Вы находитесь на странице: 1из 36

nuanns1unu1usunsu ntop 3.

2 auunnun1uu









nun1nu


unanas nnun wnnrssmr
ns.wu nn wu1wuau

1S ununuu 2550




auauaus1nu


uuuugu nnnsutun1u1au tnsaunu

nuutun1u1auatanusaunauarnauwtnasuuunn
National Electronic and Computer Technology Center {NECTEC)





nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 2
ansu q


1. snnstu n-un1usunsu NTOP 3
1.1. 1sn1:iLn1L:un:u ntop 3
1.2 1sn1:Ln1L:un:u ntop n1uv1u1L:un:u Web browser +
2. snnsaunuuauann1usunsu NTOP 5
2.1. tauaiLaunuinu1nL1L:un:u ntop 5
2.2 taua1nu:1uinu1nLin:at1u 6
2.3 :1ua:iauntauuna:1aan 7
2.+ annn1:ltu1uin:at1u 8
2.5 iuni1:n1na1 (Network Flow) 9
2.6 L:u1nn1:ltu1uin:at1utauuna:nlt uunn1u1n:1nnaa 10
2.7 an:1n1::Lautauatauuna:1aan 11
2.8 nn::utau1aann1ut1ui1a1 12
2.9 L:u1nn1:ltu1uin:at1utauuna:nlt uunn1uuannaintu 13
2.10 tauainu1nauann1an (Nulticast) 1+
2.11 :1ua:iauntauun a:1niuu (!nternet Domain) 15
2.12 nautau1aan (Host Cluster) 16
2.13 ana1utautauaLuin:at1u 16
2.1+ vnv1utautauaLuin:at1u 18
2.15 tauan1:ltL:n1:in:at1utaunlt 19
2.16 ::LLLgLnn1:tauuna:1aan 20
2.17 LvL1vtauuna:1aan 21
2.18 tauaLuin:at1un1ulu (Network Nap) 22
2.19 n1:nnnaaaa1:::v11u1aann1ulu (Natrix) 22
2.20 tauaqq1n1niLa:utuuua (Fiber Channel) 23
2.21 inLtauaLuin:at1u (Data Dump) 23
2.22 naan1na 2+
2.23 1aanvna1an (Lanau) 25
2.2+ L:u1n1n:1nnaa !CNP tauuna:1aan (Lanau) 25
2.25 a:La unL1aanv ltu1uin:at1uu1nva n (Lanau) 26
2.26 annn 1u( lu:LuLLtaun:1n:Ln1n (Lanau) 27
2.27 inLtaualu:LuLL XNL (La nau) 27
3. snnsus uunnnuu1usunsu NTOP 2S
3.1. iLauun1:nuau (Network !nterface Card) 28
3.2 nun1nuj1un1u( Lu1L:un:u ntop 29
3.3 nun11L:un:u ntop 33
3.+ nun1n1:n:auunninntn:n:1L 3+
3.5 :inann 3+
3.6 nun1n ltu1u1L:un:u ntop 35
3.7 Launuvu1 Web page 36



nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 3
1. snnstu n-un1usunsu ntop
1.1. 1sn1:iLn1L:un:u ntop
tunaun1:iLn1L:un:u ntop utunaunuu
- iLn1L:un:u Web browser tuu1 n1au1u1L:un:u Web browser 1nun
Nozilliar Firefox ua: !nternet Explorer iLunu



- vau1niLn1L:un:u Web browser tuu1ua1 lvnun vu1uiat1an
uanin:atauin:auvnnnu1L:un:u ntop ua1n1un1uvu1uiauna:n
3000 auLutau URL itu v1nin: auvnnnu1L:un:u ntop uvu1uiat1a
nuaain:aiLu 192.168.99.96 lvnun http:ff192.168.99.96000" au
Lutau URL nu:L






- vau1nu u 1L:un:u ntop :uanuvu1u:ntau1L:un:u nu:L




nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 +
1.2. 1sn1:Ln1L:un:u ntop n1uv1u1L:un:u Web browser
tunaun1:Ln1L:un:u ntop n1uv1u1L:un:u Web browser utunaunuu
- it1iuu nuasruu un1usunsu nu:L





