SlideShare uma empresa Scribd logo
1 de 22
Baixar para ler offline
ACI Netflow 구성 가이드
2017.04.06 (version 1.1)
Cisco Systems Korea
최 우 형 수석부장 (whchoi@cisco.com)
#1. LEAF Switch Netflow Enable
1 Fabric – Fabric Policies
– Switch Policies
– Fabric Node Controls
1. Node control Name 생성
2. “Feature Selection” 을 Netflow
Priority로 변경 (Default는 Analytics
Priority)
2 Fabric – Fabric Policies
– Switch Policies
– Policy Groups
1. Policy Group Name 생성
2. Node Control Policy 선택
(1번에서 생성)
1
2
#1. LEAF Switch Netflow Enable
3 Fabric – Fabric Policies
– Switch Policies
– Profiles
1. Switch Profile Name 설정
2. Switch Association 설정
(Netflow Enable 하려는 EX
스위치 설정)3
#2. Netflow Configuration - Step
Flow Monitor
Flow Record
Flow Exporter
 Source Address
 Destination Port
 Destination Address
 Netflow exporter version type
 EPG Type
 Tenant
 EPG
 VRF
 Collect Parameter
 Match Parameter
1
2
3
#2. Netflow Configuration – Flow Exporters
1 Fabric – Access Policies
- Interface Porlices
- Policies
- Analytics
- Netflow Exporters
1. Exporters Name 설정
2. Destination Port 설정
(UDP Port)
3. Destination IP Address 설정
(Flow Collector address)
4. Netflow version 설정
5. Flow Collector 위치 설정
(내부 – App EPG, 외부 – L3 EPG)
6. Flow Collector 위치 상세 설정
#2. Netflow Configuration – Flow Records
2 Fabric – Access Policies
- Interface Porlices
- Policies
- Analytics
- Netflow Records
1. Collect Parameters 설정
2. Match Parameters 설정
#2. Netflow Configuration – Flow Records
Parameter 종류 Address Family 지원
Destination IPv4/6 IPv4/IPv6 IPv4 /IPv6
Destination IPv4 IPv4 IPv6
Destination IPv6 IPv6 IPv6
Destination MAC CE Non-IP traffic only
Destination Port IPv4/IPv6 IPv4 / IPv6
Ethertype CE Non-IP traffic only
IP Protocol IPv4/IPv6 IPv4 / IPv6
Source IPv4/6 IPv4/IPv6 IPv4 / IPv6
Source IPv4 IPv4 IPv4
Source IPv6 IPv6 IPv6
Source MAC CE Non-IP traffic only
Source Port IPv4/IPv6 IPv4 / IPv6
IP TOS IPv4/IPv6 현재 지원 불가
VLAN CE/IPv4/IPv6 현재 지원 불가
#2. Netflow Configuration – Flow Records
Collection Parameters Flow Record 포함 내용
Bytes counter 항상 전송 (32bit)
Pkts Counter 항상 전송 (32bit)
Pkt Disposition 전송하지 않음
Sampler ID 전송하지 않음
Source Interface 항상 전송
TCP Flags IP Protocol matching 시에만 전송
First Pkt Timestamp 항상 전송
Recent Pkt Timestamp 항상 전송
#2. Netflow Configuration – Flow Records
2 Fabric – Access Policies
- Interface Porlices
- Policies
- Analytics
- Netflow Monitor
1. Netflow Monitor 이름 설정
2. Flow Record 설정
3. Flow Collector 설정
#3. Netflow Interface Configuration
Bridge Domain(SVI) L3OUT
Logical Interface Profile
Flow Monitor
Flow Exporter Flow Record
Logical Node Profile
1 Netflow 구성을 원하는 Tenant에 적용하는 방법
LEAF Interface Policy Group
Flow Monitor
Flow Exporter Flow Record
2 Netflow 구성을 원하는 Interface에 적용하는 방법
vPC, PC, Access Port
#3. Netflow Interface Configuration – Interface 설정 방법
1 Fabric – Access Policies
- Interface Porlices
- Policy Groups
- Leaf Policy Groups
- vPC or PC or Access Port
1. Netflow Monitor Polices
(IP Filter Type 및 Flow Monitor
Policy 설정)
#3. Netflow Interface Configuration – L3 Outside 설정 방법
1 Tenant – Networking
- External Routed Networks
- L3OUT EPG
- Logical Node Profiles
- Logical Interface Profiles
1. Netflow Monitor Polices
(IP Filter Type 및 Flow Monitor
Policy 설정)
Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
#3. Netflow Interface Configuration – BD 설정 방법
1 Tenant – Networking
- Bridge Domain
- BD
- Netflow Monitor Polices
(IP Filter Type 및 Flow Monitor
Policy 설정)
Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
LEAF Switch에서 Flow 구성 확인
Flow Collector에서 확인
Flow Collector VM에서 다중 인터페이스 구성 Tip.
1. Flow Collector 위치가 Private 구간일 경우 ,
Flow Collector의 위치를 특정 Tenant EPG에 바인딩
2. SMC와는 기존 eth0과 통신하도록 구성
ACI에서 생성된 Netflow를 StealthWatch에서 확인
SMC에서 Flow 확인 – Host List
ACI EPG 또는 BD subnet 이름과 StealthWatch Host Group 연계
SMC에서 Flow 확인 – Host List
ACI EPG or BD Name = SMC Host Groups
SMC에서 Flow 확인 – Host List
ACI EPG or BD Name = SMC Host Groups ACI EP
SMC에서 Flow 확인 – Host List
ACI EPG or BD Name = SMC Host GroupsACI EP
ACI Netflow 구성 가이드

