SlideShare ist ein Scribd-Unternehmen logo
1 von 22
Downloaden Sie, um offline zu lesen
ACI Netflow 구성 가이드
2017.04.06 (version 1.1)
Cisco Systems Korea
최 우 형 수석부장 (whchoi@cisco.com)
#1. LEAF Switch Netflow Enable
1 Fabric – Fabric Policies
– Switch Policies
– Fabric Node Controls
1. Node control Name 생성
2. “Feature Selection” 을 Netflow
Priority로 변경 (Default는 Analytics
Priority)
2 Fabric – Fabric Policies
– Switch Policies
– Policy Groups
1. Policy Group Name 생성
2. Node Control Policy 선택
(1번에서 생성)
1
2
#1. LEAF Switch Netflow Enable
3 Fabric – Fabric Policies
– Switch Policies
– Profiles
1. Switch Profile Name 설정
2. Switch Association 설정
(Netflow Enable 하려는 EX
스위치 설정)3
#2. Netflow Configuration - Step
Flow Monitor
Flow Record
Flow Exporter
 Source Address
 Destination Port
 Destination Address
 Netflow exporter version type
 EPG Type
 Tenant
 EPG
 VRF
 Collect Parameter
 Match Parameter
1
2
3
#2. Netflow Configuration – Flow Exporters
1 Fabric – Access Policies
- Interface Porlices
- Policies
- Analytics
- Netflow Exporters
1. Exporters Name 설정
2. Destination Port 설정
(UDP Port)
3. Destination IP Address 설정
(Flow Collector address)
4. Netflow version 설정
5. Flow Collector 위치 설정
(내부 – App EPG, 외부 – L3 EPG)
6. Flow Collector 위치 상세 설정
#2. Netflow Configuration – Flow Records
2 Fabric – Access Policies
- Interface Porlices
- Policies
- Analytics
- Netflow Records
1. Collect Parameters 설정
2. Match Parameters 설정
#2. Netflow Configuration – Flow Records
Parameter 종류 Address Family 지원
Destination IPv4/6 IPv4/IPv6 IPv4 /IPv6
Destination IPv4 IPv4 IPv6
Destination IPv6 IPv6 IPv6
Destination MAC CE Non-IP traffic only
Destination Port IPv4/IPv6 IPv4 / IPv6
Ethertype CE Non-IP traffic only
IP Protocol IPv4/IPv6 IPv4 / IPv6
Source IPv4/6 IPv4/IPv6 IPv4 / IPv6
Source IPv4 IPv4 IPv4
Source IPv6 IPv6 IPv6
Source MAC CE Non-IP traffic only
Source Port IPv4/IPv6 IPv4 / IPv6
IP TOS IPv4/IPv6 현재 지원 불가
VLAN CE/IPv4/IPv6 현재 지원 불가
#2. Netflow Configuration – Flow Records
Collection Parameters Flow Record 포함 내용
Bytes counter 항상 전송 (32bit)
Pkts Counter 항상 전송 (32bit)
Pkt Disposition 전송하지 않음
Sampler ID 전송하지 않음
Source Interface 항상 전송
TCP Flags IP Protocol matching 시에만 전송
First Pkt Timestamp 항상 전송
Recent Pkt Timestamp 항상 전송
#2. Netflow Configuration – Flow Records
2 Fabric – Access Policies
- Interface Porlices
- Policies
- Analytics
- Netflow Monitor
1. Netflow Monitor 이름 설정
2. Flow Record 설정
3. Flow Collector 설정
#3. Netflow Interface Configuration
Bridge Domain(SVI) L3OUT
Logical Interface Profile
Flow Monitor
Flow Exporter Flow Record
Logical Node Profile
1 Netflow 구성을 원하는 Tenant에 적용하는 방법
LEAF Interface Policy Group
Flow Monitor
Flow Exporter Flow Record
2 Netflow 구성을 원하는 Interface에 적용하는 방법
vPC, PC, Access Port
#3. Netflow Interface Configuration – Interface 설정 방법
1 Fabric – Access Policies
- Interface Porlices
- Policy Groups
- Leaf Policy Groups
- vPC or PC or Access Port
1. Netflow Monitor Polices
(IP Filter Type 및 Flow Monitor
Policy 설정)
#3. Netflow Interface Configuration – L3 Outside 설정 방법
1 Tenant – Networking
- External Routed Networks
- L3OUT EPG
- Logical Node Profiles
- Logical Interface Profiles
1. Netflow Monitor Polices
(IP Filter Type 및 Flow Monitor
Policy 설정)
Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
#3. Netflow Interface Configuration – BD 설정 방법
1 Tenant – Networking
- Bridge Domain
- BD
- Netflow Monitor Polices
(IP Filter Type 및 Flow Monitor
Policy 설정)
Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
LEAF Switch에서 Flow 구성 확인
Flow Collector에서 확인
Flow Collector VM에서 다중 인터페이스 구성 Tip.
1. Flow Collector 위치가 Private 구간일 경우 ,
Flow Collector의 위치를 특정 Tenant EPG에 바인딩
2. SMC와는 기존 eth0과 통신하도록 구성
ACI에서 생성된 Netflow를 StealthWatch에서 확인
SMC에서 Flow 확인 – Host List
ACI EPG 또는 BD subnet 이름과 StealthWatch Host Group 연계
SMC에서 Flow 확인 – Host List
ACI EPG or BD Name = SMC Host Groups
SMC에서 Flow 확인 – Host List
ACI EPG or BD Name = SMC Host Groups ACI EP
SMC에서 Flow 확인 – Host List
ACI EPG or BD Name = SMC Host GroupsACI EP
ACI Netflow 구성 가이드

