What is ntop?
Ntop is a tool that watches the traffic going in and out of your server. Traffic is the data that moves over the network. Ntop shows charts of who is talking to your server, how much data they use and which services are busy. It is like a counter at a shop door that counts every visitor.
You need root access for this guide. Root is the main administrator login of the server.
Tip: The old ntop is replaced by a newer tool called ntopng. The names and steps are close. Check which one your system offers.
Steps
- Connect to your server with SSH.
- Add the EPEL repository on Red Hat style systems. A repository is an online store of software.
This adds the extra store where ntop lives.yum install epel-release - Install ntop.
On Ubuntu or Debian useyum install ntopapt install ntopng. - Set an admin password. The old ntop asks for it with this command:
Type a password twice when asked.ntop -A - Start the service.
For ntopng useservice ntop startsystemctl start ntopng. - Make it start by itself after a reboot.
For ntopng usechkconfig ntop onsystemctl enable ntopng. - Open your browser. Go to
http://your-server-ip:3000. Ntopng uses this port by default. The old ntop often used port 3000 as well. Check your settings file if the page does not load.
Keep it safe
- Do not leave the ntop page open to everyone. It shows details about your network.
- Use your firewall to allow only your own IP address on that port.
- Use a strong admin password.
If the page does not load
- Check that the service runs with
service ntop status. - Check that the firewall allows the port.
- Read the settings file, often
/etc/ntop.conf, for the port number.
Tip: Ntop uses memory and processor power. On a small VPS, stop it when you are done.
Quick recap
- Ntop shows charts of network traffic.
- Install it from the EPEL repository, set a password and start the service.
- Open it in your browser on its port.
- Limit who can see the page.