NfSen Plugin Supporting The Virtual Network Monitoring



Similar documents
Network Security Monitoring and Behavior Analysis Pavel Čeleda, Petr Velan, Tomáš Jirsík

nfdump and NfSen 18 th Annual FIRST Conference June 25-30, 2006 Baltimore Peter Haag 2006 SWITCH

Watch your Flows with NfSen and NFDUMP 50th RIPE Meeting May 3, 2005 Stockholm Peter Haag

Detecting Botnets with NetFlow

An overview of traffic analysis using NetFlow

Network forensics 101 Network monitoring with Netflow, nfsen + nfdump

Monitoring of Tunneled IPv6 Traffic Using Packet Decapsulation and IPFIX

Network Security Monitoring and Behavior Analysis Best Practice Document

Introduction to Netflow

Network Monitoring and Management NetFlow Overview

Practical Experience with IPFIX Flow Collectors

How To Create A Network Monitoring System (Flowmon) In Avea-Tech (For Free)

Flow Based Traffic Analysis

Network Virtualization Based on Flows

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

Network Monitoring On Large Networks. Yao Chuan Han (TWCERT/CC)

OpenFlow and Software Defined Networking presented by Greg Ferro. OpenFlow Functions and Flow Tables

Flow Analysis Versus Packet Analysis. What Should You Choose?

Revealing Botnets Using Network Traffic Statistics

PANDORA FMS NETWORK DEVICES MONITORING

How NOC manages and controls inter-domain traffic? 5 th tf-noc meeting, Dubrovnik nino.ciurleo@garr.it

Scalable Extraction, Aggregation, and Response to Network Intelligence

Monitoring sítí pomocí NetFlow dat od paketů ke strategiím

PANDORA FMS NETWORK DEVICE MONITORING

Flow Analysis. Make A Right Policy for Your Network. GenieNRM

TELCO challenge: Learning and managing the network behavior

Automatic Network Protection Scenarios Using NetFlow

The Value of Flow Data for Peering Decisions

From traditional to alternative approach to storage and analysis of flow data. Petr Velan, Martin Zadnik

Network Traffic Analysis using HADOOP Architecture. Zeng Shan ISGC2013, Taibei

Limitations of Packet Measurement

IP Filter/Firewall Setup

[Optional] Network Visibility with NetFlow

Network Management & Monitoring

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

Figure 1. perfsonar architecture. 1 This work was supported by the EC IST-EMANICS Network of Excellence (#26854).

DDoS Mitigation Techniques

Wireshark Developer and User Conference

Network Traffic Analysis using HADOOP Architecture. Shan Zeng HEPiX, Beijing 17 Oct 2012

CMA5000 SPECIFICATIONS Gigabit Ethernet Module

Network Monitoring and Traffic CSTNET, CNIC

Connecting North Carolina s Future Today. Application Monitoring: ClassScape Case Study. NCSU Centennial Networking Lab

Extending Network Visibility by Leveraging NetFlow and sflow Technologies

What is VLAN Routing?

Autonomous NetFlow Probe

NetFlow/IPFIX Various Thoughts

User Documentation nfdump & NfSen

Cisco IOS Flexible NetFlow Technology

Cisco NetFlow TM Briefing Paper. Release 2.2 Monday, 02 August 2004

CISCO IOS NETFLOW AND SECURITY

Nfsight: NetFlow-based Network Awareness Tool

Configuring Flexible NetFlow

Best of Breed of an ITIL based IT Monitoring. The System Management strategy of NetEye

Case Study: Instrumenting a Network for NetFlow Security Visualization Tools

}w!"#$%&'()+,-./012345<ya

Netflow Overview. PacNOG 6 Nadi, Fiji

Overview of Network Traffic Analysis

Carrier/WAN SDN Brocade Flow Optimizer Making SDN Consumable

Who is Generating all This Traffic?

