Home General

General

By Administrator MKE Solutions
3 articles

What is FastNetMon?

What is FastNetMon? FastNetMon is a high-performance DDoS (Distributed Denial of Service) detection and mitigation tool, specifically designed to monitor large volumes of network traffic. This system can quickly identify and respond to different types of DDoS attacks, helping maintain the availability and performance of network infrastructures. Key Features of FastNetMon 1. High performance FastNetMon can process large volumes of traffic in real time, making it an effective solution for networks with high data throughput. 2. Support for multiple flow protocols It supports multiple network flow formats, such as: - NetFlow - IPFIX - sFlow - Mirror/Port span (direct packet capture) 3. DDoS attack mitigation capabilities FastNetMon allows for automated attack mitigation, either by redirecting traffic or blocking it at the network perimeter. 4. User-friendly interface Despite its power, FastNetMon offers a graphical user interface that simplifies system administration and configuration. Use Cases - Internet Service Providers (ISPs): Helps ISPs protect their infrastructure and customers from DDoS attacks, ensuring service continuity. - Data Centers: Ensures the stability of services hosted in data centers by quickly detecting and mitigating attacks. - Organizations with high traffic networks: Companies handling large volumes of data can benefit from FastNetMon’s constant monitoring and automated response to anomalies. How FastNetMon Works FastNetMon captures and analyzes network traffic in real time using flow protocols or direct packet capture. Once it detects a suspicious pattern or an ongoing attack, it can trigger mitigation mechanisms to block malicious traffic. The basic operational steps are as follows: 1. Traffic capture: FastNetMon collects network flow data or directly captured packets from the network’s switches or routers. 2. Traffic analysis: It evaluates the received traffic to identify abnormal behaviors, such as sudden traffic spikes or patterns typical of DDoS attacks. 3. Attack detection: It compares the analyzed traffic with configured thresholds to determine if an attack is occurring. 4. Automatic mitigation: If an attack is detected, FastNetMon triggers automatic mitigation actions, such as redirecting malicious traffic or applying specific filters. Benefits of Using FastNetMon - Reduced response time to attacks FastNetMon allows for immediate identification and mitigation of attacks, reducing their impact on the network. - Optimized use of network resources By blocking unwanted traffic, it improves overall network performance and ensures better service quality. - Scalability and adaptability Designed for networks of various sizes, from small corporate networks to large-scale ISP infrastructures.

Last updated on Jan 06, 2025

Color Indicator Interpretation in Top Talkers Views

Color Indicator Interpretation in Top Talkers Views In several dashboards within FNM Manager, such as the Traffic Top Talkers Incoming panel, visual indicators are used to help identify potential anomalies in network traffic. These views highlight the hosts with the highest traffic, either in bandwidth (Mbps) or packets per second (PPS), allowing for quick situational awareness. To assist with interpretation, each host entry may include a colored status indicator that reflects its current behavior compared to historical data. Meaning of the Color Indicators The colored indicators are designed to convey the relative status of a host based on recent traffic trends: - Red: Current value exceeds the historical maximum value. - Yellow: Current value exceeds 150% of the average value. - Gray: Current value is within normal operational thresholds. These indicators are available for both Mbps and PPS metrics and help distinguish between bandwidth-heavy usage and high-packet-rate behavior. Purpose and Benefits The purpose of these indicators is to improve the readability and usability of the data presented in traffic reports. They provide: - Immediate visual feedback on the current state of each host. - A simplified way to identify which hosts are behaving abnormally. - Enhanced decision-making for network engineers and NOC operators without needing to manually compare numeric values. By using these visual thresholds, FNM Manager enables faster detection of irregular patterns that may suggest congestion, attacks, or misconfigurations.

Last updated on Apr 11, 2025