No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


eSight V300R009C00 Operation Guide 10

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).


eSight NTA provides an efficient method to quickly monitor and analyze network traffic. It analyzes the entire IP network traffic based on information provided by network devices that support the NetFlow, NetStream, and Sampled Flow (sFlow) protocols, and provides top N traffic analysis reports in real time. Displaying top N traffic analysis results through comprehensive charts and tables, the NTA helps users obtain network-wide top N traffic distribution and timely detect abnormal traffic to guarantee network security.

NTA Features

  • Visible traffic: The NTA provides real-time IP traffic monitoring and displays traffic trends, so that administrators can identify and handle exceptions promptly.
  • Fault locating: The NTA provides network traffic analysis components that can analyze and audit original IP traffic and locate the source of abnormal traffic based on the analysis and audit results.
  • Reasonable planning: The NTA provides the trend analysis and user-defined report functions to offer reference for network capacity planning.

NTA Solution

The following figure uses a wired network as an example. In a wireless network, an Access Controller (AC) functions as a Network Data Exporter (NDE). In a Virtual eXtensible Local Area Network (VXLAN) network, a CE switch functions as an NDE.

Figure 12-23 NTA management process

eSight NTA collects and analyzes IP traffic information sent by the NDE (such as an S9700 switch) to monitor the entire network. Currently, only a single network traffic collector (NTC) is supported. Users can collect traffic at the core or aggregation layer or on the egress router based on the network architecture. After configurations are completed on the NDE, the NDE sends traffic logs to eSight NTA. The NTA analyzes original flow logs, adds the logs to the database, aggregates the data from multiple dimensions, such as interface, host, session, application, and protocol, and displayed the aggregated data.

On a typical campus network, network traffic monitoring can be implemented layer by layer. Users can deploy the NTC at different locations to achieve diversified monitoring effects. The common locations and their effects are as follows:

  • On an Internet egress to monitor users' online behavior
  • On a demilitarized zone (DMZ) ingress to identify users (internal users or external users)
  • At the core layer to monitor important services and applications
  • At the aggregation layer to monitor the bandwidth usage of a specified branch
Updated: 2019-09-07

Document ID: EDOC1100011877

Views: 311709

Downloads: 635

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Previous Next