Data Monitoring Switch 2 www.netoptics.com IDS nalyzer nalyzer 2 Forensic RMON RMON 2 ELEXO 20 Rue de illancourt 9200 oulogne-illancourt Téléphone : 33 (0) 4 22 0 00 Télécopie : 33 (0) 4 22 0 0 Courriel : info@elexo.fr TV : FR00722063534
Content Key Features...2 Director Part Numbers.....3 Director rchitecture...4 US port...5 Director Management...5 Typical pplication...6 In-line Monitoring of 0 Gigabit Links...8 Director Front Panel...9 Director Rear Panel...0
Introduction Net Optics Director is a key component for building a comprehensive, consolidated monitoring infrastructure for both network management and security. It extends the range of visibility for data monitoring across converged data and digital voice networks, while eliminating monitoring port contention and minimizing the number of tools needed to optimally manage the network. ports. It includes aggregation and regeneration functions, so the link-to-monitor-port mapping can be one-to-one, particular monitoring tools. Matrix switching, aggregation, and regeneration provided. Network and Span ports can be aggregated and regenerated to output ports in almost any combination. Modular design Copper links. The Director Chassis includes two DNM slots; they can be populated with the same or different DNM types. Ten -Gigabit Monitor ports are SFP-based, accepting any mix of Copper, SX, and LX interface modules. Flexible 0 Gigabit support Monitor ports. Expandable Two 0 Gigabit ports on the rear of the unit enable daisy-chaining up to ten Director chassis to expand the number of
Ease of Use 9-inch rack frame, U high Front-mounted connectors for quick and easy installation or it may be exported to a third party reporting tool such as a protocol analyzer CLI also available remotely over secure SSH connection Field-upgradeable software Compatible with all major manufacturers monitoring devices, including protocol analyzers, probes, and intrusion detection and prevention systems Monitor port Filtering Filters based on IP protocol, IP addresses, layer 4 ports, MC addresses, and VLNs Source and destination MC addresses, or ranges of addresses Source and destination IP addresses, or ranges of addresses Source and destination ports, or ranges of ports Supports IPv4 and IPv6 protocols VLN Passive, Secure Technology Passive access at up to 0 Gbps In-line links do not interfere with the data stream or introduce a point of failure Redundant power to maximize uptime In-line links default to open under a complete power-fail condition, ensuring network availability Fully RoHS compliant Unsurpassed Support Net Optics offers technical support throughout the lifetime of your purchase. Our technical support team is ts-support@netoptics.com. FQs are also available on Net Optics Web site at www.netoptics.com. 2
Director Part Numbers Chassis Part Number DIR-3400 DIR-7400 DNM Part Number DNM-00 DNM-0 DNM-200 DNM-20 DNM-220 DNM-230 DNM-300 DNM-30 DNM-320 DNM-330 Description Director Main Chassis with 0 SFP monitor ports Director Main Chassis with 0 SFP monitor ports, 2 XFP 0GbE ports, 2 XFP uplink ports Description 6-Port 0/00/000 Copper In-Line Module 2-Port 0/00/000 Copper Span Module 6-Port Gigabit SX Fiber 62.5µm In-Line Module 2-Port Gigabit SX Fiber 62.5µm Span Module 6-Port Gigabit SX Fiber 50µm In-Line Module 2-Port Gigabit SX Fiber 50µm Span Module 6-Port Gigabit LX Fiber In-Line Module 2-Port Gigabit LX Fiber Span Module 6-Port Gigabit ZX Fiber In-Line Module 2-Port Gigabit ZX Fiber Span Module 3
