ntop / ntopng

Web-based Traffic and Security Network Traffic Monitoring
http://www.ntop.org
GNU General Public License v3.0
6.28k stars 656 forks source link

cannot see networks under Netwok Tab #236

Closed AlekMarkus closed 9 years ago

AlekMarkus commented 9 years ago

hello ,

i cannot see networks Under Network Tab - all those happened after update to ntopng Professional v.2.1.151015

ntopng

this is my configuration file :

-m=10.1.1.1/24,10.1.101.1/24,10.1.109.1/24,10.1.200.200/24

lucaderi commented 9 years ago

Centos 6 ?

AlekMarkus commented 9 years ago

Yes

simonemainardi commented 9 years ago

fixed with commit 04b3a1b

AlekMarkus commented 9 years ago

Hey , its still doesn't after update

networks

dboehlke commented 9 years ago

I also appear to be having this issue, although it is more pronounced than just a empty "Networks" page.

I am running: ntopng Professional v.2.1.151016 on Ubuntu 12.04 LTS.

The issue appeared after I updated on Thursday. It was working on Wednesday.

Ntopng says it sees my local network list when starting in the log:

16/Oct/2015 12:39:32 [Ntop.cpp:929] Setting local networks to 192.168.0.0/24,172.16.0.0/16,10.0.0.0/8,38.81.66.0/23,209.208.232.0/23,209.208.241.0/24,209.208.250.0/24,50.93.246.0/23,50.93.255.0/24,162.222.47.0/24,216.17.8.0/24,38.92.136.0/24,162.222.40.0/21,162.222.40.0/23,162.222.46.0/24,103.8.239.0/24,149.5.7.0/24

On the pro dashboard, all the "Top Local Talkers" list is empty. Local addresses end up in the "Top Remote Destinations" list along with the remote addresses.

The "Local -> Remote" and "Remote -> Local" graphs at the bottom of the dashboard show no traffic.

The "Hosts"/"Network" page only shows "Unknown Network".

Perhaps the fix by simonemainardi has not made it into the Ubuntu apt packages yet.

Let me know if you would like more information.

ValentinaViscarelli commented 9 years ago

@AlekMarkus It should be fixed now. Please let me know.

AlekMarkus commented 9 years ago

Hey , I have update to the last version , but it still doesn't work.

I can see the log that adding the network , but why twice 10.1.1.0/24 ? where are the other vlans like : 10.1.101.1 and 10.1.101.9

17/Oct/2015 19:56:22 Welcome to ntopng x86_64 v.2.1.151017 - (C) 1998-15 ntop.org 17/Oct/2015 19:56:22 Built on CentOS release 6.6 (Final) 17/Oct/2015 19:56:22 Started periodic activities loop... 17/Oct/2015 19:56:22 Dumping alerts into syslog 17/Oct/2015 19:56:22 [LICENSE] ntopng systemId: F73A7AEE9206A1D8 17/Oct/2015 19:56:22 [LICENSE] ntopng is starting in demo mode 17/Oct/2015 19:56:22 Adding 10.1.1.0/24 as IPv4 local network 17/Oct/2015 19:56:22 Adding 10.1.1.0/24 as IPv4 local network 17/Oct/2015 19:56:22 Adding fe80::6e3b:e5ff:fe37:74ec/64 as IPv6 local network 17/Oct/2015 19:56:22 Adding fe80::32b5:c2ff:fe02:36a3/64 as IPv6 local network

networks2

lucaderi commented 9 years ago

Please post your complete startup command line options.

AlekMarkus commented 9 years ago

-n=1 -W=3000 -g=-1 -d=/var/tmp/ntopng.old/ -G=/var/tmp/ntopng.pid -i=eth0 -i=eth1 -F=es;ntopng;ntopng-%Y.%m.%d;http://10.1.1.20:9200/_bulk -c=ABQIAAAAqyS8slRQqo9Kcr0-E9h89hSGhgF8hR3CTnfinjU1fi7o32h8XA -m=10.1.1.1/24,10.1.101.1/24,10.1.109.1/24,10.1.200.200/24

dboehlke commented 9 years ago

It is still broken for me as well. Here is my ntopng.conf:

-G=/var/tmp/ntopng.pid -d=/var/tmp/ntopng -p=/etc/ntopng/protos.txt -i=tcp://10.60.59.14:5556 -i=tcp://10.60.59.14:5557 --local-networks="192.168.0.0/24,172.16.0.0/16,10.0.0.0/8,38.81.66.0/23,209.208.232.0/23,209.208.241.0/24,209.208.250.0/24,50.93.246.0/23,50.93.255.0/24,162.222.47.0/24,216.17.8.0/24,38.92.136.0/24,162.222.40.0/21,162.222.40.0/23,162.222.46.0/24,103.8.239.0/24,149.5.7.0/24" --disable-instantsessionpurge= --sticky-hosts=none --dns-mode=1 --disable-login=1 --dump-flows="es;flows;ntopng-%Y.%m.%d;http://localhost:9200/_bulk;" -w=3000

dboehlke commented 9 years ago

Here is the ntopng log at startup:

