Flow Analysis. Make A Right Policy for Your Network. GenieNRM



Similar documents
Traffic Monitoring using sflow

Cisco IOS Flexible NetFlow Technology

NetFlow Analytics for Splunk

NetFlow/IPFIX Various Thoughts

Flow Analysis Versus Packet Analysis. What Should You Choose?

Traffic Management for the Enterprise

Network Monitoring and Traffic CSTNET, CNIC

Traffic monitoring with sflow and ProCurve Manager Plus

Network Monitoring On Large Networks. Yao Chuan Han (TWCERT/CC)

ICND2 NetFlow. Question 1. What are the benefit of using Netflow? (Choose three) A. Network, Application & User Monitoring. B.

Introduction to Cisco IOS Flexible NetFlow

Configuring Flexible NetFlow

NetFlow Aggregation. Feature Overview. Aggregation Cache Schemes

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

The Value of Flow Data for Peering Decisions

Case Study: Instrumenting a Network for NetFlow Security Visualization Tools

NetFlow Configuration Guide, Cisco IOS Release 15M&T

NetStream (Integrated) Technology White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date

Monitoring and analyzing audio, video, and multimedia traffic on the network

Scalable Extraction, Aggregation, and Response to Network Intelligence

Network congestion control using NetFlow

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

and InMon Traffic Sentinel

Flow Based Traffic Analysis

Appendix A Remote Network Monitoring

Securing and Monitoring BYOD Networks using NetFlow

Network layer: Overview. Network layer functions IP Routing and forwarding

HP IMC User Behavior Auditor

Edge Configuration Series Reporting Overview

Cisco NetFlow TM Briefing Paper. Release 2.2 Monday, 02 August 2004

Configuring NetFlow Secure Event Logging (NSEL)

Mobile IP Network Layer Lesson 02 TCP/IP Suite and IP Protocol

Configuring RADIUS Server Support for Switch Services

Netflow Overview. PacNOG 6 Nadi, Fiji

Chapter 4 Rate Limiting

SonicOS 5.8: NetFlow Reporting

Network traffic monitoring and management. Sonia Panchen 11 th November 2010

plixer Scrutinizer Competitor Worksheet Visualization of Network Health Unauthorized application deployments Detect DNS communication tunnels

Brocade sflow for Network Traffic Monitoring

Gaining Operational Efficiencies with the Enterasys S-Series

NetFlow-Lite offers network administrators and engineers the following capabilities:

and reporting Slavko Gajin

NetFlow Configuration Guide, Cisco IOS Release 12.4

IP addressing and forwarding Network layer

Transport and Network Layer

NetFlow Configuration Guide, Cisco IOS Release 12.2SR

HP Intelligent Management Center v7.1 Network Traffic Analyzer Administrator Guide

Smart Network Access System SmartNA 10 Gigabit Aggregating Filtering TAP

Network Management & Security (CS 330) RMON

PANDORA FMS NETWORK DEVICE MONITORING

Best Practices for NetFlow/IPFIX Analysis and Reporting

NfSen Plugin Supporting The Virtual Network Monitoring

Appendix A: Configuring Firewalls for a VPN Server Running Windows Server 2003

NetFlow use cases. ICmyNet / NetVizura. Miloš Zeković, milos.zekovic@soneco.rs. ICmyNet Chief Customer Officer Soneco d.o.o.

Cisco IOS Flexible NetFlow Overview

Network Performance Monitoring at Minimal Capex

Network Management & Monitoring

Take the NetFlow Challenge!

