untitled



Similar documents
untitled

¥¤¥ó¥¿¡¼¥Í¥Ã¥È·×¬¤È¥Ç¡¼¥¿²òÀÏ Âè1²ó

Inter-IX IX/-IX 10/21/2003 JAPAN2003 2

untitled

IPv4aaSを実現する技術の紹介

main.mgp

IPSEC-VPN IPsec(Security Architecture for Internet Protocol) IP SA(Security Association, ) SA IKE IKE 1 1 ISAKMP SA( ) IKE 2 2 IPSec SA( 1 ) IPs

SCREENOS NAT ScreenOS J-Series(JUNOS9.5 ) NAT ScreenOS J-Series(JUNOS9.5 ) NAT : Destination NAT Zone NAT Pool DIP IF NAT Pool Egress IF Loopback Grou

worm hoihoi

untitled

Juniper Networks Corporate PowerPoint Template

NetFlow sflow 使ってるけど NetFlow,sFlow( 以下 xflow) で したい でも どう設定すれば正解なのかワカラン なんとなくサンプルコンフィグ通りに設定 なんとなくデータが見えてるし まいっか 2009/1/23 2

untitled

wide93.dvi

amplification attacks とは 送信元を偽装した dns query による攻撃 帯域を埋める smurf attacks に類似 攻撃要素は IP spoofing amp 2006/07/14 Copyright (C) 2006 Internet Initiative Jap

Openconfigを用いたネットワーク機器操作

untitled

Łñ“’‘‚2004

プリント


shtsuchi-janog35.5-grnet.pptx

untitled

All Rights Reserved. Copyright(c)1997 Internet Initiative Japan Inc. 1

untitled

HTTP

F コマンド

OSPF OSPF.

22 / ( ) OD (Origin-Destination)

橡3-MPLS-VPN.PDF

F コマンド

IP IP DHCP..

Agenda IPv4 over IPv6 MAP MAP IPv4 over IPv6 MAP packet MAP Protocol MAP domain MAP domain ASAMAP ASAMAP 2

untitled

宛先変更のトラブルシューティ ング

橡2-TrafficEngineering(revise).PDF

IPv6における

2011 NTT Information Sharing Platform Laboratories

075730G: 2008/7/4, /07/ A: J: E:

INR-HG5579a_Netshut_Guide_Linux-Solaris_.doc

untitled

TCP/IP Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.3 Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.4 2

untitled

26 No.62 Contents No.62

アジェンダ フローマネージメント / フロープロトコル NetFlow InMonTrafficSentinelのご紹介 日本語版の提供 ネットワーク管理 レポーティング機能 セキュリティ管理 ダッシュボード機能 ケーススタディー インフォメーション 2

8 P2P P2P (Peer-to-Peer) P2P P2P As Internet access line bandwidth has increased, peer-to-peer applications have been increasing and have great impact

Clos IP Fabrics with QFX5100 Switches

橡C14.PDF

netmap Web syslog NetFlow I/O netmap netmap OS fluentd 10GbE 1,500 50,000pps 100% netmap NetFlow i

IIJ Technical WEEK SEILシリーズ開発動向:IPv6対応の現状と未来

untitled


Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

SRX License

今日のトピック 実験結果の共有 RPKI/Router 周りの基本的な動き 今後の課題と展望 2012/7/6 copyright (c) tomop 2

PowerPoint プレゼンテーション

johokiso-internet

5 5.1 A B mm 0.1mm Nominal Scale 74

VyattaでのPPPoEとNetwork emulator


untitled

IPv6 トラブルシューティング~ ISP編~

総セク報告書(印刷発出版_.PDF

VQS Collabo Homepage

untitled

2004 SYN/ACK SYN Flood G01P014-6

tcp/ip.key

9BBH3A8_P0000

untitled

2

集中講義 インターネットテクノロジー 第5回

ITAOI2003第三屆離島資訊與應用研討會論文範例

I j

スライド 1

PowerPoint プレゼンテーション

FW Migration Guide (Single)