Mais conteúdo relacionado

Mais procurados

Openstack Neutron & Interconnections with BGP/MPLS VPNs
Openstack Neutron & Interconnections with BGP/MPLS VPNsOpenstack Neutron & Interconnections with BGP/MPLS VPNs
Openstack Neutron & Interconnections with BGP/MPLS VPNsThomas Morin
 
Faster packet processing in Linux: XDP
Faster packet processing in Linux: XDPFaster packet processing in Linux: XDP
Faster packet processing in Linux: XDPDaniel T. Lee
 
Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조Seung-Hoon Baek
 
Segment Routing
Segment RoutingSegment Routing
Segment RoutingAPNIC
 
Packet flow on openstack
Packet flow on openstackPacket flow on openstack
Packet flow on openstackAchhar Kalia
 
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)Thomas Graf
 
MPLS-based Metro Ethernet Networks Tutorial by Khatri
MPLS-based Metro Ethernet Networks Tutorial by KhatriMPLS-based Metro Ethernet Networks Tutorial by Khatri
MPLS-based Metro Ethernet Networks Tutorial by KhatriFebrian ‎
 
Cilium - Fast IPv6 Container Networking with BPF and XDP
Cilium - Fast IPv6 Container Networking with BPF and XDPCilium - Fast IPv6 Container Networking with BPF and XDP
Cilium - Fast IPv6 Container Networking with BPF and XDPThomas Graf
 
DevNetCreate - ACI and Kubernetes Integration
DevNetCreate - ACI and Kubernetes IntegrationDevNetCreate - ACI and Kubernetes Integration
DevNetCreate - ACI and Kubernetes IntegrationHank Preston
 
Open vSwitch Introduction
Open vSwitch IntroductionOpen vSwitch Introduction
Open vSwitch IntroductionHungWei Chiu
 
Vxlan deep dive session rev0.5 final
Vxlan deep dive session rev0.5   finalVxlan deep dive session rev0.5   final
Vxlan deep dive session rev0.5 finalKwonSun Bae
 
[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹
[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹
[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹InfraEngineer
 
MPLS L3 VPN Deployment
MPLS L3 VPN DeploymentMPLS L3 VPN Deployment
MPLS L3 VPN DeploymentAPNIC
 
OVN operationalization at scale at eBay
OVN operationalization at scale at eBayOVN operationalization at scale at eBay
OVN operationalization at scale at eBayAliasgar Ginwala
 
BGP Advance Technique by Steven & James
BGP Advance Technique by Steven & JamesBGP Advance Technique by Steven & James
BGP Advance Technique by Steven & JamesFebrian ‎
 
