SourceForge.net Logo



NER white paper

   
   
 
   
 
 
 
 
 
 

 
 
Table of content
  1. Introduction
  2. NER position on the network
  3. Main NER benefits
  4. On demand reports
  5. Monitoring tasks
  6. Exportation tasks
  7. Material and OS pre-requisites
 
 
 
 
 
 
 
 
 
 

 
 
SourceForge.net Logo  

Introduction

Currently, we don't get an accurate picture of how are used our networks, which computers are consuming most of the bandwidth, in which proportion, at what period of the day.
This deficiency could be satisfied with the traceability of data exchanged between all computers communicating over the networks.
From this knowledge, we could focus our efforts on real causes of  bandwidth soaring.
In the end, networks cost would be better controlled.

NER(Network Exchanges Reporter) is an answer to our needs on network traceability.
It holds the history of all network exchanges between computers for years.

Its mains assets are:

  • to lower networks infrastructures costs by detecting computers abusing bandwidth.
  • to get a complete knowledge on any past period of networks exchanges on a communication node.
  • to anticipate critical applications performances issues by detecting increase of servers  responses time.
  • to provide crucial information on networks exchanges between computers involved in an incident which may occurred several weeks ago.

 

 

 

 

 

 
SourceForge.net Logo

NER position on the network


NER position on network nodes In general, Network Exchanges Reporter is composed of several network interfaces dedicated to capture network packets.
Each network interface is connected to a communication node which is physically a port of a switch set as mirroring other ports.


 
 
 
 
 
 
 SourceForge.net Logo

Main NER benefits


High visibility on network  exchanges
You'll know with a high precision, which pairs of communicating computers are consuming most of your bandwidth.
You'll know on any past period, response time of all ports of communication of each network actor.

 
Relevant analysis tool when an incident occurs
NER brings key elements on network activity on the period of the incident.
It enables to better understand causes and effects of the incident.
 
 
Detect abuses and anomalies
Creation of monitoring tasks on many criteria permits to trigger alerts when thresholds are reached.
Thus, we can easily detect bandwidth abuses, or being alerted in case response time of crucial servers is rising.

 
 
Brings the proof in case of dispute
NER logs all network exchanges between computers, so it will tell who's doing what for the target time frame.


 
 

 
Visibility on the evolution of traffic and computers response time
On any selected period, NER shows you the evolution of the traffic and response time on any group of computers and/or networks and/or protocols.
Curves of the evolution of the top 15 protocols are shown depending on the criteria you've selected.
 
Data exportation
NER contains a sophisticated scheduler in order to export data regularly via FTP or mail.
Thus, you'll be able to use your favorite tool to create your own analysis reports.
Also, as data exportation can be done via Email, then it will be possible, for example, to remotely follow the behavior of a new application.
  
Helps in taking a decision
With NER you'll know if an application is well filling packets and so whether it is well adapted to WAN.
You'll also see how a new application is consuming your WAN bandwidth with the traffic of all ports.
   
Quantify how slow are key applications for remote users
NER gives information on response time of client computers, so it gives a good idea on how remote users feel.
 
 
 
 
 
 
 
 
 
SourceForge.net Logo

On demand reports


Focus on network exchanges evolution
Select the group of network actors on which you would to know the traffic volume or the response time evolution on a period you select and you get 1 curve for all protocols involved and 3 curves highlighting Top 5, Top 5 to 10 and Top 10 to 15 protocols.
 
 
Examples
 

Global evolution
Global evlution of the traffic
Top 5 protocols
Traffic top 5 protocols

Top 5 to 10 protocols
Top 5 to 10 protocols for traffic
Top 10 to 15 protocols
Top 10 to 15 for traffic
 
 
 
 
 

Zoom on all exchanges and response time between network actors
Select the group of network actors and the period on which you would to get the details, and you get a report as below.
 
 
Example
  
 details on traffic for all IP pairs involved
 
 
 
 
 
Another type of report, this time it's all network actors communicating with each network actor.
 
Example
 
 Details on traffic by IP
 
 
 

 
 
 
 
 
 
 SourceForge.net Logo

Monitoring tasks

Monitoring tasks enable to be alerted by Email when a threshold is reached.
 
 
Example of a declared monitoring task
 
 
Monitoring task       
 
 
 
 
 
 
 
 
 

Exportation tasks

Data exportation is done either by FTP or by Email with an attached gzip file.
Export attributes for FTP flat file are: ip_server, server_DNS_name,  server_volume_outbound_bytes, server_nb_packets_outbound, server_response_time_ms, server_protocol, server_protocol_name, server_port server_port_name, server_port_volume_outbound_bytes, server_port_nb_packets_outbound, server_port_response_time_ms, ip_client, client_DNS_name, client_volume_outbound_bytes, client_nb_packets_outbound, client_response_time_ms, client_protocol, client_protocol_name, client_port, client_port_name, client_port_volume_outbound_bytes, client_port_nb_packets_outbound, client_port_response_time_ms, total_server_client_volume_bytes, total_server_client_nb_packets, total_server_client_port_volume_bytes, total_server_client_port_nb_packets
  
 
 
 
 

 
 
 
SourceForge.net Logo

Material and OS pre-requisites


 
Material
  • PC computer type
  • 1 GB of RAM if you have less than 4 network interfaces capturing  network traffic, otherwise 2 GB.
    NER cannot captured more than 12 network interfaces.
  • 10 GB of disk space by month by network interface capturing network traffic.
 

 
Operating System (OS)
  • Linux.
  • For your information, tests have been done only on Fedora.