マルウェア対策のための研究用データセット ~ MWS Datasets 2013 ~.pptx

JANOG14-コンバージェンスを重視したMPLSの美味しい使い方

D-3案

NATディスクリプタ機能

スライド 1

output2010本文.indd

H8.6 P

01.eps

1 48


e164.arpa DNSSEC Version JPRS JPRS e164.arpa DNSSEC DNSSEC DNS DNSSEC (DNSSEC ) DNSSEC DNSSEC DNS ( ) % # (root)

Microsoft Word - sugiyama.doc

Microsoft PowerPoint ppt [互換モード]

,

iR-ADV C2230/C2220 製品カタログ

untitled

Page 1

スライド 1

Dynamic VPN Dynamic VPN IPSec VPN PC SRX IPSec VPN SRX PC IPSec 2 Copyright 2010 Juniper Networks, Inc.

NEWS&TOPICS

1 IPv6 WG OS SWG PCOSIPv6 Windows Vista 2 3 KAMEUSAGIMacOSX IPv6 2

橡Ⅲ検証実験編.PDF

ETL Webinar

total.dvi

Transcription:

Section 1 5

6

MRTG 7 Prefix RMON NetFlow

NetFlow NetFlow Data Collector DB Subnet B B Router = Exporter Subnet A AS IP Prefix 1 8 Subnet B Router = Exporter AS AS Prefix 2

NetFlow Version 5 AS AS Peer AS Origin AS Next Hop / In Out ifindex IP ICMP, TCP, UDP,... TOS TCP 9

Exporter CPU Cisco NetFlow Performance Analysis http://www.cisco.com/en/us/products/ps6601/products_white_paper0900aecd802a0eb9.shtml CPU 10

Exporter Cisco 11

Exporter Juniper M M (1) 12 firewall { filter sample-all { term one { then { sample; accept; } } } }

Exporter Juniper M M (2) 13 interfaces { ge-0/0/0 { description Sampling Interface"; link-mode full-duplex; unit 0 { family inet { filter { input sample-all; # Input output sample-all; # Output } address ***.***.***.***/30; } } }

Exporter Juniper M M (3) 14 forwarding-options { sampling { traceoptions { file sampled-debug size 5m; # Debug } input { family inet { max-packets-per-second 1000; # PPS rate 5000; # run-length 0; } } output { cflowd ***.***.***.*** { # port ****; # UDP version 5; # NetFlow autonomous-system-type origin; # Src/Dst AS Origin } } } }