Weitere ähnliche Inhalte

Was ist angesagt?

ACI MultiPod Config Guide
ACI MultiPod Config GuideACI MultiPod Config Guide
ACI MultiPod Config GuideWoo Hyung Choi
 
Introduction to OpenFlow, SDN and NFV
Introduction to OpenFlow, SDN and NFVIntroduction to OpenFlow, SDN and NFV
Introduction to OpenFlow, SDN and NFVKingston Smiler
 
OpenvSwitch Deep Dive
OpenvSwitch Deep DiveOpenvSwitch Deep Dive
OpenvSwitch Deep Diverajdeep
 
Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조Seung-Hoon Baek
 
초보자를 위한 네트워크/VLAN 기초
초보자를 위한 네트워크/VLAN 기초초보자를 위한 네트워크/VLAN 기초
초보자를 위한 네트워크/VLAN 기초Open Source Consulting
 
차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략Woo Hyung Choi
 
Introduction to nexux from zero to Hero
Introduction to nexux  from zero to HeroIntroduction to nexux  from zero to Hero
Introduction to nexux from zero to HeroDhruv Sharma
 
SDN Architecture & Ecosystem
SDN Architecture & EcosystemSDN Architecture & Ecosystem
SDN Architecture & EcosystemKingston Smiler
 
Troubleshooting BGP
Troubleshooting BGPTroubleshooting BGP
Troubleshooting BGPDuane Bodle
 
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)Thomas Graf
 
Palo alto outline course | Mostafa El Lathy
Palo alto outline course | Mostafa El LathyPalo alto outline course | Mostafa El Lathy
Palo alto outline course | Mostafa El LathyMostafa El Lathy
 
OpenFlow tutorial
OpenFlow tutorialOpenFlow tutorial
OpenFlow tutorialopenflow
 
Unknown Unicast Traffic and Ping Pollers
Unknown Unicast Traffic and Ping PollersUnknown Unicast Traffic and Ping Pollers
Unknown Unicast Traffic and Ping PollersAPNIC
 
How VXLAN works on Linux
How VXLAN works on LinuxHow VXLAN works on Linux
How VXLAN works on LinuxEtsuji Nakai
 

Was ist angesagt? (20)

ACI MultiPod Config Guide
ACI MultiPod Config GuideACI MultiPod Config Guide
ACI MultiPod Config Guide
 
Introduction to OpenFlow, SDN and NFV
Introduction to OpenFlow, SDN and NFVIntroduction to OpenFlow, SDN and NFV
Introduction to OpenFlow, SDN and NFV
 