Cisco Live Milan 2015 - BGP advance
Cisco Live Milan 2015 - BGP advanceCisco Live Milan 2015 - BGP advance
Cisco Live Milan 2015 - BGP advanceBertrand Duvivier
 
VXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksVXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksAPNIC
 
Open stack networking vlan, gre
Open stack networking   vlan, greOpen stack networking   vlan, gre
Open stack networking vlan, greSim Janghoon
 

Mais procurados (20)

Openstack Neutron & Interconnections with BGP/MPLS VPNs
Openstack Neutron & Interconnections with BGP/MPLS VPNsOpenstack Neutron & Interconnections with BGP/MPLS VPNs
Openstack Neutron & Interconnections with BGP/MPLS VPNs
 
Faster packet processing in Linux: XDP
Faster packet processing in Linux: XDPFaster packet processing in Linux: XDP
Faster packet processing in Linux: XDP
 
Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조Open vSwitch 패킷 처리 구조
Open vSwitch 패킷 처리 구조
 
Segment Routing
Segment RoutingSegment Routing
Segment Routing
 
Packet flow on openstack
Packet flow on openstackPacket flow on openstack
Packet flow on openstack
 
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
Taking Security Groups to Ludicrous Speed with OVS (OpenStack Summit 2015)
 
Deploying IPv6 on OpenStack
Deploying IPv6 on OpenStackDeploying IPv6 on OpenStack
Deploying IPv6 on OpenStack
 
MPLS-based Metro Ethernet Networks Tutorial by Khatri
MPLS-based Metro Ethernet Networks Tutorial by KhatriMPLS-based Metro Ethernet Networks Tutorial by Khatri
MPLS-based Metro Ethernet Networks Tutorial by Khatri
 
Cilium - Fast IPv6 Container Networking with BPF and XDP
Cilium - Fast IPv6 Container Networking with BPF and XDPCilium - Fast IPv6 Container Networking with BPF and XDP
Cilium - Fast IPv6 Container Networking with BPF and XDP
 
DevNetCreate - ACI and Kubernetes Integration
DevNetCreate - ACI and Kubernetes IntegrationDevNetCreate - ACI and Kubernetes Integration
DevNetCreate - ACI and Kubernetes Integration
 
Open vSwitch Introduction
Open vSwitch IntroductionOpen vSwitch Introduction
Open vSwitch Introduction
 
Vxlan deep dive session rev0.5 final
Vxlan deep dive session rev0.5   finalVxlan deep dive session rev0.5   final
Vxlan deep dive session rev0.5 final
 
[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹
[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹
[MeetUp][1st] 오리뎅이의_쿠버네티스_네트워킹
 
MPLS L3 VPN Deployment
MPLS L3 VPN DeploymentMPLS L3 VPN Deployment
MPLS L3 VPN Deployment
 
OVN operationalization at scale at eBay
OVN operationalization at scale at eBayOVN operationalization at scale at eBay
OVN operationalization at scale at eBay
 
EVPN Introduction
EVPN IntroductionEVPN Introduction
EVPN Introduction
 
BGP Advance Technique by Steven & James
BGP Advance Technique by Steven & JamesBGP Advance Technique by Steven & James
BGP Advance Technique by Steven & James
 
Cisco Live Milan 2015 - BGP advance
Cisco Live Milan 2015 - BGP advanceCisco Live Milan 2015 - BGP advance
Cisco Live Milan 2015 - BGP advance
 
VXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksVXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building Blocks
 
Open stack networking vlan, gre
Open stack networking   vlan, greOpen stack networking   vlan, gre
Open stack networking vlan, gre
 

Semelhante a ACI Netflow 구성 가이드

2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)NAIM Networks, Inc.
 
3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)NAIM Networks, Inc.
 