18/Oct/2015 13:12:42 [Prefs.cpp:612] All HTTP user login disabled 18/Oct/2015 13:12:42 [Prefs.cpp:661] Using ElasticSearch for data dump [flows][ntopng-%Y.%m.%d][http://localhost:9200/_bulk] 18/Oct/2015 13:12:42 [Ntop.cpp:931] Setting local networks to 192.168.0.0/24,172.16.0.0/16,10.0.0.0/8,38.81.66.0/23,209.208.232.0/23,209.208.241.0/24,209.208.250.0/24,50.93.246.0/23,50.93.255.0/24,162.222.47.0/24,216.17.8.0/24,38.92.136.0/24,162.222.40.0/21,162.222.40.0/23,162.222.46.0/24,103.8.239.0/24,149.5.7.0/24 18/Oct/2015 13:12:42 [Redis.cpp:105] Successfully connected to redis 127.0.0.1:6379@0 18/Oct/2015 13:12:42 [NtopPro.cpp:120] [LICENSE] Reading license from /etc/ntopng.license 18/Oct/2015 13:12:42 [Ntop.cpp:1180] Registered interface view tcp://10.60.59.14:5556 [id: 1] 18/Oct/2015 13:12:42 [Ntop.cpp:1150] Registered interface tcp://10.60.59.14:5556 [id: 0] 18/Oct/2015 13:12:42 [Ntop.cpp:1180] Registered interface view tcp://10.60.59.14:5557 [id: 11] 18/Oct/2015 13:12:42 [Ntop.cpp:1150] Registered interface tcp://10.60.59.14:5557 [id: 1] 18/Oct/2015 13:12:42 [Utils.cpp:304] User changed to nobody 18/Oct/2015 13:12:42 [main.cpp:237] PID stored in file /var/tmp/ntopng.pid 18/Oct/2015 13:12:42 [HTTPserver.cpp:458] Please read https://github.com/ntop/ntopng/blob/dev/doc/README.SSL if you want to enable SSL. 18/Oct/2015 13:12:42 [HTTPserver.cpp:501] Web server dirs [/usr/share/ntopng/httpdocs][/usr/share/ntopng/scripts] 18/Oct/2015 13:12:42 [HTTPserver.cpp:504] HTTP server listening on port 3000 18/Oct/2015 13:12:42 [main.cpp:290] Working directory: /var/tmp/ntopng 18/Oct/2015 13:12:42 [main.cpp:292] Scripts/HTML pages directory: /usr/share/ntopng 18/Oct/2015 13:12:42 [Ntop.cpp:260] Welcome to ntopng x86_64 v.2.1.151018 - (C) 1998-15 ntop.org 18/Oct/2015 13:12:42 [Ntop.cpp:265] Built on Ubuntu 12.04.5 LTS 18/Oct/2015 13:12:42 [PeriodicActivities.cpp:53] Started periodic activities loop... 18/Oct/2015 13:12:42 [RuntimePrefs.cpp:32] Dumping alerts into syslog 18/Oct/2015 13:12:42 [NtopPro.cpp:234] [LICENSE] ntopng systemId: CDD6A54E9206AB23 18/Oct/2015 13:12:42 [NtopPro.cpp:245] [LICENSE] ntopng license: DCF4E7A8AFF4F27B49E12B8E19B2D51A1475685990201C735E 18/Oct/2015 13:12:42 [NtopPro.cpp:266] [LICENSE] Maintenance is available until Wed Oct 5 11:46:30 2016 [352 days left] 18/Oct/2015 13:12:42 [NetworkInterface.cpp:1450] Started packet polling on interface tcp://10.60.59.14:5556 [id: 1]... 18/Oct/2015 13:12:42 [CollectorInterface.cpp:93] Collecting flows on tcp://10.60.59.14:5556 18/Oct/2015 13:12:42 [NetworkInterface.cpp:1450] Started packet polling on interface tcp://10.60.59.14:5557 [id: 11]... 18/Oct/2015 13:12:42 [CollectorInterface.cpp:93] Collecting flows on tcp://10.60.59.14:5557

dboehlke commented 9 years ago

Here is my "Hosts"/'Networks" page:

screen shot 2015-10-18 at 1 24 59 pm

lucaderi commented 9 years ago

@dboehlke I have tested this tonight with the code in git and for me it works. Can I please login to your system to see what happens? There are a few issues not just one (I see on your picture that ntopng is analysing 49 Gbit, not too bad for ntopng).

simonemainardi commented 9 years ago

I was able to (partially) fix this issue. A double strtok was preventing some local networks from being added.

screen shot 2015-10-18 at 11 46 08 pm

Local networks and hosts belonging to each network are now correctly listed. I am still experiencing some issues on aggregated network statistics. For this reason I staged the code into my local repository (https://github.com/simonemainardi/ntopng). I will wait until everything works OK before pushing it into the official dev. If you guys in the meanwhile want to try the code and help me, you are welcome.

dboehlke commented 9 years ago

I checked ntopng Professional v.2.1.151019 this morning and it is still not recognizing the local-networks list. I have not pulled down "simonemainardi's" local repository yet, but that will be my next step.

To "lucaderi's" comment. I need to check with our security people to see if I can give you access. The server running ntopng is inside one of our data centers and that makes things sticky security wise. We we should be able to do something.

I am impressed with ntopng's performance. I am feeding sflow from EX series Juniper switches in the data centers to nProbes running on another server and this instance of ntopng uses zmq connections to talk to the nprobes.

Thanks!

screen shot 2015-10-19 at 1 24 34 pm

simonemainardi commented 9 years ago

guys, hope the latest commits fix this issue. I've tested it thoroughly and it seems OK. Please let me know.

AlekMarkus commented 9 years ago

hey , i have update to the last version and its working. :)

Thanks @simonemainardi

simonemainardi commented 9 years ago

:)

dboehlke commented 9 years ago

I have applied the update at well and it is working! Thanks!

screen shot 2015-10-20 at 12 12 46 pm