Crannog NetFlow Tracker

Review: Crannog Software NetFlow Tracker

NetFlow Tracker mines information from routers and switches to give detailed traffic analysis.

Written by Alan Stevens

Larger Image

Crannog Software's NetFlow Tracker is an application that collects and interprets a huge amount of data from any IOS-based Cisco router or switch, providing detailed, real-time information about the traffic those devices are handling.

NetFlow is a standard component of Cisco's IOS operating system. It can tell administrators the source and destination address of every packet processed, along with port, protocol and class of service details - much like an RMON probe, but with no need for additional hardware. And because it has been used as the basis of a new IETF standard, called IPFix (IP Flow Information eXport), NetFlow has now been widely adopted by other manufacturers.

This means the Tracker application can also retrieve traffic information from Enterasys, Huawei, Juniper and other IPFix-compatible networking devices, again without the need for additional hardware other than a server on which to host the Crannog software.

That server will need plenty of fast disk space to hold the collected data, with a Raid setup recommended for large production networks. No database engine is required, however, as an implementation of the popular MySQL application that can be deployed on either Windows, Linux or Solaris is included as part of the package.

The hardest part of installing and configuring the software is turning on the NetFlow/IPFix export on devices to be monitored (exports are set per interface), though Crannog provides detailed information on the initial adjustments that need to be made. The application itself is very straightforward, with a Java GUI accessible from a browser that is quite easy to master.

A high-level view of the exported data shows the devices being monitored, leaving administrators to drill down through the interfaces on those devices to find the information required. It is possible to resolve source and destination IP addresses and display URLs on most of the on-screen reports, for example.

The time range display features simple point-and-click tools to zoom in and out, and a choice between graphical charts and spreadsheet-like tabular reports. Custom report filters can be defined and data exported in CSV format for analysis using other applications.

One drawback of the original NetFlow Tracker product was a limit of 14 days' storage due to the default one-minute sampling interval. The latest V2.0 release features an optional Advanced Services Module (ASM) that extends this, however, with a choice of six storage levels for long-term trend analysis, though the amount of detail kept is reduced the longer the information is stored.

We were given access to a live deployment at an Irish university and were impressed both with the amount of information collected and the tools provided to handle it. Tracker's responsiveness is excellent even when, as in our case, the server is accessed remotely over an internet connection.

How the data collected by NetFlow Tracker is interpreted is, of course, down to individual organisations. We could see its usefulness in isolating faults, capacity planning and general network and security monitoring.

NetFlow Tracker is aimed squarely at network support staff, though interface changes to make it more user-friendly are in the pipeline. Those wanting high level management reports might look at the NetFlow Monitor application as an alternative.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Product overview

Ratings

  • Our rating: n/a
  • Average user rating:

Verdict

Tracker collects very detailed traffic information based on Cisco NetFlow technology to aid network troubleshooting, capacity planning and security enforcement.

Pros: Uses existing NetFlow technology so no extra probe hardware needed; supports IPFix standard; multi-platform application with bundled MySQL database server.

Cons: Huge amount of detailed data can be difficult to manage; interface and tools unsuitable for non-technicians.

Best prices

reader comments

related articles

 

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation