Showing posts with label System Networking. Show all posts
Showing posts with label System Networking. Show all posts

COBIT - Control Objectives for Information and Related Technology

The Control Objectives for Information and related Technology (COBIT) is a good framework strategy to help an organization maintain standards and develop a system of IT governance. COBIT is a common methodology used by many companies in order to develop a systematic means to meet compliance laws.

Why COBIT?
COBIT consists of 34 IT processes and is a way for an organization to use in its attempts to "balance risk and control in a cost-effective manner" (Pederiva, 2003).

Situation Analysis
  • Does your enterprise’s IT support the business?
  • Is it aligned with the business?
  • Is your IT performing to its optimal capability?
  • Is your IT adding value to the business?
  • Are IT risks being effectively mitigated?
  • Are your IT investments being effectively managed throughout their life cycle?
  • Is the importance of governance understood at all levels of your enterprise?
  • Are the benefits of your IT being maximized?
If you did not answer yes to all of the above questions, your enterprise does not have an effective IT governance framework in place. Most, if not all, business activities are affected by IT, with an increasingly visible impact to end users. Successful enterprises recognize the need to maximize the value of IT-related investments and that the need for the governance of IT is greater now than ever before. The best way to ensure this is to implement an IT governance framework.

An effective IT governance framework:
  • Provides clear direction to ensure that IT investments support the business
  • Is an effective way to manage change.
  • Creates value for the business in alignment with enterprise objectives
  • Addresses the complete life cycle of IT investment
COBIT, developed by ISACA®, is a comprehensive IT governance framework.
COBIT 4.1 addresses every aspect of IT and is the only governance framework that addresses the complete life cycle of IT investment.

What Does COBIT Do?
COBIT:
  • Improves IT efficiency and effectiveness
  • Helps IT understand the needs of the business
  • Puts practices in place to meet the business needs as efficiently as possible
  • Helps executives understand and manage IT investments throughout their life cycle
  • Provides a method to assess whether IT services and new initiatives are meeting business requirements and are likely to deliver the benefits expected
  • Helps to develop and document the appropriate organizational structures, processes and tools for effective management of IT
  • Provides an authoritative, international set of generally accepted practices that helps boards of directors, executives and managers increase the value of IT and reduce related risks

What are the Benefits of Implementing COBIT?
There is a clear difference between enterprises that manage their IT well and those that don’t, or can’t. Implementation of COBIT is a sign of a well-run enterprise, as it is a proven and internationally accepted set of tools and techniques.
The benefits of implementing COBIT include:
  • A common language for executives, business and IT staff
  • A view, understandable to management, of what IT does
  • A better understanding of how the business and IT can work together for successful delivery of IT initiatives
  • Better alignment, based on a business focus
  • Better quality IT services
  • Improved efficiency and optimization of cost
  • Reduced operational risk
  • More effective management of IT
  • Clear policy development
  • More efficient and successful audits
  • Clear ownership and responsibilities, based on process orientation
COBIT is a Road Map to Good IT Governance 
  • Accepted globally as a set of tools that ensures IT is working effectively
  • Functions as an overarching framework
  • Provides common language to communicate goals, objectives and expected results to all stakeholders
  • Based on, and integrates, industry standards and good practices in:
  • Strategic alignment of IT with business goals
  • Value delivery of services and new projects
  • Risk management
  • Resource management
  • Performance measurement


IT Governance Is the Key Issue
Enterprises are sacrificing money, productivity and competitive advantage by not implementing effective IT governance
Executives need a better way to:
  • Direct IT for optimal advantage
  • Measure the value provided by IT
  • Manage IT-related risks

Microsoft's ISA Server (Internet Security and Acceleration Server)

Microsoft's ISA Server (Internet Security and Acceleration Server) is the successor to Microsoft's Proxy Server 2.0 (see proxy server) and is part of Microsoft's .NET support. ISA Server provides the two basic services of an enterprise firewall and a Web proxy/cache server. ISA Server's firewall screens all packet-level, circuit-level, and application-level traffic. The Web cache stores and serves all regularly accessed Web content in order to reduce network traffic and provide faster access to frequently-accessed Web pages. ISA Server also schedules downloads of Web page updates for non-peak times.

ISA Server allows administrators to create policies for regulating usage based on user, group, application, destination, schedule, and content type criteria. ISA Server is designed to work with Windows 2000 and later operating systems and to take advantage of Windows' Kerberos security. ISA Server includes a software development kit (SDK).

ISA Server comes in two editions, Standard Edition and Enterprise Edition. Standard Edition is a stand-alone server that supports up to four processors. Enterprise Edition is for large-scale deployments, server array support, multi-level policy, and computers with more than four processors. Licenses are based on the number of processors.

ISA Server carries new terms that need to be understood before attempting product deployment on the network.
  • Array a group of ISA computers that are located close together, for example a department, office, and region. There are two types of arrays:
Domain Arraysthat use Active Directory. A domain array can encompass computers located within a single domain.Independent Arrays – allow storage of information not in the Active Directory, but in a local configuration database. This array is mainly used in NT 4.0 based networks.
  • Rulewith rules, the system administrator can set up a series of protocols to govern sites, contents, protocols, and IP packet filters.
  • Array policya set of rules that define the array policy. Such a policy can be applied to any specific (and single) array.
  • Enterprise policy – enterprise-level policies contain similar rules to those established in array policies but they are applied to multiple arrays.
With ISA Server, array policies can be used to modify enterprise policies making them more restrictive. However, it is not possible for an array policy to ease restrictions imposed by the enterprise policy.

ISA Server supports many more functions than its predecessor. The following options are available with this new product:
  • Firewall – the Firewall client is an extension to the ISA Server that features an enhanced set of functions allowing it to compete with other similar products available on the IT market. With Firewall client, Active Directory can be supported from Windows 2000 (or the SAM databases from NT). These are used to provide specific security functions at user or group level. This feature is not supported by a majority of third-party products that use either separate user databases or IP addressing. Firewall functions are enhanced to support so called stateful packet inspection, i.e. a solution for improved security where data packets passing through the firewall are intercepted and analyzed at either a protocol or connectivity level.
  • Policy-based administration – ISA Server lets the administrators manage using predefined policy rules. Policies can include a set of consistent rules regarding users, groups of users, protocols etc. A specific policy may apply to a single array or globally, to the whole enterprise. For businesses that use networks with Active Directory enhancements, multi-tiered enterprise policies are those that match their needs to have a comprehensive IT system, to facilitate management of the entire enterprise and its infrastructure.
  • Virtual Private Network Support – ISA Server provides an easy solution to create VPN – based networks. The wizards supplied with ISA Server help to configure VPN tunneling and may activate the RRAS service if not already initialized.
  • Dynamic IP filtering – depending on the security policy used, an enterprise can dynamically open firewall ports for authorized Internet users on a session-by-session basis. This considerably simplifies the administrator’s duties in situations where there are applications that frequently change ports though they communicate with each other.
  • IDS (Intrusion Detection System) – Microsoft has equipped the ISA Server with an Intrusion Detection System. This module had been purchased from Internet Security Systems, the leading developer in these IT solutions. Thus, ISA offers out-of-box support for preventing several types of attacks including WinNuke, Ping of Death, Land, UDP bombs, POP Buffer Overflow, Scan Attack. Once an attack has been detected and identified, ISA may decide either to disable the attack or notify administrators about the event.
  • Web Cache – ISA Server provides fast Web caching performance. Administrators are allowed to automatically refresh frequently requested www pages on reverse and scheduled caching basis.
  • Reports  the major point of contrast between ISA and its predecessor i.e. Proxy Server 2.0 is that ISA features numerous report generating possibilities. By scheduling report generation connected. for example, with the users’ actions or security related events, managing ISA Server based networks is a simple task.
  • Gatekeeper H.323 – this component allows ISA Server to manage IP telephony calls or H.323-based VoIP applications (for example Microsoft NetMeeting 3.0). The DNS SRV record must be registered in order to have gatekeeper enabled.
  • Client Deployment – with SecureNAT (Network Address Translation) feature, ISA Server delivers to clients and servers a transparent and secure access to the Internet with no need to configure extra software on client machines. SecureNAT allows monitoring of all traffic in ISA Server.
Therefore, instead of being a simple product improvement, Microsoft Internet Security and Acceleration Server fills a gap in the range of this type of products available at the Redmond colossus and is trying to jump aggressively into the mass market sector associated with Web security and fast Web access. The new potential implemented in ISA Server is expected to allow Microsoft to compete effectively in this business area.
It should be noted that Microsoft’s engineers carefully integrate all products together to bring the Company’s vision of a .NET platform to businesses.

