup and view all the answers
If a Netflow device is working properly, what should the 'Last Received Netflow' indicate?
If a Netflow device is working properly, what should the 'Last Received Netflow' indicate?
Signup and view all the answers
Which action might help resolve the issue of displaying 'Never' in the Last Received Netflow?
Which action might help resolve the issue of displaying 'Never' in the Last Received Netflow?
Signup and view all the answers
What is a common sign that the Netflow source is not sending data?
What is a common sign that the Netflow source is not sending data?
Signup and view all the answers
What troubleshooting step is NOT relevant when addressing the Netflow reception issue?
What troubleshooting step is NOT relevant when addressing the Netflow reception issue?
Signup and view all the answers
Which scenario would NOT likely cause the Last Received Netflow to show a past date?
Which scenario would NOT likely cause the Last Received Netflow to show a past date?
Signup and view all the answers
Study Notes
NTA Flow Requirements
- SolarWinds NTA supports various flow protocols, including NetFlow, sFlow, J-Flow, and IPFIX.
- NetFlow versions 1, 5, and 9 are supported. NetFlow v9 requires a template with all necessary fields.
- sFlow versions 2, 4, and 5 are supported.
- J-Flow versions 2, 4, and 5 are supported.
- IPFIX is supported for IPv4 traffic generated by ESX 5.1 and later, and by VMware vSwitches.
- NetStream versions 5 and 9 are supported.
- NetFlow Lite is supported on Cisco Catalyst 2960-X, 2960-XR, 3560-CX, and 2960-CX devices.
- Some devices export flows without specifying sampled status; SolarWinds NTA treats these flows as unsampled.
Cisco Flexible NetFlow Configuration
- Exporting flows on some Cisco devices (like the 4500 series with Supervisor 7) requires Flexible NetFlow.
- Scripts and documentation are not guaranteed and carry no warranty.
- The example provided demonstrates a proper configuration for a Cisco 4507 with Supervisor 7 to successfully export flows.
Difference Between Polling Engine and Collector in NTA
- Flow collectors gather flow records from devices that have flow-enabled.
- Collectors process and analyze the gathered flow data, and present the data in a web-based interface.
- Polling engines ping devices to request data.
- SolarWinds NTA is a collector, not a polling engine.
How NTA Works
- SolarWinds NTA collects CBQoS and flow data, processes it, and presents it in reports.
- NTA analyzes bandwidth consumption based on user, applications, protocols, and IP address groups
- NTA tracks conversations (internal and external)
- NTA provides detailed traffic analysis over time intervals (minutes, days, or months).
- Data travels from flow-enabled devices to the NTA collector which stores data in the NTA Flow Storage database.
- CBQoS implementations function similarly to flow-enabled implementations, except NetFlow collector polls each device.
NTA Supported Protocols
- Supported flow protocols in NTA include NetFlow, sFlow, J-Flow, and IPFIX.
- Sampled flow data collection collects a sample of the data.
- Non-sampled flow data collection collects all the data.
- NetFlow v9 configuration is the same as version 5 but uses a predefined template that is exported in separate flows.
- sFlow v2, v4, and v5 are supported.
- J-Flow is supported.
- IPFIX is supported for IPv4 traffic from ESX 5.1 and later. NetStream v5 and v9 are supported.
Setting Up Network Devices to Export NTA Data
- Configure your devices to send flow data to NTA on port 2055 (default).
- Each device must be configured to export data to NTA and monitored by NPM.
- Interfaces exporting data to NTA must be monitored in NPM.
- Interface index numbers must match in the collected flow data.
Flow Environment Best Practices
- Determine where to enable NetFlow for optimal data visibility and performance. Prioritize core or distribution layers over access layers.
- Be mindful to ensure traffic data collection is not unnecessarily duplicating data.
Required Fields in SolarWinds NTA
- NTA uses templates with mandatory and optional fields to structure flow data.
- Failure to include required fields will result in the flow data being ignored.
