SURFnet6 Network Monitoring and Reporting Hans Trompert, SURFnet.

Slides:



Advertisements
Similar presentations
Network Monitoring System In CSTNET Long Chun China Science & Technology Network.
Advertisements

Top-Down Network Design Chapter Nine Developing Network Management Strategies Copyright 2010 Cisco Press & Priscilla Oppenheimer.
Release 5.1, Revision 0 Copyright © 2001, Juniper Networks, Inc. Advanced Juniper Networks Routing Module 9: Static Routes & Routing Table Groups.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 8: Monitoring the Network Connecting Networks.
CCNA1 v3 Module 9 v3 CCNA 1 Module 9 JEOPARDY K. Martin Galo Valencia.
Transitioning to IPv6 April 15,2005 Presented By: Richard Moore PBS Enterprise Technology.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
Internet Multicast Routing  group addressing  class D IP addresses  link layer multicast  two protocol functions  group management –IGMP  route establishment.
Spring 2000CS 4611 Introduction Outline Statistical Multiplexing Inter-Process Communication Network Architecture Performance Metrics.
IST 201 Chapter 9. TCP/IP Model Application Transport Internet Network Access.
Network Management Workshop intERlab at AIT Thailand March 11-15, 2008 Network Operations and Network Management.
Implementing a Highly Available Network
QoS Solutions Confidential 2010 NetQuality Analyzer and QPerf.
5/12/011 eircom net IP Network Karl Jeacle
COS 338 Day DAY 16 Agenda Capstone Proposals Overdue 3 accepted, 3 in mediation Capstone progress reports still overdue I forgot to mark in calendar.
Introduction. 2 What Is SmartFlow? SmartFlow is the first application to test QoS and analyze the performance and behavior of the new breed of policy-based.
NetFlow Analyzer Drilldown to the root-QoS Product Overview.
1 Version 3.0 Module 9 TCP/IP Protocol and IP Addressing.
Monitoring System Monitors Basics Monitor Types Alarms Actions RRD Charts Reports.
Chapter 4 Queuing, Datagrams, and Addressing
Netflow Overview PacNOG 6 Nadi, Fiji. Agenda Netflow –What it is and how it works –Uses and Applications Vendor Configurations/ Implementation –Cisco.
IST 228\Ch3\IP Addressing1 TCP/IP and DoD Model (TCP/IP Model)
Chapter Eleven An Introduction to TCP/IP. Objectives To compare TCP/IP’s layered structure to OSI To review the structure of an IP address To look at.
Module 1: Reviewing the Suite of TCP/IP Protocols.
CCNA Introduction to Networking 5.0 Rick Graziani Cabrillo College
1 Version 3.1 Module 4 Learning About Other Devices.
Petrozavodsk State University, Alex Moschevikin, 2003NET TECHNOLOGIES Internet Control Message Protocol ICMP author -- J. Postel, September The purpose.
Hands-on Networking Fundamentals
Chapter 4: Managing LAN Traffic
1 ESnet Network Measurements ESCC Feb Joe Metzger
NetfFow Overview SANOG 17 Colombo, Sri Lanka. Agenda Netflow –What it is and how it works –Uses and Applications Vendor Configurations/ Implementation.
1 © 2004, Cisco Systems, Inc. All rights reserved. Chapter 4 Routing Fundamentals and Subnets/ TCP/IP Transport and Application Layers.
Session 2 Security Monitoring Identify Device Status Traffic Analysis Routing Protocol Status Configuration & Log Classification.
1 Pieter Meulenhoff KPN Research ROOT2002 I-Mode Performance Monitoring Use of ROOT in telecommunications at KPN Pieter Meulenhoff.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Network Services Networking for Home and Small Businesses – Chapter 6.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 2 Module 9 Basic Router Troubleshooting.
NetFlow: Digging Flows Out of the Traffic Evandro de Souza ESnet ESnet Site Coordinating Committee Meeting Columbus/OH – July/2004.
workshop eugene, oregon What is network management? System & Service monitoring  Reachability, availability Resource measurement/monitoring.
Chapter 4 Network Layer Computer Networking: A Top Down Approach 6 th edition Jim Kurose, Keith Ross Addison-Wesley March 2012 A note on the use of these.
Network – internet – part2  Address at diff. layers  Headers at diff. layers  Equipment at diff. layers.
Secured Network Design
CCNA 1 v3.0 Module 11 TCP/IP Transport and Application Layers.
Computer Security Workshops Networking 101. Reasons To Know Networking In Regard to Computer Security To understand the flow of information on the Internet.
Jennifer Rexford Princeton University MW 11:00am-12:20pm Measurement COS 597E: Software Defined Networking.
1 Network Measurement Summary ESCC, Feb Joe Metzger ESnet Engineering Group Lawrence Berkeley National Laboratory.
Open-Eye Georgios Androulidakis National Technical University of Athens.
Net Flow Network Protocol Presented By : Arslan Qamar.
Network design Topic 2 Existing network infrastructure.
Slide #1 CIT 380: Securing Computer Systems TCP/IP.
Cisco Confidential © 2013 Cisco and/or its affiliates. All rights reserved. 1 Cisco Networking Training (CCENT/CCT/CCNA R&S) Rick Rowe Ron Giannetti.
Page 12/9/2016 Chapter 10 Intermediate TCP : TCP and UDP segments, Transport Layer Ports CCNA2 Chapter 10.
1 Version 3.1 Module 10 Intermediate TCP/IP (Layer 4)
Connect communicate collaborate Performance Metrics & Basic Tools Robert Stoy, DFN EGI TF, Madrid September 2013.
Communication Networks NETW 501 Tutorial 2
Cisco I Introduction to Networks Semester 1 Chapter 6 JEOPADY.
1 Netflow Collection and Aggregation in the AT&T Common Backbone Carsten Lund.
1 © 2004, Cisco Systems, Inc. All rights reserved. CCNA 2 v3.1 Module 8 TCP/IP Suite Error and Control Messages.
Application Protocol - Network Link Utilization Capability: Identify network usage by aggregating application protocol traffic as collected by a traffic.
Voice Performance Measurement and related technologies
The Transport Layer Implementation Services Functions Protocols
Network Operations and Network Management
Semester 1 Cisco Discovery JEOPADY Chapter 3.
8 Network Layer Part V Computer Networks Tutun Juhana
Chapter 8: Monitoring the Network
Chapter 4 Network Layer Computer Networking: A Top Down Approach 5th edition. Jim Kurose, Keith Ross Addison-Wesley, April Network Layer.
Network Models CCNA Instructor Training Course October 12-17, 2009
Use of Simplex Satellite Configurations to support Internet Traffic
OSI Reference Model Kashif Ishaq.
Multicasting Unicast.
Presentation transcript:

