Agenda. sflow intro. sflow architecture. sflow config example. Summary

Similar documents
NetStream (Integrated) Technology White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date

NetFlow: What is it, why and how to use it? Miloš Zeković, ICmyNet Chief Customer Officer Soneco d.o.o.

Configuring Flexible NetFlow

Flow Analysis Versus Packet Analysis. What Should You Choose?

Monitoring Network Traffic Using sflow Technology on EX Series Ethernet Switches

SolarWinds Technical Reference

MONITORING NETWORK TRAFFIC USING sflow TECHNOLOGY ON EX SERIES ETHERNET SWITCHES

Configuring NetFlow-lite

The Value of Flow Data for Peering Decisions

Configuring NetFlow Secure Event Logging (NSEL)

NetFlow Performance Analysis

LogLogic Cisco NetFlow Log Configuration Guide

Catalyst 6500/6000 Switches NetFlow Configuration and Troubleshooting

Cisco Integrators Cisco Partners installing and implementing the Cisco Catalyst 6500 Series Switches

Netflow Overview. PacNOG 6 Nadi, Fiji

How to configure an Advanced Expert Probe as NetFlow Collector

Appendix A Remote Network Monitoring

Wireshark Developer and User Conference

Cisco ASA and NetFlow Using ASA NetFlow with LiveAction Flow Software

How-To Configure NetFlow v5 & v9 on Cisco Routers

HP IMC User Behavior Auditor

Configuring NetFlow Secure Event Logging (NSEL)

NetFlow-Lite offers network administrators and engineers the following capabilities:

Introduction to Netflow

Network Traffic Analyzer

Network Management & Monitoring

Tue Apr 19 11:03:19 PDT 2005 by Andrew Gristina thanks to Luca Deri and the ntop team

Cisco IOS Flexible NetFlow Technology

How To Mirror On An Ipfix On An Rspan Vlan On A Pc Or Mac Or Ipfix (Networking) On A Network On A Pnet (Netnet) On An Uniden (Netlan

Flow Monitor Configuration. Content CHAPTER 1 MIRROR CONFIGURATION CHAPTER 2 SFLOW CONFIGURATION CHAPTER 3 RSPAN CONFIGURATION...

Cisco Catalyst 4948E NetFlow- lite

Flow Monitor Configuration. Content CHAPTER 1 MIRROR CONFIGURATION CHAPTER 2 RSPAN CONFIGURATION CHAPTER 3 SFLOW CONFIGURATION...

Network Monitoring and Management NetFlow Overview

LogLogic Cisco NetFlow Log Configuration Guide

Using The Paessler PRTG Traffic Grapher In a Cisco Wide Area Application Services Proof of Concept

Network traffic monitoring and management. Sonia Panchen 11 th November 2010

H3C Firewall and UTM Devices DNS and NAT Configuration Examples (Comware V5)

QRadar SIEM 7.2 Flows Overview

Traffic Mirroring Commands on the Cisco IOS XR Software

RSA Security Analytics Netflow Collection Configuration Guide

RSA Security Analytics Netflow Collection Configuration Guide

Network Agent Quick Start

Getting Started with Configuring Cisco IOS NetFlow and NetFlow Data Export

AlliedWare Plus OS How To Use sflow in a Network

Whitepaper. NetFlow vs. sflow: A Technical Review. plixer. International

Configuring NetFlow Data Export (NDE)

Configuring NetFlow. Information About NetFlow. NetFlow Overview. Send document comments to CHAPTER

Monitoring and Analyzing Switch Operation

Cisco IOS NetFlow Version 9 Flow-Record Format

Integrated Traffic Monitoring

CSE331: Introduction to Networks and Security. Lecture 12 Fall 2006

Quick Start for Network Agent. 5-Step Quick Start. What is Network Agent?

Quick Start for Network Agent. 5-Step Quick Start. What is Network Agent?