- The required fields are determined by the device exporting the flows,
- Several field types are detailed, including Protocol, Source Address, Destination Address, InterfaceRx, Bytes, InitiatorOctets, ResponderOctets, and optional fields.
Add Flow-Enabled Devices and Interfaces to the Database
-
Specify the NTA server as the destination for flow data exports.
-
Only devices with discovered interfaces by NPM can be added as flow sources.
-
Flow-enabled devices in the NTA database must be designated as flow sources.
-
Separately add devices to NPM and designate them as flow sources in NTA.
Disable Flow Sources and Enable/Disable CBQoS-Enabled Devices
- Disable NetFlow and CBQoS monitoring through the NTA settings in the SolarWinds Platform Web Console.
NTA Charts
- NTA charts summarize widget-related data, displaying different types, including stack area, stack spline area, stack line, line, spline, and bar charts.
- Pie charts in NTA show the Top 5 Endpoints widget with absolute percentages.
- Charts offer features for zooming, disabling data series, and interactive exploration for detailed view.
Create Custom Views with NTA
- Use the Flow Navigator to create custom traffic views.
- These views can contain multiple conditions on devices, applications, time periods, or other criteria.
- Configure filters by selecting particular application types or particular IP addresses or hostnames.
Local NetFlow Source
- The Local NetFlow Source in SolarWinds NTA can present live traffic data from the main polling engine, providing a basic insight.
- When installing NTA 4.6 or later, and upgrading a previous version, the Local NetFlow Source requires manual enablement.
- Managing the Local NetFlow Source occurs through operations in the SolarWinds Platform Web Console.
NBAR Applications
- SolarWinds NTA monitors NBAR2 application traffic, using application classification.
- Displays unknown or unclassified applications based on available classifications.
Monitor Applications and Service Ports
- To monitor ports or applications in NTA, configure them in the NTA Settings -> Application and Service Ports section.
IP Address Groups Unification with IPAM
- NTA 2020.2 can unify IP address groups with SolarWinds IPAM.
- Import IPAM IP address groups to use the same way as standard NTA IP address groups.
- Use IP address groups in Flow Navigator or NTA searches.
NTA Settings Page
- Contains settings for NetFlow management, applications and service ports, or autonomous systems.
- Provides options for managing these settings.
Top Talker Optimization in NTA
- Top Talker Optimization reduces processing load by filtering less bandwidth-intensive flows.
- Configure the maximum percentage of traffic to collect.
NetFlow Collector Services
- Monitor NetFlow collector services to view their status.
- The status and ports that collectors are listening to for NetFlow data are provided.
Edit or Add Collection Ports in NTA
- Allows modification of listening ports for flow packets.
DNS Resolution Options in NTA
- NTA supports options for DNS resolution of IP addresses to hostnames.
- There are options for immediate resolving (default) and on-demand resolving.
How Default DNS Resolution Works in NTA
- Hostnames are stored directly in individual flows.
- NTA waits for DNS server responses, then uses the resolved hostname for flows from the IP address for the next 7 days.
- If there's no DNS resolution after a minute, querying is repeated.
- Unresolved hostnames are stored based on their IP addresses.
Troubleshoot Collector Services in NTA
- Troubleshoot issues by checking the status of the SolarWinds NetFlow Services.
- Ensure the database connection, CPU, and memory are sufficient and working correctly.
Configure Flow Alerts
- Configure alerts based on custom SWQL queries, not just default thresholds.
Configure the Alert Application Present in Top Applications/Application Not Present
- Application, or NBAR2 application in Top Applications and NBAR2 Applications lists; missing in the applicable widgets.
Configure the Alert NetFlow source not receiving any data.
- Alert when a node or interface does not send data over a defined time period.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge on the responsibilities of organizations when incorporating third-party content and the essentials of managing network products like those from SolarWinds. This quiz covers various aspects of network management, including BGP fields and packet templates. Enhance your understanding of best practices in network management.