Download presentation
Presentation is loading. Please wait.
Published byAron Jefferson Modified over 8 years ago
1
NERSC Overview Karen Schafer
2
Wireless Ruckus centralized controller 802.11a/g/n Employee, Visitor, and Guest Access Captive portal registration for visitor and employee access Guestpass must be generated by NERSC employee
3
IPv6 Current – Provider dependent address block – DNS, Email, and www mandate met – Separate infrastructure, connectivity Future – Provider independent block acquired – Will deploy/migrate in 100G environment
4
ESnet5/100G Implementation Current – Juniper M320 connected at 10G – Alcatel Lucent connected at 100G Future (near term) – iBGP between border routers – OSPF internal, area 0 – Strict primary/secondary policy
5
NERSC 100G Security Monitoring Jim Mellander (Scott Campbell)
6
100GB Monitoring Design ACL LAG Data In Manager Bro Cluster 100G Router Workers
7
100Gb IDS: Front Hardware ACL LAG Data In 100G Router Router: MLXe-16, running 5.4c OS Data enters and is Policy Routed to LAG Group based on ACL – Allows for maximum flexibility. LAG Group load balances across 10G interfaces using source and dest IP addresses for flow symmetry. ACL is blunt tool – severe limitations on what you can make decisions on. Unclean.
8
100Gb Monitoring: Bro Cluster Manager Bro Cluster Workers Bro Cluster is “out of the box” without significant functional changes. Small number of worker nodes is a product of our traffic profile (Very heavy tail). Note: While per worker maximum data rate is 10G/s, this problem is addressed via shunting.
9
Bro Policy Shunt unit is a single connection based on TCP 5-tuple. If enough connections between two IP pairs are observed (high water mark), the pair of hosts are shunted. As connections close, the count can fall below a low water mark and the IP pair shunt is removed. Number of Connections Seen between two IPs High Water Low Water
10
Data Volume vs. Efficiency As expected, the larger the volume of data per connection size, the greater the shunt efficiency.
11
ROC Graph: Conn Size vs. %Total Data 0MB 200MB 400MB 600MB 800MB 1000MB 1200MB Connection Data (to + from) in MB 100% 80% 60% 40% 20% 0% 99.3 % Connections < 1 MB
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.