Phapano ke efe lipakeng tsa NetFlow le IPFIX bakeng sa Network Flow Monitoring?

NetFlow le IPFIX ka bobeli ke mahlale a sebelisoang bakeng sa ho lekola phallo ea marang-rang le tlhahlobo. Ba fana ka leseli mabapi le mekhoa ea sephethephethe sa marang-rang, ba thusa ho ntlafatsa ts'ebetso, ho rarolla mathata le tlhahlobo ea ts'ireletso.

NetFlow:

NetFlow ke eng?

NetFlowke tharollo ea mantlha ea ho beha leihlo phallo, e qapiloeng ke Cisco ho elella bofelong ba lilemo tsa bo-1990. Ho na le liphetolelo tse 'maloa tse fapaneng, empa boholo ba lisebelisoa li thehiloe ho NetFlow v5 kapa NetFlow v9. Le ha mofuta o mong le o mong o na le bokhoni bo fapaneng, ts'ebetso ea mantlha e ntse e tšoana:

Ntlha ea pele, router, switch, firewall, kapa mofuta o mong oa sesebelisoa o tla nka tlhahisoleseding mabapi le "phallo" ea marang-rang - ha e le hantle ke sete sa lipakete tse arolelanang likarolo tse tloaelehileng tse kang mohloli le aterese ea sebaka, mohloli le sebaka seo u eang ho sona, le protocol. mofuta. Ka mor'a hore phallo e felile kapa nako e boletsoeng esale pele e fetile, sesebelisoa se tla romela litlaleho tsa phallo ho mokhatlo o tsejoang e le "mokelli oa phallo".

Qetellong, "flow analyzer" e na le moelelo oa litlaleho tseo, e fana ka lintlha ka mokhoa oa litšoantšo, lipalo-palo, le tlaleho e qaqileng ea histori le ea nako ea sebele. Ha e le hantle, babokelli le bahlahlobisisi hangata ke ntho e le 'ngoe, hangata ba kopantsoe ho ba tharollo e kholoanyane ea ho hlahloba ts'ebetso ea marang-rang.

NetFlow e sebetsa ka mokhoa o hlakileng. Ha mochini oa moreki o fihla ho seva, NetFlow e tla qala ho nka le ho kopanya metadata ho tsoa phallo. Kamora hore seboka se felisoe, NetFlow e tla romella mokelli rekoto e le 'ngoe e felletseng.

Leha e ntse e sebelisoa hangata, NetFlow v5 e na le meeli e mengata. Libaka tse romelloang kantle ho naha li tsitsitse, ho beha leihlo ho ts'ehetsoa feela ka lehlakoreng la ingress, 'me mahlale a morao-rao a kang IPv6, MPLS, le VXLAN ha a tšehetsoe. NetFlow v9, eo hape e bitsoang Flexible NetFlow (FNF), e sebetsana le tse ling tsa mefokolo ena, e lumellang basebelisi ho haha ​​​​litempele tsa tloaelo le ho eketsa tšehetso bakeng sa mahlale a macha.

Barekisi ba bangata le bona ba na le ts'ebetsong ea bona ea NetFlow, joalo ka jFlow e tsoang Juniper le NetStream ho tsoa Huawei. Leha tlhophiso e ka fapana ka mokhoa o itseng, ts'ebetso ena hangata e hlahisa lirekoto tsa phallo tse tsamaellanang le babokelli ba NetFlow le bahlahlobisisi.

Lintlha tsa bohlokoa tsa NetFlow:

~ Phallo Data: NetFlow e hlahisa lirekoto tsa phallo tse kenyelletsang lintlha tse kang liaterese tsa IP tsa mohloli le moo u eang teng, likou, litempe tsa linako, lipalo tsa pakete le li-byte, le mefuta ea protocol.

~ Tlhokomelo ea Sephethephethe: NetFlow e fana ka ponahalo mefuteng ea sephethephethe sa marang-rang, e lumellang batsamaisi ho tseba lits'ebetso tse holimo, li-endpoints le mehloli ea sephethephethe.

~Ho lemoha ka mokhoa o sa tloaelehang: Ka ho hlahloba lintlha tsa phallo, NetFlow e ka lemoha liphapang tse kang tšebeliso e feteletseng ea bandwidth, tšubuhlellano ea marang-rang, kapa mekhoa e sa tloaelehang ea sephethephethe.

~ Ts'ireletso ea Ts'ireletso: NetFlow e ka sebelisoa ho bona le ho batlisisa liketsahalo tsa ts'ireletso, joalo ka litlhaselo tsa ho hana tšebeletso (DDoS) kapa liteko tse sa lumelloeng tsa ho fihlella.

Liphetolelo tsa NetFlow: NetFlow e bile teng ha nako e ntse e ea, 'me mefuta e fapaneng e lokollotsoe. Liphetolelo tse ling tse hlokomelehang li kenyelletsa NetFlow v5, NetFlow v9, le Flexible NetFlow. Mofuta o mong le o mong o hlahisa lintlafatso le bokhoni bo eketsehileng.