The minimum hardware requirements recommended by Microsoft for this product are:
  • 300MHz or higher Pentium II compatible CPU,
  • 256 MB of RAM,
  • 2 GB hard-disk space on NTFS formatted partition,
  • 200 MB of available hard-disk space for installation.
ISA Server requires a computer running Windows 2000 upgraded to Service Pack 1 or greater.
Problems with insufficient server capacity may occur with this type of configuration. Thus, for various ISA Server usage scenarios, the hardware should be adequately strengthened.
If ISA Server is to be used as a firewall, one will need to consider how powerful the CPU should be in terms of throughput requirements.

Throughput requirements
Recommended CPU
Less than 25 Mbyte/s
Pentium II 300 MHz – 500 MHz
From 25 Mbyte/s to 50 Mbyte/s
Pentium III 550 MHz or better
More than 50 Mbyte/s
Pentium III 550 MHz or better for each 50Mb
Table 1 CPU capacity requirements vs. throughput

Obviously these values can only be used as a reference when planning the ISA Server’s hardware to meet the expected load. This may vary in function or various usage scenarios (such as the type of transmitted data).

In case ISA Server is to be deployed as a Forward Cache, in addition to an adequate CPU capacity consider also requirements for RAM and high free disk space available for caching purposes.

Number of users
Recommended processor
Minimal RAM capacity (Mb)
Recommended disk space allocated for caching
Up to 250
Pentium II 300 MHz
256
4 GB
250 – 2000
Pentium III 550 MHZ
256
10 GB
More than 2000
Pentium III 550 MHz for every 2,000 users
256 for every 2000 users
10 GB for every 2,000 users
Table 2 – Capacity planning for forward caching server applications
   
Secure Internet Access is one of the fundamental features provided by ISA Server. It is increasingly necessary to improve security tools and check users that access the network from outside, especially in a situation where the Global Web is vulnerable to outside interference from viruses, trojan horses or hacker attacks.  One may also wish to improve security to monitor network users and protect the network from potential Internet threats. To face this challenge and provide solutions for a broad landscape of users, Microsoft has implemented three types of clients in ISA Server:
  • Firewall clients – all computers that have Firewall Client software installed and active,
  • SecureNat clients – all computers that do not have Firewall Client software installed,
  • Web Proxy clients – all Web browser clients are configured to use ISA Server.
     
Reference Site:
About ISA server installation


Network Monitoring System Tools

Network Monitor is a network server monitoring tool which checks for failures and fixes them automatically. In network management terms, network monitoring is the phrase used to describe a system that continuously monitors a network and notifies a network administrator though messaging systems (usually e-mail) when a device fails or an outage occurs. Network monitoring is usually performed through the use of software applications and tools. At the most basic level, ping is a type of network monitoring tool. Other commercial software packages may include a network monitoring system that is designed to monitor an entire business or enterprise network. Some applications are used to monitor traffic on your network, such as VoIP monitoring, video stream monitoring, mail server (POP3 server) monitoring, and others.

While an intrusion detection system monitors a network for threats from the outside, a network monitoring system monitors the network for problems caused by overloaded and/or crashed servers, network connections or other devices. For example, to determine the status of a webserver, monitoring software may periodically send an HTTP request to fetch a page. For email servers, a test message might be sent through SMTP and retrieved by IMAP or POP3.

Commonly measured metrics are response time, availability and uptime, although both consistency and reliability metrics are starting to gain popularity. The widespread addition of WAN optimization devices is having an adverse effect on most network monitoring tools -- especially when it comes to measuring accurate end-to-end response time because they limit round trip visibility. Status request failures - such as when a connection cannot be established, it times-out, or the document or message cannot be retrieved - usually produce an action from the monitoring system. These actions vary -- an alarm may be sent (via SMS, email, etc.) to the resident sysadmin, automatic failover systems may be activated to remove the troubled server from duty until it can be repaired, etc.