- vau1niaaniuuLn1L:un:u :naula Username ua: Password tau
nnua::LLinauuuun1:Ln1L:un:uann:u nu:L (Username taunnua
::LLLu1L:un:u ntop na admin" ua: Password tuaunLn1:n1vun
tn:nnnu1L:un:u ntop)








- vau1nu u:aL::u1n 25 1u1v 1L:un:u ntop nu:Ln1L:un:uau1u
auL:n 1nuvu1a1L:un:u ntop vau1nnnLn :uanuna nu:L




nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 5
2. snnsaunuuauann1usunsu ntop
2.1. tauaiLaunuinu1nL1L:un:u ntop
v1nnaun1:v:1Lnutauanuj1uin u1nL1L:un:u ntop it u
1L:un:u ntop na1L:un:ua:1: ua:uL::1utuau1u1:L1u
n1:nun1n1u( Lu1L:un:u ntop
ln:iLunnou11L:un:u ntop
nuan1:ltu1u1L:un:u ntop iLaunu
iuut1uiva aa1v:Lnltu1u1L:un:u ntop
n1n1uvnLLauinu1nL1L:un:u ntop 1nu:1uvun1n1uv1un1uivnun
ua:n1n1uv11Linu1nLn1:ltu1u1L:un:u ntop
n11uvu1utauaqanunn1u( Lu1L:un:u ntop

tauanuj1un1u( iva 1ua1u1:nit11Ln1nviuu uurun ntop nu:L

























nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 6
2.2. taua1nu:1uinu1nLin:at1u
v1nnaun1:v:1L:1ua:iaun1nu:1uvuvuntauin:at1u itu
taaLn:nvv1n1:n:1LtauaLuin:at1u (Network !nterface Card)
vu1uiat !P address tauin:auv n:1LtauaLuin:at1u
ana1uL:u1ntauauLL Unicast ua: Nulticast tauvuin: at1u
ana1utu1ntauunninnLuin:at1u
ana1u::v1 1u !P unninn nL Non-!P unninn
annn1::La utauatauvuin:at1uuunn1u1n:1nnaa uvu1uiLu 1Ln
na1u1v (bytesfsec)

tauaiva1u a1u1:nit 11Lviuu asu uau auutns au nu nu:L










nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 7
2.3. :1ua:iauntauuna:1aan
v1nnaun1:v:1LtauaiLaunuinu1nLin:at1utauuna:1aan itu
vu1uiat1anuanin:a (!P address)
vu1uiataLn:nnnLin:at1u (NAC address)
1niuu (Domain)
L:u1nn1:ltu1uin:at1u (Bandwidth) 1nunniLu:aua:taun1:ltu1u
in:at1uvuvun

:1ua:iauntauuna:1aaniva1u a1u1:nit11Ln1nviuu asu snuartaun
ua1aan nu:L













nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 8
2.+. annn1:ltu1uin:at1u
v1nnaun1:v:1Lan:1n1:n1::Lautauatauin:at1uvuvun (Throughput)
n1ut1utaui1a1 itu
an:1n1::Lautauatauvuin:at1ulu 10 u1vvua1
an:1n1::Lautauatauvuin:at1ulu 1 t11uuvua1
an:1n1::Lautauatauvuin:at1utau1uvua1
an:1n1::Lautauatauvuin:at1utauinauvua1

lu:LuLLtaun:1n:Ln1n a1u1:nit11L1nv iuu asu ann nns1unu
tnsaunu nu:L








nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 9
2.5. iuni1:n1na1 (Network Flow)
v1nnaun1:v:1LL:u1ntauaLuin:at1utauuna:Lana u a1u1:nit11Ln1nv
iuu asu tuntsn1wa {Network Flows) nu:L


































nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 10
2.6. L:u1nn1:ltu1uin:at1utauuna:nlt uunn1u1n:1nnaa
v1nnaun1:v:1L11una:nltun1:ltu1uin:at1uiLuL:u1niv11: 1nuuunn1u
1n:1nnaa nuna1Lu
TCP
UDP
!CNPf!CNPv6
DLC
!PX
Decnet
ARPfRARP
AppleTalk
NetBios
OS!
!Pv6
STP
!PS

a1u1:nit11Ln1nviuu 1ws1nnaa uau auutns au nuuunnnu1ws1nnaa
nu:L














nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 11
2.7. an:1n1::Lautauatauuna:1aan
v1nnaun1:v:1L11LLuuna:nltun1::Lautauan1un11ui:1iv11:
(Current Throughput), inuun11ui:1lun1::LautauaLuin:at1uauaniv11:
(Peak Throughput) ua:n1iaau1nu:1utaun11ui:1lun1:autauaiLuiv11:
(Average Throughput) a1u1:nit11Lviuu 1ws1nnaa ansnnnssua
uauaua1aan {Throughput) nu:L





















nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 12
2.8. nn::utau1aann1ut1ui1a1
v1nnaun1:v:1L11 n1ulu 2+ t11uutau1u una:nltu n1:ltu1uin:at1uiLu
:aua:iv11:tauL:u1nn1:ltu1uvuvun a1u1:nit11Ln1nviuu 1ws1nnaa
nnssuua1aannnuutan nu:L






















nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 13
2.9. L:u1nn1:ltu1uin:at1utauuna:nlt uunn1uuannaintu
v1nnaun1:v:1L11una:nltun1:ltu1uuna:uanaintuiL uL:u1niv11: itu
uannaint u1n1n:Lau1nataua 1nun FTP
uannaint u1n1n Web 1nun HTTP
P2P uannaintu 1nun Bittorent, eDonkey, azaa ua: nutella
uannaint u1n1n Chat 1nun Nessenger
uannaint u1n1n:Lauiuaa 1nun Nail
uannaint uau( 1nun DNS, DHCP-BOOTP, Telnet, NBios-!P, SNNP,
NNTP, NFSfAFS ua: X11

a1u1:nit11Lntaua1nviuu 1aw as u uauatns aunuuunnnu
uawwatnuu nu:L
















nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 1+
2.10. tauainu1nLuann1an (Nulticast)
v1nnaun1:v:1L:1ua:iauninu1nLtauaLuin:at1uL::invuann1an
(Nulticast Traffic) 11un1::Lua:auiLuL:u1niv1ln a1u1:nit11Ln1nviuu
1aw as u uan nnan

































nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 15

2.11. :1ua:iauntauuna:1niuu (!nternet Domain)
v1nnaun1:v:1L11una:1niuu v:auna:in:auuut1uun1:: LautauaiLu
L:u1niv11: 1nuuunn1u1n:1nnaa TCP, UDP, !CNP, ua: !CNPv6 a1u1:n
it11Ln1nv iuu 1aw asu autnastu n1ntuu {Internet Domain) nu
:L















nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 16
2.12. nautau1aan (Host Cluster)
v1nnaun1:v:1Lnnn::un1:nun utau1aan a1u1:nit11Ln1nviuu 1aw
asu nauua1aan nu:L






2.13. ana1utautauaLuin:at1u
v1nnaun1:v:1LL:u1ntauaLuin:at1u 1nunniLuana1utauL:u1ntaua
Luin:at1uvuvun itu
ana1u::v1 1un1:nunu::v11uin:at1un1uuan-in:at1un1ulu,
in:at1un1ulu-in:at1un1uuan ua: n1:nunun1uluin:at1u iLu
ana1uiv11:
ana1u::v1 1u1n:1nnaa TCP nL UDP taun1:nunu::v11uin:at1u
n1uuan-in:at1un1ulu, in:at1un1ulu-in:at1un1uuan ua:
n1uluin:at1un1unuiauiLuana1uiv11:

tauaiva1u a1u1:nit11Ln1nviuu 1aw asu anauuauauauu
tnsaunu





nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 17









nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 18
2.1+. vnv1utautauaLuin:at1u
v1nnaun1:v:1L1aanun1::Laut aua1Lluv nv1uln iLuL:u1niv11: it u
v1nnaun1:v:1L11
1aann1uluin:at1uun1::Lautau a1Luu1aann1ulun1unuiauiLu
L:u1niv11:
1aann1uluin:at1uun1::Lautau a1Luu1aann1uuan (in: at1u
n1uuan) iLuL:u1niv11:

