25: Part ( ) Chief Technology Officer mshindo@fivefront.com SNMP MRTG HP/OV RMON INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 2 1
SNMP IfInUcastPkts, IfOutUcastPkts IfInOctets, IfOutOctets INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 3 SNMP End to End INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 4 2
End to End AS INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 5 NetFlow Cisco Cisco, Juniper, AlaxalA, etc. sflow InMon Foundry, Extreme, AlaxalA, Force10, HP, etc. IPFIX IETF NetFlow V9 INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 6 3
QoS INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 7 NetFlow NetFlow Src / Dst IP Src /Dst ToS NetFlow Src IF Src IP Dst IF Dst IP Proto Bytes Active Idle 10 a.a.a.a 24 x.x.x.x 6 1234 327 4 15 b.b.b.b 24 y.y.y.y 17 23456 1920 25 24 c.c.c.c 3 z.z.z.z 6 5678 54 10 INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 8 4
Inactive Timer default = 15 Active Timer default = 30 TCP FIN or RST 30 15 INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 9 NetFlow 1 5 7 8 9 BGP AS Catalyst Switch IPFIX INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 10 5
NetFlow V5 PDU 0 15 16 31 Version SysUptime unix-_secs unix-_nsecs ID <1> <n> INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 11 NetFlow V5 0 15 16 31 IP IP nexthop sysuptime sysuptime first TCP AS ToS AS INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 12 6
NetFlow V9 RFC 3954 Informational IPFIX IPFIX INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 13 NetFlow Cisco V5, V8, V9 Cisco 12000 100:1 7 15% CPU INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 14 7
sflow NetFlow Cisco?? RFC 3176 [sflow V4] Informational INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 15 sflow NetFlow / 1 sflow PDU sflow I/F NextHop AS I/F Etc. INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 16 8
sflowvs NetFlow V5 IPv6 IP IPX AppleTalk BGP BGP Next Hop Community AS PATH Local Preference Agent INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 17 Flow 2 4 5 BGP community RFC 3176 CPU/BGP nexthop MPLS NAT Vendor-specific INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 18 9
IPFIX IP Flow Information export draft-ietf-ipfix-architecture-12.txt draft-ietf-ipfix-protocol-23.txt draft-ietf-ipfix-info-14.txt 49 th IETF Dec. 2000, (rtfm2 realtime traffic flow measurement 2 BOF) 51 st IETF August 2001 (ipfx BOF) sflow, NetFlow, LFAP, etc. WG PSAMP Packet Sampling WG 54 th IETF July 2002 INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 19 IPFIX Metering Process 1 Observation Point 1 Metering Process 1 Metering Process n Observation Point m Metering Process n Observation Domain 1 Exporting Process IP Collector Collector Observation Point 1 Observation Point m Observation Domain K IPFIX INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 20 10
TLV INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 21 Template Flowset & Data Flowset Data Flowset Template Flowset FlowSet ID = 256 Length = 60 FlowSet ID = 0 Length = 28 bytes Template ID = 256 Field Count = 5 IPv4_SRCADDR Length = 4 IPv4_DSTADDR Length = 4 IPv4_NEXT_HOP Length = 4 IN_PKTS Length = 8 IN_BYTES Length = 8 10.10.0.1 10.20.0.30 10.254.0.1 34947 5434325 10.10.0.3 10.33.5.124 10.254.0.1 3434 95048 Rec#1 Rec#2 16bits 32bits INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 22 11
IPFIX NetFlow V SCTP/PR-SCTP UDP TCP IE Template Withdraw Message IPsec or TLS INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 23 CPU INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 24 12
Systematic Sampling Count-based N N N Time-based Random Sampling n-out-of-n N N N Uniform or Non-Uniform Probabilistic INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 25 100 1,000 INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 26 13
AdventNet NetFlow Analyzer (N) ARBOR Networks peakflow (N, S) Foundry Networks IronView (S) GenieNRM GenieATM (N, S) InMon InMon Traffic Sentinel (S, N) INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 27 CAIDA cflowd (N) flow-tools & FlowScan(N) InMon sflowtools (S), sflowtrend (S) NFDUMP & NfSen (N) ntop ntop(n, S, I) Many More!!! INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 28 14
flow-tools flow-{capture, cat, dscan, expire, export, fanout, filter, gen, header, import, log2rrd, mask, merge, nfilter, print, receive, report, rpt2rrd, rptfmt, send, split, stat, tag, xlate} NetFlow V1, V5, (V6), V7, V8 INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 29 FlowScan cflowd / flow-tools / argus / lfapd (collector) + RRD (D/B) + RDDTools (visualization) Platform : UNIX http://www.caida.org/tools/utilities/flowscan/index.xml INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 30 15
GenieATM 6000 NetFlow V1, V5, V7, V9 sflow V4, V5 NetStream http://www.fivefront.com/products/genie/atm6000/function.html INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 31 ARBOR peakflow NetFlow V5, V7, V9 sflow V2, V4, V5 http://www.arbornetworks.com/products_x.php INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 32 16
InMon Traffic Sentinel sflow NetFlow V1, V5, V7, V9 http://www.msol.co.jp/it/inmon/i-tokucho.html INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 33 NetFlow http://www.cisco.com/en/us/products/ps6601/product s_ios_protocol_group_home.html NetFlow V9 RFC http://www.fivefront.com/technology/flow/rfc3954- jp.html Flow http://www.sflow.org/ IPFIX http://www.ietf.org/html.charters/ipfix-charter.html http://www.switch.ch/tf-tant/floma/software.html INTERNET WEEK 2006/12/08 Copyright 2006 Fivefront Corporation, All Rights Reserved. 34 17