### and edit it to fit your needs.
###
### ntop is easily launched with options by referencing this file from
### a command line like this:
###
### ntop @/etc/ntop.conf
###
### Remember, options may also be listed directly on the command line, both
### before and after the @/etc/ntop.conf.
###
### For switches that provide values, e.g. -i, the last one matters.
### For switches just say 'do things', e..g -M, if it's ANYWHERE in the
### commands, it will be set. There's no unset option.
###
### You can use this to your advantage, for example:
### ntop @/etc/ntop.conf -i none
### Overrides the -i in the file.
### NOTE: This should not be root unless you really understand the security risks.
--user ntop
--db-file-path /var/ntop
--interface eth0
#--no-mac
### NOTE: To log to a specific facility, use --use-syslog=local3
### NOTE: The = is REQUIRED and no spaces are permitted.
--use-syslog
#--track-local-hosts
### NOTE: --http-server 3000 is the default
--http-server 3000
#--https-server 3001
### NOTE: Uses dotted decimal and CIDR notation. Example: 192.168.0.0/24
### The addresses of the interfaces are always local and don't need to be specified.
#--local-subnets xx.xx.xx.xx/yy
#--domain mydomain.com
### NOTE: For more than casual use, you probably want this.
#--daemon
#-P [directory]指定.db檔存放路徑
#-u [user]指定service啓動user
#-A 設定admin密碼,ntop會內建admin管理者帳號於ntop中
4.查看首次啓動所需動作
less /usr/share/doc/ntop-3.0/1STRUN.txt
5.編修/etc/ntop.conf檔
vi /etc/ntop.conf
內容如下:
#eth0 是我的單塊網卡 lo是迴路
--interface eth0,lo
#--no-mac
#由於我只是一臺機器所以下面的沒加,假如您是在路由器或網關上請把對應的ip段改成自己的
--local-subnets 192.168.10.0/24
#運行端口
--http-server 3000
#數據庫存放路徑
--db-file-path /usr/share/ntop
#守護進程方式運行
--daemon
#用戶名
--user ntop
#默認運行等級
--trace-level 3
#跳過任何錯誤
--disable-schedyield
6.啓動ntop
/etc/init.d/ntop start
7.查看網絡流量
http://localhost:3000/
8.停止爲
/etc/init.d/ntop stop
http://www.ntop.org/ntop.html爲ntop首頁 ,裏面有相關資料及抓圖等
ntop若是架設在hub下時便能監控到網絡上任何的封包。但若是架設在switch環境下時,除非是開放SPAN的功能否則只能監測給自己的封包。
本機測試環境爲單機,標準安裝。未配置插件條件下。如有興趣可自行研究插件 由於ntop需要監聽端口,所以最好用iptables限定某些ip能夠瀏覽 否則可能帶來安全性問題