YouTube2Text

Network Monitoring — Transcript

by Santelmo · 5,938 words · 1,174 segments · language en · Watch on YouTube

Full transcript

  1. 0:04hello there
  2. 0:05good day on this video lecture
  3. 0:09i'm going to discuss network monitoring
  4. 0:15okay so for
  5. 0:16the topic outline so on this video i'll
  6. 0:19be covering the introduction about
  7. 0:21network monitoring the monitor
  8. 0:25types of information
  9. 0:28network monitoring configurations
  10. 0:31network monitoring methods performance
  11. 0:35monitoring
  12. 0:36this includes performance indicators
  13. 0:39performance monitoring functions
  14. 0:42fault monitoring problems
  15. 0:45of fault monitoring and fault monitoring
  16. 0:49functions
  17. 0:50and the accounting monitoring so this is
  18. 0:54part
  19. 0:54and continuation of the f-cups that we
  20. 0:57have
  21. 0:58discussed on the previous video on the
  22. 1:00network management overview
  23. 1:03so let's start so
  24. 1:07network monitoring is basically
  25. 1:09concerned
  26. 1:10with observing and
  27. 1:14analyzing the status and behavior of the
  28. 1:16end systems
  29. 1:18so when you say and systems this
  30. 1:20pertains to computers
  31. 1:21servers printers right
  32. 1:25um voip these are the components that
  33. 1:28can be found on the end segment of the
  34. 1:30network
  35. 1:31okay so also intermediate systems
  36. 1:35so intermediate systems pertains to
  37. 1:38the devices that is located are situated
  38. 1:40between
  39. 1:41the end systems or end devices so this
  40. 1:44includes
  41. 1:45uh routers switches firewalls
  42. 1:48okay so those are intermediate systems
  43. 1:51layer two or layer three switches
  44. 1:54okay and sub networks so pertaining to
  45. 1:57the vlans
  46. 1:58that make up the network to be managed
  47. 2:01okay so what are the issues in
  48. 2:05network monitoring okay so first
  49. 2:08is what to monitor so a systems
  50. 2:11administrator
  51. 2:13so one of our duties and responsibility
  52. 2:16of course is to monitor the network
  53. 2:20okay but what do we have to monitor in
  54. 2:23the network
  55. 2:24so define what is to be monitored okay
  56. 2:28so next would be how do we how do we
  57. 2:31monitor it
  58. 2:32how to obtain information from the
  59. 2:34managed resources
  60. 2:36when you say managed resources this
  61. 2:38pertains to the managed objects
  62. 2:40okay and this managed objects are
  63. 2:43the ant systems intermediate systems and
  64. 2:45the subnets
  65. 2:47okay and
  66. 2:51what to do with the monitor information
  67. 2:52so how the monitor information is used
  68. 2:55in various management functional levels
  69. 2:58so basically
  70. 2:59on what to monitor being a systems
  71. 3:01administrator so what do we want to
  72. 3:03monitor on the network
  73. 3:04so basically we want to monitor the
  74. 3:06performance of the network
  75. 3:08the behavior of the network right the
  76. 3:12activities on the network okay
  77. 3:16so we are not monitoring
  78. 3:19the persons or the personal involved
  79. 3:22within the organizations but their
  80. 3:23activities over the infrastructure
  81. 3:26okay and how do we monitor it so
  82. 3:29basically we are using a third party
  83. 3:30software
  84. 3:31okay so we have a lot of applications
  85. 3:33that we can use
  86. 3:35for monitoring monitoring the network
  87. 3:36monitoring the
  88. 3:38bandwidth monitoring the throughput so
  89. 3:41basically in here
  90. 3:43we are using mostly application software
  91. 3:45or programs
  92. 3:47okay and what do we do with the monitor
  93. 3:50information so after gathering all those
  94. 3:52information
  95. 3:53after the observation and analysis so
  96. 3:57what do we do with this information okay
  97. 4:00so basically this information can be
  98. 4:02used
  99. 4:04for future planning okay so maybe
  100. 4:08at the current situation you are
  101. 4:09encountering some difficulties or
  102. 4:11problems regarding your network
  103. 4:13and the result of your observation and
  104. 4:15analysis
  105. 4:16might help you improve the performance
  106. 4:18of the network in the future
  107. 4:21okay so basically what to do with the
  108. 4:23monitor information is
  109. 4:24that would help you the team and
  110. 4:27organization
  111. 4:28to improve the service provided on the
  112. 4:31infrastructure
  113. 4:33okay next
  114. 4:36monitor types of information okay so
  115. 4:39this talks about
  116. 4:40the static information so when you say
  117. 4:43static information
  118. 4:44these are the information that could be
  119. 4:46hardly changes
  120. 4:47okay so current configuration
  121. 4:50information so example if we're talking
  122. 4:52about the router
  123. 4:53so the number and identification of
  124. 4:55ports on the router is considered to be
  125. 4:56static information
  126. 4:58okay so the number of lan or the
  127. 5:01internet interfaces on the router
  128. 5:04is considered to be static information
  129. 5:07also if we're talking about these
  130. 5:09switches the number of ports available
  131. 5:11on the switch
  132. 5:12is considered to be static information
  133. 5:15all right so next would be dynamic
  134. 5:19information
  135. 5:20so dynamic information changes
  136. 5:23frequently
  137. 5:24okay so information related to events in
  138. 5:27the network
  139. 5:28so the change of state of a device
  140. 5:32for instance the router serial 0 0
  141. 5:350 goes down and then after a second it
  142. 5:38went up
  143. 5:39okay so this our dynamic information the
  144. 5:41change of state from
  145. 5:42on to off or from up down
  146. 5:45these are considered to be dynamic
  147. 5:47information okay
  148. 5:49so the transition or transmission and
  149. 5:51reception of packets
  150. 5:53are considered to be dynamic information
  151. 5:56okay so this would
