How to Get NetFlow from Cisco 3750s. Joe Buchanan System Engineer Manager www.lancope.com



Similar documents
Ethernet Access (Formerly Converged Ethernet Access) Operations Manual

Atlanta Rankings 2014

National Bureau for Academic Accreditation And Education Quality Assurance PUBLIC HEALTH

Maximize Network Visibility with NetFlow Technology. Andy Wilson Senior Systems Engineer Lancope

How To Know The Nursing Workforce

Number of Liver Transplants Performed Updated October 2005

Lodging, Rental Car and Meal Taxes on Travelers in the Top 50 U.S. Cities

The Most Affordable Cities For Individuals to Buy Health Insurance

with NetFlow Technology Adam Powers Chief Technology Officer

Cornell Law School February 2014 Public Interest Low Income Protection Plan

ANGELOUECONOMICS 2012 INDUSTRY HOTSPOTS

Trends in U.S. Consumer Broadband Pricing

APPENDIX 1: SURVEY. Copyright 2010 Major, Lindsey & Africa, LLC. All rights reserved.

Big Impact. BUILDING BUSINESS ONE DEAL AT A TIME

Grantee City State Award. Maricopa County Phoenix AZ $749,999. Colorado Youth Matter Denver CO $749,900

Q Utility Rebate Report. Fort Worth, TX

ITIL Foundation. Learn about process improvements, benefits, and challenges of ITIL, and get your ITIL Foundation certification.

Employee Benefits Alert

Form LM-3 Common Reporting Errors

The New Analytical Mindset For Finance and Accounting Professionals

Office Space FOR LEASE. Humber Green Medical Centre Toronto. 100 Humber College Blvd. Toronto, Ontario M9V 5G4. For more information, please contact:

Office Space FOR LEASE. Derry & Tomken Business Centre. 979 & 989 Derry Road East, Mississauga. For more information, please contact:


Architectural Hardware Consulting Services

The Kronos Cloud Tour. Andrew Manos Director Cloud Services Dan Rooney Cloud Principal

Comprehensive Course Schedule

The Housing Downturn in the United States 2009 First Quarter Update

U.S. NEWS RANKING OF MEDICAL COLLEGES 2012

Zillow Negative Equity Report

Architectural hardware consulting services

Bringing Enterprise-class Network Performance and Security Management Together using NetFlow

The Geography of Foreign Students in U.S. Higher Education: Origins and Destinations. Neil G. Ruiz, The Brookings Institution, February 11, 2015

Department of Veterans Affairs Quarterly Notice to Congress on Data Breaches Third Quarter of Fiscal Year 2015 April 1, 2015 through June 30, 2015

Date Title Location Start Time CEU Contact information Acupuncture Points and Meridians Bridgeport, CT 9 a.m.

The MetLife Market Survey of Assisted Living Costs

DON T JUST MAKE A LIVING. MAKE LIVING BETTER. ENGINEERING & OPERATIONS OPPORTUNITIES

Accredited TOGAF 9, ArchiMate 2 and IT4IT Training Course Calendar June 2016 onwards

Additional information >>> HERE <<< Getting Free Instant Access freight broker training and job placement - Review

Q Utility Rebate Report. Houston, TX

2015 NFL Annual Selection Meeting R P O CLUB PLAYER POS COLLEGE ROUND 2

Cultural Diversity May Be Increasing in Both Canada and the United States, But Important Differences Remain. By Dr. Doug Norris

SDN Applications for IXPs and Service Providers. Jason Kleeh Senior Product Manager January, 2013

United States Market Analysis

EMPLOYER PAY OR PLAY EXCISE TAXES WHERE ARE WE NOW?

in Large Cities,

Made Possible by Generous Support From: RETAIL INSIGHT. Spotlight On Retail Employees

Your Global Network Integrator. DENVER DUSSELDORF LONDON WASHINGTON DC

NetFlow-Lite offers network administrators and engineers the following capabilities:

Post-Graduation Survey Results 2013 College of Fine Arts School of Design Undergraduate

UNIVERSITY OF PITTSBURGH SCHOOL OF MEDICINE MATCH RESULTS FOR CLASS OF Anesthesiology Dermatology - 4

SOFTWARE DEFINED NETWORKING: A PATH TO PROGRAMMABLE NETWORKS. Jason Kleeh September 27, 2012

Understanding Flow and Packet Deduplication

DERRY & TOMKEN BUSINESS CENTRE

Beyond Monitoring Root-Cause Analysis

How to Change Your Address with the Immigration Court and Government Attorneys

UNIVERSITY OF PITTSBURGH SCHOOL OF MEDICINE MATCH RESULTS FOR 2015

List of Allocation Recipients

Table of Contents. Enhanced Use Leases Awarded. Introductory Statement Lease Awards Departmental Enhanced-Use Lease Priorities...

