Movatterモバイル変換


[0]ホーム

URL:


ntop

ntopng is a network traffic probe that provides 360° Network visibility, with its ability to gather traffic information from traffic mirrors, NetFlow exporters, SNMP devices, Firewall logs, Intrusion Detection systems.

ntopng has been written in a portable way in order to virtually run on every Unix platform, including Linux, FreeBSD, pfSense, OPNsense, MacOS and on Windows as well. ntopng captures traffic from SPAN/mirror ports or TAP devices usinglibpcap orPF_RING (on Linux) for best performance. Or you can use it in combination withnProbe to collect NetFlow/sFlow from routers and switches, ornProbe Cento to analyze 100 Gbit links at full rate.

ntopng – yes, it’s all lowercase – provides a intuitive, encrypted web user interface for the exploration of realtime and historical traffic information.

ntopng-application-analysis
at a glance

Key Features

  • Realtime network traffic, active flows and hosts
  • Top talkers, AS, L7 application protocols, categories
  • Protocol and application detection powered by nDPI
  • Custom reports on historical data with metrics and trends
  • Application latencies, Round Trip Time (RTT), throughput
  • TCP metrics including retransmissions, out of order, packet loss
  • Multimedia and VoIP metrics including jitter, MOS
  • Hosts geolocalisation
  • Multi‑interface support: mirror, TAP, flow collection
  • Packet capture via libpcap and PF_RING
  • Flow collection from nProbe, NetFlow and sFlow exporters
Works great with nProbe!

ntopng works even better in distributed networks or high-speed links when paired with nProbe or nProbe Cento!

Ideal for Every Environment

Use Cases

Flow Collection in Enterprise Networks

Monitor hundreds of thousands of hosts with zero‑delay traffic analysis on high‑speed uplinks.
Flow collection requires ntopng to be used in conjunction with nProbe which can act as probe/proxy.
The communication between nProbe and ntopng takes place over ZeroMQ, a publish-subscribe protocol that allows ntopng to communicate with nProbe.
A remote nProbe is physically monitoring a mirror from a NIC and sending monitored flows to ntopng, or is collecting NetFlow v5/v9/IPFIX or sFlow from one or more exporters (routers or switches). nProbe Cento allows you to monitor even 100 Gbit links when processing packets from a mirror port, yet providing application protocol information by running nDPI.

Mirror (SPAN) ports or TAP devices allow network monitoring tools to observe all packets flowing through the network for for network visibility, troubleshooting, threat detection, and capacity planning, without generating traffic or altering the data path.

  • Mirror Port (SPAN): available on most managed switches, duplicates traffic from selected ports or VLANs to a dedicated monitoring port.
  • TAP Device: transparently copies all network traffic at the physical layer, acting as a bump-in-the-wire and providing a fail-safe method for capturing traffic.

A physical NIC card connected to a mirror can be monitored by ntopng itself by simply specifying its interface name. This configuration can be used to monitor a mirror port from a switch, or in conjunction with a TAP device by aggregating two directions from two network interfaces. Alternatively, it is possible to use ntopng in combination with nProbe or nProbe Cento to scale up to 100 Gbit.

Combine L7 visibility, IDS integration, syslog ingestion and alerts for full awareness. ntopng, in addition to behavioral checks able to detect traffic anomalies, can ingest events from IDS systems like Suricata enriching traffic analytics with security insights for faster threat detection and response.

Specifications

Tech Specs

  • Linux
  • FreeBSD
  • Windows x64 (including Windows 10/11)
  • macOS
  • RaspbianOS
  • Web GUI available through any HTML5-ready browser
  • HTTP-based RESTful API
  • TLS/HTTPS support
  • Lua scriptability
Small NetworkMedium NetworkLarge Network
Traffic100 Mbps1 Gbps10 Gbps and above
Processor2 cores4 cores8+ cores
Memory2 GB4 GB16+ GB

For further information please check theHardware Sizing notes.

  • Ethernet
  • IPv4/IPv6
  • TCP/UDP/ICMP
  • GTP/GRE/MPLS/VXLAN
  • DHCP/BOOTP/NetBIOS/DNS…
  • 450+ Layer-7 application protocols supported by nDPI

ntopng Community is distributed under the GNU GPLv3 license. Professional and Enterprise versions are subject to the EULA terms as well.

versions

Choose Your Version

Did you already install the software?

Select the version that fits your needs. Different versions unlock different features and capacity.

Check thecomparison table for the features set about the various versions.

Community (Open Source)
Free
  • Reatime visibility and top talkers
  • Layer-7 application detection
  • Historical timeseries for hosts
  • VLAN, OS, Country and AS stats
  • Alerts and notifications
  • Active monitoring and network discovery
  • Designed for home and network practitioners
  • Small networks
Pro
299€
  • All Community features included
  • Interfaces aggregation in a unified View
  • LDAP authentication
  • Exterprise-level alert notifications
  • Extended behavioral checks and alerts
  • Network matrix timeseries
  • Designed for offices and small enterprises
  • Small/medium networks
Enterprise M/L/XL/XXL
499+€
  • All Pro features included
  • Historical data and reports
  • Extended SNMP support
  • NetFlow/sFlow exporters statistics
  • Identity management with VPNs
  • Infrastructure monitoring
  • Designed for large organisations, HSPs, ISPs, ...
  • Large networks
Screenshots

Gallery

ntop

High-performance network traffic monitoring and analysis tools.

Newsletter
go top
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.

[8]ページ先頭

©2009-2025 Movatter.jp