  152. 5:57uh basically depend on the number of
  153. 6:00packet that traverses over the
  154. 6:02network so this is considered to be
  155. 6:04dynamic
  156. 6:05or ever changing information okay so
  157. 6:08this would depend
  158. 6:09on the number of packet reverses over
  159. 6:12the
  160. 6:13infrastructure okay so the next one
  161. 6:16would be
  162. 6:17statistical the statistical information
  163. 6:21was derived from
  164. 6:23dynamic information okay so example are
  165. 6:26the and
  166. 6:26the average number of packets
  167. 6:28transmitted per unit time
  168. 6:30so the number of packets dropped
  169. 6:33from the network the number of packets
  170. 6:36um
  171. 6:37prohibited and denied by the access
  172. 6:40lists
  173. 6:41okay so configured on the router so
  174. 6:43these are all
  175. 6:44statistical information okay
  176. 6:48so next would be the organization of the
  177. 6:51management information base
  178. 6:53so when you say mib or the management
  179. 6:56information base
  180. 6:57this is basically the database
  181. 6:59containing the information
  182. 7:01pertinent to network management
  183. 7:04and organic organization of the mib
  184. 7:08includes of course the statistical
  185. 7:11database
  186. 7:12the dynamic database and this the
  187. 7:14statistical or the static sorry static
  188. 7:16database in here
  189. 7:18okay so again when we say statistical
  190. 7:21these are
  191. 7:22information derived from dynamic
  192. 7:25okay and static database these are the
  193. 7:28configurations
  194. 7:29fixed on the devices okay
  195. 7:33so this includes
  196. 7:36this components here okay the
  197. 7:39configuration database the sensor
  198. 7:41database
  199. 7:42for the dynamic databases so you've got
  200. 7:45the event the state
  201. 7:46okay like what we have mentioned earlier
  202. 7:49and the statistical database are of
  203. 7:50course
  204. 7:52the the statistics or the data derived
  205. 7:55from
  206. 7:55dynamic databases all right
  207. 7:58so the mib is basically the storage
  208. 8:02of the configured information on the
  209. 8:05device
  210. 8:08okay so let's talk about monitoring
  211. 8:10system components
  212. 8:11so the first one would be monitoring
  213. 8:13application
  214. 8:15we have mentioned earlier on how do we
  215. 8:17monitor or how do we come up
  216. 8:19with the information okay so derived
  217. 8:23from the
  218. 8:23infrastructure okay so
  219. 8:26or what tools are we gonna use to
  220. 8:29capture the information or the data
  221. 8:32or the packet that we need during the
  222. 8:34monitoring so of course
  223. 8:36we will be using the monitoring
  224. 8:38application
  225. 8:39so monitoring application includes the
  226. 8:42functions of monitoring
  227. 8:44that are visible to the user okay
  228. 8:47example performance
  229. 8:49fault accounting so these are all
  230. 8:52functions of monitoring that is or that
  231. 8:55are visible to the end users
  232. 8:58okay so basically performance you'll see
  233. 9:00it and you feel it
  234. 9:02okay so by by using tools
  235. 9:06like um the speed test
  236. 9:09okay so for the internet connectivity so
  237. 9:11we can see and compare
  238. 9:13okay so having a benchmark the
  239. 9:15performance of the network
  240. 9:18all right so aside from monitoring
  241. 9:20application we also have the
  242. 9:22manager function so manager function
  243. 9:25performs the basic monitoring function
  244. 9:28of retrieving information
  245. 9:32okay so from the previous discussion on
  246. 9:34the management
  247. 9:36overview or the network management
  248. 9:38overview we've talked about
  249. 9:40the manager agent paradigm
  250. 9:43all right so on the manager agent
  251. 9:47paradigm so we've talked about the
  252. 9:49duties and responsibilities or the
  253. 9:51function of
  254. 9:51each okay where in the manager is
  255. 9:54basically the application residing on
  256. 9:57the server where the administrator is in
  257. 10:00okay
  258. 10:01and the agent is basically
  259. 10:05uh the operating systems or the software
  260. 10:09residing on the managed object that
  261. 10:12captures
  262. 10:12information locally and for word data
  263. 10:16on the manager okay so the
  264. 10:20manager function you also have the agent
  265. 10:22function
  266. 10:23okay so which captures data or gathers
  267. 10:26records
  268. 10:27okay so from the managed object or mos
  269. 10:30so every managed devices on the
  270. 10:32infrastructure has an agent
  271. 10:35and the agent function is of course to
  272. 10:37fetch data from
  273. 10:39the local device and forward it to the
  274. 10:41manager
  275. 10:42so the manager function is to perform
  276. 10:44basic monitoring function of retrieving
  277. 10:46information
  278. 10:47so it receives data from the agent
  279. 10:51all right so also we kept on mentioning
  280. 10:55managed object
  281. 10:56or managed objects so what are this so
  282. 10:59managed objects
  283. 11:00pertains to a management information
  284. 11:04that represents resources and their
  285. 11:07activities
  286. 11:08so managed objects or mo's are
  287. 11:11routers switches firewalls workstations
  288. 11:14servers
  289. 11:15these are all managed objects okay so
  290. 11:18the device that we are monitoring and
  291. 11:20controlling
  292. 11:21are said to be managed object all right
  293. 11:24next would be a monitoring agent so the
  294. 11:27monitoring agent generates
  295. 11:29summaries and statistical analysis of
  296. 11:31this management information
  297. 11:34okay and we use it for
  298. 11:38future planning that's what i've said on
  299. 11:40the introduction
  300. 11:41all right so next would be the
  301. 11:44functional architecture
  302. 11:45of network monitoring the manager agent
  303. 11:49paradigm or model that we have presented
