TransPac Flow Data: Collection and Analysis

Similar documents
Tier3 Network Issues. Richard Carlson May 19, 2009

perfsonar: End-to-End Network Performance Verification

NfSen Plugin Supporting The Virtual Network Monitoring

Best of Breed of an ITIL based IT Monitoring. The System Management strategy of NetEye

Network Performance and Possible Improvement For Medical Demonstration

Firewall Defaults, Public Server Rule, and Secondary WAN IP Address

IPv6 measurement in CSTNET. CSTNET, CNIC, Sep. 2014

Wireshark Developer and User Conference

A High-Performance Storage and Ultra-High-Speed File Transfer Solution

Introducing FortiDDoS. Mar, 2013

Visualizing Traffic on Network Topology

Connecting North Carolina s Future Today. Application Monitoring: ClassScape Case Study. NCSU Centennial Networking Lab

NSF IRNC Program International Deployment and Experimental Efforts with SDN in 2013

NFSEN - Update 13th TF-CSIRT Meeting 23. September 2004 Malta Peter Haag

Case Study: Instrumenting a Network for NetFlow Security Visualization Tools

EVALUATING NETWORK BUFFER SIZE REQUIREMENTS

Network Security Platform 7.5

How To Monitor Network Traffic On A Cell Phone

Flow Based Traffic Analysis

How To Set Up Foglight Nms For A Proof Of Concept

Network performance monitoring Insight into perfsonar

Whitepaper. NetFlow vs. sflow: A Technical Review. plixer. International

Monitoring of Tunneled IPv6 Traffic Using Packet Decapsulation and IPFIX

THE ROAD TO IPV6: KU SERVICE EXPERIENCES ON DUAL-STACK

CISCO CONTENT SWITCHING MODULE SOFTWARE VERSION 4.1(1) FOR THE CISCO CATALYST 6500 SERIES SWITCH AND CISCO 7600 SERIES ROUTER

NetFlow Feature Acceleration

The Value of Flow Data for Peering Decisions

Running an OpenStreetMap cache server in Asia

nfdump and NfSen 18 th Annual FIRST Conference June 25-30, 2006 Baltimore Peter Haag 2006 SWITCH

Many network and firewall administrators consider the network firewall at the network edge as their primary defense against all network woes.

Introduction to Netflow

Windows Server 2012 R2 Hyper-V: Designing for the Real World

Watch your Flows with NfSen and NFDUMP 50th RIPE Meeting May 3, 2005 Stockholm Peter Haag

Agenda. sflow intro. sflow architecture. sflow config example. Summary

Firewall Defaults and Some Basic Rules

How To Set Up A Network Measurement Toolkit For A Network Performance Test On A Network With A Network (Networking) On A Microsoft Ipa 2.5 (Netware) On An Ipa2 (Netcom) On Your Computer

ABSTRACT 1.1 MEASUREMENT APPROACHES 1. INTRODUCTION 2. OCXMON/CORAL PASSIVE MONITORING OF INTERNET TRAFFIC AT SUPERCOMPUTING 98

Overview of Network Measurement Tools

Network Monitoring and Traffic CSTNET, CNIC

Understanding Flow and Packet Deduplication

Network Performance Tools

How valuable DDoS mitigation hardware is for Layer 7 Sophisticated attacks

VALIDATING DDoS THREAT PROTECTION

If you already have your SAN infrastructure in place, you can skip this section.

Aggregate speed and availability optimize your business connectivity. Visit for more information. Protonyx Data Services,

Autonomous NetFlow Probe

and reporting Slavko Gajin

Voice Internet Phone Gateway

Copyright & trademark notices. Notices. Copyright Acknowledgment

Designing and Deploying a Distributed Architecture for Research Data Management

Q&A. DEMO Version

NetFlow-Lite offers network administrators and engineers the following capabilities:

Securing and Monitoring BYOD Networks using NetFlow

perfsonar Host Hardware

Cisco Secure Access Control Server Solution Engine

Contents. Digital Video Surveillance Basic Troubleshooting Guide

Pacnet Global EIPL Point-to-Multipoint Service

NSC E

UCi2i Video Conference Endpoint Firewall Requirements. UCi2i Video Conference Endpoint Firewall Requirements

Click on Start Control Panel Windows Firewall. This will open the main Windows Firewall configuration window.