Configuring SNMP and using the NetFlow MIB to Monitor NetFlow Data

Network Monitoring and Management NetFlow Overview

Internet Firewall CSIS Packet Filtering. Internet Firewall. Examples. Spring 2011 CSIS net15 1. Routers can implement packet filtering

Integrated Traffic Monitoring

The Ecosystem of Computer Networks. Ripe 46 Amsterdam, The Netherlands

Getting Started with Configuring Cisco IOS NetFlow and NetFlow Data Export

Configuring a Load-Balancing Scheme

Details. Some details on the core concepts:

Monitoring Network Traffic Using sflow Technology on EX Series Ethernet Switches

Using IPM to Measure Network Performance

PANDORA FMS NETWORK DEVICES MONITORING

Enabling NetFlow and NetFlow Data Export (NDE) on Cisco Catalyst Switches

Observer Probe Family

Chapter 2 Quality of Service (QoS)

AlliedWare Plus OS How To Use sflow in a Network

MONITORING NETWORK TRAFFIC USING sflow TECHNOLOGY ON EX SERIES ETHERNET SWITCHES

Extending Network Visibility by Leveraging NetFlow and sflow Technologies

Network Agent Quick Start

IP Addressing Introductory material.

NetFlow: What is it, why and how to use it? Miloš Zeković, ICmyNet Chief Customer Officer Soneco d.o.o.

enetworks TM IP Quality of Service B.1 Overview of IP Prioritization

Redefine Network Visibility in the Data Center with the Cisco NetFlow Generation Appliance

Computer Networks 1 (Mạng Máy Tính 1) Lectured by: Dr. Phạm Trần Vũ

Flow Monitor for WhatsUp Gold v16.2 User Guide

A Summary of Network Traffic Monitoring and Analysis Techniques

Network forensics 101 Network monitoring with Netflow, nfsen + nfdump

Research on Errors of Utilized Bandwidth Measured by NetFlow

Introduction to Netflow

Traffic Monitoring in a Switched Environment

Configuring NetFlow. Information About NetFlow. Send document comments to CHAPTER

CS 457 Lecture 19 Global Internet - BGP. Fall 2011

nfdump and NfSen 18 th Annual FIRST Conference June 25-30, 2006 Baltimore Peter Haag 2006 SWITCH

Carrier/WAN SDN Brocade Flow Optimizer Making SDN Consumable

UltraFlow -Cisco Netflow tools-

Beyond Monitoring Root-Cause Analysis

ForeScout CounterACT. Device Host and Detection Methods. Technology Brief

Transcription:

Flow Analysis Make A Right Policy for Your Network GenieNRM

Why Flow Analysis? Resolve Network Managers Challenge as follow: How can I know the Detail and Real-Time situation of my network? How can I do Load Balance job among the Outgoing Links? How can I know the destination sites every IP Block belong to my network go to and the percentage of Application included on those flow? How can I know Who connect to my network from outside? Is it attacking? How I can estimate the Growth of my network?

Traffic Accounting Challenges Cost Adding RMON probes everywhere is very costly and this does not include cost of administering RMON probes Building solutions for viewing, monitoring, and managing traffic flows within a network is expensive Limited Visibility for Network Traffic Accounting L2 Traffic Matrix, such as MAC Addresses, VLAN (802.1q) and Class of Service (802.1p) are not available Visibility of traffic within some wiring closets is sometimes limited to port-based byte information only Huge Impact to Network Performance

sflow Technology RFC 3176 Statistical Sampling Technology HP patented and proven technology (over 10 years) that employs Statistical Packet Sampling and SNMP data to monitor network flows in a network. Most Packet Sampling implementations just use information within an IP packet (e.g., what about VLAN and SNMP information). What is RFC 3176 sflow Technology sflow is a Statistical Sampling Technology an Open Standard sflow delivers full L2-L4 network-wide traffic flow information

The Details of RFC 3176 sflow agent JetCore ASIC Statistical Packet Sampling Technology Or Velocity Mgmt. Module sflow Datagram Packet Header Analysis MAC IPv6 VLAN (802.1q and 802.1p) IPv4 Header, including TCP, UDP, and ICMP IPX (FastIron 4802 or JetCore modules only) AppleTalk (FastIron 4802 or JetCore modules only) Input/output ports Next hop address Source AS, Source Peer AS Destination AS Path Communities, local preference User IDs (TACACS/RADIUS) for source/destination URL associated with source/destination Interface Statistics (RFC 1573, RFC 2233, and RFC 2358)