Private cloud network architecture (2018)
Private cloud network architecture (2018)Private cloud network architecture (2018)
Private cloud network architecture (2018)Gasida Seo
 
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어NHN FORWARD
 
Radware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUIRadware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUI윤기 정
 
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기Hyperledger Korea User Group
 
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료choi kyumin
 
ACL - cisco 2811 router
ACL - cisco 2811 router ACL - cisco 2811 router
ACL - cisco 2811 router 준기 홍
 
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개OpenStack Korea Community
 
DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit) DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit) ymtech
 
웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD활 김
 
Opendaylight beryllium
Opendaylight berylliumOpendaylight beryllium
Opendaylight berylliumCheolmin Lee
 
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...OpenStack Korea Community
 
[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술NAVER D2
 
resource on openstack
 resource on openstack resource on openstack
resource on openstackjieun kim
 
20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석rootfs32
 

Semelhante a ACI Netflow 구성 가이드 (20)

2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)2nd SDN Interest Group Seminar-Session3 (121218)
2nd SDN Interest Group Seminar-Session3 (121218)
 
3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)3rd SDN Interest Group Seminar-Session 3 (130123)
3rd SDN Interest Group Seminar-Session 3 (130123)
 
L4교육자료
L4교육자료L4교육자료
L4교육자료
 
Private cloud network architecture (2018)
Private cloud network architecture (2018)Private cloud network architecture (2018)
Private cloud network architecture (2018)
 
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
[2018] NHN 모니터링의 현재와 미래 for 인프라 엔지니어
 
Radware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUIRadware Alteon Introduction - new GUI
Radware Alteon Introduction - new GUI
 
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
1908 Hyperledger Fabric 소개 및 첫 네트워크 구축하기
 
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
플랫폼데이2013 workflow기반 실시간 스트리밍데이터 수집 및 분석 플랫폼 발표자료
 
ACL - cisco 2811 router
ACL - cisco 2811 router ACL - cisco 2811 router
ACL - cisco 2811 router
 
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
[OpenStack Days Korea 2016] Track2 - 아리스타 OpenStack 연동 및 CloudVision 솔루션 소개
 
DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit) DPDK (Data Plane Development Kit)
DPDK (Data Plane Development Kit)
 
웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD웹기반원격감시제어 2010 CPD
웹기반원격감시제어 2010 CPD
 
Opendaylight beryllium
Opendaylight berylliumOpendaylight beryllium
Opendaylight beryllium
 
Kafka slideshare
Kafka   slideshareKafka   slideshare
Kafka slideshare
 
DPDK
DPDKDPDK
DPDK
 
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
[OpenStack Days Korea 2016] Track2 - How to speed up OpenStack network with P...
 
[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술[112]clova platform 인공지능을 엮는 기술
[112]clova platform 인공지능을 엮는 기술
 
KAFKA 3.1.0.pdf
KAFKA 3.1.0.pdfKAFKA 3.1.0.pdf
KAFKA 3.1.0.pdf
 
resource on openstack
 resource on openstack resource on openstack
resource on openstack
 
20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석20150818 jun lee_openstack juno release 내용 분석
20150818 jun lee_openstack juno release 내용 분석
 

Mais de Woo Hyung Choi

Network Jumbo Frame Config Guide
Network Jumbo Frame Config GuideNetwork Jumbo Frame Config Guide
Network Jumbo Frame Config GuideWoo Hyung Choi
 
ACI Microsegment Config Guide
ACI Microsegment Config GuideACI Microsegment Config Guide
ACI Microsegment Config GuideWoo Hyung Choi
 
차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략Woo Hyung Choi
 
Cisco network analytics 솔루션
Cisco network analytics 솔루션Cisco network analytics 솔루션
Cisco network analytics 솔루션Woo Hyung Choi
 
ACI MultiPod Config Guide
ACI MultiPod Config GuideACI MultiPod Config Guide
ACI MultiPod Config GuideWoo Hyung Choi
 
Cisco sddc solution 소개
Cisco sddc solution 소개Cisco sddc solution 소개
Cisco sddc solution 소개Woo Hyung Choi
 
ACI DHCP 구성 가이드
ACI DHCP 구성 가이드ACI DHCP 구성 가이드
ACI DHCP 구성 가이드Woo Hyung Choi
 
ACI MultiFabric 소개
ACI MultiFabric 소개ACI MultiFabric 소개
ACI MultiFabric 소개Woo Hyung Choi
 

Mais de Woo Hyung Choi (12)

Network Jumbo Frame Config Guide
Network Jumbo Frame Config GuideNetwork Jumbo Frame Config Guide
Network Jumbo Frame Config Guide
 
ACI Microsegment Config Guide
ACI Microsegment Config GuideACI Microsegment Config Guide
ACI Microsegment Config Guide
 