SURFnet6 Network Monitoring and Reporting Hans Trompert, SURFnet

Information needs Connected organizations NOC / SURFnet / research Annual report Information detail

Monitoring versus Reporting -Monitoring -real-time -status -alarms -Reporting -afterwards -over a specific time period (day, week, month, year)

Information source and destination Avici SSR Nortel ERS8600 Nortel OM5200 Nortel OME6500 Nortel OME1060 SURFnet6 operations Real-time customer reporting Security

Equipment and interface Optical devicesCPLTL1 OM5200TL1 (+ SNMP) OME6500TL1 (+ SNMP) OME1060SNMP Data devicesERS8600SNMP Avici SSRSNMP + Netflow

Reporting: SNMP metrics SNMP metrics: -Interface in/out octet counters -Interface in/out packet counters (unicast/broadcast/multicast) -Interface input/output errors -Interface availability -Temperature -Memory -CPU -Device uptime -and more …

Reporting: TL1 metrics TL1 metrics: -Input/Output Frames -Errored frames -Discarded frames -Transmit and receive power levels -Errored Seconds - number of seconds that have had CRC errors -Severely Errored Seconds - after 10 seconds of ES we start counting SES -UnAvailable Seconds - Seconds where we had no sync -and more …

Monitoring: SNMP traps SNMP traps -Fan -Temperature -Voltage -Link Up/Down -Bay Controller -Module -PIM + MSDP -BGP -VRRP -ISIS -and more …

Monitoring: TL1 events TL1 Events -Equipment -Circuit pack missing/mismatch/failed -Fan failed/missing -Power failure A or B -High temperature -Shelf -Software upgrade failed/mismatch/…. -Database integrity fail/restore in progress/… -Amplifier -input/output loss of signal -automatic shutoff -and many, many more