Resources Occupation

Technology Comparison (1) MRTG NetFlow RMON-II XRMON sflow Control real-time congestion problems Real-time segment counters Y N Y Y Y Real-time top talkers N N Y Y Y In/out view on interface 1/2 1/2 N N Y MAC address N N Y Y Y IPv4, ICMP, TCP, UDP N Y Y Y Y IPv6, IPX, DecNet4, AppleTalk, FrameRelay N N Y Y Y Plan for growth In/out view on interface 1/2 1/2 N N Y MAC address N N Y Y Y IPv4, ICMP, TCP, UDP N Y Y Y Y IPv6, IPX, DecNet4, AppleTalk, FrameRelay N N Y Y Y Optimize BGP peering and routing policies Source/Destination/Peer AS N 1/2 N N Y Full AS Path N N N N Y IP-Next Hop N Y N N Y

Technology Comparison (2) Account and bill for usage VLAN N N N 1/2 Y IP-Subnet N Y N N Y IP/UDP/TCP source/destination N Y Y Y Y Priority N N N N Y Quantifiable flow accounting accuracy N/A N N Y Y Protect against security threats Real-time top talkers N N Y Y Y Real-time correlation of traffic & route N N N N Y Scalability Switch ports/collector Medium Bad Bad Good Good Wire speed N/A 1/2 1/2 Y Y Switch/router resources Medium Bad Bad Good Good Configuration SNMP Y N Y Y Y Work through firewall - command line N Y N N Y

Why RFC-3176 beats SNMP, RMON-I, RMON-II and NetFlow Support for Packet Header Capture (NO payload capture key requirement for Service Providers) Additional IP Information: Route Table and Next Hop Address Source and Destination AS Destination AS Path Packet and Byte Count, from Layer 2 up to Layer 4, based on Input and Output ports Interface SNMP Counters no SNMP polling required! EtherARPs VLAN (802.1q) and Class of Services (802.1p) IPX and AppleTalk IP Address, IP Subnets, and Type of Service (TOS Bits) TCP, UDP, or ICMP traffic Autonomous Systems BGP Communities

Functions and Features Flow Monitor According to users setting, display the graph of Traffic Rate, Volume, Packet and Session. Traffic Monitor and alarm by different color light. Flow Analysis Discovery the problem of network by TOP N report. Snapshot Real-Time flow TOP N analysis in a short time, like X-ray. Users can get the source of attack immediately using this function. Billing Count by Input and Output Volume. System Management User, Raw Data, Multiple Devices export Data

Traffic Monitoring According to users setting, system will show the statues of traffic by different color light

Report Traffic Rate Volume

Report(Cont.) Packet Session

Report Show by Weekly History Report Support lots of Report s s type Make PDF File Weekly Report

Comparison Report Comparison Report

Trend Report Trend Report

TOP N Report(Inbound Volume) Show by IP or AS Show the newest ranking every 5 min.

TOP N Report(Inbound Application)

Top N Class C Traffic Show the Real- Time Ranking by C Class

Top N IP Pair Traffic Show the Real- Time ranking by IP pair

DDOS Detect Packet No. is increasing but Volume is not

DDOS Detect Analysis the Real-Time status of this Interface Rank by IP

DDOS Detect This site is not normal

DDOS Detect Analysis the site to find the source of attack Rank by IP

DDOS Detect The result is:there are more than 40,000 clients attack the site in the same time

Raw Data Store Raw Data Store

sflow Devices Subscribe Sampling function

Flow-based Billing/Accounting Bandwidth on Demand Administrator/Customer Selection thru Web Rate-Limit Adjust Billing Policy Selection Billing Model Flat Rate Billing by Bandwidth Demanding Billing By Flow Hybrid (Base + Over-usage)

Advantage and Difference It s Real-Time Analyzer, not by Log It s an Appliance, easy to install and maintain Build-in Data Base Web Interface Can hand on large flow up to 2.5G by modules designed. Easy to set filters then display the traffic report Easy to find the source of attack

Genie Netelligent Structure

Q & A

GenieNRM Visualize your Virtual Service Thank You!