ntopng is a network traffic probe that provides 360° Network visibility, with its ability to gather traffic information from traffic mirrors, NetFlow exporters, SNMP devices, Firewall logs, Intrusion Detection systems.
ntopng has been written in a portable way in order to virtually run on every Unix platform, including Linux, FreeBSD, pfSense, OPNsense, MacOS and on Windows as well. ntopng captures traffic from SPAN/mirror ports or TAP devices usinglibpcap orPF_RING (on Linux) for best performance. Or you can use it in combination withnProbe to collect NetFlow/sFlow from routers and switches, ornProbe Cento to analyze 100 Gbit links at full rate.
ntopng – yes, it’s all lowercase – provides a intuitive, encrypted web user interface for the exploration of realtime and historical traffic information.
ntopng works even better in distributed networks or high-speed links when paired with nProbe or nProbe Cento!
Monitor hundreds of thousands of hosts with zero‑delay traffic analysis on high‑speed uplinks.
Flow collection requires ntopng to be used in conjunction with nProbe which can act as probe/proxy.
The communication between nProbe and ntopng takes place over ZeroMQ, a publish-subscribe protocol that allows ntopng to communicate with nProbe.
A remote nProbe is physically monitoring a mirror from a NIC and sending monitored flows to ntopng, or is collecting NetFlow v5/v9/IPFIX or sFlow from one or more exporters (routers or switches). nProbe Cento allows you to monitor even 100 Gbit links when processing packets from a mirror port, yet providing application protocol information by running nDPI.
Mirror (SPAN) ports or TAP devices allow network monitoring tools to observe all packets flowing through the network for for network visibility, troubleshooting, threat detection, and capacity planning, without generating traffic or altering the data path.
A physical NIC card connected to a mirror can be monitored by ntopng itself by simply specifying its interface name. This configuration can be used to monitor a mirror port from a switch, or in conjunction with a TAP device by aggregating two directions from two network interfaces. Alternatively, it is possible to use ntopng in combination with nProbe or nProbe Cento to scale up to 100 Gbit.
Combine L7 visibility, IDS integration, syslog ingestion and alerts for full awareness. ntopng, in addition to behavioral checks able to detect traffic anomalies, can ingest events from IDS systems like Suricata enriching traffic analytics with security insights for faster threat detection and response.
Small Network | Medium Network | Large Network | |
Traffic | 100 Mbps | 1 Gbps | 10 Gbps and above |
Processor | 2 cores | 4 cores | 8+ cores |
Memory | 2 GB | 4 GB | 16+ GB |
For further information please check theHardware Sizing notes.
ntopng Community is distributed under the GNU GPLv3 license. Professional and Enterprise versions are subject to the EULA terms as well.
Did you already install the software?
Select the version that fits your needs. Different versions unlock different features and capacity.
Check thecomparison table for the features set about the various versions.