NetFlow v9 Export Format

Troubleshooting the Firewall Services Module

NetFlow Aggregation. Feature Overview. Aggregation Cache Schemes

Configuring NetFlow. Information About NetFlow. NetFlow Overview. Send document comments to CHAPTER

Traffic Mirroring Commands on the Cisco ASR 9000 Series Router

Scrutinizer. Getting Started Guide. A message from Plixer International:

Configuring NetFlow. Information About NetFlow. Send document comments to CHAPTER

Flow Analysis. Make A Right Policy for Your Network. GenieNRM

IPS Attack Protection Configuration Example

J-Flow on J Series Services Routers and Branch SRX Series Services Gateways

NetFlow use cases. ICmyNet / NetVizura. Miloš Zeković, milos.zekovic@soneco.rs. ICmyNet Chief Customer Officer Soneco d.o.o.

Traffic monitoring with sflow and ProCurve Manager Plus

Networking Fundamentals Part of the SolarWinds IT Management Educational Series

How To Set Up Foglight Nms For A Proof Of Concept

DEPLOYMENT GUIDE Version 1.2. Deploying the BIG-IP LTM for SIP Traffic Management

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

Integrated Traffic Monitoring

CloudEngine Series Data Center Switches. Cloud Fabric Data Center Network Solution

Software Defined Networking and the design of OpenFlow switches

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

and reporting Slavko Gajin

Cisco - Configure the 1721 Router for VLANs Using a Switch Module (WIC-4ESW)

SolarWinds Technical Reference

NetFlow The De Facto Standard for Traffic Analytics

Overview. Why use netflow? What is a flow? Deploying Netflow Performance Impact

Configuring NetFlow on Cisco ASR 9000 Series Aggregation Services Router

Beyond Monitoring Root-Cause Analysis

Fluke Networks NetFlow Tracker

Cisco IOS NetFlow Version 9 Flow-Record Format

CCT vs. CCENT Skill Set Comparison

Cisco DNS-AS Troubleshooting

Configure IOS Catalyst Switches to Connect Cisco IP Phones Configuration Example

Certes Networks Layer 4 Encryption. Network Services Impact Test Results

SolarWinds Technical Reference

Lab Configure IOS Firewall IDS

Table of Contents. Cisco Mapping Outbound VoIP Calls to Specific Digital Voice Ports

Network forensics 101 Network monitoring with Netflow, nfsen + nfdump

sflow Why You Should Use It And Like It NANOG 39 February 04-07, 2007

Lab Characterizing Network Applications

Traffic analysis with NetFlow

OpenFlow and Software Defined Networking presented by Greg Ferro. OpenFlow Functions and Flow Tables

Recommendations for Network Traffic Analysis Using the NetFlow Protocol Best Practice Document

CS 78 Computer Networks. Internet Protocol (IP) our focus. The Network Layer. Interplay between routing and forwarding

INTRODUCTION TO FIREWALL SECURITY

CHAPTER 1 WhatsUp Flow Monitor Overview. CHAPTER 2 Configuring WhatsUp Flow Monitor. CHAPTER 3 Navigating WhatsUp Flow Monitor

Flow Monitor for WhatsUp Gold v16.2 User Guide

Transcription:

sflow Features

Agenda sflow intro. sflow architecture sflow config example Summary 1

What is sflow? sflow is a technology for monitoring traffic in data networks containing switches and routers. S9700 supports sflow v5. The sflow Agent uses sampling technology to capture traffic statistics from the device it is monitoring. sflow Datagrams are used to immediately forward the sampled traffic statistics to an sflow Collector for analysis. sflow Datagram UDP 6343(default) sflow collector sflow agent Traffic sflow Datagram Client Client sflow Report 2

sflow vs Netflow sflow Easy in egress & ingress Direction direction Frame type L2 and L3 Flow table Sampling. Accuracy Reaction Complex Application scenario OK in a normally condition. Fast & timely; no more than 1 second. Simple Traffic Monitoring / Statistic & Abnormal traffic Detection; Don't care flow scale. Netflow Normally ingress. Egress is much more complex. Only IP Need a large flow table because of 7 tuple key. Very good if flow table can hold all flows. It even has the flow's during, volume Normal, Flow aging. Complex in troubleshooting and deployment Accounting & Traffic Monitoring/Statistic & Abnormal traffic Detection 3