The Benefits of Network Monitoring
Network Monitoring can
  • Proactively Warn You of Problems. With proactive network monitoring your IT department can be alerted to issues before they turn into serious problems and down time. If monitoring was in place in the example above the System Administrator could have added disk space or removed older files prior to the SQL Server going down, resolved Exchange data corruption before the email server went down, and updated hotfixes on the web server to prevent hacking before it occurred.
  • Track Your Network’s Growth. Network monitoring can also assist you with gathering data to keep track of your network’s growth. Chances are a lot has changed with your network over the past several years. New Servers have come online, perhaps you’ve added a new wireless network, more workstations and printers, and so forth. All of this can add to network traffic loads, leading to overtaxed network connections and possible growth issues. Network monitoring allows you to know what you have and how it’s being used, so you can proactively look to resolve problems before they start.
  • Help with Capacity Planning. Network monitoring allows you to track how much disc space and network bandwidth you’re using, enabling you to do capacity planning based on your usage trends. The result: you can proactively plan and budget for your future systems needs.
  • Meet Service Level Agreements. Is your department or company is required to meet a Service Level Agreement with a specific percentage of uptime on your network and network resources? If so, monitoring these things ensures that you are indeed meeting the requirements.
Here is a comparison of some notable network monitoring systems:
Name IP SLA Reports Logical Grouping Trending Trend Prediction Auto Discovery Agent SNMP Syslog Plugins Triggers / Alerts WebApp Distributed Monitoring Inventory Data Storage Method License Maps Access Control IPv6
AdRem NetCrunch No Yes Yes No Yes No Yes Yes Yes Yes Viewing, Acknowledging No Yes SQL Commercial Yes Yes Unknown
AccelOps Yes Yes Yes Yes Yes Supported Yes Yes Yes Yes Full Control Yes Yes PostgreSQL Commercial Yes Yes Unknown
AggreGate Network Manager Yes Yes Yes Yes Yes Supported Yes Yes Yes Yes Full Control Yes Yes MySQL, MS SQL, PostgreSQL, Oracle, Firebird, HSQLDB Limited free, Commercial Yes Yes Unknown
Argus Yes Yes No No No Yes Yes Yes Yes Yes Viewing, Acknowledging Yes Unknown Berkeley DB Artistic License No Yes Yes
Avaya VPFM Yes Yes Yes No Yes Yes Yes Yes Yes Yes Full Control Yes Yes MySQL Commercial Yes Yes Yes
Cacti Yes Yes Yes Yes Via plugin No Yes Yes Yes Yes Full Control Yes Yes RRDtool, MySQL GPL Plugin Yes Yes
collectd No No No No Push model;
multicast possible
Supported Yes Yes Yes Yes Viewing Yes No RRDtool GPLv2 No Apache ACL Yes
Dhyan Network management System Yes Yes Yes Unknown Yes Supported Yes Yes Yes Yes Full Control Yes Yes MySQL, Oracle, Derby Commercial Yes Yes Yes
dopplerVUE Yes Yes Yes No Yes Yes Yes Yes Yes Yes Full Control Yes Yes MS SQL Commercial Yes Yes Yes
ExtraHop Yes Yes Yes No Yes N/A Yes No No Yes Full Control With ECM Yes Proprietary Commercial Yes Yes Yes
Name IP SLA Reports Logical Grouping Trending Trend Prediction Auto Discovery Agent SNMP Syslog Plugins Triggers / Alerts WebApp Distributed Monitoring Inventory Data Storage Method License Maps Access Control IPv6
FreeNATS Yes Yes No No Yes Yes No Via plugin Yes In PHP Code Full Control No No MySQL GPL No Yes Unknown
Ganglia No Yes Yes No Via gmond check in Yes Via plugin No Yes No Viewing Yes Unknown RRDtool BSD Yes No Unknown
HP Network Node Manager (NNMi) Yes Yes Yes Yes Yes No Yes Via integration Yes Yes Full Control Yes Yes PostgreSQL, Oracle Database Commercial Yes Yes Yes
Kaseya Network Monitor Yes Yes Yes No Yes No Yes Yes Yes Yes Full Control Yes Yes FirebirdSQL Commercial Yes Yes Unknown
IBM Tivoli Network Manager Possible via configuration Yes Yes Yes Yes No Yes Yes Yes Yes Yes Yes Yes MySQL, Oracle Database, DB2 Commercial Yes Yes Yes
Icinga Via plugin Yes Yes No Via plugin Supported Via plugin Via plugin Yes Yes Full Control Yes Via plugin MySQL, PostgreSQL, Oracle Database GPL Yes Yes Yes
InterMapper Yes Yes Yes No Yes Yes Yes Yes Yes Yes Viewing Yes Yes PostgreSQL Limited free, Commercial Yes Yes Yes
IPHost Network Monitor Yes Yes Yes No Yes Yes Yes No Yes Yes Viewing, Acknowledging, Reporting Yes No FirebirdSQL Commercial No No Unknown
isyVmon Yes Yes Yes No Via plugin Yes Yes Yes Yes Yes Full Control Yes Via plugin RRDtool, MySQL Limited free, Commercial Via plugin Yes Yes
LiveAction Yes Yes Yes No Yes No Yes No Yes Yes Viewing, Reporting Yes Yes Yes Commercial Yes Yes Yes