Director rchitecture The following diagram shows a schematic view of the architecture of the Director device shown as a Matrix Switch with DNM with 6 in-line network ports DNM with 2 Span or out-of-band network ports Four configurable 0GbE XFP ports n. n.3 n.5 n.7 n.9 n. n2. n2.2 n2.3 n2.4 n2.5 n2.6 n2.7 n2.8 n2.9 n2.0 n2. n2.2 t. t.2 t2. t2.2 n.2 n.4 n.6 n.7 n.0 n.2 Filters t. t.2 t2. t2.2 m. m.2 m.3 m.4 m.5 m.6 m.7 m.8 m.9 m.0 Key: Network or Span port Monitor Port ggregating switch conection Dim lternate configurations for 0 GbE XFP ports Figure : Director internal architecture 0 SFP monitor ports Director can be viewed as a matrix switch with up to 28 inputs, or Network ports, and 4 outputs, or Monitor ports. 4
while Span DNM models support 2 Span ports. The diagram shows one in-line and one Span DNM. oth in-line and Span DNMs are available with either Copper or SX, LX, or ZX Fiber interfaces. Different DNM types can be mixed in the same chassis, for example, one in-line Copper DNM and one Span Fiber DNM. The modules are hot-pluggable for easy serviceability. One or both DNM slots can be populated. The DNM slots are numbered for the slot on the left and 2 for the slot on the right. If only one slot is populated, it should be slot. oth Span oth Monitor One Span and one Monitor chassis for expansion. US port located on the back is reserved for future functionality. Director Management administrators. The CLI runs locally over an RS-232 serial port or remotely over a secure SSH connection. Web Manager System Manager n SNMP platform-based tool to mange all the Director and other Net Optics itap-enabled devices on your network 5
Director Typical pplication The following diagram shows a typical application using Director to implement a comprehensive, consolidated monitoring infrastructure. 2 www.netoptics.com IDS nalyzer nalyzer 2 Forensic RMON RMON 2 Figure 2: Director-centric network monitoring infrastructure,q WKLV H[DPSOH HLJKW QHWZRUN OLQNV DUH PRQLWRUHG E\ VL[ PRQLWRULQJ GHYLFHV 7KH FRPSDQ\ V H[WHUQDO DFFHVV LV SURWHFWHG E\ D ÀUHZDOO VKRZQ LQ WKH XSSHU OHIW RI WKH GLDJUDP 7KH OLQN UXQV WKURXJK D URXWHU WKHQ LQ OLQH WKURXJK 'LUHFWRU DQG WKHQ WR D VZLWFK WKDW GLVWULEXWHV WUDIÀF WKURXJKRXW D GHSDUWPHQW Network Links 7KH UHVW RI WKH GHSDUWPHQW V VZLWFKHV DUH VKRZQ EXW RQO\ WKH FRQQHFWLRQV WR 'LUHFWRU DUH LOOXVWUDWHG 7KH IRXU GHSDUWment switches shown in the lower right are cross-connected for fault tolerance. ll four of the cross-connected links DUH SDVVHG LQ OLQH WKURXJK 'LUHFWRU DV LQGLFDWHG E\ WKH VODQWLQJ SXUSOH OLQHV VR WKH\ FDQ EH WKRURXJKO\ PRQLWRUHG IRU SHUIRUPDQFH WXQLQJ VHFXULW\ DQG WURXEOH VKRRWLQJ %HFDXVH VR PDQ\ FULWLFDO OLQNV SDVV LQ OLQH WKURXJK 'LUHFWRU LW V good to know that they are completely passive connections Director does not slow down or interfere with the in-line WUDIÀF DQG WKH OLQNV VWD\ RSHQ WR SDVV WUDIÀF HYHQ LI ERWK RI WKH 'LUHFWRU SRZHU VXSSOLHV DUH UHPRYHG :KHQ SRZHU LV UHPRYHG &RSSHU LQ OLQH OLQNV PD\ EH GURSSHG IRU D VKRUW SHULRG RI WLPH³OHVV WKDQ VHFRQG³ZKLOH UHOD\V VZLWFK WR RSHQ WKH OLQN 6XEVHTXHQWO\ WKH QHWZRUN UH HVWDEOLVKHV WKH OLQNV DQG WUDIÀF UHVXPHV ÁRZLQJ Purple line indicates an in-line Tap Figure 3: Detail of in-line Taps shown in Figure 2 In the middle of Figure 2, three other departmental switches are monitored through their Span ports. One of the VZLWFKHV KDQGOHV *E( WUDIÀF VR LWV 6SDQ SRUW JRHV WR RQH RI WKH 'LUHFWRU *E( ;)3 SRUWV 2QH RI WKH RWKHU VZLWFKHV *E( 6SDQ SRUWV FDUULHV WKUHH GLVWLQFW W\SHV RI WUDIÀF²H PDLO 9R,3 DQG :HE SDJHV²DV LQGLFDWHG E\ WKH WKUHH colored circles on the Span link. 6