SNMP based volume reporting Internet Connected organizations Border router Amsterdam1 (SARA) Border router Amsterdam2 (TeleCity II) Core router Amsterdam2 (TeleCity II) Core router Amsterdam1 (SARA) -Total external traffic -Per traffic class (AMS-IX, Global, privat peers) -Per provider/peer -Total SURFnet internal traffic -Per connected organization

SURFnet external traffic volume -SURFnet external traffic volume -Ams-IX -Private peers (via Ams-IX), including: -Chello, Planet, XS4all -Garnier Projects, Abovenet, UUnet, Cogent -NREN -Geant2 -SINET -Abilene -Global -Global Crossing -Cable & Wireless

SURFnet external traffic volume

SURFstat: Real-time connected organization traffic volume reporting -Software -Net-SNMP -Python -RRDtool -Features -Easy administration by labeling connections with keywords in interface description on router -Different graph resolutions: day, week, month, year, decade -1 minute measurement interval -Reports on -volume (bits in/out) -packets (unicast/multicast/broadcast)

SURFstat: UvA (many users)

SURFstat: CWI (few users)

Netflow – flow information -Netflow uses the common 5-tuple definition, where a flow is defined as a unidirectional sequence of packets all sharing all of the following 5 values: 1.Source IP address 2.Destination IP address 3.Source TCP port 4.Destination TCP port 5.IP protocol -Most common fields in Netflow record: -5-tuple information -Input and output SNMP interface index -Timestamps for the flow start and finish time -Number of bytes and packets observed in the flow

Netflow – versions v1 First try v5 Most used version v6 Encapsulation information v7 Switch information v8 Several aggregation forms v9 Template Based, allowing many combinations, supports IPv6 IPFIX aka v10; IETF Standardized NetFlow 9 with Enterprise fields and other community input

Netflow setup Internet Connected organizations Border router Amsterdam1 (SARA) Border router Amsterdam2 (TeleCity II) Core router Amsterdam2 (TeleCity II) Core router Amsterdam1 (SARA) FLOWmon perfSONAR test NFSEN PeakFlow Fan out

Netflow applications -connected organizations: -FLOWmon detailed traffic reporting -SURFflow (Arbor Peakflow / NFSEN) suspicious traffic pattern reporting -SURFnet-CERT: -NFSEN suspicious traffic pattern reporting historical flow data queries profiles for custom reports -Geant2 JRA1 perfSONAR probes -Flow Subscription Measurement Point -Flow Selection and Aggregation Measurement Archive

FLOWmon Detailed traffic reporting: -total traffic -prefix-based flow grouping -reports on: -IP version (v4/v6) -IP protocol (TCP, UDP, ICMP, GRE, …) -TCP port (HTTP, SMTP, NNTP, FTP, SSH, …) -UDP port (domain, RTSP, VPN, …) -top N connected organizations -destination AS traffic

UvA traffic by IP protocol

Connected organization to world traffic by TCP destination port

SURFflow Reports on suspicious traffic patterns like: -Unusual amount of flows  DOS attack -Flows from one host to many ports on other host  portscan -From 1 host to same port on many hosts  break- in attempt making use of known bug -From many hosts to specific (set of) port(s) to many other hosts  virus/worm -etc …

Active measurements: RTTPL Round Trip Time and Packet Loss monitoring -measurement probes throughout the network -central storage of results -active measurements by injecting ICMP echo request packets -measuring min/max/avg RTT and jitter -both IPv4 and IPv6 -both unicast and multicast (under development) -measuring packet loss -20 pings per minute -report matrices per minute/hour/day/month -results between two probes in graphs

RTTPL report matrices

RTTPL Nijmegen - Amsterdam

Active measurements: Connected organization availability -measuring availability by sending ICMP Echo Requests to connected organization router -measurement includes last mile to connected organization plus connected organization router port (unlike commercial providers) -Cisco routers with Service Assurance Agent software on both Amsterdam1 and Amsterdam2 -results stored in database and reported monthly -redundancy in measurements by ORing results from Amsterdam1 and Amsterdam2

Thank you