Name IP SLA Reports Logical Grouping Trending Trend Prediction Auto Discovery Agent SNMP Syslog Plugins Triggers / Alerts WebApp Distributed Monitoring Inventory Data Storage Method License Maps Access Control IPv6
Munin No No Yes Yes No Yes Yes No Yes Partial Viewing Unknown Unknown RRDtool GPL Unknown Unknown Yes
Nagios Via plugin Yes Yes No Via plugin Supported Via plugin Via plugin Yes Yes Yes Yes Via plugin Flat file, SQL GPL Yes Yes Yes
NagiosXI Via plugin Yes Yes No Via plugin Supported Via plugin Via plugin Yes Yes Full Control Yes Via plugin MySQL, PostgreSQL Commercial Yes Yes Yes
NetMRG Yes Yes Yes Yes Via plugin No Yes Yes Yes Yes Full control Yes Yes RRDtool, MySQL GPL Yes Yes Unknown
NetQoS Performance Center Yes Yes Yes Yes Yes No Yes Yes Yes Yes Viewing, Acknowledging, Reporting Yes Yes Yes Commercial Yes Yes Unknown
Network Instruments Observer Infrastructure Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Full Control Yes Yes Proprietary Database Commercial Yes Yes Yes
NetXMS No Yes Yes Yes Yes Yes Yes Yes Yes Yes Full Control Yes No MySQL, MS SQL, Oracle, PostgreSQL, SQLite GPL Yes Yes No
Nimsoft Monitoring Solution Yes Yes Yes Yes Yes Supported Yes Yes Yes Yes Viewing, Acknowledging, Reporting Yes Yes SQL Commercial Yes Yes Unknown
Observium No No No No Yes No Yes Yes No Yes Full Control No Yes RRDtool, MySQL GPLv3 Yes Yes Yes
Name IP SLA Reports Logical Grouping Trending Trend Prediction Auto Discovery Agent SNMP Syslog Plugins Triggers / Alerts WebApp Distributed Monitoring Inventory Data Storage Method License Maps Access Control IPv6
OpenKBM Yes Yes Yes Yes Yes Supported Yes Yes Yes Yes Yes Yes Yes Proprietary with JDBC support Commercial Yes Yes Yes
OpenNMS Yes Yes Yes Unknown Yes Supported Yes Yes Yes Yes Full Control Yes Yes JRobin, PostgreSQL GPLv3 Yes Yes Yes
OPNET's AppResponse Xpert Yes Yes Yes Yes Yes No Yes No Yes Yes Viewing, Acknowledging, Reporting Yes No Yes Commercial Yes Yes Unknown
Opsview Yes Yes Yes No Yes Yes Yes Yes Yes Yes Full Control Yes No SQL GPL Yes Yes Yes
PacketTrap No Yes Yes Unknown Yes Yes Yes Yes Yes Yes Viewing, Reporting Yes Unknown SQL Commercial Unknown Unknown Unknown
Pandora FMS Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Full Control Yes Yes MySQL, PostgreSQL, Oracle GPLv2; (Enterprise edition available) Yes Yes Yes
Performance Co-Pilot No Yes Yes No No Yes No No Yes Yes No Yes No Flat file GPL, LGPL No No Unknown
PRTG Network Monitor Yes Yes Yes Yes Yes Supported Yes Yes Yes Yes Full Control Yes Yes Proprietary Freeware and Commercial Yes Yes Yes
Scrutinizer Yes Yes Yes No No No Yes Yes Yes Yes Viewing, Acknowledging, Reporting Yes Yes MySQL Limited free, Commercial Yes Yes Yes
Name IP SLA Reports Logical Grouping Trending Trend Prediction Auto Discovery Agent SNMP Syslog Plugins Triggers / Alerts WebApp Distributed Monitoring Inventory Data Storage Method License Maps Access Control IPv6
ServersCheck Yes Yes Yes No Yes Supported Yes Yes Yes Yes Full Control Yes No Flat file, ODBC Commercial Yes Yes Unknown
SevOne Yes Yes Yes Yes Yes No Yes No Yes Yes Full Control Yes Unknown MySQL Commercial Yes Yes Yes
Solarwinds Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Full Control Yes Yes SQL Commercial Yes Yes Yes
Shinken Via plugin Yes Yes No Via plugin Yes Via plugin Via plugin Yes Yes Viewing, Acknowledging, Reporting Yes Via plugin Flat file, MySQL, Oracle, CouchDB, Sqlite AGPL Yes No Unknown
Spiceworks No Yes Yes No Yes Supported Yes No Yes Yes Full Control Yes Yes Sqlite Commercial (Free) Yes Yes No
TclMon Yes Yes Yes No Yes Supported Yes Yes Yes Yes Viewing No No RRDTool BSD Yes Yes No
Verax NMS Yes Yes Yes Yes Yes No Yes Yes Yes Yes Full Control Yes No Oracle, MySQL Commercial Yes Yes Unknown
WhatsUpGold Yes Yes Yes No Yes Yes Yes Yes Yes Yes Full Control Yes Yes SQL Commercial Yes Yes Yes
Xymon/Hobbit Yes Yes Yes No No Yes Via Plugin No Yes Yes Viewing, Acknowledging Yes No Flat file GPL No Apache ACL No
Name IP SLA Reports Logical Grouping Trending Trend Prediction Auto Discovery Agent SNMP Syslog Plugins Triggers / Alerts WebApp Distributed Monitoring Inventory Data Storage Method License Maps Access Control IPv6
Zabbix Yes Yes Yes No Yes Supported Yes Yes Yes Yes Full Control Yes Yes Oracle, MySQL, PostgreSQL, IBM DB2, SQLite GPL Yes Yes Yes
Zenoss Yes Yes Yes Yes Yes No Yes Yes Yes Yes Full Control Yes Yes ZODB, MySQL, RRDtool GPL Yes Yes Yes
Zyrion Traverse Yes Yes Yes Yes Yes Supported Yes Yes Yes Yes Full Control Yes Yes SQL Commercial Yes Yes Unknown
Name IP SLA Reports Logical Grouping Trending Trend Prediction Auto Discovery Agent SNMP Syslog Plugins Triggers / Alerts WebApp Distributed Monitoring Inventory Data Storage Method License Maps Access Control IPv6