SDDC Strategy 1.3
SDDC Strategy 1.3SDDC Strategy 1.3
SDDC Strategy 1.3
 
차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략차세대 데이터센터 네트워크 전략
차세대 데이터센터 네트워크 전략
 
Cisco network analytics 솔루션
Cisco network analytics 솔루션Cisco network analytics 솔루션
Cisco network analytics 솔루션
 
Cisco DC 전략
Cisco DC 전략Cisco DC 전략
Cisco DC 전략
 
ACI DHCP Config Guide
ACI DHCP Config GuideACI DHCP Config Guide
ACI DHCP Config Guide
 
ACI MultiPod Config Guide
ACI MultiPod Config GuideACI MultiPod Config Guide
ACI MultiPod Config Guide
 
Cisco sddc solution 소개
Cisco sddc solution 소개Cisco sddc solution 소개
Cisco sddc solution 소개
 
ACI DHCP 구성 가이드
ACI DHCP 구성 가이드ACI DHCP 구성 가이드
ACI DHCP 구성 가이드
 
ACI MultiFabric 소개
ACI MultiFabric 소개ACI MultiFabric 소개
ACI MultiFabric 소개
 
ACI MultiPod 구성
ACI MultiPod 구성ACI MultiPod 구성
ACI MultiPod 구성
 

Último

Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...Kim Daeun
 
캐드앤그래픽스 2024년 5월호 목차
캐드앤그래픽스 2024년 5월호 목차캐드앤그래픽스 2024년 5월호 목차
캐드앤그래픽스 2024년 5월호 목차캐드앤그래픽스
 
[Terra] Terra Money: Stability and Adoption
[Terra] Terra Money: Stability and Adoption[Terra] Terra Money: Stability and Adoption
[Terra] Terra Money: Stability and AdoptionSeung-chan Baeg
 
MOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution DetectionMOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution DetectionKim Daeun
 
도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'
도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'
도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'Hyundai Motor Group
 
Grid Layout (Kitworks Team Study 장현정 발표자료)
Grid Layout (Kitworks Team Study 장현정 발표자료)Grid Layout (Kitworks Team Study 장현정 발표자료)
Grid Layout (Kitworks Team Study 장현정 발표자료)Wonjun Hwang
 
A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)Tae Young Lee
 

Último (7)

Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
 
캐드앤그래픽스 2024년 5월호 목차
캐드앤그래픽스 2024년 5월호 목차캐드앤그래픽스 2024년 5월호 목차
캐드앤그래픽스 2024년 5월호 목차
 
[Terra] Terra Money: Stability and Adoption
[Terra] Terra Money: Stability and Adoption[Terra] Terra Money: Stability and Adoption
[Terra] Terra Money: Stability and Adoption
 
MOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution DetectionMOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution Detection
 
도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'
도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'
도심 하늘에서 시속 200km로 비행할 수 있는 미래 항공 모빌리티 'S-A2'
 
Grid Layout (Kitworks Team Study 장현정 발표자료)
Grid Layout (Kitworks Team Study 장현정 발표자료)Grid Layout (Kitworks Team Study 장현정 발표자료)
Grid Layout (Kitworks Team Study 장현정 발표자료)
 
A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)
 