IPFIX:

IPFIX ke eng?

Tekanyetso ea IETF e hlahileng mathoasong a lilemo tsa bo-2000, Internet Protocol Flow Information Export (IPFIX) e ts'oana haholo le NetFlow. Ebile, NetFlow v9 e sebelitse e le motheo oa IPFIX. Phapang e ka sehloohong pakeng tsa tse peli ke hore IPFIX ke mokhoa o bulehileng, 'me o tšehetsoa ke barekisi ba bangata ba marang-rang ntle le Cisco. Ntle le likarolo tse 'maloa tse ling tse kenyellelitsoeng ho IPFIX, lifomate li batla li tšoana. Ebile, IPFIX ka linako tse ling e bitsoa "NetFlow v10".

Ka lebaka la ho tšoana ha eona le NetFlow, IPFIX e natefeloa ke ts'ehetso e pharalletseng har'a litharollo tsa ho lekola marang-rang hammoho le lisebelisoa tsa marang-rang.

IPFIX (Internet Protocol Flow Information Export) ke mokhoa o bulehileng oa protocol o entsoeng ke Internet Engineering Task Force (IETF). E ipapisitse le litlhaloso tsa NetFlow Version 9 mme e fana ka sebopeho se emeng bakeng sa ho romella lirekoto tsa phallo ho tsoa lisebelisoa tsa marang-rang.

IPFIX e haha ​​​​holim'a mehopolo ea NetFlow le ho e holisa ho fana ka maemo le ho sebelisana ho feta barekisi le lisebelisoa tse fapaneng. E hlahisa mohopolo oa litempele, e lumellang tlhaloso e matla ea sebopeho sa rekoto ea phallo le litaba. Sena se nolofalletsa ho kenyelletsa masimo a tloaelo, tšehetso ea liprothokholo tse ncha, le katoloso.

Lintlha tsa bohlokoa tsa IPFIX:

~ Mokhoa o Thehiloeng ho Sebopeho: IPFIX e sebelisa li-templates ho hlalosa sebopeho le likahare tsa lirekoto tsa phallo, tse fanang ka phetoho ea ho amohela libaka tse fapaneng tsa data le tlhahisoleseding e khethehileng ea protocol.

~ Tšebelisano-'moho: IPFIX ke tekanyetso e bulehileng, e netefatsang bokhoni bo tsitsitseng ba ho shebella phallo ho barekisi le lisebelisoa tse fapaneng tsa marang-rang.

~ Tšehetso ea IPv6: IPFIX ka tlhaho e tšehetsa IPv6, e etsa hore e tšoanelehe bakeng sa ho beha leihlo le ho sekaseka sephethephethe ho marang-rang a IPv6.

~Tshireletso e ntlafetseng: IPFIX e kenyelletsa likarolo tsa ts'ireletso tse kang ts'ireletso ea Transport Layer Security (TLS) le ho hlahloba botšepehi ba molaetsa ho sireletsa lekunutu le botšepehi ba data ea phallo nakong ea phetisetso.

IPFIX e tšehetsoa haholo ke barekisi ba lisebelisoa tse fapaneng tsa marang-rang, e leng se etsang hore e be khetho e sa nkeng lehlakore le e amoheloang ke batho ba bangata bakeng sa ho hlahloba phallo ea marang-rang.

 

Joale, phapang ke efe lipakeng tsa NetFlow le IPFIX?

Karabo e bonolo ke hore NetFlow ke Cisco proprietary protocol e hlahisitsoeng ho pota 1996 mme IPFIX ke mokhatlo oa eona oa litekanyetso o amohetsoeng.

Li-protocol ka bobeli li sebeletsa sepheo se le seng: ho nolofalletsa baenjiniere ba marang-rang le batsamaisi ho bokella le ho sekaseka phallo ea sephethephethe sa IP ea boemo ba marang-rang. Cisco e ntlafalitse NetFlow e le hore li-switches le li-routers li ka hlahisa tlhahisoleseling ena ea bohlokoa. Ka lebaka la taolo ea lisebelisoa tsa Cisco, NetFlow e ile ea fetoha maemo a de-facto bakeng sa tlhahlobo ea sephethephethe sa marang-rang. Leha ho le joalo, bahlolisani ba indasteri ba ile ba hlokomela hore ho sebelisa melaoana e laoloang ke qothisana lehlokoa le eona e ne e se mohopolo o motle, ka hona IETF e ile ea etella pele boiteko ba ho tiisa melaoana e bulehileng ea tlhahlobo ea sephethephethe, e leng IPFIX.

IPFIX e ipapisitse le mofuta oa 9 oa NetFlow mme e ile ea hlahisoa ho pota 2005 empa ho nkile lilemo tse ngata ho fumana kamohelo ea indasteri. Mothating ona, liprothokholo tse peli li hlile li ts'oana mme leha lentsoe NetFlow le ntse le atile haholo ts'ebetsong (leha e se kaofela) e tsamaellana le maemo a IPFIX.