OpenvSwitch Deep Dive
OpenvSwitch Deep DiveOpenvSwitch Deep Dive
OpenvSwitch Deep Dive
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조
 
초보자를 위한 네트워크/VLAN 기초
초보자를 위한 네트워크/VLAN 기초초보자를 위한 네트워크/VLAN 기초
초보자를 위한 네트워크/VLAN 기초
 
차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략
 
Introduction to nexux from zero to Hero
Introduction to nexux  from zero to HeroIntroduction to nexux  from zero to Hero
Introduction to nexux from zero to Hero
 
ACI DHCP Config Guide
ACI DHCP Config GuideACI DHCP Config Guide
ACI DHCP Config Guide
 
How BGP Works
How BGP WorksHow BGP Works
How BGP Works
 
SDN Architecture & Ecosystem
SDN Architecture & EcosystemSDN Architecture & Ecosystem
SDN Architecture & Ecosystem
 
Troubleshooting BGP
Troubleshooting BGPTroubleshooting BGP
Troubleshooting BGP
 
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
 
VLAN vs VXLAN
VLAN vs VXLANVLAN vs VXLAN
VLAN vs VXLAN
 
Palo alto outline course | Mostafa El Lathy
Palo alto outline course | Mostafa El LathyPalo alto outline course | Mostafa El Lathy
Palo alto outline course | Mostafa El Lathy
 
OpenFlow tutorial
OpenFlow tutorialOpenFlow tutorial
OpenFlow tutorial
 
NETCONF YANG tutorial
NETCONF YANG tutorialNETCONF YANG tutorial
NETCONF YANG tutorial
 
Unknown Unicast Traffic and Ping Pollers
Unknown Unicast Traffic and Ping PollersUnknown Unicast Traffic and Ping Pollers
Unknown Unicast Traffic and Ping Pollers
 
How VXLAN works on Linux
How VXLAN works on LinuxHow VXLAN works on Linux
How VXLAN works on Linux
 
Network virtualization
Network virtualizationNetwork virtualization
Network virtualization
 

Ähnlich wie ACI Netflow 구성 가이드

2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)NAIM Networks, Inc.
 
3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)NAIM Networks, Inc.
 
Private cloud network architecture (2018)
Private cloud network architecture (2018)Private cloud network architecture (2018)
Private cloud network architecture (2018)Gasida Seo
 
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어NHN FORWARD
 
Radware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUIRadware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUI윤기 정
 
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기Hyperledger Korea User Group
 
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료choi kyumin
 
ACL - cisco 2811 router
ACL - cisco 2811 router ACL - cisco 2811 router
ACL - cisco 2811 router 준기 홍
 
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개OpenStack Korea Community
 
DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit) DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit) ymtech
 
웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD활 김
 
Opendaylight beryllium
Opendaylight berylliumOpendaylight beryllium
Opendaylight berylliumCheolmin Lee
 
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...OpenStack Korea Community
 
[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술NAVER D2
 
resource on openstack
 resource on openstack resource on openstack
resource on openstackjieun kim
 
20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석rootfs32
 

Ähnlich wie ACI Netflow 구성 가이드 (20)

2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)
 
3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)
 
L4교육자료
L4교육자료L4교육자료
L4교육자료
 
Private cloud network architecture (2018)
Private cloud network architecture (2018)Private cloud network architecture (2018)
Private cloud network architecture (2018)
 
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
 
Radware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUIRadware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUI
 
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
 
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
 
ACL - cisco 2811 router
ACL - cisco 2811 router ACL - cisco 2811 router
ACL - cisco 2811 router
 
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
 
DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit) DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit)
 
웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD
 
Opendaylight beryllium
Opendaylight berylliumOpendaylight beryllium
Opendaylight beryllium
 
Kafka slideshare
Kafka   slideshareKafka   slideshare
Kafka slideshare
 
DPDK
DPDKDPDK
DPDK
 
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
 
[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술
 
KAFKA 3.1.0.pdf
KAFKA 3.1.0.pdfKAFKA 3.1.0.pdf
KAFKA 3.1.0.pdf
 
resource on openstack
 resource on openstack resource on openstack
resource on openstack
 