Agenda SFlow intro. SFlow architecture SFlow config example Summary 4

sflow walk-through 5 sflow export process Sup CPU Counter Sampling Buffer Flow Sampling Buffer 6 Sampled Header & Other info. 4 Control Channel sflow Datagram LC LC CPU 3 Sampled Header & Other info. Packet Processor 2 1 Packet Packet 5

sflow @ Packet Processor s pipeline Input Packet Ingress Parser L2/L3 Lookup Ingress ACL InBound sflow Output Packet OutBound sflow Egress ACL Egress Packet Modify Egress Parser 6

Agenda SFlow intro. SFlow architecture SFlow config example Summary 7

Config Example # config sflow Agent [Quidway] sflow agent ip 3.3.3.1 # config sflow Collector: ID=2; IP address=3.3.3.2, description= netserver [Quidway] sflow collector 2 ip 3.3.3.2 description netserver Specify the flowsampling rate 1/4000 [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] sflow flow-sampling rate 4000 [Quidway-GigabitEthernet0/0/2] sflow flow-sampling collector 2 Use collector 2 [Quidway-GigabitEthernet0/0/2] sflow flow-sampling inbound [Quidway-GigabitEthernet0/0/2] sflow flow-sampling outbound [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] sflow counter-sampling interval 120 Specify the countersampling interval 120 seconds 8

Verify <Quidway> display sflow sflow Version 5 Information: ------------------------------------------------------------------------- Agent Information: IP Address: 3.3.3.1 Address family: IPV4 Vpn-instance: N/A -------------------------------------------------------------------------- Collector Information: Collector ID: 2 IP Address: 3.3.3.2 Address family: IPV4 Vpn-instance: N/A Port: 6343 Datagram size: 1400 Time out: N/A Description: netserver Specify the flowsampling rate 1/4000 -------------------------------------------------------------------------- Port on slot 1 Information: Interface: GE0/0/2 Flow-sample collector: 2 Counter-sample collector : 2 Flow-sample rate(1/x): 4000 Counter-sample interval(s): 120 Flow-sample maxheader: 128 Flow-sample direction: IN,OUT 9 Use collector 2 Specify the countersampling interval 120 seconds

display sflow statistics <Quidway> display sflow statistics sflow Version 5 statistic Information: -------------------------------------------------------------------------- Collector 1 Current sample sequence:22388 Collector 2 Current sample sequence:22388 The current sampling -------------------------------------------------------------------------- sequence number. Port on slot 1 statistic Information: Interface: GE0/0/1 Flow-sample sequence : N/A Counter-sample sequence : 44778 Flow-sample inbound pool: N/A Flow-sample outbound pool: N/A ================================================================================ <Quidway> display sflow statistics slot 1 sflow Version 5 statistic Information: -------------------------------------------------------------------------- Port on slot 1 statistic Information: Interface: GE0/0/1 Flow-sample sequence : N/A Counter-sample sequence : 44778 Flow-sample inbound pool: N/A Flow-sample outbound pool: N/A -------------------------------------------------------------------------- 10

Agenda SFlow intro. SFlow architecture SFlow config example Summary 11

Summary : Top 5 thing to remember 1. sflow don t care flow scale. 2. sflow can statistic L2 & L3 3. sflow s reaction is faster 4. sflow is sampling packets 5. sflow is suitable in Traffic Monitoring / Statistic & Abnormal traffic Detection, etc; Not accounting. 12

HUAWEI ENTERPRISE ICT SOLUTIONS A BETTER WAY Copyright 2012 Huawei Technologies Co., Ltd. All Rights Reserved. The information in this document may contain predictive statements including, without limitation, statements regarding the future financial and operating results, future product portfolio, new technology, etc. There are a number of factors that could cause actual results and developments to differ materially from those expressed or implied in the predictive statements. Therefore, such information is provided for reference purpose only and constitutes neither an offer nor an acceptance. Huawei may change the information at any time without notice.