NanoPi R4S: Implementing a Transparent Network Monitor=============================================================Now that hobbyist ARM boards come with multiple 1GbE network ports, they start to have application in the network realm. The NanoPi R4S is equipped with up to 4GB of RAM, and a Rockchip 3399 64bit CPU which has 6 cores @ 1.8GHz, readily capable of being a homebrew router or transparent proxy. Let's focus on how to implement a transparent network monitor for starters. Onboard you will be generating Netflow and SNMP that can be consumed by ntopng to monitor your local network. You will be able to see top talkers, flows, device fingerprints and more. All from a convenient web interface with historical lookback. You can deploy behind or infront of the router, between a modem and the router, or between a single machine while staying invisible to Layer 3. Things you will need:******************
Upon logging in you will be prompted to do some setup. Choose a new password & shell. Generate your locale.
nano /etc/udev/rules.d/70-persistent-net.rules and replace the MAC address in ATTR{address} with the MAC of your eth0 or eth1 in the following:
nano /etc/network/interfaces
This configuration ensures that our onboard network interfaces are left unconfigured and only bound to the bridge which possess no IP address on the network.
ifup br0 to bring up the interface.
nano /etc/systemd/system/ntopng.service
systemctl enable ntopng && systemctl start ntopng now you can login to the web interface at http://your_ip:3000 and set a new password. Connect the physical ports to the network we want to monitor and you will see flows should start being collected.Thoughts:*************Now that you are able to see what your network is doing, you will be able to troubleshoot issues easier (or understand why your network is talking to AS8003.) Keep in mind it can be a source of dropped packets, if you are running it inline and not on a mirrored port. I have not (yet) seen the NanoPi introduce issues on an 1GB home network. If we wanted to scale this up to 10GB we could repeat this process on beefier hardware that supports DPDK. |