Network Traffic Analysis (NTA) & Observability
Network traffic analysis showing every flow in and out: which user, device and application, where the bandwidth goes, and what should not be there at all.
Shows all traffic in and out of your network: which user, device and application, which ports and protocols, where it goes and how much bandwidth it takes.
Also called
network traffic analysis, traffic analyser, NetFlow analyzer, bandwidth management, bandwidth utilisation, bandwidth monitoring, packet analysis, network observability, deep packet inspection.
What it does
- Flow analytics Conversations by source, destination, port and application.
- Identity-aware Every flow tagged with the device and user from NAC.
- Top talkers Find what’s consuming bandwidth in seconds.
- Anomaly detection Scans, spikes and unusual destinations.
- Automatic response Hand off to NAC to contain a device.
- Forensics Search flow history during an incident.
- Inbound & outbound visibility Every conversation in and out of your network, and between internal segments.
- Rich context on every flow Application, port, protocol, URL, geo-location, ASN, MAC, hostname and user.
- Bandwidth consumption Usage by user, device, application and site.
Common concerns
- Bandwidth hogs you can’t name
- Top talkers by user, device and application
- Suspicious east-west traffic
- Anomaly alerts that can trigger NAC
- Investigations without evidence
- Flow history per device
Questions and answers
- Do we need SPAN?
- No. Flow export from existing routers and switches is enough. SPAN adds depth where available.
- What can we see for each flow?
- Application, port and service, protocol, URL, location, ASN, MAC address, hostname, user and bandwidth used.
- What does NV-NTO show us?
- All traffic entering and leaving your network and moving inside it: which user, device and application, which ports, services and protocols, where it goes and how much bandwidth it uses.
- What details are available for each flow?
- Application, port and service, protocol, URL, geo-location, ASN, MAC address, hostname, user and bandwidth consumption.
- Can we see traffic by country?
- Yes. A world flow map shows incoming and outgoing traffic by country, and you can filter by any country, port or application.
- How does it spot threats?
- It detects abnormal use of ports, protocols and services, unusual destinations and sudden spikes, and highlights traffic that could be a threat or a data leak.
- Can we find who is using the bandwidth?
- Yes. Top talkers by user, device, application and site show what is consuming bandwidth in seconds.
- What happens when suspicious traffic is found?
- NV-NTO can hand the device to NV-ZT-NAC for quarantine, forward the event to your SIEM and record the flow evidence in NV-ITOPS.
- Which data sources are supported?
- Flow export such as NetFlow, sFlow and IPFIX from routers, switches and firewalls, and SPAN port mirroring where deeper visibility is needed.
- Does it help investigations?
- Yes. Flow history per device and user gives investigators the evidence of who talked to whom, when and how much.
Often deployed with
- Zero Trust NAC Knows every device the moment it connects and decides where it may go. Works with any switch, any hypervisor and any mix of enforcement, without changing your network.
- Infrastructure Health & Performance Watches everything your business runs on: network devices, servers, endpoints, databases, cloud, hypervisors and applications. You hear about a problem first, on the channel you prefer.
Guides
- Seeing every flow: traffic observability for security teams What to look for in your network traffic and how to act on it.