  304. 11:51on the network management overview
  305. 11:53now let's have some recap in here okay
  306. 11:56so the manager agent model
  307. 11:57is basically the relationship between
  308. 12:01the manager and the agent okay
  309. 12:04so the monitoring application is
  310. 12:07basically a manager function okay
  311. 12:11and on a managed object there is an
  312. 12:13agent
  313. 12:14and of course an agent function so the
  314. 12:17communications between the server
  315. 12:20having the management application or the
  316. 12:22manager
  317. 12:24to the agent so basically this is
  318. 12:27true or via the use of the simple
  319. 12:30network management protocol or snmp
  320. 12:32so we'll be talking about snmp in the
  321. 12:35next and upcoming videos
  322. 12:38all right so for the model of
  323. 12:41summarization
  324. 12:42okay so again in here is the server this
  325. 12:45is where the systems administrator is
  326. 12:47seated
  327. 12:47okay monitoring the performance of the
  328. 12:49network via the application
  329. 12:52and we have here the monitoring agent
  330. 12:55whose primary
  331. 12:57purpose is to summarize okay
  332. 13:00so the information forwarded by these
  333. 13:02agents
  334. 13:03so there might be two or more devices
  335. 13:07or a lot of mo's connected to the
  336. 13:10um to the monitoring agent okay
  337. 13:14so that's it next
  338. 13:17how about the network monitoring
  339. 13:19configuration
  340. 13:21okay so letter a here
  341. 13:24manage resources in a manager system
  342. 13:27okay so there is a possibility that we
  343. 13:30are actually monitoring
  344. 13:32okay so a device where the application
  345. 13:35where the manager
  346. 13:37is also installed for example
  347. 13:40you want to monitor the performance of
  348. 13:42your server
  349. 13:43so as a systems administrator you are
  350. 13:46seated in front of the server and you
  351. 13:48are using definitely
  352. 13:49a monitoring application okay now this
  353. 13:52monitoring application performs a
  354. 13:54manager function
  355. 13:55which is to receive information from
  356. 13:59the agent okay so the agent is on the
  357. 14:02managed object
  358. 14:03now if it happens that you are
  359. 14:05monitoring itself or monitoring the
  360. 14:08the server okay so where the application
  361. 14:10and the agent is stored
  362. 14:12so that is this model here okay
  363. 14:16so that would be possible okay so you
  364. 14:18are monitoring your own device
  365. 14:20okay so the agent is installed on the
  366. 14:22server the manager is also installed on
  367. 14:25the server
  368. 14:26all right next
  369. 14:29resources in the agent system so
  370. 14:32with this type of model the monitoring
  371. 14:34application or the manager function
  372. 14:37or simply say manager is
  373. 14:40stored or installed in a computer
  374. 14:44okay different from where the agent is
  375. 14:48installed
  376. 14:49so for example this is a server here and
  377. 14:51i have here a router
  378. 14:53okay and i manage the router
  379. 14:56using the subnet or the internet okay
  380. 15:00so that is this resources in the agent
  381. 15:02system
  382. 15:03okay or also it is also possible to
  383. 15:08monitor okay or to control
  384. 15:11any devices are managed object outside
  385. 15:15the network or it could be over the
  386. 15:16internet
  387. 15:18and we have here an agent function
  388. 15:21which is to summarize all the
  389. 15:23information gathered from demos
  390. 15:27okay and the fourth one would be a proxy
  391. 15:30monitor agent so again when say proxy
  392. 15:33this is the software that we use so that
  393. 15:36this
  394. 15:37proprietary software can communicate
  395. 15:39with an open systems and vice versa
  396. 15:42all right next
  397. 15:46network monitoring methods so how do we
  398. 15:49monitor
  399. 15:50the network so one is via
  400. 15:53polling okay so when you say polling
  401. 15:56this is a request response interaction
  402. 15:59between the manager and the agent
  403. 16:01so polling is basically initiated by the
  404. 16:05manager
  405. 16:06going to the agent okay so
  406. 16:09a manager sends a request to an agent
  407. 16:12which processes the request and responds
  408. 16:14with information from hmib
  409. 16:18all right so for example if i am the
  410. 16:20systems administrator and i
  411. 16:22am seated in a computer where i control
  412. 16:26and configure for instance a router okay
  413. 16:29so i am using puti puti is basically
  414. 16:33my manager okay and on the router
  415. 16:37this router uses an ios so basically the
  416. 16:40ios
  417. 16:41captures data okay from its mib
  418. 16:45okay or from its virtual database and
  419. 16:48that data will be forwarded to the puti
  420. 16:51to present it to the administrator so
  421. 16:53that is an example of polling
  422. 16:55okay for instance the administrator
  423. 16:58wishes to display or to know the routing
  424. 17:01table of the router
  425. 17:03so we simply execute the command show ip
  426. 17:05route
  427. 17:06on the putsy application okay
  428. 17:09so that is an example of polling where
  429. 17:12in the manager
  430. 17:14send a request to the agent and the
  431. 17:16agent will respond
  432. 17:18with the request of the manager so
  433. 17:20that's polling
  434. 17:21okay so all the show commands that we
  435. 17:24use
  436. 17:24in cisco routers or cisco switches
  437. 17:28or in firewall are all examples of
  438. 17:32polling all right so
  439. 17:35a manager may use polling to learn about
  440. 17:38the configuration it is managing
  441. 17:40to obtain periodically an update or
  442. 17:44or an update of conditions or
  443. 17:46investigate an
  444. 17:47area in detail after being altered
  445. 17:51to a problem so if the action is
  446. 17:55initiated by