20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석
 

Mehr von Woo Hyung Choi

Network Jumbo Frame Config Guide
Network Jumbo Frame Config GuideNetwork Jumbo Frame Config Guide
Network Jumbo Frame Config GuideWoo Hyung Choi
 
ACI Microsegment Config Guide
ACI Microsegment Config GuideACI Microsegment Config Guide
ACI Microsegment Config GuideWoo Hyung Choi
 
Cisco network analytics 솔루션
Cisco network analytics 솔루션Cisco network analytics 솔루션
Cisco network analytics 솔루션Woo Hyung Choi
 
Cisco sddc solution 소개
Cisco sddc solution 소개Cisco sddc solution 소개
Cisco sddc solution 소개Woo Hyung Choi
 
ACI DHCP 구성 가이드
ACI DHCP 구성 가이드ACI DHCP 구성 가이드
ACI DHCP 구성 가이드Woo Hyung Choi
 
ACI MultiFabric 소개
ACI MultiFabric 소개ACI MultiFabric 소개
ACI MultiFabric 소개Woo Hyung Choi
 

Mehr von Woo Hyung Choi (9)

Network Jumbo Frame Config Guide
Network Jumbo Frame Config GuideNetwork Jumbo Frame Config Guide
Network Jumbo Frame Config Guide
 
ACI Microsegment Config Guide
ACI Microsegment Config GuideACI Microsegment Config Guide
ACI Microsegment Config Guide
 
SDDC Strategy 1.3
SDDC Strategy 1.3SDDC Strategy 1.3
SDDC Strategy 1.3
 
Cisco network analytics 솔루션
Cisco network analytics 솔루션Cisco network analytics 솔루션
Cisco network analytics 솔루션
 
Cisco DC 전략
Cisco DC 전략Cisco DC 전략
Cisco DC 전략
 
Cisco sddc solution 소개
Cisco sddc solution 소개Cisco sddc solution 소개
Cisco sddc solution 소개
 