tauaiva1u a1u1:nit 11Ln1nviuu 1aw ununuauaua nu:L









nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 19
2.15. tauan1:ltL:n1:in:at1utaunlt
v1nnaun1:v:1L11LLuunltn1uluin:at1ultL:n1:uannaintu v:alt
L:n1:a:1:auL1u it u unltnulnun1:lt L:n1:i1L v:aaiuaaau iLunu
a1u1:nit11Ln1nviuu 1aw tnunutns aununnu1u wasnu1u nu:L







nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 20
2.16. ::LLLgLn n1:tauuna:1aan
v1nnaun1:v:1L11una:1aanluin:at1uu::LLLgLnn1: (Operating System)
a:1: itu ::LLLgLnn1: Window v:a Linux a1u1:nit11Ln1nviuu 1aw
tnunutnsaununnu1u sruuugunnnsua1aan nu:L









nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 21
2.17. LvL1vtauuna:1aan
v1nnaun1:v:1L11una:1aanluin:at1uuLvL1vv:av1vu1va:1:Lu
in:at1u itu v1vu1viLu ateway, Printer, DHCP server, DHCP client v:a
au( a1u1:nit11Ln1nviuu 1aw tnunutnsaununnu1u nmanumr
ua1aan nu:L






















nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 22
2.18. tauaLuin:at1un1ulu (Network Nap)
v1nnaun1:v:1Ln1:n1:itau1uunutau1aann1uluin:at1u v: a Nap
a1u1:nit11Ln1nviuu 1aw tnunutns aununnu1u nma numrua
1aan nu:L






2.19. n1:nnnaaaa1:::v11u1aann1ulu (Natrix)
v1nnaun1:v:1L11 1aann1uluin: at1uun1:n unuiauiL uL:u1niv11:
a1u1:nit11Ln1nviuu 1aw tnunutns aununnu1u n ma numrua
1aan nu:L








nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 23
2.20. tauaqq1n1niLa:utuiua (Fiber Channel)
v1nnaun1:v:1Ltaua:1ua:iauninu1nLtau aLutauaqq1n1niLa:utuiua
(Fiber Channel) itu naun1:v:1L
L:u1ntau aLuin:at1uLutauaqq1n1niLa:utuiua
an:1n1::LautauaLuin:at1u (Throughput) Lu1niLa: utuiua
nn::uLut auaqq1n1niLa:utuiua
:1ua:iauntau1aanLu1niLa:utuiua

tauaiva1ua1u1:nit 11Ln1nviuu uaa qqnm 1wtuasuuutua
{Fiber Channel) nu: L







2.21. inLtauaLuin:at1u (Data Dump)
v1nnaun1:inLtauaLuin:at1ulu:LuLLn1u( itu : LuLLn1anu: (Text
format) v:alu:LuLL XNL (XNL format) a1u1:nit11L1nviuu
assnusr1uuu tn uuauauutnsaunu {Data Dump) nu:L iuuuivu1:
a1v:LLnnavnaun1:u1taua1n1L:un:u ntop 1L1in:1:vnauanivua1nv
1L:un:u ntop 1nin:uu11lv itu a1u11Lv11aanvltu1uin:at1uau1u1u
ivu1:aun1uu1uL1utauaunn: iLunu 1L:un:uva1u1:nu1u1nutauaaan
1n1L:un:u ntop 1nun wget iLunu












nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 2+
2.22. naan1na
v1nnaun1:n:1uu1un1:v1u1utau1L:un:u ntop v:aaan1na (Log File) tau
1L:un:u ntop a1u1:nit11Ln1nviuu assnusr1uuu naan1wa nu:L



















nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 25
2.23. 1aanvna1an (Lanau)
v1nnaun1:v:1L111aanvna1anua:1:L1u a1u1:n1L Activate 1nviuu uan
au Host Last Seen nu:L









2.2+. L:u1n1n:1nnaa !CNP tauuna:1aan (Lanau)
v1nnaun1:v:1L:1uu1utauain:at1uian1:1n:1nnaa !CNP tauuna:1aan
a1u1:nit11L Activate ua: n1nviuu uanau ICMP Watch nu: L







nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 26
2.25. a:LaunL1aanvltu1uin:at1uu1nvan (Lanau)
v1nnaun1: Top Five tau1aanvltu1uin:at1uu1nvan a1u1:nit11L
Activate ua: n1nviuu uanau PDA nu:L (iuuuivu1:a1v:L PDA
1nuian1:)


























nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 27
2.26. annn1u( lu:LuLLtaun:1n:Ln1n (Lanau)
v1nnaun1:aLnutauain:at1uL::invn1u( itu tauain:at1uL::inv
Ethernet Packet lu 10 t11uuv ua1 lvaulu:LuLLn:1n:Ln1n nu:L a1u1:n
it11LaLnutaua1nv uanau Round-Robin Databases nu:L