  447. 17:56the manager we call it polling
  448. 17:59all right okay
  449. 18:02so how about if for instance the router
  450. 18:06interface serial zero zero goes down and
  451. 18:10the router sends a notification
  452. 18:13onto the manager okay so is it polling
  453. 18:17again with this example okay
  454. 18:20so the agent initiated the action and we
  455. 18:24call it event reporting
  456. 18:26all right so event reporting the
  457. 18:29information flow is initiated from the
  458. 18:31agent to the manager
  459. 18:32when you say polling it is from the
  460. 18:34manager
  461. 18:35to agent all right so the counterpart of
  462. 18:38polling is event reporting
  463. 18:41so an agent may generate report
  464. 18:43periodically
  465. 18:44to give the manager its current status
  466. 18:47or
  467. 18:47whenever a significant event happens
  468. 18:50okay so like for inside for instance
  469. 18:54due to intermittent uh interfaces
  470. 18:58okay so your serial zeros like zero zero
  471. 19:01goes down after a second it went up
  472. 19:05okay so there is a notification from
  473. 19:07your screen
  474. 19:08okay so about the status of the
  475. 19:10interface and we call it event reporting
  476. 19:14okay so when you're printing something
  477. 19:16okay for instance
  478. 19:18and the printer runs out of paper so
  479. 19:20there is a notification in your screen
  480. 19:23be a sort of a message informing you
  481. 19:26that
  482. 19:27the printer is running out of paper so
  483. 19:30that is an example of reporting
  484. 19:32okay or event reporting all right
  485. 19:36so this is good for detecting problem as
  486. 19:39soon as they occur
  487. 19:40okay so because this is real time
  488. 19:43all right you could even configure your
  489. 19:45device to have some event reporting by
  490. 19:48your your cell phone or via a mobile app
  491. 19:51on your gadgets all right so that
  492. 19:55would ease the troubleshooting
  493. 20:01okay so next would be performance
  494. 20:04monitoring
  495. 20:06okay so performance monitoring is
  496. 20:09measuring the performance of the network
  497. 20:12or performance monitoring
  498. 20:15that's absolutely required in network
  499. 20:17management
  500. 20:19okay so the objective
  501. 20:22is to detect and fix problems that cause
  502. 20:26performance degradation so you've got
  503. 20:28slowing performance
  504. 20:30okay the performance is worse than
  505. 20:34the usual all right so you've got
  506. 20:38performance monitoring in there okay and
  507. 20:41what do we do with that well the
  508. 20:43performance monitoring
  509. 20:46can be used to better plan network
  510. 20:48upgrades
  511. 20:50okay so basically if you're going to
  512. 20:52implement a network
  513. 20:54so on its first run or initial run the
  514. 20:57network is doing good
  515. 20:58okay and then after some time okay so of
  516. 21:01course the network
  517. 21:03ages down okay you've got the number of
  518. 21:06um
  519. 21:07connections also increases okay so what
  520. 21:10will happen is
  521. 21:11basically there would be performance
  522. 21:13degradation due to
  523. 21:14aging technology okay or due to an
  524. 21:18increase
  525. 21:19in the number of users okay
  526. 21:22so to to better upgrade
  527. 21:26or to better plan and do some network
  528. 21:28upgrades
  529. 21:29that would help okay via performance
  530. 21:32monitoring
  531. 21:33okay or we could address the problem via
  532. 21:35performance monitoring
  533. 21:37so what are the problems in selecting
  534. 21:39and using appropriate indicators or
  535. 21:40metrics
  536. 21:42okay so basically the first one would be
  537. 21:46too many indicators and use okay
  538. 21:49so it's just like you enabled all the
  539. 21:52features that you have
  540. 21:54on the application okay so for instance
  541. 21:59when you installed microsoft office okay
  542. 22:02so you have
  543. 22:02or you are given these options what
  544. 22:05specific
  545. 22:06feature okay needs to be installed
  546. 22:09on your microsoft office package so you
  547. 22:12have the option to choose let's say
  548. 22:15word powerpoint excel okay but you also
  549. 22:18have this
  550. 22:19choose all or select all and then you
  551. 22:21install it
  552. 22:22okay now the thing is you have a lot of
  553. 22:25applications
  554. 22:26installed on your computer but you are
  555. 22:28not actually using them all
  556. 22:30right so that is similar with having
  557. 22:34too many indicators in use or by having
  558. 22:39too many components that we want to
  559. 22:42monitor
  560. 22:43and yet some of it we are we are not
  561. 22:46using it
  562. 22:47okay the meaning of most indicators
  563. 22:52are not yet clearly understood okay so
  564. 22:55we simply
  565. 22:56choose to enable them all but we don't
  566. 22:59know
  567. 23:00where to use it or how what's the
  568. 23:02significance of it
  569. 23:03or what's the importance of it on your
  570. 23:05organization
  571. 23:06okay so be careful when you install
  572. 23:09performance
  573. 23:10monitoring applications because some of
  574. 23:12it might not be needed in the
  575. 23:14organization
  576. 23:15okay so take note that whenever we check
  577. 23:18the features
  578. 23:19on the applications so that would cause
  579. 23:22traffic
  580. 23:23and that traffic would cause performance
  581. 23:25degradation
  582. 23:26so you choose only indicators which
  583. 23:30the organization might need most
  584. 23:34all right next would be some indicators
  585. 23:36are supported by
  586. 23:38some manufacturers only okay so
  587. 23:41why there is too many indicators in use
  588. 23:44because
  589. 23:44of the bullet number three so if i am
  590. 23:47using apple then i'll be using
  591. 23:50monitoring applications for apple so
  592. 23:53i'll
