
Ggatten at waddell
Jan 12, 2010, 8:02 AM
Post #21 of 21
(1801 views)
Permalink
|
Not sure what you mean by "packages", but udp is routable unless you're filtering somewhere. Not familiar with your router either, but obviously if the flows don't make it to the nTop host it can't display them. ________________________________ From: ntop-bounces [at] listgateway <ntop-bounces [at] listgateway> To: ntop [at] unipi <ntop [at] unipi> Sent: Tue Jan 12 09:57:08 2010 Subject: Re: [Ntop] ntop and netflow Thanks, Gary. It seems that I cannot receive packages from my router. It is a fonera router running OpenWRT. I'm using this command to send packages: fprobe -ibr-lan SERVERIP:2055 (where SERVERIP is my ntop-server) According to this <http://weblog.etherized.com/?p=127> manual, it should do the trick - but doesn't. My server and my router are not on the same network. Maybe packages to UDP port 2055 are not routed via WAN? Thanks, Chris On Tue, Jan 12, 2010 at 4:17 PM, Gary Gatten <Ggatten [at] waddell> wrote: Netstat looks correct. To confirm netflow records are arriving at the ntop host, use tcpdump. Also, before you can view netflow data you must "switch nic" to the netflow interface. ________________________________ From: ntop-bounces [at] listgateway <ntop-bounces [at] listgateway> To: ntop [at] unipi <ntop [at] unipi> Sent: Tue Jan 12 09:07:17 2010 Subject: Re: [Ntop] ntop and netflow Hello, I already activated the netflow-plugin as described by Arthur. netstat reveals the following: root [at] bo:/home/ssms# netstat -an|grep 2055 udp 0 0 0.0.0.0:2055 0.0.0.0:* Should there be my IP address instead of the bunch of 0's? Thanks, Chris On Mon, Jan 11, 2010 at 11:36 PM, arthur dent <dent103 [at] hotmail> wrote: from the web interface... plugins -> netflow and make your settings there also make sure you have udp port opened in iptables ________________________________ From: intemann [at] gmail Date: Mon, 11 Jan 2010 18:52:40 +0100 To: ntop [at] unipi Subject: Re: [Ntop] ntop and netflow Ok. How would I enable the plugin? Thanks, Chris On Mon, Jan 11, 2010 at 6:41 PM, Gary Gatten <Ggatten [at] waddell> wrote: You must "enable" the netflow plugin. Also run netstat -an and look for 2055. Lastly, netflow is udp and telnet is tcp. ________________________________ From: ntop-bounces [at] listgateway <ntop-bounces [at] listgateway> To: ntop [at] listgateway <ntop [at] listgateway> Sent: Mon Jan 11 11:27:58 2010 Subject: [Ntop] ntop and netflow Hello list, I posted this topic to the ntop-misc list already. However, since that list does not seem to be highly populated, I will address my issue again on this list: I installed ntop on a Linux box and want to add a netflow client. Therefore, I entered a Local Collector UDP Port (2055). However, external client cannots connect, nor does telnet to port 2055 work, or does a portscan reveal an open udp port 2055. Do I miss any package? I'm running Debian and just typed "apt-get install ntop" There is no firewall blocking connections to that port. Why is ntop not listening for netflow clients? Thanks in advance, Chris "This email is intended to be reviewed by only the intended recipient and may contain information that is privileged and/or confidential. If you are not the intended recipient, you are hereby notified that any review, use, dissemination, disclosure or copying of this email and its attachments, if any, is strictly prohibited. If you have received this email in error, please immediately notify the sender by return email and delete this email from your system." _______________________________________________ Ntop mailing list Ntop [at] listgateway http://listgateway.unipi.it/mailman/listinfo/ntop ________________________________ _______________________________________________ Ntop mailing list Ntop [at] listgateway http://listgateway.unipi.it/mailman/listinfo/ntop "This email is intended to be reviewed by only the intended recipient and may contain information that is privileged and/or confidential. If you are not the intended recipient, you are hereby notified that any review, use, dissemination, disclosure or copying of this email and its attachments, if any, is strictly prohibited. If you have received this email in error, please immediately notify the sender by return email and delete this email from your system." _______________________________________________ Ntop mailing list Ntop [at] listgateway http://listgateway.unipi.it/mailman/listinfo/ntop <font size="1"> <div style='border:none;border-bottom:double windowtext 2.25pt;padding:0in 0in 1.0pt 0in'> </div> "This email is intended to be reviewed by only the intended recipient and may contain information that is privileged and/or confidential. If you are not the intended recipient, you are hereby notified that any review, use, dissemination, disclosure or copying of this email and its attachments, if any, is strictly prohibited. If you have received this email in error, please immediately notify the sender by return email and delete this email from your system." </font>
|