In this installation, Director has ten additional Span ports and one in-line link that are available for expansion, when more links need to be monitored. Monitoring Tools Still referring to Figure 2, six monitoring tools are connected to Director. They include protocol and performance analyzers, connected network links, and the connections can be switched easily, using the Director CLI, without ever moving a One of the network monitoring tools is capable of handling more than Gbps, so it is attached to a 0 Gigabit XFP The two green RMON monitoring tools at the bottom are the same type of tool. Two identical tools provide the capability of monitoring a greater amount of data than a single tool can handle. nother reason to use identical monitoring 7
2 www.netoptics.com Director To create an in-line link on a 0 Gigabit network segment, use an external network Tap. Figure 4 shows an LC Fiber Tap being used to send two half-duplex data streams to two 0-Gigabit Director ports. This 0 Gbps LC Fiber Tap Router 0 Gbps Switch Director Monitoring tools Figure 4: 0 Gigabit in-line network connection using a network Tap be a problem in most cases because network links typically operate at 30 percent or less capacity to prevent congestion. Port ggregator Tap Router < 0 Gbps total Switch Director Monitoring tools Figure 5: 0 Gigabit in-line network connection using a Port ggregator Tap 8
Director 'LUHFWRU )URQW 3DQHO The features of the Director front panel are shown in the following diagram. 0 SFP Monitor Ports Director 2 3 4 2 XFP Configurable 0GbE Ports DNM with 0/00/000 Copper Network Ports (6 In-line or 2 Span Ports) DNM with SX Fiber Network Ports (6 In-line or 2 Span Ports) 5 2 0 LINK 00 CT 000 In-Line 0/00/000 In-Line Gigait www.netoptics.com 6 Power LEDs 7 8 9 0 2 3 4 5 6 7 8 9 0 2 2 Director Network Module (DNM) Slots Monitor Ports Network Ports Figure 6: Director Front Panel Monitor Port LEDs (DFK 0RQLWRU SRUW KDV WZR OLJKW HPLWWLQJ GLRGH /(' LQGLFDWRUV 7KH /LQN /(' LV LOOXPLQDWHG ZKHQ D OLQN LV HVWDEOLVKHG 7KH $FWLYLW\ /(' EOLQNV ZKHQ WUDIÀF LV SDVVLQJ WKURXJK WKH SRUW 7KH\ DUH ORFDWHG LQ WKH PLGGOH EHWZHHQ WKH two rows of SFPs. DNM / Network Port LEDs (DFK HWZRUN RU 6SDQ SRUW KDV WZR /('V 7KH /LQN /(' LV LOOXPLQDWHG ZKHQ D OLQN LV HVWDEOLVKHG 7KH $FWLYLW\ /(' EOLQNV ZKHQ WUDIÀF LV SDVVLQJ WKURXJK WKH SRUW 7KH /LQN /(' DOVR LQGLFDWHV WKH OLQN VSHHG DPEHU IRU 0ESV \HOORZ IRU 0ESV DQG JUHHQ IRU D 0ESV *ESV 7KH\ DUH LQWHJUDWHG LQ WKH 5- FRQQHFWRUV /LQN on the left and ctivity on the right. (DFK *LJDELW )LEHU HWZRUN RU 6SDQ SRUW KDV D VLQJOH /(',W LOOXPLQDWHV VROLG ZKHQ D OLQN LV HVWDEOLVKHG DQG LW ÁDVKHV ZKHQ WUDIÀF LV SDVVLQJ WKURXJK WKH SRUW 7KHVH /LQN /('V DUH ORFDWHG EHORZ WKH /& ÀEHU FRQQHFWRUV 0 Gigabit Port LEDs (DFK FRQÀJXUDEOH *LJDELW SRUW KDV D VLQJOH /(',W LOOXPLQDWHV VROLG ZKHQ D OLQN LV HVWDEOLVKHG DQG LW ÁDVKHV ZKHQ WUDIÀF LV SDVVLQJ WKURXJK WKH SRUW 7KHVH /LQN /('V DUH ORFDWHG WR WKH OHIW RI WKH ;)3 ÀEHU FRQQHFWRUV Power LEDs 7ZR /(' LQGLFDWRUV IRU SRZHU RQH IRU HDFK RI WKH UHGXQGDQW SRZHU VXSSOLHV 9
Director Rear Panel The features of the Director rear panel are shown in the following diagram. US Port Management Port 2 XFP Daisy-chain 0GbE Ports Power Supply Module Power Supply Module RS232 Management INPUT OUTPUT Port SERIL NUMER XXXXXX RS-232 Port SR, LR, or ER Fiber XFP Modules Redundant Hot-swappable Power Supplies Figure 7: Director Rear Panel US Port Reserved for future functionality RS-232 Port D9 serial port for the CLI Management Port the CLI runs over an SSH connection through this port; Indigo management tools, when available, will connect through this port XFP Daisy-chain 0GbE Ports 0 chassis Power Supply Modules with integrated cooling fans; each supply can power the unit independently; dual supplies provide redundancy to maximize uptime; -48VDC models are also available 0