USA IN-PERSON VOTING OPPORTUNITIES 2010 SWEDISH ELECTION

Wireshark Developer and User Conference

ALERT HEALTH CARE REFORM LAW HUMAN CAPITAL PRACTICE 90-DAY WAITING PERIOD AND ORIENTATION PERIOD: FINAL REGULATIONS EXPLAINED BACKGROUND

UNIVERSITY OF PITTSBURGH SCHOOL OF MEDICINE MATCH RESULTS FOR 2011

Best Practices in Legal IT. How to share data and protect critical assets across the WAN

The MetLife Market Survey of Nursing Home & Home Care Costs

AT&T Device Support Center Holiday Operating Hours (November/December)

Additional details >>> HERE <<<

IRS ISSUES FINAL REGULATIONS FOR COMPARATIVE EFFECTIVENESS RESEARCH FEES

Cisco Nexus 1000V Virtual Ethernet Module Software Installation Guide, Release 4.0(4)SV1(1)

Cisco IOS Flexible NetFlow Technology

Netflow Overview. PacNOG 6 Nadi, Fiji

Rates are valid through March 31, 2014.

Physical Therapy Marketing Success :: physical therapy assistant schools usa

Physical Therapy Marketing Success :: physical therapy assistant schools usa

Network Management & Monitoring

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

Network Performance + Security Monitoring

Cisco NetFlow Generation Appliance (NGA) 3140

REVOLUTIONIZE THE WAY YOU VIEW YOUR NETWORK GAIN A UNIFIED VIEW OF SECURITY AND NETWORK OPERATIONS ACROSS PHYSICAL AND VIRTUAL NETWORKS

UNIVERSITY OF PITTSBURGH SCHOOL OF MEDICINE MATCH RESULTS FOR CLASS OF Anesthesiology - 9. Dermatology - 1. Emergency Medicine - 12

QRadar Security Intelligence Platform Appliances

U.S. Department of Housing and Urban Development: Weekly Progress Report on Recovery Act Spending

OFFICE OF INSPECTOR GENERAL SPECIAL FRAUD ALERT FRAUD AND ABUSE IN NURSING HOME ARRANGEMENTS WITH HOSPICES

CCNA Cisco Associate- Level Certifications

Catalyst 6500/6000 Switches NetFlow Configuration and Troubleshooting

US News & World Report Best Undergraduate Engineering Programs: Specialty Rankings 2014 Rankings Published in September 2013

Accredited TOGAF 9 and ArchiMate 2 Training Course Calendar February 2016 onwards

Hiring and Compensation

FMLA AMENDED TO PROVIDE LEAVE TO

Transcription:

How to Get NetFlow from Cisco 3750s and Other Non-NetFlow NetFlow Enabled Devices Joe Buchanan System Engineer Manager www.lancope.com

Network Flow Collection Internet NetFlow Fields src and dst IP src and dst port start time end time NetFlow Packets packet count byte count... StealthWatch Flow Collector

Flow Monitoring Dual Benefit to IT Network Team hinterface Utilization hzone Z Traffic hservice Traffic hqos Monitoring hasn Monitoring hintra-site monitoring hmpls visibility ibilit Security Team hbehavior-based IDS hptp file sharing detection ti Worm and Malware propagation detection hnetwork Acceptable Use policy enforcement hattack context and 3 rd party correlation

Flow monitoring dual benefit to IT Network Team hinterface Utilization hzone Traffic hservice Traffic hqos Monitoring hasn Monitoring hintra-site monitoring hmpls visibility Security Team hbehavior-based IDS hptp file sharing detection Worm and Malware propagation detection hnetwork Acceptable Use policy enforcement hattack context and 3 rd party correlation

NetFlow = Visibility Traditional SNMP NetFlow Reporting

NetFlow = Visibility

NetFlow Supported Devices Cisco 1700 Cisco 800 Cisco 1900 Cisco 2800 Not Supported Huawei Quidway Cisco 3750 Juniper Networks Cisco 2900 Cisco 7200 VXR Cisco 7600 Cisco 3900 Nortel Networks Cisco XR 12000 Cisco Nexus 7000 Cisco Catalyst 6500

