NetFlow thiab IPFIX yog ob qho tib si thev naus laus zis siv rau kev saib xyuas thiab tshuaj xyuas network. Lawv muab kev nkag siab txog cov qauv tsheb khiav hauv lub network, pab txhim kho kev ua tau zoo, kev daws teeb meem, thiab kev txheeb xyuas kev nyab xeeb.
NetFlow:
NetFlow yog dab tsi?
NetFlowyog thawj qhov kev soj ntsuam xyuas kev daws teeb meem, Ameslikas tsim los ntawm Cisco thaum xyoo 1990s. Ntau qhov sib txawv muaj nyob, tab sis feem ntau kev xa tawm yog raws li NetFlow v5 lossis NetFlow v9. Txawm hais tias txhua lub version muaj peev xwm sib txawv, cov haujlwm yooj yim tseem zoo ib yam:
Ua ntej, ib lub router, hloov, firewall, lossis lwm yam khoom siv yuav ntes cov ntaub ntawv ntawm lub network "ntws" - ib qho ntawm cov pob ntawv uas qhia txog cov yam ntxwv xws li qhov chaw thiab qhov chaw nyob, qhov chaw, thiab qhov chaw nres nkoj, thiab raws tu qauv. hom. Tom qab cov dej ntws mus dormant los yog lub sij hawm ua ntej tau dhau mus, lub cuab yeej yuav xa cov ntaub ntawv ntws mus rau ib qho chaw hu ua "flow collector".
Thaum kawg, "flow analyzer" ua rau kev nkag siab ntawm cov ntaub ntawv no, muab kev nkag siab hauv daim ntawv ntawm kev pom, txheeb cais, thiab cov ncauj lus kom ntxaws txog keeb kwm thiab lub sijhawm qhia. Hauv kev xyaum, cov neeg sau khoom thiab cov tshuaj ntsuam xyuas feem ntau yog ib qho chaw, feem ntau ua ke rau hauv lub network loj dua kev soj ntsuam kev daws teeb meem.
NetFlow ua haujlwm raws li lub xeev. Thaum tus neeg siv lub tshuab ncav cuag tus neeg rau zaub mov, NetFlow yuav pib ntes thiab sau cov metadata los ntawm qhov ntws. Tom qab qhov kev sib tham raug kaw lawm, NetFlow yuav xa ib daim ntawv tiav rau tus neeg sau.
Txawm hais tias nws tseem niaj hnub siv, NetFlow v5 muaj ntau qhov kev txwv. Cov teb xa tawm raug kho, kev saib xyuas tsuas yog txhawb nqa hauv kev coj ua, thiab cov thev naus laus zis niaj hnub xws li IPv6, MPLS, thiab VXLAN tsis txaus siab. NetFlow v9, kuj muaj npe raws li Flexible NetFlow (FNF), hais txog qee qhov kev txwv no, tso cai rau cov neeg siv los tsim cov qauv kev cai thiab ntxiv kev txhawb nqa rau cov thev naus laus zis tshiab.
Ntau tus neeg muag khoom kuj muaj lawv tus kheej kev siv ntawm NetFlow, xws li jFlow los ntawm Juniper thiab NetStream los ntawm Huawei. Txawm hais tias qhov kev teeb tsa yuav txawv me ntsis, cov kev siv no feem ntau tsim cov ntaub ntawv ntws uas sib xws nrog NetFlow cov neeg sau khoom thiab cov tshuaj ntsuam xyuas.
Cov yam ntxwv tseem ceeb ntawm NetFlow:
~ Cov ntaub ntawv ntws: NetFlow tsim cov ntaub ntawv ntws uas suav nrog cov ntsiab lus xws li qhov chaw thiab chaw nyob IP chaw nyob, chaw nres nkoj, sijhawm teev, pob ntawv thiab cov lej suav, thiab hom kev cai.
~ Kev saib xyuas tsheb: NetFlow muab kev pom zoo rau hauv cov qauv kev sib txuas hauv network, tso cai rau cov thawj coj txheeb xyuas cov ntawv thov sab saum toj, qhov kawg, thiab cov chaw khiav tsheb.
~Kev kuaj pom tsis meej: Los ntawm kev txheeb xyuas cov ntaub ntawv ntws, NetFlow tuaj yeem kuaj pom qhov tsis txaus ntseeg xws li kev siv bandwidth ntau dhau, kev sib txuas hauv network, lossis cov qauv tsheb tsis zoo.
~ Kev soj ntsuam kev ruaj ntseg: NetFlow tuaj yeem siv los tshawb xyuas thiab tshawb xyuas qhov xwm txheej kev nyab xeeb, xws li kev xa tawm tsis lees paub ntawm kev pabcuam (DDoS) kev tawm tsam lossis kev sim nkag tsis tau tso cai.
NetFlow Versions: NetFlow tau hloov zuj zus mus rau lub sijhawm, thiab cov ntawv sib txawv tau raug tso tawm. Qee qhov tseem ceeb tshaj plaws suav nrog NetFlow v5, NetFlow v9, thiab NetFlow yooj yim. Txhua version qhia txog kev txhim kho thiab muaj peev xwm ntxiv.