An overview of traffic analysis using NetFlow

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET

Netflow For Incident Detection 1

High Performance Storage System. Overview

Signature-aware Traffic Monitoring with IPFIX 1

Network Monitoring System with Scheduler

Secure File Sharing SRFS on Ether with host-to-host IPSec connection over the Pacific Ocean link

CHAPTER 1 WhatsUp Flow Monitor Overview. CHAPTER 2 Configuring WhatsUp Flow Monitor. CHAPTER 3 Navigating WhatsUp Flow Monitor

Accelerating Microsoft Exchange Servers with I/O Caching

Science DMZs Understanding their role in high-performance data transfers

AlliedWare Plus OS How To Use sflow in a Network

Performance and Bandwidth Testing for Data Circuits

NetFlow/IPFIX Various Thoughts

Overview. Why use netflow? What is a flow? Deploying Netflow Performance Impact

SolarWinds. Understanding SolarWinds Charts and Graphs Technical Reference

UKCMG Industry Forum November 2006

Course Contents CCNP (CISco certified network professional)

Source-Connect Network Configuration Last updated May 2009

Linux NIC and iscsi Performance over 40GbE

McAfee Network Security Platform 8.2

Fluke Networks NetFlow Tracker

my forecasted needs. The constraint of asymmetrical processing was offset two ways. The first was by configuring the SAN and all hosts to utilize

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

Application Note. Cell Janus Load Balancing Algorithms Technical Overview

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

How To Back Up A Computer To A Backup On A Hard Drive On A Microsoft Macbook (Or Ipad) With A Backup From A Flash Drive To A Flash Memory (Or A Flash) On A Flash (Or Macbook) On

Setting up pfsense as a Stateful Bridging Firewall.

IPv6/IPv4 Automatic Dual Authentication Technique for Campus Network

NetFlow: What is it, why and how to use it? Miloš Zeković, ICmyNet Chief Customer Officer Soneco d.o.o.

WhatsUpGold. v NetFlow Monitor User Guide

August 9 th 2011, OSG Site Admin Workshop Jason Zurawski Internet2 Research Liaison NDT

Flow Analysis Versus Packet Analysis. What Should You Choose?

Technical Brief. DualNet with Teaming Advanced Networking. October 2006 TB _v02

How To Fix A Fault Notification On A Network Security Platform (Xc) (Xcus) (Network) (Networks) (Manual) (Manager) (Powerpoint) (Cisco) (Permanent

Load Balance Router R258V

Mobile IP Network Layer Lesson 02 TCP/IP Suite and IP Protocol

WAN Optimization in MPLS Networks- the Transparency Challenge!

How To Monitor A Network On A Network With Bro (Networking) On A Pc Or Mac Or Ipad (Netware) On Your Computer Or Ipa (Network) On An Ipa Or Ipac (Netrope) On

Deploying Riverbed Cascade and Steelheads. A Best Practices Whitepaper

Science DMZ Security

Transcription:

TransPac Flow Data: Collection and Analysis INTERNATIONAL Hans Addleman Network Engineer, International Networks University Information Technology Services Indiana University addlema@iu.edu Supported by the National Science Foundation

TransPAC Netflow Overview Started collecting flow records in February 2015 Current collection is 1 in 50 packets Netflow Version 5 Moving to IPFIX for speed and IPv6 soon Using NFDUMP toolkit with NFSEN.

