Author: Alfredo Cardigliano

Technologies and Trends

Secure ZMQ Flow Collection Now Enabled by Default

Starting September 1st, 2026 (ntopng 6.7.280831 and later), cleartext flow data over ZMQ is no longer accepted by default. CURVE encryption is now enabled by default on ZMQ collection interfaces in ntopng. The same change applies to nProbe and Cento, which now also send ZMQ data encrypted by default. If no dedicated encryption key has been configured, ntopng falls back to a public built-in key pair. This provides protection against accidental cleartext exposure and ensures that encryption is enabled out of the box. However, users are strongly encouraged to configure dedicated keys as soon as possible, especially in production …
Technologies and Trends

Introducing PF_RING 9.4: Expanding Capabilities Across Capture, Flow Processing and Hardware Support

We are pleased to announce the release of PF_RING 9.4, bringing new capabilities for packet capture and flow processing, along with important improvements across the PF_RING kernel module, capture drivers, flow tracking, and system integration. Multi-Timeline Extraction with nPCAP PF_RING 9.4 adds support for multi-timeline extraction from n2disk dump sets, with timestamp-based data aggregation through nPCAP. This makes it possible to work more efficiently with traffic distributed across multiple timelines (e.g. load-balanced to multiple streams or interfaces), allowing traffic to be correlated and reconstructed based on timestamps, even when dumped to different …
Technologies and Trends

Saying Goodbye to Hierarchical Clusters in ntopng

The hierarchical cluster architecture was originally introduced to allow multiple ntopng instances to be organized in a parent/child topology. Child instances collected and analyzed local traffic, while parent instances aggregated information from multiple children to provide a centralized view of the network. At the time, this approach addressed a common requirement: monitoring geographically distributed sites while maintaining a central point of visibility. However, networking environments and the ntop ecosystem have both evolved considerably since then. Building a distributed deployment with nProbe and ntopng Today, the same use cases can be …
nProbe

Observability: Enabling High-Resolution Timeseries in ntopng

Modern observability platforms are expected to answer questions that traditional monitoring systems were never designed to handle: Conventional network timeseries are excellent for long-term capacity planning and trend analysis, but they often smooth away the short-lived events that matter most during troubleshooting and incident analysis. With the introduction of High-Resolution Timeseries, ntopng closes this visibility gap by enabling historical traffic analysis at 15 second, or even lower, granularity, directly embedded into flow records.  Why High-Resolution Timeseries Matter Traditional flow records aggregate counters over the entire lifetime of a connection. While this approach …
ntopng

Building Custom ntopng Dashboards Using Grafana and ClickHouse

Modern network monitoring is no longer just about collecting data, it’s more about turning large volumes of time-series data into actionable insights. When enabling dump to ClickHouse, both for raw flow data and timeseries, users can build a highly scalable and flexible observability stack that goes far beyond traditional dashboards. In fact, in this post we explore the advantages of using Grafana to create custom dashboards on top of ntopng time-series data stored in ClickHouse. From ntopng to ClickHouse: A Scalable Time-Series Pipeline ntopng continuously generates rich time-series metrics, including: …
ntopng

Single Sign-On on ntopng with OpenID Connect (OIDC)

ntopng has always supported multiple authentication methods to fit different environments: local accounts, LDAP, RADIUS, HTTP basic auth, etc. Now it also supports OpenID Connect (OIDC), bringing native Single Sign-on (SSO) support for any standards-compliant Identity Provider (IdP), including Keycloak, Okta, Auth0, Azure AD / Entra ID, Google Workspace, and more. Why SSO? Managing separate credentials for every tool in a network operations centre is a maintenance burden and a security risk. Passwords get reused, accounts get forgotten, and off-boarding a staff member means hunting down every application they had …
cento

nProbe Cento at Scale: Flow Offload Acceleration on Napatech

High-speed networks continue to push the limits of software-based monitoring and security applications. As link speeds grow and traffic patterns become more complex, efficiently analyzing packets while maintaining per-flow state, for updating stats and running Deep Packet Inspection, is increasingly challenging. By leveraging on our long term experience with high-speed packet processing, modern architectures, and state of the art data structures, during the past years we developed nProbe Cento, a high-performance NetFlow probe able to keep up with 100+ Gbit/s on adequate servers. However, this requires quite some resources (mainly …
ntopng

ntopng Direct Dump Mode for High-Speed Flow Collection

When ntopng receives flows from nProbe (NetFlow collector) or nProbe Cento (100 Gbit probe) over ZMQ or Kafka, each flow must go through several processing stages before it is finally stored in the database. These stages include metadata enrichment, classification, analytics, behavioural checks, and additional internal operations. While this processing pipeline is essential for ntopng’s real-time monitoring, it naturally adds latency between the moment a flow arrives and when it becomes queryable in the (ClickHouse) storage backend. In large deployments ingesting thousands or hundreds of thousands of flows per second, …
nScrub

nScrub 1.8: Performance, Flexibility, and Hardware Support

We are excited to announce the release of nScrub 1.8, the latest version of our high-performance DDoS protection and traffic scrubbing solution. This update brings significant improvements to the engine, new configuration options, expanded hardware support, and broader packaging availability. Engine Enhancements The 1.8 release introduces several performance optimizations and functional upgrades across the nScrub engine: New Options API Improvements The REST API has been extended to give administrators finer control over traffic mirroring: Tools and Packaging Updates Miscellaneous Improvements nScrub 1.8 is now available! We recommend all users upgrade to …
Technologies and Trends

PF_RING 9.2: Extended Offloads On Napatech and NVIDIA

We are excited to announce the release of PF_RING 9.2. This release brings numerous improvements across the core library, kernel module, and drivers, with a strong focus on stability, performance, and compatibility with modern Linux kernels and hardware platforms. PF_RING Kernel Module and Library The user-space library has been refined to improve stability and compatibility, with improvements in IPv6 and GRE packet decoding, and compatibility with the latest nDPI library for Layer-7 detection. The kernel module introduces several important enhancements, including improved namespace and container support, enabling smoother operation in virtualized and …
ntopng

ntopng 6.6: IXP/Telco Traffic Observability, Faster Flow Collection

We’re excited to announce the release of ntopng 6.6, available today! This release focuses on Autonomous Systems (AS) analytics, a major rework of the flow collection engine to provide better correlations and improve performance, and a native ClickHouse Cloud integration. But, as usual, there are many other improvements. Key Breakthroughs Autonomous Systems Intelligence ntopng 6.6 introduces brand new Autonomous Systems dashboards, Sankey visualizations, and comprehensive AS statistics.You can now easily understand traffic relationships between transit and origin ASes, track top contributors, and visualize AS-level traffic flows in real time. The release also brings: These …
nProbe

nProbe 11.0: Smarter Flow Analysis, Deeper Protocol Visibility, Enhanced GTP Traffic Correlation

We’re excited to announce the release of nProbe 11.0. This release incorporates several improvements and brings major improvements in flow analysis, tunnel handling, and TCP statistics, along with new features that make nProbe even more flexible and robust for complex network monitoring environments. Key Highlights Advanced TCP Flags Analysis nProbe 11.0 introduces enhanced TCP flag analysis, enabling more precise insights into TCP session behavior and improving visibility into flow state transitions. Enhanced GTP-C/GTP-U Traffic Correlation With this new release we have enhanced our GTP traffic processing and correlation (GTP-C with GTP-U) architecture. …