VXLAN: Scaling Data Center Capacity. White Paper

Catalyst 6500/6000 Switches NetFlow Configuration and Troubleshooting

Voice over IP. Demonstration 1: VoIP Protocols. Network Environment

Recommendations for Network Traffic Analysis Using the NetFlow Protocol Best Practice Document

Troubleshooting LANs with Wirespeed Packet Capture and Expert Analysis

Nemea: Searching for Botnet Footprints

Large-Scale Geolocation for NetFlow

Research on Errors of Utilized Bandwidth Measured by NetFlow

FlowMon. Complete solution for network monitoring and security. INVEA-TECH

enetworks TM IP Quality of Service B.1 Overview of IP Prioritization

UltraFlow -Cisco Netflow tools-

NetFlow use cases. ICmyNet / NetVizura. Miloš Zeković, milos.zekovic@soneco.rs. ICmyNet Chief Customer Officer Soneco d.o.o.

NB6 Series Quality of Service (QoS) Setup (NB6Plus4, NB6Plus4W Rev1)

Emerald. Network Collector Version 4.0. Emerald Management Suite IEA Software, Inc.

How to configure an Advanced Expert Probe as NetFlow Collector

Securing Local Area Network with OpenFlow

HP Intelligent Management Center v7.1 Network Traffic Analyzer Administrator Guide

SolarWinds Certified Professional. Exam Preparation Guide

plixer Scrutinizer Competitor Worksheet Visualization of Network Health Unauthorized application deployments Detect DNS communication tunnels

Multi Stage Filtering

SDN, OpenFlow and the ONF

Network Monitoring. By: Delbert Thompson Network & Network Security Supervisor Basin Electric Power Cooperative

NetFlow-Lite offers network administrators and engineers the following capabilities:

Introduction to Cisco IOS Flexible NetFlow

Application Performance Management - Deployment Best Practices Using Ixia- Anue Net Tool Optimizer

Using IPM to Measure Network Performance

Log Management with Open-Source Tools. Risto Vaarandi SEB Estonia

Advanced VSAT Solutions Bridge Point-to-Multipoint (BPM) Overview

From Fieldbus to toreal Time Ethernet

Stateful Firewalls. Hank and Foo

Security Toolsets for ISP Defense

Software-Defined Networking for the Data Center. Dr. Peer Hasselmeyer NEC Laboratories Europe

NetFlow Aggregation. Feature Overview. Aggregation Cache Schemes

Transcription:

NfSen Plugin Supporting The Virtual Network Monitoring Vojtěch Krmíček krmicek@liberouter.org Pavel Čeleda celeda@ics.muni.cz Jiří Novotný novotny@cesnet.cz

Part I Monitoring of Virtual Network Environments in FEDERICA Network Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 2 / 24

Virtual World of FEDERICA Network Virtualization several virtual links inside one physical link. Virtual nodes + virtual links virtual network infrastructure. VN2 VP VN3 Virtual Slice N.... Virtual Slice II VN1 VP VP VN2 VP VP VP VN4 VP VN3 Virtual Networks (slices) VN1 VN4 VN3 Virtual Slice I VN1 VP VP VN4 VP Virtual Nodes GARR IT DFN DE CESNET CZ PSNC PL Physical Infrastructure Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 3 / 24

VLAN Networks and NetFlow IEEE 802.1Q also known as VLAN tagging. Multiple bridged networks share the same physical link. Default NetFlow record doesn t contain VLAN tag field. We need to add VLAN tag information to the flow record. Physical Line VLAN 1203 VLAN 1202 VLAN 1201 (4B1h) Ethernet Frame 00:0C:29:11:79:C3 Destination MAC 00:0C:29:62:C7:EC Source MAC 81 00 04 B1 802.1Q Header C0 A8 01 03 Src IP C0 A8 01 01 Dst IP Payload NetFlow Record extended with VLAN field 30.276 Duration TCP 192.168.1.3:2545 Proto Src IP : Port 192.168.1.1:80 Dst IP : Port.A.R.. Flags 9240 Packets 220 Bytes 1201 VLAN Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 4 / 24