TransPAC Netflow Hardware 2 Dell Servers do the work Flow Collector Dell R720 with Xeon E5-2650 processors 4.2TB total storage space on RAID5 array Flow Processor Dell R420 with Xeon E5-2430 (24 cores) 384G ram Servers connected by dedicated 10G link. Collecting ~35G a month of netflow data.

Top Talkers by Source AS Inbound to TransPAC 2% 2501 The Univeristy of Tokyo 3% 2% 2% 7660 Asia Pacific Advanced Network 3% 3% 17716 NaBonal Taiwan University 18127 Tsukuba- WAN Network 9264 Academic Sinica Network 7% 58% 1237 Korea InsBtute of Science and Technology InformaBon Network 3836 Thai Social/ScienBfic, Academic and Research Network 2500 WIDE Project 23456 2 byte to 4 byte 4621 UNINET- TH

Top Talkers by Des8na8on AS Inbound to TransPAC 7% 18% 7% 7% 22388 TransPAC 194 University CorporaBon for Atmospheric Research 8% 229 Merit 680 DFN 292 ESNET 789 IN2P3 160 University of Chicago 786 JANET 8% 26 Cornell University 32 Stanford University 12% 9% 10%

Top Talkers by Source AS Outbound from TransPAC 4% 5% 4% AS7941 Internet Archive 5% 28% AS1701 NaBonal AeronauBcs and Space AdministraBon AS70 NaBonal Library of Medicine AS6629 NOAA AS195 San Diego Supercomputer Center AS5663 US Geological Survery 8% AS3152 Fermi NaBonal Accelerator Laboratory AS194 University CorporaBon for Atmospheric Research AS11318 Georgetown University 12% AS20033 NaBonal ClimaBc Data Center

Top Talkers by Des8na8on AS Outbound from TransPAC 5% 5% AS55824 NKN Core Network AS7497 CSTNET 30% AS18127 Tsukuba- WAN Network AS9264 Academic Sinica Network AS3836 Thai Social/ScienBfic, Academic and Research Network AS7472 NaBonal University of Singapore 7% AS3363 Hong Kong University of Science and Technology AS45773 PERN AS Content Servie Provider 8% 17% AS7660 Asia Pacific Advanced Network AS23456 2 byte to 4 byte AS Conversion 10%

TransPAC Top Ports Top Ports in use Feb- 2015 to July 2015 5% 12% 21% 28% Tunnels IPERF Rsync Aspera File Xfer NTP FragmentaBon Unknown

Testing and Tunneling Lots of traffic transiting TransPAC is secure. Lots of test traffic flowing. (iperf, bwctl, perfsonar) Top Ports in use Feb- 2015 to July 2015 5% 28% Tunnels 12% IPERF Rsync 21% Aspera File Xfer NTP Fragmen tabon Unknow n

UDP/TCP Port 0 Lots of traffic on UDP and TCP port 0. Fragmentation? A network may not have Jumbo Frames enabled in the path 5% グラフ タイトル 12% 28% Tunnels IPERF Rsync 21% Aspera File Xfer NTP Fragmen tabon Unknow n

April 2015 Large Transfer 78% of the top 10 traffic in April was between 2 institutions. The University of Tokyo National Center for Atmospheric Research Inbound towards NCAR April 2015 Inbound from Japan to USA Large file transfer between 2 institutions Can we help make this transfer better? Gives us a clue to what type of researchers are using our network. Reach out to other researchers in same field. Smaller transfers but still large noticed in March as well. 78% 22% Other Data Big data Xfer

March 2015 Large Transfer 68% of the Top 10 Traffic in March was a data transfer Georgetown University to the Academic Sinica Network March 2015 Outbound from USA to Taiwan 32% Data Transfer Other Traffic 68%

Netflow Final Thoughts Great for statistics and traffic analysis. Netflow is ALSO a powerful tool for finding ongoing trouble in your network.

Questions / Comments http://internationalnetworking.iu.edu Hans Addleman - addlema@iu.edu TransPAC4 NSF IRNC Award: #1450904