Technologies and Trends

How we Redesigned Search in ntopng

ntopng has had a search box for a while, but it we made it better to allow search for menu entries too! This to speed up and improve the user experience and navigation in ntopng. We added a short guided tour so you know what it can do. What you can search for It’s one box for two jobs. First, it filters every entry of the ntopng menu, so you can jump to a page or a setting by typing a few letters instead of hunting through the sidebar. Second, …
Announce

October 20th: Join us for the ntopng 7.0 Webinar

Is your network monitoring keeping pace with AI, larger infrastructures, and the growing need for real observability? We’re excited to introduce ntopng 7.0, alongside new releases of the rest of the ntop suite. This is one of the biggest ntopng releases to date: a new AI-assisted analysis engine, native SIEM integration, a network-to-site hierarchy for large deployments, BGP visibility, a completely rebuilt observability/timeseries backend on ClickHouse, and a modernized Vue.js frontend. We want to walk you through it live, with a Q&A session at the end of the event. Here …
Technologies and Trends

AI Dashboards in ntopng: Build Charts by Asking

If you’ve opened ntopng recently you may have noticed a new entry under the dashboards menu: AI Dashboards. Instead of picking a metric, a chart type and a time range from a form, you describe what you want to see in plain language and nAnalyst writes the query, picks the visualization and drops the widget on the page. This post walks through what they are, how to use them, and how to edit what you build. Similar to Grafana dashboards, we wanted to add a customizable interface to create custom …
nDPI

Introducing the nDPI TCP Fingerprint: A Stable, Patent-Free Way to Fingerprint TCP Stacks

Every TCP connection starts with a SYN, and that first packet says a lot about the machine that sent it. The Linux, Windows, macOS and Android stacks each set different flags, choose different initial TTLs, advertise different receive windows, and, above all, lay out their TCP options in different orders. Passive TCP fingerprinting turns those differences into a compact signature. Today we are announcing the nDPI TCP Fingerprint (TCPFP), a modern, open, patent-free TCP fingerprint format that has been included in nDPI for a few years now. It is implemented …
ISP/BGP

AS/IXP Traffic Observability: From Flows to AI-Assisted Root-Cause Analysis

  For most network operators, traffic visibility is not mandated by regulation, so it tends to be reactive rather than continuous: a “manual” investigation happens only after something breaks. Combined with limited time to review telemetry and the cost/data-sovereignty concerns of cloud-based visibility platforms, this leaves a real gap for AS operators and IXP participants who need to understand what is actually happening on their transit and peering links. ntop’s response is an open-source, on-premise stack (free at the community tier, with a paid enterprise tier funding development ) built …
Announce

Introducing nDPI TLS Fingerprint: A Stable, Collision-Resistant Successor to JA4

TLS client fingerprinting has become one of the workhorse techniques in network security, and JA4 (FoxIO) has been the de facto standard for identifying TLS clients from their ClientHello messages. But recent production experience at ntop surfaced two real limitations, and today we’re announcing nDPI TLS Fingerprint (TLSFP in short), an open, patent-free extension of JA4 that addresses both. Ephemeral Extensions Break Hash Stability JA4 builds its fingerprint from the full set of TLS extensions a client presents, hashed together with the cipher suite list. The trouble is that not …
ntopng

ntopng User Interface: Introducing the New Navigation Bar

In our continuous effort to improve user experience and make network monitoring more intuitive, we have completely redesigned the ntopng Navigation Bar. As our feature set expands—with crucial additions like the nAnalyst automated pipeline, specialized AI Dashboards, and high-resolution Observability analytics—the legacy menu structure needed a logical evolution to reduce deep nesting and facilitate daily operations. We have completely rearranged the main categories to help you find what you need faster, drawing a clear line between operational network monitoring, analysis tools, and security/alerting policies. Key Structural Updates Dashboard & Advanced …
Technologies and Trends

Elevate Your Network Visibility with ntop Professional Training November 2026

As network architectures evolve, staying ahead of performance issues and modern cybersecurity threats requires deep visibility and mastery of your tools. Here at ntop, our product range spans from high-speed packet capture to advanced traffic analysis. With our continuous updates and feature additions, keeping up with the ecosystem can be a challenge. Whether you are configuring large enterprise installations or looking to minimize the learning curve for new team members, this structured training will equip you with everything you need to build a tailored monitoring infrastructure. What’s New? Mastering ntopng …
Announce

Cento 2.6: ClickHouse Support, Enhanced Tunnel Visibility, PQC, and more

We are pleased to announce the release of cento 2.6, bringing a broad set of new capabilities and improvements to high-performance traffic processing and flow export. This release expands cento’s integration with the ntop ecosystem, adds new visibility into tunneled traffic, introduces Post-Quantum Cryptography (PQC) support, and delivers important improvements across protocol dissection, security, and performance. ClickHouse Export Cento 2.6 introduces ClickHouse export support, using a schema compatible with ntopng. This makes it easier to feed high-volume flow data into ClickHouse-based deployments and integrate cento into existing ntopng-oriented data pipelines. ClickHouse settings …
Cybersecurity

ntop and the EU Cyber Resilience Act

Under the EU Cyber Resilience Act (CRA), it has become compulsory for manufacturers of products sold on the EU market to report exploited vulnerabilities and severe incidents. As a result, ntop is fully committed to compliance with these new requirements. Since September 11, 2026, Article 14 of the CRA requires ntop to report security issues directly to the ENISA Single Reporting Platform (SRP). When a report is submitted here, it is simultaneously routed to both ENISA and the relevant national Computer Security Incident Response Team (CSIRT). We are required to report two …
Announce

nProbe 11.2: BGP/BMP Support, OT Protocols, Faster Flow Collection

We are pleased to announce the release of nProbe 11.2, bringing major new capabilities for network visibility, routing intelligence, flow analysis, and OT monitoring. This release significantly expands nProbe beyond traditional flow collection and export, adding BGP/BMP route enrichment, OT protocols support, collection deduplication, enhanced IPv6 handling. Flow collection has also been optimized to deliver higher performance with respect to version 11. Furthermore the export of information elements has been aligned with Cento, making them interchangeable. BGP/BMP Support and Route Enrichment One of the highlights of nProbe 11.2 is native support for BGP …
Technologies and Trends

Seeing Where Your Traffic Goes: Flow and Alert Geomaps

A flow table tells you which hosts are talking. A map tells you where. ntopng has two geomap views built on the same idea: one for live flows, one for flow alerts and together they answer “who are we communicating with around the world” and “where are the alerts coming from”. Here’s how to use both. Live flows on a map First, pick the interface you want to look at. Use the interface dropdown at the top left of the page. Open Flows > Live Flows > Geo Map View. …