NetFlow VLAN Support in FEDERICA Project NetFlow VLAN Issues NetFlow version 5 doesn t support VLAN tags. NetFlow version 9 defines VLAN tags (see RFC 3954). Routers and probes doesn t support VLAN export. NetFlow collectors doesn t support VLAN handling. Proposed Solution Dedicated FlowMon probes with VLAN support. We have added VLAN tag information as DST_AS field. Flow start Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Intf VLAN 06:49:55.049 299.996 ICMP 192.168.3.2:0 -> 192.168.3.1:0.0 969 1.3 M 8 1203 06:49:55.657 299.997 ICMP 192.168.3.1:0 -> 192.168.3.2:8.0 969 1.3 M 9 1203 06:51:10.255 299.752 ICMP 192.168.3.2:0 -> 192.168.1.1:8.0 968 1.3 M 8 1203 06:51:10.255 299.752 ICMP 192.168.1.1:0 -> 192.168.3.2:0.0 968 1.3 M 9 1203 06:51:36.593 299.824 ICMP 192.168.1.3:0 -> 192.168.1.1:0.0 1936 2.6 M 6 1201 06:51:37.189 299.848 ICMP 192.168.1.1:0 -> 192.168.1.3:8.0 1936 2.6 M 7 1201 VLAN tag information is crucial for virtual circuits monitoring! Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 5 / 24

Architecture of NetFlow Monitoring System DFN DE PSNC PL Virtual Node Cloud GARR IT CESNET CZ Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 6 / 24

Architecture of NetFlow Monitoring System Probe Probe DFN DE PSNC PL Virtual Node Cloud GARR IT CESNET CZ Probe Probe Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 6 / 24

Architecture of NetFlow Monitoring System Probe Probe DFN DE PSNC PL Data Analysis Center Virtual Node Cloud GARR IT CESNET CZ Probe Probe Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 6 / 24

Architecture of NetFlow Monitoring System DFN DE PSNC PL Virtual Node Cloud GARR IT CESNET CZ Current System Deployment Probe Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 6 / 24

Single Node Monitoring Using Tapped Traffic Copper/Multimode/ Monomode TAP Copper/Multimode/ Monomode TAP Copper/Multimode/ Monomode TAP Copper/Multimode/ Monomode TAP FlowMon Probe 8000 Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 7 / 24

Block Structure of NetFlow Monitoring System FlowMon Probe 8000 Web Interface NfSen Collector Plugins Backend Frontend Processing and Presentation Layer NetFlow Data Storage NFDUMP Toolset Collector Layer packets flows FlowMon Exporter Fiber TAP Packet Data Inside VLANs FEDERICA Traffic FlowMon Exporter flows packets Fiber TAP flows FlowMon Exporter packets Fiber TAP NetFlow Generation Layer Network Layer Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 8 / 24

Part II NfSen Default Collector Features Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 9 / 24

NetFlow Processing with NFDUMP Available Flow Statistics Raw NetFlow data. Top N statistics. Flow filtering (via IP addresses, protocols, VLAN,... ). Flow aggregation (IP addresses, protocols, VLAN,... ). VLAN tags and interface numbers. Flow start Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Intf VLAN 06:49:55.049 299.996 ICMP 192.168.3.2:0 -> 192.168.3.1:0.0 969 1.3 M 8 1203 06:49:55.657 299.997 ICMP 192.168.3.1:0 -> 192.168.3.2:8.0 969 1.3 M 9 1203 06:51:10.255 299.752 ICMP 192.168.3.2:0 -> 192.168.1.1:8.0 968 1.3 M 8 1203 06:51:10.255 299.752 ICMP 192.168.1.1:0 -> 192.168.3.2:0.0 968 1.3 M 9 1203 06:51:36.593 299.824 ICMP 192.168.1.3:0 -> 192.168.1.1:0.0 1936 2.6 M 6 1201 06:51:37.189 299.848 ICMP 192.168.1.1:0 -> 192.168.1.3:8.0 1936 2.6 M 7 1201 06:54:55.355 299.997 ICMP 192.168.3.2:0 -> 192.168.3.1:0.0 969 1.3 M 8 1203 06:54:55.964 299.996 ICMP 192.168.3.1:0 -> 192.168.3.2:8.0 969 1.3 M 9 1203 06:56:10.317 299.781 ICMP 192.168.1.1:0 -> 192.168.3.2:0.0 968 1.3 M 9 1203 06:56:10.317 299.781 ICMP 192.168.3.2:0 -> 192.168.1.1:8.0 968 1.3 M 8 1203 06:56:36.649 299.916 ICMP 192.168.1.3:0 -> 192.168.1.1:0.0 1936 2.6 M 6 1201 06:56:37.245 299.941 ICMP 192.168.1.1:0 -> 192.168.1.3:8.0 1936 2.6 M 7 1201 06:57:01.952 0.000 UDP 194.132.52.193:138 -> 194.132.52.195:138 2 513 5 1200 Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 10 / 24

