ntopNG
The Next Generation Traffic Analyst
for Netgate, Osigate, Mikrotik, Watchguard, Sophos, Juniper, Sonicwall ... firewall platforms.
a High-Speed Web-based Traffic Analysis and Flow Collection package on pfsense/opnsense. Also a network traffic probe that monitors concurrent network usage. ntopNG is based on libpcap/PF_RING and it has been written in a portable way in order to virtually run on pfsense / opnsense / routerOS platform. ntopNG provides a intuitive, encrypted web user interface for the exploration of real time and historical traffic information.
ntopNG Main Features
- Sort network traffic according to many criteria including IP address, port, Layer-7 (L7) application protocols, throughput, Autonomous Systems (ASs)
- Show real time network traffic and active hosts
- Produce long-term reports for several network metrics including throughput and L7 application protocols
- Top talkers (senders/receivers), top Autonomous Systems, top Layer 7 application protocols
- Monitor and report live throughput, network and application latency, Round Trip Time (RTT), TCP statistics (re-transmissions, out of order packets, packet lost), and bytes and packets transmitted
- Store on disk persistent traffic statistics to allow future explorations and post-mortem analysis
- Geo-locate and overlay hosts in a geographical map
- Discover Layer-7 application protocols (Facebook, YouTube, BitTorrent, etc) by leveraging on nDPI, ntop Deep Packet Inspection (DPI) technology
- Analyze IP traffic and sort it according to the source/destination
- Report IP protocol usage sorted by protocol type
- Produce HTML5/AJAX network traffic statistics
- Full support for IPv4 and IPv6
- Full Layer-2 support (including ARP statistics)
- GTP/GRE detunnelling
- Flexible alerts handling
- SNMP v1/v2c/v3 support and continuous monitoring of SNMP devices
- Identity Management, including correlation of VPN users to traffic
- Focused on network / intra-network cybersecurity measurement
- Behavioral traffic analyses such as lateral movements and periodic traffic detection