Mona ke tafole e akaretsang liphapang lipakeng tsa NetFlow le IPFIX:

Karolo NetFlow IPFIX
Tšimoloho Theknoloji ea thepa e ntlafalitsoeng ke Cisco Protocol e tloaelehileng ea indasteri e thehiloeng ho NetFlow Version 9
Boemo ba maemo Theknoloji e khethehileng ea Cisco Open standard e hlalosoang ke IETF ho RFC 7011
Ho tenyetseha Mefuta e ntlafalitsoeng e nang le likarolo tse ikhethang Ho tenyetseha le ho sebelisana ho hoholo ho feta barekisi
Sebopeho sa data Lipakete tsa boholo bo tsitsitseng Mokhoa o ipapisitseng le litempele bakeng sa liforomo tsa rekoto tsa phallo tseo u ka li khethang
Template Support Ha e tšehetsoe Lithempleite tse matla bakeng sa kenyelletso ea sebaka se feto-fetohang
Tšehetso ea barekisi Haholo-holo lisebelisoa tsa Cisco Tšehetso e pharaletseng ho pholletsa le barekisi ba marang-rang
Katoloso Boikemisetso bo fokolang Kenyelletso ea masimo a tloaelo le data e ikhethileng ea ts'ebeliso
Phapang ea Protocol Liphetoho tse khethehileng tsa Cisco Tšehetso ea Native IPv6, likhetho tse ntlafalitsoeng tsa rekoto ea phallo
Likarolo tsa Tšireletso Likarolo tse fokolang tsa ts'ireletso Transport Layer Security (TLS) encryption, botšepehi ba molaetsa

Tlhokomelo ea Phallo ea Marang-rangke pokello, tlhahlobo, le ho beha leihlo sephethephethe se haola le marang-rang kapa karolo ea marang-rang. Lipheo li ka fapana ho tloha ho mathata a khokahanyo ea mathata ho ea ho ho rera kabo ea bandwidth ea nako e tlang. Tlhokomelo ea phallo le sampole ea liphutheloana e ka ba ea thusa ho khetholla le ho lokisa litaba tsa ts'ireletso.

Tlhokomelo ea phallo e fa lihlopha tsa marang-rang maikutlo a matle mabapi le hore na marang-rang a sebetsa joang, a fana ka leseli mabapi le ts'ebeliso ea kakaretso, ts'ebeliso ea ts'ebeliso, mathata a ka bang teng, liphoso tse ka bonts'ang lits'oso tsa ts'ireletso, le tse ling. Ho na le litekanyetso le lifomate tse fapaneng tse sebelisoang ho lekola phallo ea marang-rang, ho kenyeletsoa NetFlow, sFlow, le Internet Protocol Flow Information Export (IPFIX). E 'ngoe le e' ngoe e sebetsa ka tsela e fapaneng hanyane, empa kaofela li fapane le seipone sa boema-kepe le tlhahlobo e tebileng ea lipakete ka hore ha li nke litaba tsa pakete e 'ngoe le e' ngoe e fetang boema-kepe kapa ka switch. Leha ho le joalo, tlhahlobo ea phallo e fana ka tlhaiso-leseling e ngata ho feta SNMP, eo hangata e lekanyelitsoeng ho lipalo-palo tse pharalletseng joalo ka ts'ebeliso ea lipakete ka kakaretso le bandwidth.

Lisebelisoa tsa Phallo ea Marang-rang li Bapisoa

Sebopeho NetFlow v5 NetFlow v9 Phalla IPFIX
E butsoe kapa e na le thepa Thepa Thepa Bula Bula
Mohlala kapa Phallo e Thehiloe Haholo-holo Phallo Thehiloe; Mokhoa oa sampole oa fumaneha Haholo-holo Phallo Thehiloe; Mokhoa oa sampole oa fumaneha Mohlala Haholo-holo Phallo Thehiloe; Mokhoa oa sampole oa fumaneha
Tlhahisoleseding e Hapilwe Metadata le lintlha tsa lipalo, ho kenyelletsa le li-byte tse fetisitsoeng, li-interface counters joalo-joalo Metadata le lintlha tsa lipalo, ho kenyelletsa le li-byte tse fetisitsoeng, li-interface counters joalo-joalo Lihlooho tse Felletseng tsa Pakete, Litefiso tsa Pakete e sa Feleng Metadata le lintlha tsa lipalo, ho kenyelletsa le li-byte tse fetisitsoeng, li-interface counters joalo-joalo
Tlhokomelo ea ho kena / Egress Ingress Feela Ho kena le ho tsoa Ho kena le ho tsoa Ho kena le ho tsoa
IPv6/VLAN/MPLS Support No Ee Ee Ee

Nako ea poso: Mar-18-2024