NfSen Profiles The profile is defined by its name, type and profile filter(s). The profile applies to the graphical and to the numerical view. The profiles are set manually by network administrator. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 11 / 24

NfSen Alerts The alerts allow to execute actions based on conditions. Triggered alert typically sends an email to administrator. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 12 / 24

NfSen Plugins The plugins allow to extend NfSen with new functionality. The plugins run automated tasks every 5 minutes. The plugins allow display any results of NetFlow measurement. Plugin Report Automatic run every 5 min Notification.pm Register Output Email nfsen.conf Web Interface Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 13 / 24

Part III NfSen Plugin Supporting The Virtual Network Monitoring Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 14 / 24

Plugin Motivation and Goals Plugin Motivation No VLAN monitoring tool in FEDERICA. No analysis of VLAN traffic. No visualization of VLAN traffic. But we need to observe traffic in slices. Plugin Goals Detailed and long-term VLAN stats. Regular reporting to email. Visualization of VLAN data. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 15 / 24

Plugin Architecture Plugin consists of three components: Plugin frontend, plugin backend and database. FlowMon Probe 8000 NfSen Collector Graphs Stats Reports Plugin Frontend NfSen WWW Frontend Reports DB Update Plugin Backend DB Query NetFlow Data Storage PostgreSQL Database flows FlowMon Exporter FlowMon Exporter flows FlowMon Exporter packets packets Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 16 / 24

Plugin Frontend - VLAN Overview Main navigation bar with stats, reporting and about. Traffic visualization divided by flows, packets and traffic. Detailed traffic statistics. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 17 / 24

Plugin Frontend - VLAN Overview Main navigation bar with stats, reporting and about. Traffic visualization divided by flows, packets and traffic. Detailed traffic statistics. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 17 / 24

Plugin Frontend - VLAN Overview Main navigation bar with stats, reporting and about. Traffic visualization divided by flows, packets and traffic. Detailed traffic statistics. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 17 / 24

Plugin Frontend - VLAN Details I Graph visualization divided by protocols. Detailed traffic statistics by protocols. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 18 / 24

Plugin Frontend - VLAN Details I Graph visualization divided by protocols. Detailed traffic statistics by protocols. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 18 / 24

Plugin Frontend III - VLAN Details II Protocol statistics for top 5 ports in chosen VLAN. Protocol statistics for top 5 talkers in chosen VLAN. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 19 / 24

Plugin Frontend III - VLAN Details II Protocol statistics for top 5 ports in chosen VLAN. Protocol statistics for top 5 talkers in chosen VLAN. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 19 / 24

Plugin Frontend - VLAN Reporting I Possibility to add a new email address for reporting. Listing of existing email addresses for reporting. Activation/inactivation of particular email address. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 20 / 24

Plugin Frontend - VLAN Reporting I Possibility to add a new email address for reporting. Listing of existing email addresses for reporting. Activation/inactivation of particular email address. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 20 / 24

Plugin Frontend - VLAN Reporting I Possibility to add a new email address for reporting. Listing of existing email addresses for reporting. Activation/inactivation of particular email address. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 20 / 24

Plugin Frontend - VLAN Reporting II Example of the email report. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 21 / 24

Part IV Conclusion Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 22 / 24

Conclusion NetFlow Based Monitoring Monitoring system delivers detailed traffic information. Used tools support NetFlow with full VLAN processing. NetFlow data are provided via NfSen collector. NfSen Plugin Supporting VLAN Monitoring Provides detailed statistics about VLAN traffic. Gives the graphical representations of the traffic structure. Allows regular reporting to the email. Generally supports monitoring of VLAN networks. Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 23 / 24

Thank You For Your Attention www.fp7-federica.eu NfSen Plugin Supporting The Virtual Network Monitoring Vojtěch Krmíček krmicek@liberouter.org Pavel Čeleda celeda@ics.muni.cz Jiří Novotný novotny@cesnet.cz FlowMon Probe Krmíček, Čeleda, Novotný NfSen Plugin Supporting The Virtual Network Monitoring 24 / 24