Legends:
Product Name 
The name of the software, linked to its Wikipedia article. Any software listed without being linked to its article, demonstrating its notability, will be removed.
IP SLAs Reports 
Feature reports on IP SLAs
Logical Grouping 
Support arranging the hosts or devices it monitors into user-defined groups
Trending 
Provide trending of network data over time
Trend Prediction 
The software feature algorithms designed to predict future network statistics
Auto Discovery 
The software automatically discover hosts or network devices it is connected to
Agent 
The product rely on a software agent that must run on hosts it is monitoring, so that data can be pushed back to a central server. "Supported" means that an agent may be used, but is not mandatory. An SNMP daemon does not count as an agent.
SNMP 
Able to retrieve and report on SNMP statistics
Syslog 
Able to receive and report on Syslogs
Plugins 
Architecture of the software based on a number of 'plugins' that provide additional functionality
Triggers/Alerts 
Capable of detecting threshold violations in network data, and alerting the administrator in some form.
WebApp 
Runs as a web-based application
  • No: There is no web-based frontend for this software.
  • Viewing: Network data can be viewed in a graphical web-based frontend
  • Acknowledging: Users can interact with the software through the web-based frontend to acknowledge alarms or manipulate other notifications.
  • Reporting: Specific reports on network data can be configured by the user and executed through the web-based frontend.
  • Full Control: ALL aspects of the product can be controlled through the web-based frontend, including low-level maintenance tasks such as software configuration and upgrades.
Distributed Monitoring 
Able to leverage more than one server to distribute the load of network monitoring.
Inventory 
Keeps a record of hardware and/or software inventory for the hosts and devices it monitors
Data Storage Method 
Main method used to store the network data it monitors.
License 
License released under (e.g. GPL, BSD license, etc.)
Maps 
Features graphical network maps that represent the hosts and devices it monitors, and the links between them.
Access Control 
Features user-level security, allowing an administrator to prevent access to certain parts of the product on a per-user or per-role basis
IPv6 
Supports monitoring IPv6 hosts and/or devices, receiving IPv6 data, and running on an IPv6-enabled server. Supports communication using IPv6 to the SNMP agent via an IPv6 address.
source: wiki