Network Monitoring Flashcards
There are tools that show interface statistics or Status on the following:
Link State
Speed and Duplex factors
Send and Receive Traffic
Cyclic Redundancy Check (CRC) errors
Giants and Runts
Encapsulation errors
Byte Count
A great monitoring tools are:
Zabbix
Grafana
Solar Winds
LibreNMS
Giants and Runts refer to the actual_______ _____ in a frame
packet size
Networks must be monitored in a number of ways, including:
performance, traffic, and environmental
this tool allows you to manage and monitor network devices from a single comuter:
Simple Network Management Protocol ( SNMP )
_________ are installed on a device to communicate with SNMP
Agents
A machine that communicates with a managed device is called a:
SNMP Manager and use the following ports for listening,
Unencrypted - UDP 162
Encrypted - TLS 10162
Network managed devices or agents run on these ports:
non-encrypted use - UDP listen on port 161
Encrypted use - TLS listen on port 10161
this helps with the communication between the Agent and SNMP manager that’s built into the Agent, like a database:
Management Information Base (MIB)
This is a standard query within SNMP that consists of an NMS
Get
this is setup on the managed devices itself
Trap
considered a batch of Gets
Walk
this tool is setup on Linux and is also considered a batch of Gets:
SnMPWalk
There are 3 versions of SNMP
SNMP version 1 does not support encryption at all
SNMP version 2 slightly expanded the command set and has encrypt
SNMP version 3 more robust TLS ecryption
An ______ _________ is an organization of managed devices
SNMP community
The following are open source NMS for graphing SNMP data:
Cacti
Nagios
Zabbix
Spiceworks
Where is a place to setup and view logs:
Windows - Event Viewer and
Unix systems utilizes SYSlog - standard format / works well with SNMP uses hierarchy of errors, like displays the worst to least problematic
History Logs
Change Logs
_____ _______ are a big deal, packets that are coming in and out of network that are clustered or messed up. Abnormal warnings of these might signify security breaches or broken equipment
Error rates
__________ is basically the monitoring of how your CPU is working, is it being overworked, where and why?
Utilization
this metric in Network monitoring lets you know when a host, server, or switch is having issues sending and receiving data.
Packet Drops
This metric is telling us how much data we are actually moving through our throughputs.
Bandwidth
A specialized metric that lets you know that all of a file was received in the proper sequence.
File Integrity
_______________ helps identify irregular activity that needs to be investigated.
Baselines
This actually brings all of the monitoring services into one:
Security information and event management (SIEM)