What is network monitoring?
Network monitoring is the continuous checking of network devices, addresses and traffic so faults, conflicts and suspicious activity are found before they disrupt users. Ontech ICTM monitors device availability and latency with scheduled ICMP ping, manages IP addressing with subnet scans and conflict detection, backs up device configurations over SSH and analyses NetFlow, IPFIX and sFlow records.
A network can fail loudly, when a link or switch goes down, or quietly, when duplicate IP addresses cause intermittent faults, a configuration change is lost, or a compromised host starts sending data somewhere it should not. Good network monitoring covers all of these, not only whether a device answers.
ICTM approaches the network from four angles: availability (is each device reachable and how fast), addressing (which IPs are allocated, free or in conflict), configuration (a stored copy of each device's running configuration) and traffic (flow records exported by routers, switches and firewalls, analysed for signs of attack).
Documentation sits alongside the monitoring: topology, VLANs and wireless networks are recorded and drawn as a map, and bandwidth figures you supply feed a capacity forecast, so the network team works from one place.
What ICTM does for network monitoring
Device availability and latency
Ping monitored devices over ICMP on a schedule, record uptime and latency, and raise an alert after repeated failures. Manual and bulk ping tests help when troubleshooting.
IP address management
Manage subnets and IP allocations, detect address conflicts, and scan a subnet with an nmap ping sweep that records responding hosts with MAC address and hostname.
Configuration backups
Pull each device's running configuration over SSH and store it, so you have a known-good copy before and after changes.
Flow collection and network detection
Receive NetFlow v5/v9, IPFIX and sFlow exports and analyse them for port scans, command-and-control beaconing, lateral movement, DNS tunnelling, data exfiltration and brute-force attempts.
Topology, VLAN and wireless records
Document devices, links, VLANs and wireless networks and view them as a topology map maintained by your network team.
Capacity forecasting
Apply a linear trend to the bandwidth figures you provide to estimate when a link will cross warning or critical thresholds.
FortiGate firewall monitoring
Test the connection to a FortiGate, read its CPU and memory figures and synchronise its traffic logs into ICTM.
Firewall rule audits
Parse FortiGate, Palo Alto, Cisco ASA, pfSense and iptables configurations, run twelve rule checks, score the rule set and produce a PDF report with AI commentary for reviewers.
WireGuard remote access
Set up a WireGuard server on the ICTM host, add and remove peers, and generate client configurations with QR codes for remote staff.
ICTM modules: Network Dashboard · Network Monitoring · Ping Test · IPAM Dashboard · IP Subnets · IP Conflicts · Config Backups · Network Topology · VLAN Management · Wireless Networks · Capacity Planning · Firewall Management · Firewall Security Audit · WireGuard VPN · Network Detection & Response
What ICTM monitors on the network, and how
| What | How ICTM does it | What you get |
|---|---|---|
| Device availability | Scheduled ICMP ping | Uptime, latency and an alert after repeated failures |
| IP address space | Recorded allocations plus nmap ping sweeps of subnets | Live hosts with MAC and hostname; IP conflicts |
| Device configuration | SSH pull of the running configuration | Stored configuration backups |
| Traffic behaviour | NetFlow v5/v9, IPFIX and sFlow collection | Flow records and detections such as scans, beaconing and exfiltration |
| Firewall rule sets | Parsing of FortiGate, Palo Alto, Cisco ASA, pfSense and iptables configurations | Rule findings, a score and a PDF report |
| Link capacity | Linear trend on bandwidth figures you supply | Estimated date a link reaches warning or critical levels |
Use cases
Branch connectivity
See at a glance which branch routers and links are reachable and how latency is trending.
Troubleshooting intermittent faults
Find duplicate IP addresses and unknown hosts on a subnet before chasing hardware problems.
Safe configuration changes
Back up a device's configuration before a change window so it can be compared or restored afterwards.
Spotting unusual traffic
Use flow detections to find hosts that are scanning, beaconing or moving unusual volumes of data.
Firewall review for an audit
Produce a scored, documented review of firewall rule sets as evidence for security and compliance audits.
Benefits
Faster fault isolation
Availability, addressing and configuration data in one place shorten the path from symptom to cause.
Security from network data
Flow analysis turns traffic you already export into detections for common attack behaviour.
Recoverable configurations
Stored device configurations reduce the impact of failed changes and hardware replacement.
Documented network
Topology, VLAN and IP records give new staff and auditors an accurate picture of the network.
Frequently asked questions
Which protocols does ICTM use to monitor the network?
ICTM uses ICMP ping for availability and latency, nmap ping sweeps for subnet scans, SSH to back up device configurations, and NetFlow v5/v9, IPFIX and sFlow for traffic analysis. For FortiGate firewalls it also connects to the device to read CPU, memory and traffic logs.
What is the difference between network monitoring and network detection and response?
Network monitoring asks whether devices and links are working. Network detection and response (NDR) asks whether the traffic itself looks malicious — for example a host scanning the network or beaconing to an external server. ICTM does both: ping and IPAM for availability and addressing, flow analysis for detection.
Can ICTM draw a network topology map?
Yes. You record devices, links, VLANs and wireless networks and ICTM draws them as a topology map. The map reflects what your team records, so it doubles as network documentation for new staff, change planning and audits.
How does ICTM detect IP address conflicts?
ICTM keeps a record of subnets and allocated addresses and flags conflicts where the same address is allocated more than once. Subnet scans with an nmap ping sweep show which hosts actually respond, with MAC address and hostname, so you can compare what is live against what is recorded.
Which firewalls can ICTM audit?
ICTM parses rule sets from FortiGate, Palo Alto, Cisco ASA, pfSense and iptables, runs twelve rule checks such as overly permissive rules, scores the result and produces a PDF report. Live CPU, memory and traffic-log collection is available for FortiGate.
Does network monitoring raise data-protection questions?
It can, because flow records contain IP addresses that may relate to people. ICTM pseudonymises IP addresses in flow data, supports access and erasure requests by purging a person's flow records, and deletes flow data, alerts and baselines on default retention periods of 30, 180 and 365 days.