  593. 23:53if i'm using linux i'll be using
  594. 23:55monitoring application for you
  595. 23:57for linux okay so
  596. 24:00that would lead to many indicators
  597. 24:03in use okay next would be
  598. 24:07frequently the indicators are accurately
  599. 24:11measured but incorrectly interpreted by
  600. 24:13human
  601. 24:13or the management application there's a
  602. 24:15problem here okay
  603. 24:17so we've gathered the data
  604. 24:20accurately and correctly but when we
  605. 24:23interpreted it
  606. 24:24well problem arises all right
  607. 24:28so we've got an incorrect interpretation
  608. 24:30of the results
  609. 24:32okay next would be
  610. 24:36the calculation of indicators takes too
  611. 24:38much time
  612. 24:40why performance aggregation okay
  613. 24:43so that is because of traffic
  614. 24:47why there is too much traffic because
  615. 24:49you have too many indicators
  616. 24:51checked on your monitoring application
  617. 24:54okay so it's a chain reaction
  618. 25:01okay so next is how do we measure
  619. 25:04performance indicators
  620. 25:06okay so it's either service oriented
  621. 25:09okay so when say service oriented we've
  622. 25:12talked about
  623. 25:13availability so availability pertains to
  624. 25:16the percentage of time that the network
  625. 25:18system or
  626. 25:19component or an application is available
  627. 25:22for a user
  628. 25:23okay so we measured service oriented
  629. 25:27via the availability of the device
  630. 25:30the availability of the resources okay
  631. 25:34next would be the response time so how
  632. 25:37long it takes for a response to appear
  633. 25:39at a user's terminal after the user's
  634. 25:42accident calls for it okay response time
  635. 25:46for example you have encountered an
  636. 25:48error on your system or on your computer
  637. 25:51and you seek help from the help desk
  638. 25:54how long would it take for the help test
  639. 25:56to address your problem
  640. 25:57response time okay
  641. 26:01or how fast are they to resolve the
  642. 26:04issues that you have
  643. 26:05response time next would be accuracy
  644. 26:08the percentage of time that no errors in
  645. 26:11the transmission
  646. 26:12and delivery of information because if
  647. 26:16there is an
  648. 26:16error there is a tendency to retransmit
  649. 26:19the data
  650. 26:20okay so again service oriented
  651. 26:24network performance indicators are
  652. 26:27measured using availability
  653. 26:29response time and accuracy
  654. 26:32so the second is efficiency oriented
  655. 26:37okay so efficient efficiency oriented
  656. 26:41we talked about throughput okay
  657. 26:45throughput is the rate at which
  658. 26:46application oriented events
  659. 26:48file transfers occur okay so throughput
  660. 26:52is related to bandwidth okay
  661. 26:55but if we are after the efficiency we're
  662. 26:58not talking about bandwidth
  663. 27:00but we measure it instead using
  664. 27:02throughput
  665. 27:03now what's the difference between
  666. 27:04throughput and bandwidth
  667. 27:06bandwidth is basically the
  668. 27:09frequency is the difference between the
  669. 27:11highest and the lowest frequency
  670. 27:13so in say bandwidth we're talking about
  671. 27:15the capacity
  672. 27:16okay the capacity of the internet what
  673. 27:18is your maximum speed
  674. 27:20all right what is your minimum speed
  675. 27:22minimum is zero maximum is 100 for
  676. 27:25instance
  677. 27:25so that range from 0 to 100 is said to
  678. 27:29be the bandwidth
  679. 27:30all right when you say throughput this
  680. 27:32is the actual transfer of data
  681. 27:35so if you have 0 to 100 mb and
  682. 27:38you're getting 90 mb then that is the
  683. 27:41throughput
  684. 27:42all right next would be utilization
  685. 27:46so the percentage of the theoretical
  686. 27:49capacity of a resource
  687. 27:50example transmission line switch cpu
  688. 27:54that is being used
  689. 27:56okay so we can
  690. 27:59monitor this via an application or
  691. 28:02if you are using your your pc you can
  692. 28:05monitor the cpu utilization the ram
  693. 28:07utilization
  694. 28:08okay via the task manager and that is an
  695. 28:11efficiency oriented
  696. 28:12performance indicator okay
  697. 28:16so we measure the performance either
  698. 28:19via efficiency oriented or service
  699. 28:22oriented so of course that would depend
  700. 28:25okay next
  701. 28:28now from the figure here okay
  702. 28:31so what is or what are the elements of
  703. 28:34response time
  704. 28:36okay so how long would it take for a
  705. 28:39device to respond
  706. 28:40on your inquiry okay is it real time
  707. 28:44no there's no such thing as real time in
  708. 28:46the network
  709. 28:47the mere fact that your data traverses
  710. 28:49on the cable
  711. 28:51on this interfaces it causes delay
  712. 28:55okay so the truth is for
  713. 28:58every response that we're getting okay
  714. 29:00so there
  715. 29:01is an integration of delays on it all
  716. 29:04right
  717. 29:05so the elements of response time these
  718. 29:07are delays
  719. 29:08okay so if you observe here now from the
  720. 29:12equation
  721. 29:13okay so that's what i'm saying earlier
  722. 29:14when your data traverses on the cable
  723. 29:17there is delay and it gets into the
  724. 29:19hardware there is delay
  725. 29:21okay so going back again to the cable
  726. 29:23another delay and so on
  727. 29:25okay so therefore response time
  728. 29:28is equals to the inbound terminal delay
  729. 29:32plus the inbound queueing time all right
  730. 29:36plus the inbound service time and so on
  731. 29:39so basically
  732. 29:40there is always delay for every response
  733. 29:43time
  734. 29:44right so it's just that as systems
  735. 29:47administrator how do we minimize
  736. 29:50delays okay
