Network Monitoring Techniques and Tools
Incidents become easier to analyse when you have useful signals. Structure monitoring and the examination of technical information to identify anomalies. Strengthen your ability to guide investigations and discuss service status.
- Duration
- 5 days 35 hours
- Code
- RES60FR Code
Presentation
For optimal security, a network must be properly monitored using SNMP protocols and data formats.
Objectives
This course familiarises participants with SNMP (Simple Network Management Protocol) protocols and data formats and teaches network security monitoring flow techniques.
Program
1. Introduction to network monitoring
Network monitoring challenges
- Architecture: networks, servers and clients.
- Heterogeneous systems and equipment.
- LAN and WAN networks.
What are network monitoring and control?
- What should be monitored?
- Which tools should be used?
Monitoring approaches
- The stealth approach.
- The cooperative approach.
Examples of approaches in open-source tools
- The SNMP approach.
- The OSI approach.
- Proprietary approaches.
2. Network observation tools
- Observing network traffic.
- Quantitative and qualitative approaches.
- Example tools: Wireshark and ntop.
- Network performance monitoring tools: SmokePing.
- Network testing tools: Nmap.
3. Simple Network Management Protocol
- History: origins of SNMPv1.
- The agent-manager paradigm.
- SNMP requests and responses.
- Polling agents versus unsolicited notifications.
- Traps and notifications.
- Using SNMP-based monitoring applications.
4. Management Information Base and Structure of Management Information
- Defining and identifying management information.
- Using ASN.1.
- Organising data into MIB modules.
- Standard and proprietary MIBs.
5. SNMP developments
- Security: authentication and confidentiality.
- Versions 2c and 3.
6. Implementation issues
- Choosing a version.
- Configuring equipment.
- Supported agents and MIBs.
- Alarms and notifications.
- Extending agents.
7. Monitoring applications
- Which applications should be used?
- Open-source versus commercial tools.
- Monitoring application examples: Munin, Nagios, Big Brother and OpManager.
8. Practical exercises
- Planning, configuring and testing a network.
- Implementing SNMP agents on systems: Windows and/or Linux servers, switches and routers.
- Command-line queries and use of MIB Browser.
- Analysing the encoding of exchanged information.
- MIB analysis.
- Configuring SNMP versions 1 and 2c.
- Using SNMPv3 security.
- Using Munin and SmokePing.
- Using Wireshark.
- Using Nmap.
- Configuring and using NET-SNMP.
- SNMP-based open-source software: MRTG and CACTI.
- Monitoring applications: Nagios, Big Brother and OpManager.
Audience
This course is intended for network administrators and systems engineers.
Prerequisites
Basic networking and TCP/IP knowledge.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en