2.27. inLtaualu:LuLL XNL (Lanau)
v1nnaun1:nutaua1n1L:un:u ntop lu:LuLL XNL format lva1u1:nit11L
n1nviuu uanau XML Data Dump nu: L














nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 28
3. snnsus uunnnuu1usunsu ntop
3.1. iLauun1:nuau (Network !nterface Card)
lun:nvin: auvv1n1:nnnu1L:un:u ntop un1:nuauu1nn11vuuau nnua
::LLa1naun1:iLauun1:nuauin aiLauuaLn:nlun1:n:1LtauaLu
in:at1u 1 sn1:iLauun1:nuau a1u1:nit11L1nviuu nuasruu tuauu
nnsnuau nu:L





























nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 29
3.2. nun1nuj1un1u( Lu1L:un:u ntop
nun1i:ununuj1utau1L:un:u ntop itu
nun1nuj1u
o iaann1:nuauvltlun1:n:1LtauaLuin:at1u
o vu1uiatna:nlun1:i: unntaua1n1L:un:u ntop n1uv1u
1L:un:u Web browser
o 1vuntaun1:iLn1L:un:u ntop
nun1n1:uanuna
o an:1n1::in:ttauvu1i1Lintau1L:un:u Web browser
o n1u1lun1:uanuna
o 1u1uun1lun1:uanuna
nun1inu1nL1n:1nnaa1an
o n:1L1n:1nnaaa:1:L1u
nun1inu1nLtauaqq1n1niLa:utuuua
nun1ivnuntuau
o n1:nun1in u1nLn1:nn1: Nemory
nun1n1:un 1t1L:un:u ntop (Debugging)
o nun1inu1nu Debugging Node
o nun1inu1nL Syslog

n1:nun1nuj1un1u( a1u1:nit11Lnun11nviuu nuasruu nnnnns1u
nu nnntsunu {Startup Options) nu:L





nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 30






nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 31








nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 32








nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 33
3.3. nun11L:un:u ntop
n1:nun1Lu1L:un:u ntop itu
n1t1ui1a1n1:inLtauaau Database (RRD Database)
n1inu1nLLanaun1u(

a1u1:nit11Lnun11n viuu nuasruu nnnnns1unu nnn
1usunsu {Preferences) nu:L








nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 3+
3.+. nun1n1:n:auunninntn:n:1 L
v1nn:nvnnua::LL1unaun1:n:1LL1uun ninn v:a1unaun1:n:1LL1u
1n:1nnaa a1ltiuu ut1ulun1::auunninn 1nua1u1:nit11Lnun 11nviuu
nuasruu nnnnns1unu nsauwntnn {Packet Filter) nu:L








3.5. :inann
v1nnnua::LLnaun1::inn1n1u( vinunL:Lunu11 lvivuaun1i:unu
a1u1:nit11L:in1nv iuu nuasruu nnnnns1unu stT nan n
{Reset Stats) nu:L







nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 35
3.6. nun1nltu1u1L:un:u ntop
1L:un:u ntop a1u1:nlvnnua::LLlvavsnlta u( a1u1:nit1nu1L:un:u
ntop n1uv1u1L:un:u Web Browser 1n 1nunua::LLa1u1:nit 11Lnun1n
lt1nv iuu nuasruu nnnnns1unu nnnn1u {Web Users) nu:L






























nuan1:ltu1u1L:un:u ntop 3.2 aLLn1u11vu vu1 36
3.7. Launuvu1 Web Page
v1nnnua::LL1unaun1:lvnltnuauit1nuL1uvu1 Web Page tau1L:un:u
ntop a1u1:nit11LLaunuvu1 Web Page 1nviuu nuasruu nnnnns1u
nu uanu URL {Protect URLs) nu:L

Вам также может понравиться