  737. 29:53next performance monitoring functions
  738. 29:57okay so this includes performance
  739. 29:59measurement
  740. 30:00and performance analysis now let's talk
  741. 30:04about performance measurement
  742. 30:06so this is the actual gathering of
  743. 30:08statistics
  744. 30:09about network traffic and timing okay
  745. 30:13so we do it via observation
  746. 30:16okay and of course with the help of
  747. 30:18tools we get it
  748. 30:20okay so typically performed by agents
  749. 30:23within network devices and
  750. 30:26we these agents forward the data
  751. 30:29to the manager okay so by uh snmp
  752. 30:34and of course the systems administrator
  753. 30:37can view and analyze okay so that data
  754. 30:42okay so example includes the amount of
  755. 30:46data in and out of the node
  756. 30:47or the number of connections traffic per
  757. 30:50connection
  758. 30:51so that's performance measurement okay
  759. 30:54next would be performance analysis so
  760. 30:57analyzing the guard data
  761. 30:59and presenting it so example you've got
  762. 31:02the total the average the min max
  763. 31:04histogram
  764. 31:05something like the statistical
  765. 31:06information about the gathered data
  766. 31:09we call it performance analysis okay
  767. 31:12and usually we compare it or we do a
  768. 31:15benchmark of it on the previous records
  769. 31:17that we have
  770. 31:18okay and we are expecting
  771. 31:22okay so we've got the improvement
  772. 31:25or better service provided to the end
  773. 31:27users
  774. 31:29all right next is
  775. 31:33synthetic traffic generation so what is
  776. 31:35this so generating artificial traffic
  777. 31:38load
  778. 31:38to test okay your network so for
  779. 31:41instance
  780. 31:42if i'm going to design a network that is
  781. 31:44good for for
  782. 31:46100 workstations and i only have 10 here
  783. 31:49so i could use the synthetic traffic
  784. 31:51generator to test
  785. 31:53whether the network is capable of having
  786. 31:56100 workstations though i only have 10.
  787. 31:59okay so something like doing a
  788. 32:01simulation test
  789. 32:03okay it permits the network to be
  790. 32:05observed under controlled
  791. 32:07load okay
  792. 32:11all right so next would be a typical
  793. 32:14performance related questions
  794. 32:16okay so performance measurements can be
  795. 32:19used
  796. 32:20to answer a number of questions so these
  797. 32:23questions could help us
  798. 32:25improve the performance okay so
  799. 32:29if we are asked or invited okay so to
  800. 32:32ask questions
  801. 32:33on how to improve the performance
  802. 32:36of the network well these questions
  803. 32:39could help you
  804. 32:40okay number one why is the response so
  805. 32:43slow
  806. 32:45so if you are the i.t personal and i am
  807. 32:48the
  808. 32:48end users and they ask you this question
  809. 32:50how would you answer it
  810. 32:52why is the response so slow are you
  811. 32:55going
  812. 32:56to give me answers like because the
  813. 32:57internet is low
  814. 32:59or maybe we have um increased the number
  815. 33:03of users on the network
  816. 33:04on the network that is why the response
  817. 33:06is so slow
  818. 33:08okay and you ask the same question okay
  819. 33:11same questions
  820. 33:12were asked after a year
  821. 33:15and how would you address it are you
  822. 33:17going to give us the same answer
  823. 33:20okay so this is a very loaded question
  824. 33:22so why is the response so slow
  825. 33:24okay next would be why is the
  826. 33:27transmission rate so high so this is
  827. 33:29somehow technical
  828. 33:31okay retransmission happens because
  829. 33:34the data or there is a drop on the
  830. 33:36transmission of packets
  831. 33:38okay so if there is a drop in the
  832. 33:40transmission of packet the tendency is
  833. 33:42the devices will retransmit it
  834. 33:44especially if you are transmitting a tcp
  835. 33:47packets
  836. 33:48okay so that requires an acknowledgement
  837. 33:51all right
  838. 33:53next is traffic evenly distributed among
  839. 33:56network users
  840. 33:58or are there source destination pairs
  841. 34:01with unusually heavy traffic
  842. 34:04okay so for instance in an organization
  843. 34:07basically
  844. 34:08we give um traffic or we give bandwidth
  845. 34:12okay to every department depending on
  846. 34:16their
  847. 34:16functions and the organization okay so
  848. 34:20allowing or assigning bandwidth to
  849. 34:24marketing
  850. 34:25is different compared to assigning
  851. 34:28bandwidth to accounting personnel
  852. 34:31all right so you you assign bandwidth
  853. 34:35depending on its function okay
  854. 34:38in the organization all right
  855. 34:42next what is the percentage for its type
  856. 34:45of packet transmitted
  857. 34:47so there should be a higher percent
  858. 34:50of a successful transmission than
  859. 34:52failure
  860. 34:53okay next what is the channel
  861. 34:56utilization and throughput
  862. 34:58so we discussed throughput and defined
  863. 35:00throughput earlier
  864. 35:02and the channel utilization okay so
  865. 35:05we're talking about the ratio here okay
  866. 35:07so out of
  867. 35:08say you'll have 30 mbps
  868. 35:12okay for instance okay so that's your
  869. 35:16your bandwidth what are you getting from
  870. 35:18it
  871. 35:19are you getting 30 also are you getting
  872. 35:22just 20
  873. 35:23okay so utilization
  874. 35:27is it should be higher okay
  875. 35:30and the throughput should also be higher
  876. 35:32it should be close to
  877. 35:33the bandwidth all right
  878. 35:36next what is the effect of traffic load
  879. 35:38on utilization
  880. 35:40throughput and time delays okay
  881. 35:44so basically with this
  882. 35:47with every traffic on the network
  883. 35:50your performance has the tendency to