How to Troubleshoot with NetFlow: An Example

How to Troubleshoot with NetFlow: An Example

How to Troubleshoot with NetFlow: An Example

How to Troubleshoot with NetFlow: An Example

How to Troubleshoot with NetFlow: An Example

How to Troubleshoot with NetFlow: An Example

The Layer-2 Visibility Problem FlowSensor (NetFlow Enabled) NetFlow Collector NetFlow NetFlow Catalyst 3750 (No NetFlow) Catalyst 6500 (NetFlow Enabled)

How to Gain NetFlow From Your 3750 FlowSensor AE Light-weight, cost-effective 1U network appliance Collects Ethernet frames and exports NetFlow v9 StealthWatch Flow Collector Monitor up to (5) 3750s simultaneously Works with any NetFlow v9 capable flow collector NetFlow FlowSensor Model Capacity Disk Interfaces AE-1000 1 Gbps 73GB 3 or 5 AE-2000 2.5 Gbps 160GB 3 or 5

How to Measure Performance Between Hosts SRCIP DSTIP PROTO DPORT SPORT PKTS BYTES RTT SRT... TCP 80 5749 73 9,092 65ms 230ms... TCP 5749 80 103 78,020 65ms 230ms... StealthWatch FlowSensor SPAN round trip time across the network same as ping output RTT time it takes the server to process a request SRT

Capturing NetFlow Per 3750 Link FlowSensor capture port SPAN interface description

Capturing NetFlow Per 3750 Link

Capturing Netflow Per 3750 Link

10G Monitoring with Stackable FlowSensors FlowSensor AE-2000 FlowSensor AE-2000 2.5G 10G 7.5G 5.0G 2.5G 16x 1G 2.5G StealthWatch Flow Collector NetFlow FlowSensor AE-2000 FlowSensor AE-2000 2.5G Ethernet loadbalancer vendors... 2.5G

FlowSensor VE (Virtual Edition) Lightweight, virtual appliance for VMware ESX 3.5 and 4.0 Captures and records all VM2VM communications cat o within the virtual network environment Exports NetFlow v9 FREE to download and try (visit lancope.com to register and download) VMware Server StealthWatch Flow Collector NetFlow

StealthWatch NetFlow Replicator Dedicated NetFlow replication appliance Designed to copy and redistribute flows of NetFlow packets based on a rule-set that you define Original i UDP source IP and payload is preserved Simple, easy to configure, web-based, 1U network appliance Promiscuous Mode allows installation without changing NetFlow export IPs Search Replicator on NetFlow Ninjas blog for more info http://netflowninjas.typepad.com/blog/2009/09/stealthwatch-flow-replicator-holy-cow-this-thing-is-popular.html NetFlow StealthWatch Flow Replicator NetFlow NetFlow NetFlow

In Summary Flow-based technologies provide unrivaled scale and cost effectiveness in large enterprise environments NetFlow is not just for netops, its value extends across all IT from compliance auditing to helpdesk support Enable NetFlow on as many devices as you can to maximize visibility, the more the better NetFlow is ideal for monitoring port dense datacenters and large distributed WAN NetFlow is ideal for monitoring port dense datacenters and large distributed WAN environments. No probes are required.

NetFlow 101 Boot Camp Event site: http://lancope.com/news/events/netflowseminar.aspx 22 New Cities in 2010! Minneapolis, MN February 17, 2010 Washington DC July, 22, 2010 Atlanta, GA February 25, 2010 Hartford, CT March 11, 2010 Toronto, ON March 18, 2010 Phoenix, AZ August 5, 2010 Chicago, IL August 12, 2010 Cleveland, OH August 19, 2010 New York, NY San Francisco, CA April 1, 2010 September 2, 2010 Houston, TX April 8, 2010 Denver, CO April 15, 2010 Baltimore, MD May 13, 2010 Seattle, WA May 20, 2010 San Jose, CA June 3, 2010 Dallas, TX July 7, 2010 Pittsburgh, PA September 16, 2010 Charlotte, NC September 30, 2010 Boston, MA October 7, 2010 Los Angeles, CA October 21, 2010 New York, NY November 11, 2010 Miami, FL December 9, 2010

Thank You Joe Buchanan System Engineer Manager www.lancope.com com