ACI DHCP 구성 가이드
ACI DHCP 구성 가이드ACI DHCP 구성 가이드
ACI DHCP 구성 가이드
 
ACI MultiFabric 소개
ACI MultiFabric 소개ACI MultiFabric 소개
ACI MultiFabric 소개
 
ACI MultiPod 구성
ACI MultiPod 구성ACI MultiPod 구성
ACI MultiPod 구성
 

ACI Netflow 구성 가이드

  • 1. ACI Netflow 구성 가이드 2017.04.06 (version 1.1) Cisco Systems Korea 최 우 형 수석부장 (whchoi@cisco.com)
  • 2. #1. LEAF Switch Netflow Enable 1 Fabric – Fabric Policies – Switch Policies – Fabric Node Controls 1. Node control Name 생성 2. “Feature Selection” 을 Netflow Priority로 변경 (Default는 Analytics Priority) 2 Fabric – Fabric Policies – Switch Policies – Policy Groups 1. Policy Group Name 생성 2. Node Control Policy 선택 (1번에서 생성) 1 2
  • 3. #1. LEAF Switch Netflow Enable 3 Fabric – Fabric Policies – Switch Policies – Profiles 1. Switch Profile Name 설정 2. Switch Association 설정 (Netflow Enable 하려는 EX 스위치 설정)3
  • 4. #2. Netflow Configuration - Step Flow Monitor Flow Record Flow Exporter  Source Address  Destination Port  Destination Address  Netflow exporter version type  EPG Type  Tenant  EPG  VRF  Collect Parameter  Match Parameter 1 2 3
  • 5. #2. Netflow Configuration – Flow Exporters 1 Fabric – Access Policies - Interface Porlices - Policies - Analytics - Netflow Exporters 1. Exporters Name 설정 2. Destination Port 설정 (UDP Port) 3. Destination IP Address 설정 (Flow Collector address) 4. Netflow version 설정 5. Flow Collector 위치 설정 (내부 – App EPG, 외부 – L3 EPG) 6. Flow Collector 위치 상세 설정
  • 6. #2. Netflow Configuration – Flow Records 2 Fabric – Access Policies - Interface Porlices - Policies - Analytics - Netflow Records 1. Collect Parameters 설정 2. Match Parameters 설정
  • 7. #2. Netflow Configuration – Flow Records Parameter 종류 Address Family 지원 Destination IPv4/6 IPv4/IPv6 IPv4 /IPv6 Destination IPv4 IPv4 IPv6 Destination IPv6 IPv6 IPv6 Destination MAC CE Non-IP traffic only Destination Port IPv4/IPv6 IPv4 / IPv6 Ethertype CE Non-IP traffic only IP Protocol IPv4/IPv6 IPv4 / IPv6 Source IPv4/6 IPv4/IPv6 IPv4 / IPv6 Source IPv4 IPv4 IPv4 Source IPv6 IPv6 IPv6 Source MAC CE Non-IP traffic only Source Port IPv4/IPv6 IPv4 / IPv6 IP TOS IPv4/IPv6 현재 지원 불가 VLAN CE/IPv4/IPv6 현재 지원 불가
  • 8. #2. Netflow Configuration – Flow Records Collection Parameters Flow Record 포함 내용 Bytes counter 항상 전송 (32bit) Pkts Counter 항상 전송 (32bit) Pkt Disposition 전송하지 않음 Sampler ID 전송하지 않음 Source Interface 항상 전송 TCP Flags IP Protocol matching 시에만 전송 First Pkt Timestamp 항상 전송 Recent Pkt Timestamp 항상 전송
  • 9. #2. Netflow Configuration – Flow Records 2 Fabric – Access Policies - Interface Porlices - Policies - Analytics - Netflow Monitor 1. Netflow Monitor 이름 설정 2. Flow Record 설정 3. Flow Collector 설정
  • 10. #3. Netflow Interface Configuration Bridge Domain(SVI) L3OUT Logical Interface Profile Flow Monitor Flow Exporter Flow Record Logical Node Profile 1 Netflow 구성을 원하는 Tenant에 적용하는 방법 LEAF Interface Policy Group Flow Monitor Flow Exporter Flow Record 2 Netflow 구성을 원하는 Interface에 적용하는 방법 vPC, PC, Access Port
  • 11. #3. Netflow Interface Configuration – Interface 설정 방법 1 Fabric – Access Policies - Interface Porlices - Policy Groups - Leaf Policy Groups - vPC or PC or Access Port 1. Netflow Monitor Polices (IP Filter Type 및 Flow Monitor Policy 설정)
  • 12. #3. Netflow Interface Configuration – L3 Outside 설정 방법 1 Tenant – Networking - External Routed Networks - L3OUT EPG - Logical Node Profiles - Logical Interface Profiles 1. Netflow Monitor Polices (IP Filter Type 및 Flow Monitor Policy 설정) Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
  • 13. #3. Netflow Interface Configuration – BD 설정 방법 1 Tenant – Networking - Bridge Domain - BD - Netflow Monitor Polices (IP Filter Type 및 Flow Monitor Policy 설정) Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
  • 14. LEAF Switch에서 Flow 구성 확인
  • 16. Flow Collector VM에서 다중 인터페이스 구성 Tip. 1. Flow Collector 위치가 Private 구간일 경우 , Flow Collector의 위치를 특정 Tenant EPG에 바인딩 2. SMC와는 기존 eth0과 통신하도록 구성
  • 17. ACI에서 생성된 Netflow를 StealthWatch에서 확인
  • 18. SMC에서 Flow 확인 – Host List ACI EPG 또는 BD subnet 이름과 StealthWatch Host Group 연계
  • 19. SMC에서 Flow 확인 – Host List ACI EPG or BD Name = SMC Host Groups
  • 20. SMC에서 Flow 확인 – Host List ACI EPG or BD Name = SMC Host Groups ACI EP
  • 21. SMC에서 Flow 확인 – Host List ACI EPG or BD Name = SMC Host GroupsACI EP