IPFIX:
IPFIX yog dab tsi?
Tus qauv IETF uas tau tshwm sim thaum xyoo 2000s, Internet Protocol Flow Information Export (IPFIX) yog qhov zoo ib yam li NetFlow. Qhov tseeb, NetFlow v9 tau ua lub hauv paus rau IPFIX. Qhov sib txawv tseem ceeb ntawm ob yog IPFIX yog tus qauv qhib, thiab tau txais kev txhawb nqa los ntawm ntau tus neeg muag khoom sib txuas ntawm Cisco. Nrog rau kev zam ntawm ob peb qhov chaw ntxiv ntxiv hauv IPFIX, cov ntawv tawm tswv yim yog ze li qub. Qhov tseeb, IPFIX qee zaum txawm hu ua "NetFlow v10".
Raws li ib feem ntawm nws qhov zoo sib xws rau NetFlow, IPFIX txaus siab rau kev txhawb nqa dav dav ntawm kev saib xyuas cov kev daws teeb meem nrog rau cov khoom siv network.
IPFIX (Internet Protocol Flow Information Export) yog tus txheej txheem qhib tsim los ntawm Internet Engineering Task Force (IETF). Nws yog raws li NetFlow Version 9 specification thiab muab cov qauv qauv rau kev xa tawm cov ntaub ntawv ntws los ntawm cov khoom siv hauv network.
IPFIX tsim raws li cov ntsiab lus ntawm NetFlow thiab nthuav lawv kom muaj kev hloov pauv ntau dua thiab kev sib koom ua ke ntawm cov neeg muag khoom sib txawv thiab cov khoom siv. Nws qhia txog lub tswv yim ntawm cov qauv, tso cai rau cov ntsiab lus dynamic ntawm cov ntaub ntawv ntws thiab cov ntsiab lus. Qhov no ua rau muaj kev suav nrog kev cai teb, kev txhawb nqa rau cov txheej txheem tshiab, thiab kev nthuav dav.
Cov yam ntxwv tseem ceeb ntawm IPFIX:
~ Template-Based Approach: IPFIX siv cov qauv los txheeb xyuas cov qauv thiab cov ntsiab lus ntawm cov ntaub ntawv ntws, muab kev yooj yim hauv kev ua raws cov ntaub ntawv sib txawv thiab cov ntaub ntawv tshwj xeeb.
~ Kev sib koom tes: IPFIX yog tus qauv qhib, kom ntseeg tau tias muaj peev xwm saib xyuas cov peev txheej thoob plaws cov neeg muag khoom sib txawv thiab cov khoom siv sib txawv.
~ Kev them nyiaj yug IPv6: IPFIX ib txwm txhawb nqa IPv6, ua rau nws tsim nyog rau kev saib xyuas thiab txheeb xyuas kev tsheb khiav hauv IPv6 tes hauj lwm.
~Txhim khu kev ruaj ntseg: IPFIX suav nrog kev ruaj ntseg nta xws li Thauj Txheej Kev Ruaj Ntseg (TLS) encryption thiab cov lus qhia kev ncaj ncees los tiv thaiv kev tsis pub lwm tus paub thiab kev ncaj ncees ntawm cov ntaub ntawv ntws thaum sib kis.
IPFIX tau txais kev txhawb nqa dav dav los ntawm ntau tus neeg muag khoom sib txuas lus, ua rau nws yog tus neeg muag khoom-nruab nrab thiab tau txais kev xaiv dav dav rau kev saib xyuas lub network.
Yog li, qhov txawv ntawm NetFlow thiab IPFIX yog dab tsi?
Cov lus teb yooj yim yog tias NetFlow yog Cisco proprietary raws tu qauv qhia nyob ib ncig ntawm 1996 thiab IPFIX yog nws cov qauv lub cev pom zoo kwv tij.
Ob txoj kev cai ua haujlwm tib lub hom phiaj: ua kom cov kws tsim khoom siv network thiab cov thawj coj los sau thiab txheeb xyuas cov theem IP kev khiav dej num hauv network. Cisco tau tsim NetFlow kom nws cov keyboards thiab routers tuaj yeem tso tawm cov ntaub ntawv tseem ceeb no. Muab qhov tseem ceeb ntawm Cisco iav, NetFlow tau dhau los ua tus txheej txheem de-facto rau kev txheeb xyuas tsheb khiav hauv network. Txawm li cas los xij, cov neeg sib tw hauv kev lag luam pom tau hais tias kev siv cov txheej txheem tswj hwm los ntawm nws cov thawj coj sib tw tsis yog lub tswv yim zoo thiab yog li IETF tau coj kev rau siab los ua tus qauv qhib rau kev tsom xam tsheb, uas yog IPFIX.
