Might be in the prefs db file? You can always just delete everything and deactivate everything from the GUI. Restart ntop and start over.
Gary >>> [EMAIL PROTECTED] 10/17/2006 4:26 PM >>> Where are the configs held? I've only got the one router configured at this time - sending to 9001. I configured a second interface on NTop for giggles, and defined port 9002 for it. I would like to blow the current config away but the only thing I can find are the db files - and I'm not sure which of those is safe to blow away. On 10/17/06, Gary Gatten <[EMAIL PROTECTED]> wrote: > MAYBE each netflow interface needs a different port? Maybe delete the > netflow configs on ntop and start over creating just one virtual > interface for one of the routers and see if that works? > > >>> [EMAIL PROTECTED] 10/17/2006 3:00 PM >>> > But I am directly connected to that network. We have two ISP > connections, each with a router, and I planned to get netflow exports > from both...? > > I'm currently getting netflow packets from the one router, on the > correct NIC, but ntop isn't doing anything with them... > > On 10/17/06, Gary Gatten <[EMAIL PROTECTED]> wrote: > > >From the config page: > > > > If the NetFlow probe is monitoring only a single network, then this > is > > all you need to set. If the NetFlow probe is monitoring multiple > > networks, then pick one of them for this setting and use the -m | > > --local-subnets parameter to specify the others. > > > > This interface is called 'virtual' because the ntop host is not > really > > connected to the network you specify here. > > > > So, my ntop is on 1.1.1.0/24 and I have some networks I'm > monitoring: > > 2.2.2.0/24, 3.3.3.0/24, 4.4.4.0/24. My netflowed core router is > > actually on 1.1.1.0/24 but that doesn't really matter. From what I > can > > tell it's only to distinguish "local" traffic from "remote" traffic, > but > > as mentioned you typically must add more networks with the -m from > the > > command line. In my case my vvirtual netflow address is > > 2.2.2.0/255.255.255.0 and my other local nets I added with -m. In > my > > case any networks I own are local and anything else (internet) is > > remote. > > > > HTH > > > > Gary > > > > > > > > >>> [EMAIL PROTECTED] 10/17/2006 12:48 PM >>> > > When you go to plugins/netflow/configure and you create a new > netflow > > device, you give it a name, tell it what port to listen on, what do > > you put in for the "Virtual NetFlow Interface Network Address"? > > > > I've left everything else alone... > > _______________________________________________ > > Ntop mailing list > > [email protected] > > http://listgateway.unipi.it/mailman/listinfo/ntop > > > > > =========================================================================== > > > > > > > > > > > > "This email is intended to be reviewed by only the intended > recipient > > and may contain information that is privileged and/or confidential. > > If you are not the intended recipient, you are hereby notified that > > any review, use, dissemination, disclosure or copying of this email > > and its attachments, if any, is strictly prohibited. If you have > > received this email in error, please immediately notify the sender > by > > return email and delete this email from your system." > > > > _______________________________________________ > > Ntop mailing list > > [email protected] > > http://listgateway.unipi.it/mailman/listinfo/ntop > > > _______________________________________________ > Ntop mailing list > [email protected] > http://listgateway.unipi.it/mailman/listinfo/ntop > > =========================================================================== > > > > > > "This email is intended to be reviewed by only the intended recipient > and may contain information that is privileged and/or confidential. > If you are not the intended recipient, you are hereby notified that > any review, use, dissemination, disclosure or copying of this email > and its attachments, if any, is strictly prohibited. If you have > received this email in error, please immediately notify the sender by > return email and delete this email from your system." > > _______________________________________________ > Ntop mailing list > [email protected] > http://listgateway.unipi.it/mailman/listinfo/ntop > _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop =========================================================================== "This email is intended to be reviewed by only the intended recipient and may contain information that is privileged and/or confidential. If you are not the intended recipient, you are hereby notified that any review, use, dissemination, disclosure or copying of this email and its attachments, if any, is strictly prohibited. If you have received this email in error, please immediately notify the sender by return email and delete this email from your system." _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