  884. 35:52decrease
  885. 35:53okay so if you want to address really
  886. 35:56the performance you have to improve
  887. 35:58the bandwidth you have to improve the
  888. 36:00throughput
  889. 36:02the utilization and that would diminish
  890. 36:05delays
  891. 36:07okay next when does traffic load start
  892. 36:10to degrade system performance
  893. 36:13okay so for example in school okay
  894. 36:16so if you have a class at 7 30 in the
  895. 36:18morning okay so
  896. 36:19when you came in there early at six
  897. 36:21o'clock okay so basically you're gonna
  898. 36:23have a good
  899. 36:25internet access a better internet access
  900. 36:28but as the number of students increases
  901. 36:31in the campus
  902. 36:32so you will experience some degradation
  903. 36:36in terms of internet access that is
  904. 36:38because
  905. 36:39a number of users okay a bulk of users
  906. 36:43are trying to access the same resource
  907. 36:45that you are accessing
  908. 36:47okay so you should be able to know
  909. 36:50the time when the performance
  910. 36:53aggregation
  911. 36:54happens on the network and also you
  912. 36:56should be able to identify
  913. 36:58okay the the peak okay i mean
  914. 37:02during what time would be the
  915. 37:05a very good or excellent internet access
  916. 37:08every sunday
  917. 37:09all right or maybe 4 30 to 9 we've got
  918. 37:12a better internet access that is because
  919. 37:15less users
  920. 37:16are in the campus during that time okay
  921. 37:19so a systems administrator
  922. 37:21you should know okay the time
  923. 37:25when to start the
  924. 37:28allocation of the resources okay so to
  925. 37:31anticipate the
  926. 37:32[Music]
  927. 37:33volume of users in the network to avoid
  928. 37:36performance degradation okay so we have
  929. 37:39some sort of reallocation of resources
  930. 37:41maybe
  931. 37:42right and the last one would be
  932. 37:46what is the maximum capacity of the
  933. 37:48channel under normal operating
  934. 37:49conditions
  935. 37:50and how many active users are necessary
  936. 37:53to reach this
  937. 37:54maximum okay so again as network
  938. 37:57administrator
  939. 37:58or a systems administrator you should
  940. 37:59know that
  941. 38:01this channel or that this network
  942. 38:04or that this internet could only
  943. 38:08allow 100 people to access okay
  944. 38:11so if you have more than 100 then
  945. 38:15performance duplication starts or begins
  946. 38:19okay and a systems administrator you
  947. 38:21should have
  948. 38:23the solution to that okay so again the
  949. 38:26possible solution is
  950. 38:27there might be a need for reallocation
  951. 38:30of resources all right
  952. 38:35okay so next would be fault monitoring
  953. 38:39okay so to detect faults as quickly as
  954. 38:42possible
  955. 38:43after they occur and to identify the
  956. 38:45cause of the fault so that correctional
  957. 38:47action may be taken
  958. 38:49so a systems administrator well it's our
  959. 38:51duty to
  960. 38:52[Music]
  961. 38:54maintain okay a fault free
  962. 38:57network okay so
  963. 39:00problems on fault monitoring so this
  964. 39:03includes fault detection problem
  965. 39:05so there is an observable fault example
  966. 39:07deadlock
  967. 39:08okay so device not monitorable deadlock
  968. 39:12is unobservable i mean you don't know
  969. 39:15when it will be coming
  970. 39:16okay so we all know that that luck
  971. 39:18happens only if
  972. 39:20the resources requested by the
  973. 39:22application cannot be granted
  974. 39:24okay so there is also partial or
  975. 39:27partially observable faults
  976. 39:29inefficient to pinpoint what a problem
  977. 39:31is
  978. 39:32okay or uncertainty in observation
  979. 39:35so not clear what really the problem is
  980. 39:39okay so that's a fault detection problem
  981. 39:42you don't know the source of the problem
  982. 39:44so how can we solve it
  983. 39:46next would be fault isolation problems
  984. 39:49so multiple potential causes
  985. 39:52too many related observations sometimes
  986. 39:55this is our
  987. 39:56problem we have a lot of information we
  988. 39:58have a lot of
  989. 39:59a lot of inputs and we have a hard time
  990. 40:02to
  991. 40:02digest okay so we have too many related
  992. 40:06observations that is why
  993. 40:08so that takes a slow in solving the
  994. 40:11problem
  995. 40:12okay interferences between diagnosis
  996. 40:15and local recovery procedures and
  997. 40:18absence of automated testing tools so we
  998. 40:20do it manually
  999. 40:21so you've got fault isolation problem
  1000. 40:25all right now considering this diagram
  1001. 40:28here
  1002. 40:29okay we only have one link
  1003. 40:32okay connecting to the server now what
  1004. 40:35will happen if this t1 link fails
  1005. 40:39okay so it's dc or disconnected
  1006. 40:44okay so what it says here is that
  1007. 40:48whenever you you create connections to
  1008. 40:51the server for
  1009. 40:52instance there might be a sort of
  1010. 40:54redundancy
  1011. 40:55okay so that when the primary link goes
  1012. 40:57down so there is an alternate or backup
  1013. 40:59link
  1014. 41:00okay so that will capture
  1015. 41:03okay so the the connections
  1016. 41:08with the server or with the devices
  1017. 41:11all right so if the
  1018. 41:15primary link goes up so there is also a
  1019. 41:18chance that
  1020. 41:19it will go back to the original state i
  1021. 41:22mean
  1022. 41:22so the backup will go on the backup
  1023. 41:25state
  1024. 41:26and the primary will go on the primary
  1025. 41:29duty
  1026. 41:30all right
  1027. 41:34okay so propagation of failures to a
  1028. 41:36higher layers so basically
  1029. 41:38being a systems administrator you should
  1030. 41:40know where each component
  1031. 41:43of a network device works okay so for