IPFIX yog raws li NetFlow version 9 thiab yog thawj zaug qhia txog xyoo 2005 tab sis siv qee lub xyoo kom tau txais kev lag luam. Nyob rau ntawm lub sijhawm no, ob txoj cai tseem ceeb yog tib yam thiab txawm tias lo lus NetFlow tseem muaj ntau dua qhov kev siv (tab sis tsis yog tag nrho) yog sib xws nrog IPFIX tus qauv.
Nov yog cov lus qhia txog qhov sib txawv ntawm NetFlow thiab IPFIX:
Yam | NetFlow | IPFIX |
---|---|---|
Keeb kwm | Proprietary technology tsim los ntawm Cisco | Kev lag luam-tus qauv raws tu qauv raws li NetFlow Version 9 |
Standardization | Cisco tshwj xeeb technology | Qhib tus qauv txhais los ntawm IETF hauv RFC 7011 |
Yooj yim | Evolved versions nrog cov yam ntxwv tshwj xeeb | Kev hloov pauv ntau dua thiab kev sib cuam tshuam ntawm cov neeg muag khoom |
Cov ntaub ntawv hom | Tas-size pob ntawv | Template-based mus kom ze rau customizable flow record formats |
Kev them nyiaj yug Template | Tsis txhawb | Dynamic templates rau kev hloov pauv hauv kev suav nrog |
Tus neeg muag khoom txhawb nqa | Feem ntau Cisco cov khoom siv | Kev txhawb nqa dav thoob plaws cov neeg muag khoom network |
Extensibility | Txwv customization | suav nrog cov kev cai teb thiab cov ntaub ntawv thov tshwj xeeb |
Cov txheej txheem sib txawv | Cisco tshwj xeeb variations | Native IPv6 kev txhawb nqa, txhim kho cov ntaub ntawv sau tseg |
Kev ruaj ntseg nta | Txwv kev ruaj ntseg nta | Thauj Txheej Kev Ruaj Ntseg (TLS) encryption, lus ncaj ncees |
Network Flow Monitoringyog kev sau, tsom xam, thiab saib xyuas cov tsheb khiav mus los ntawm ib qho chaw muab los yog lub network. Lub hom phiaj yuav txawv los ntawm kev daws teeb meem kev sib txuas mus rau kev npaj kev faib bandwidth yav tom ntej. Kev saib xyuas cov dej ntws thiab kev kuaj cov pob ntawv tuaj yeem tseem muaj txiaj ntsig hauv kev txheeb xyuas thiab kho cov teeb meem kev nyab xeeb.
Kev soj ntsuam kev khiav dej num muab cov pab pawg sib tham txog lub tswv yim zoo ntawm kev ua haujlwm hauv lub network, muab kev nkag siab txog kev siv tag nrho, kev siv daim ntawv thov, muaj peev xwm tsis muaj zog, qhov tsis zoo uas yuav ua rau muaj teeb meem kev nyab xeeb, thiab lwm yam. Muaj ntau ntau cov qauv sib txawv thiab cov qauv siv hauv kev soj ntsuam xyuas network, suav nrog NetFlow, sFlow, thiab Internet Protocol Flow Information Export (IPFIX). Txhua txoj haujlwm sib txawv me ntsis, tab sis txhua qhov txawv ntawm qhov chaw nres nkoj mirroring thiab kev soj ntsuam cov pob ntawv sib sib zog nqus kom lawv tsis ntes cov ntsiab lus ntawm txhua pob ntawv hla dhau qhov chaw nres nkoj lossis los ntawm kev hloov pauv. Txawm li cas los xij, kev saib xyuas ntws tau muab cov ntaub ntawv ntau dua li SNMP, uas feem ntau txwv rau cov txheeb cais dav dav xws li pob ntawv tag nrho thiab kev siv bandwidth.
Network Flow Tools Muab piv
Feature | NetFlow v5 | NetFlow v9 | sFlow | IPFIX |
Qhib lossis Proprietary | Muaj tswv | Muaj tswv | Qhib | Qhib |
Sampled los yog Flow Based | Feem ntau Flow Based; Qauv qauv muaj | Feem ntau Flow Based; Qauv qauv muaj | Qauv | Feem ntau Flow Based; Qauv qauv muaj |
Cov ntaub ntawv raug ntes | Metadata thiab cov ntaub ntawv txheeb cais, suav nrog bytes hloov pauv, interface suav thiab lwm yam | Metadata thiab cov ntaub ntawv txheeb cais, suav nrog bytes hloov pauv, interface suav thiab lwm yam | Ua kom tiav pob ntawv Headers, Ib nrab Pob Pob Payloads | Metadata thiab cov ntaub ntawv txheeb cais, suav nrog bytes hloov pauv, interface suav thiab lwm yam |
Ingress/Egress Monitoring | Ingress nkaus xwb | Ingress thiab Egress | Ingress thiab Egress | Ingress thiab Egress |
Kev them nyiaj yug IPv6 / VLAN / MPLS | No | Yog lawm | Yog lawm | Yog lawm |
Lub sij hawm xa tuaj: Mar-18-2024