15 Exporter router: router: 10.1.1.162 10.1.1.162 ifindex: ifindex: 20 20 period: period: 02/21/2006 02/21/2006 15:14:46 Src 15:14:46 - - 02/21/2006 AS Dst 02/21/2006 15:32:49 15:32:49 JST AS JST Src Src AS AS Dst Dst AS AS Pkts Pkts Pkts/sec Pkts/sec Bytes Bytes Bits/sec Bits/sec ------ ------ ------ ------ ------------- ------------- ------------- ------------- ------------- ------------- ------------- ------------- 0 0 0 0 810 810 0.747922 0.747922 666379 666379 4922.47 4922.47 router: router: 10.1.1.162 10.1.1.162 ifindex: ifindex: 22 22 router: period: period: 02/21/2006 02/21/2006 15:14:46 router: 10.1.1.162 15:14:46 - - 02/21/2006 10.1.1.162 32!? ifindex: 02/21/2006 15:32:49 15:32:49 JST JST Src Src AS AS Dst Dst AS ifindex: 20 AS Pkts 20 period: Pkts Pkts/sec Pkts/sec Bytes Bytes Bits/sec Bits/sec ------ ------ ------ ------ ------------- period: 01/01/1970 01/01/1970 09:00:00 ------------- ------------- 09:00:00 - ------------- ------------- - 02/21/2006 02/21/2006 13:59:33 ------------- ------------- 13:59:33 JST JST Src ------------- 0 0 0 0 1 Src Network 1 0.000923361 Network Dst Dst Network Network Pkts 0.000923361 79 79 0.583564 Pkts Bytes Bytes ------------------ ------------------ ------------------ ------------------ ------------- ------------- 0.583564 ------------- ------------- 10.1.122.56/32 router: router: 10.1.1.162 10.1.122.56/32 192.168.75.236/32 192.168.75.236/32 1826 1826 2655004 2655004 10.1.1.162 10.1.123.202/32 ifindex: ifindex: 23 10.1.123.202/32 192.168.143.165/32 192.168.143.165/32 759 759 1100015 1100015 23 10.1.116.84/32 period: period: 02/21/2006 02/21/2006 15:14:46 10.1.116.84/32 10.124.148.112/32 15:14:46 - - 02/21/2006 02/21/2006 15:32:49 10.124.148.112/32 714 15:32:49 JST 714 1034511 1034511 10.1.124.61/32 JST Src Src AS AS Dst Dst AS 10.1.124.61/32 10.126.73.208/32 AS Pkts Pkts Pkts/sec 10.126.73.208/32 507 Pkts/sec Bytes Bytes Bits/sec507 689825 689825 10.1.122.85/32 Bits/sec ------ ------ ------ ------ ------------- 10.1.122.85/32 192.168.121.187/32 ------------- -------------192.168.121.187/32 405 ------------- ------------- -------------405 567893 567893 10.1.123.193/32 ------------- 0 0 0 10.1.123.193/32 10.84.7.172/32 0 8307 8307 7.67036 10.84.7.172/32 362 7.67036 7432711 7432711 54904.6362 508693 508693 10.1.98.80/32 10.1.98.80/32 10.124.148.248/32 10.124.148.248/32 54904.6 293 293 426022 426022 10.1.124.134/32 10.1.124.134/32 192.168.99.89/32 192.168.99.89/32 273 273 395603 395603 10.1.124.164/32 10.1.124.164/32 10.85.41.155/32 10.85.41.155/32 179 179 256694 256694 10.1.122.24/32 10.1.122.24/32 10.204.139.210/32 10.204.139.210/32 155 155 208942 208942 10.1.116.84/32 10.1.116.84/32 10.86.93.108/32 10.86.93.108/32 145 145 208151 208151 10.1.116.68/32 10.189.248.228/32 257 118917 10.1.116.68/32 10.189.248.228/32 257 118917 10.1.103.37/32 10.1.103.37/32 10.95.44.209/32 10.95.44.209/32 170 170 106664 106664

Collector/Analyzer Cisco ARBOR peakflow, GenieATM cflowd by CAIDA flow-tools nfdump/nfsen cflowd flow-tools 16

cflowd ARTS Origin AS Dest Prefix TCP Exporter FreeBSD 17

nfdump http://nfdump.sourceforge.net/ 18

NfSen NFDUMP Web http://sourceforge.net/projects/nfsen/ 19

flow-tools http://www.splintered.net/sw/flow-tools/ NetFlow PostgresSQL, MySQL DB Ad-Hoc DWH flow-report 20

Excel S-PLUS R 21

Excel Src or Dst AS Excel Import 65,536 x 256 MS Office Excel 2003 Src AS, Dst AS, Prefix 22 Byte Src or Dst AS

R The R Project for Statistical Computing http://www.r-project.org/ S R S 23

Section 2-24

Section 3 33

IP? Inbound : Outbound : 34

1. Outbound 24h? 35

12 20 7 8% 7 8% 24 36

2. In Out Out In Out ADSL FTTH!? Outbound Traffic FTTH ADSL! 37 Inbound Traffic

In Out Out In Out In ADSL Out 1 10G FTTH ADSL, FTTH ISP Kenjiro Cho, Kensuke Fukuda, Hiroshi Esaki and Akira Kato. The Impact and Implications of the Growth in Residential User-to-User Traffic. SIGCOMM2006 2 8 38

ISP ISP 39 ISP : IP : IP ISP : 1 1 : 6 ISP =1/2048, =1/5000

ISP ISP IP? 40

Special Thanks to THX!! IIJ JANOG18 41

by VzB 42