  1032. 41:45instance router router basically works
  1033. 41:47on the layer three
  1034. 41:48okay so it just works in the layer two
  1035. 41:50okay so if there would be a problem for
  1036. 41:53instance
  1037. 41:54okay so on the connections on the router
  1038. 41:57so basically that would be propagated
  1039. 41:59onto the application layer okay so if
  1040. 42:02there would be problem with the
  1041. 42:03connections here
  1042. 42:04that can be visualized on the
  1043. 42:06application layer so we could have
  1044. 42:07something like
  1045. 42:08if we can initially ping the connection
  1046. 42:10then after some time we've got request
  1047. 42:12timeout
  1048. 42:13all right or if there would be a problem
  1049. 42:17on the lower layer
  1050. 42:18so that would be propagating up to the
  1051. 42:20highest layer
  1052. 42:22all right so that would aid
  1053. 42:25troubleshooting
  1054. 42:26okay so how would you start
  1055. 42:27troubleshooting in here so are you going
  1056. 42:29to use
  1057. 42:31a bottom up approach or a top down
  1058. 42:33approach
  1059. 42:35okay so usually if there will be a
  1060. 42:36problem on the hardware
  1061. 42:38that propagates onto the higher layers
  1062. 42:43so you should know okay the techniques
  1063. 42:46okay that is being used on
  1064. 42:49troubleshooting
  1065. 42:50network troubleshooting specifically
  1066. 42:55okay so next would be default monitoring
  1067. 42:58functions
  1068. 43:00so let's start with logs or lagging
  1069. 43:02facilities so record important events
  1070. 43:04and errors so lag should be accessible
  1071. 43:09by managers via polling so we have
  1072. 43:12introduced and defined
  1073. 43:13polling okay from the previous slides
  1074. 43:16okay
  1075. 43:16so there should be a lagging facilities
  1076. 43:19okay
  1077. 43:20event reporting sending events error to
  1078. 43:24managers
  1079. 43:25sending alarms to manager
  1080. 43:28to warm possible problems so we're
  1081. 43:30talking we're talking about
  1082. 43:31notifications here okay so notifications
  1083. 43:36that would be initiated by the agent to
  1084. 43:38the manager
  1085. 43:40you could also use diagnosis uh
  1086. 43:42diagnostic function like the
  1087. 43:44connectivity test
  1088. 43:46so traceroute okay or tracer
  1089. 43:50right trace route on the routers and
  1090. 43:52tracer on
  1091. 43:54the computers you can also use the
  1092. 43:56response time
  1093. 43:57test okay
  1094. 44:00the live nest test or the ping
  1095. 44:04okay the protocol integrity test
  1096. 44:08you bring one two seven zero zero one so
  1097. 44:11that is the test where your protocol
  1098. 44:12stack is
  1099. 44:14properly working okay you could also
  1100. 44:17use the loopback test okay or
  1101. 44:20same with the protocol integrity test
  1102. 44:22something like one two seven zero zero
  1103. 44:24one
  1104. 44:24it's a look back all right
  1105. 44:28next how about accounting so accounting
  1106. 44:31monitoring
  1107. 44:32keeping track of the users usage of
  1108. 44:35network resources
  1109. 44:38so communication facilities
  1110. 44:41computer hardware software and systems
  1111. 44:44and
  1112. 44:45services okay so how do you monitor the
  1113. 44:48utilization for instance
  1114. 44:50of an employee okay so
  1115. 44:53we use application okay so as always
  1116. 44:56for every monitoring activities so we
  1117. 44:59use
  1118. 44:59applications so you we don't want this
  1119. 45:02to
  1120. 45:03perform manually all right so
  1121. 45:06usage may be
  1122. 45:08[Music]
  1123. 45:09need to be broken down by account by
  1124. 45:13project
  1125. 45:13or by individual user for appropriate
  1126. 45:16accounting purposes
  1127. 45:19okay so before we end up let's wrap up
  1128. 45:23so let's summarize what we have
  1129. 45:25discussed and learned from this
  1130. 45:27video so first we talked about network
  1131. 45:29monitoring
  1132. 45:31okay and it is the most basic aspect
  1133. 45:34of network management okay
  1134. 45:37or part of the system's administration
  1135. 45:41or systems administrators duty and
  1136. 45:43responsibility
  1137. 45:45okay we also talked about the purpose of
  1138. 45:48network monitoring
  1139. 45:50that is to gather information about the
  1140. 45:51status and behavior of the network
  1141. 45:53elements
  1142. 45:54okay so information to be gathered
  1143. 45:58includes
  1144. 45:58static okay dynamic and statistical
  1145. 46:01information
  1146. 46:03monitoring methods we've talked about
  1147. 46:05polling and event reporting
  1148. 46:06okay polling initiated by the manager
  1149. 46:10and event reporting initiated by the
  1150. 46:12agent
  1151. 46:13also we've talked about the monitoring
  1152. 46:15functions performance monitoring
  1153. 46:18fault monitoring and accounting
  1154. 46:20monitoring
  1155. 46:22okay so if you will observe okay so
  1156. 46:25network monitoring is more on the
  1157. 46:27performance
  1158. 46:28fault and accounting where is security
  1159. 46:32and configuration we've got f cops right
  1160. 46:35fcaps fault is there configuration is
  1161. 46:39missing
  1162. 46:40all right so accounting is there
  1163. 46:44you've got performance is there and
  1164. 46:47security is not in there
  1165. 46:49okay so the configuration
  1166. 46:52and security will be covered on the next
  1167. 46:55video
  1168. 46:56okay so that is network control all
  1169. 46:58right
  1170. 46:59so that ends up the video so thank you
  1171. 47:02for sticking around and thanks for
  1172. 47:04watching have a great day
  1173. 47:10[Music]
  1174. 47:17you

About this transcript

This page contains the full transcript of Network Monitoring by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 5,938 words across 1,174 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.