TF e DMTF. rviços de rede. A.FUNDAMENTOS &...

14

Transcript of TF e DMTF. rviços de rede. A.FUNDAMENTOS &...

Page 1: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher
Page 2: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

A.FUNDAMENTOS & ARQUITECTURAS DE GESTÃO

•Apresentação da motivação para a normalização.

•Principais arquitecturas normalizadas pela OSI, IETF e DMTF.

B.TECNOLOGIAS & MECANISMOS AVANÇADOS

•Apresentação do estado da arte.

•Discussão sobre áreas de investigação promissoras.

C.PRÁCTICAS CORRENTES & ANÁLISE DE CASOS DE ESTUDO

•Estudo e experimentação com ferramentas populares.

•Análise de casos típicos de gestão integrada de serviços de rede.

PROGRAMA

Introdução

Page 3: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

I.“Network Management: An introduction to principles and practice.”

•M. Subramanian, Addison-Wesley, 1999.

II.“SNMP, SNMPv2, SNMPv3 & RMON 1 and 2.”

•W. Stallings, Addison-Wesley, 1998.

III.“Network Management, MIBs and MPLS: Principles,

Design and Implementation.”

•S. Morris, Addison-Wesley, 2003.

IV.“Network Services Magement Framework.”

•B. Dias, Universidade do Minho, 2004.

BIBLIOGRAFIA

Introdução

Page 4: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

48

Multi Router Traffic Grapher (MRTG)

•It is used for monitorization of routers interfaces and network

bandwidth usage. It can help diagnosing/debugging network

problems using simple statistical analysis of the network usage.

•It is based on SNMP (v1 or v2c) for pooling information.

It can monitor any MIB variables, not only interfaces usage.

(by default, pooling intervals are fixed to 5 minutes)

•It generates statistcs reports for web vizualization.

(graphics are created in PNG file format)

•It can present daily, weekly, monthly and yearly graphs.

•Resource: http://www.mrtg.org/

Page 5: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

49

Multi Router Traffic Grapher (MRTG)

Sam

ple

Dai

ly M

RTG

Sa

mpl

e D

aily

MR

TG

Sam

ple

Dai

ly M

RTG

Sa

mpl

e D

aily

MR

TG

Gra

phG

raph

Gra

phG

raph

Fonte:

Open Source Network Administration

James Kretchmar

Prentice Hall, September 2003.

Page 6: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

50

SmokePing

•It is a latency and jitter measurement tool.

•It can measure, store and display latency, latency distribution

and packet loss statistics.

•It uses the RRDtoolgraphing tool to maintain a long-term

data-store and to draw graphs (ala MRTG).

•Resource: http://oss.oetiker.ch/smokeping/

Page 7: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

51

SmokePing Sa

mpl

e Sa

mpl

e Sa

mpl

e Sa

mpl

e Sm

okeP

ing

Smok

ePin

gSm

okeP

ing

Smok

ePin

gG

raph

Gra

phG

raph

Gra

phFonte:

Open Source Network Administration

James Kretchmar

Prentice Hall, September 2003.

Page 8: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

52

Neo •It is a command line text based monitorization and

configuration tool.

•It uses SNMP (v1 or v2c) as the network management protocol.

•It supports host discovery on a network device (or on a collection

of network devices) and port layout on network devices.

•It can enable and disable network ports and create statistics

reports on a per-port bandwidth usage (text tables).

•Resource: http://www.ktools.org/neo/

Page 9: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

53

Neo n

eo: stats entry-switch.example.com

Probing devices ...

Getting first set of stats...

Getting second set of stats...

Port statistics:

p type u lnkadmapkbs

ikbs

okbs

ppsippsoppsierpsoerps

------------------------------------------------------------------

1 100TX 100 On 20 0 20 26 0 26 0

0

2 100TX 100 On 19 0 19 26 0 26 0

0

3 100TX 10 On 20 0 20 27 0 27 0

0

4 100TX -

On 0 0 0 0 0 0 0 0

5 100TX -

On 0 0 0 0 0 0 0 0

6 100TX 100 On 50455 50042 413 7157 7051 106 0

0

7 100TX 10 On 19 0 19 26 0 26 0

0

8 100TX 100 On 19 0 19 26 0 26 0

0

9 100TX 100 On 19 0 19 26 0 26 0

0

10 100TX -

On 0 0 0 0 0 0 0 0

11 100TX 100 On 19 0 19 26 0 26 0

0

12 100TX 100 On 19 0 19 27 0 27 0

0

13 100?X * 100 On 382 368 14 84 71 13 0

0

14 100?X * -

On 0 0 0 0 0 0 0 0

15 loop 10 On 59 28 31 80 40 40

0 0

Fonte:

Open Source Network Administration

James Kretchmar

Prentice Hall, September 2003.

Page 10: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS (NOT SO) OPEN SOURCE

PARTE C

54

NetFlow

•It is not a client tool (or management application) like MRTG orNeo.

It is a server tool (like a management agent) that must run on routers.

•It was created by Cisco but some others routers/switches

manufactures call also support it.

•It permits the analysis of the content of the packets flowing through

a router or switch (it generates statistics on a per flow basis).

•It generates statistical data that can be logged on an external device

and to be later processed by other third-party tools, like Flow-Tools.

•It is a powerful data gathering software.

(There are some good complementary flow collector tools.)

Page 11: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

55

Sysmon

•It is a services and reachabilitymonitoring tool.

•It can generate events and send alarm messages to persons

or applications.

•It can use a web interface or a command line interface.

•Its configuration file is complex...

•Resource: http://www.sysmon.org/

Page 12: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

56

Sysmon

Fonte:

Sysmon Web Site

http://www.sysmon.org/

Page 13: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

57

Nagios

•It’s also a network services monitoring tool, like Sysmon, just better...

•It supports:

-Escalation of events

-Configuration Templates

-Monitoring time periods

-Modular test plug-ins

-Passive testing/polling

-Host and contact grouping

-Flap detection

-Dependencies not mandatory

•Resource: http://www.nagios.org/

Page 14: TF e DMTF. rviços de rede. A.FUNDAMENTOS & …marco.uminho.pt/~dias/MIECOM/GR/Docs/MIECOM-GR-AULAS-parte-C.pdf · 48 PARTE C FERRAMENTAS OPEN SOURCE Multi Router Traffic Grapher

FERRAMENTAS OPEN SOURCE

PARTE C

58

TCP-Dump

•It is a PDU analyzer for link (frame), network (packet),

transport (segment) and application (messages, etc) layers...

•It is not graphic nor directly supports a web interface.

•Care should be taken due to processing and analisys of private data.

•It is, nowadays, less important due to the use of real switching

devices (instead of repeaters and hubs) and other new tools that are

becoming more important, like Ethereal and Snort.

•Resources: http://www.tcpdump.org/

http://www.ethereal.com/

http://www.snort.org/