ACI Netflow 구성 가이드

  • 1. ACI Netflow 구성 가이드 2017.04.06 (version 1.1) Cisco Systems Korea 최 우 형 수석부장 (whchoi@cisco.com)
  • 2. #1. LEAF Switch Netflow Enable 1 Fabric – Fabric Policies – Switch Policies – Fabric Node Controls 1. Node control Name 생성 2. “Feature Selection” 을 Netflow Priority로 변경 (Default는 Analytics Priority) 2 Fabric – Fabric Policies – Switch Policies – Policy Groups 1. Policy Group Name 생성 2. Node Control Policy 선택 (1번에서 생성) 1 2
  • 3. #1. LEAF Switch Netflow Enable 3 Fabric – Fabric Policies – Switch Policies – Profiles 1. Switch Profile Name 설정 2. Switch Association 설정 (Netflow Enable 하려는 EX 스위치 설정)3
  • 4. #2. Netflow Configuration - Step Flow Monitor Flow Record Flow Exporter  Source Address  Destination Port  Destination Address  Netflow exporter version type  EPG Type  Tenant  EPG  VRF  Collect Parameter  Match Parameter 1 2 3
  • 5. #2. Netflow Configuration – Flow Exporters 1 Fabric – Access Policies - Interface Porlices - Policies - Analytics - Netflow Exporters 1. Exporters Name 설정 2. Destination Port 설정 (UDP Port) 3. Destination IP Address 설정 (Flow Collector address) 4. Netflow version 설정 5. Flow Collector 위치 설정 (내부 – App EPG, 외부 – L3 EPG) 6. Flow Collector 위치 상세 설정
  • 6. #2. Netflow Configuration – Flow Records 2 Fabric – Access Policies - Interface Porlices - Policies - Analytics - Netflow Records 1. Collect Parameters 설정 2. Match Parameters 설정
  • 7. #2. Netflow Configuration – Flow Records Parameter 종류 Address Family 지원 Destination IPv4/6 IPv4/IPv6 IPv4 /IPv6 Destination IPv4 IPv4 IPv6 Destination IPv6 IPv6 IPv6 Destination MAC CE Non-IP traffic only Destination Port IPv4/IPv6 IPv4 / IPv6 Ethertype CE Non-IP traffic only IP Protocol IPv4/IPv6 IPv4 / IPv6 Source IPv4/6 IPv4/IPv6 IPv4 / IPv6 Source IPv4 IPv4 IPv4 Source IPv6 IPv6 IPv6 Source MAC CE Non-IP traffic only Source Port IPv4/IPv6 IPv4 / IPv6 IP TOS IPv4/IPv6 현재 지원 불가 VLAN CE/IPv4/IPv6 현재 지원 불가
  • 8. #2. Netflow Configuration – Flow Records Collection Parameters Flow Record 포함 내용 Bytes counter 항상 전송 (32bit) Pkts Counter 항상 전송 (32bit) Pkt Disposition 전송하지 않음 Sampler ID 전송하지 않음 Source Interface 항상 전송 TCP Flags IP Protocol matching 시에만 전송 First Pkt Timestamp 항상 전송 Recent Pkt Timestamp 항상 전송
  • 9. #2. Netflow Configuration – Flow Records 2 Fabric – Access Policies - Interface Porlices - Policies - Analytics - Netflow Monitor 1. Netflow Monitor 이름 설정 2. Flow Record 설정 3. Flow Collector 설정
  • 10. #3. Netflow Interface Configuration Bridge Domain(SVI) L3OUT Logical Interface Profile Flow Monitor Flow Exporter Flow Record Logical Node Profile 1 Netflow 구성을 원하는 Tenant에 적용하는 방법 LEAF Interface Policy Group Flow Monitor Flow Exporter Flow Record 2 Netflow 구성을 원하는 Interface에 적용하는 방법 vPC, PC, Access Port
  • 11. #3. Netflow Interface Configuration – Interface 설정 방법 1 Fabric – Access Policies - Interface Porlices - Policy Groups - Leaf Policy Groups - vPC or PC or Access Port 1. Netflow Monitor Polices (IP Filter Type 및 Flow Monitor Policy 설정)
  • 12. #3. Netflow Interface Configuration – L3 Outside 설정 방법 1 Tenant – Networking - External Routed Networks - L3OUT EPG - Logical Node Profiles - Logical Interface Profiles 1. Netflow Monitor Polices (IP Filter Type 및 Flow Monitor Policy 설정) Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
  • 13. #3. Netflow Interface Configuration – BD 설정 방법 1 Tenant – Networking - Bridge Domain - BD - Netflow Monitor Polices (IP Filter Type 및 Flow Monitor Policy 설정) Netflow Monitor 대상을 Common에 두면 Multi-Tenant를 위해 편리하게 구성 가능
  • 14. LEAF Switch에서 Flow 구성 확인
  • 16. Flow Collector VM에서 다중 인터페이스 구성 Tip. 1. Flow Collector 위치가 Private 구간일 경우 , Flow Collector의 위치를 특정 Tenant EPG에 바인딩 2. SMC와는 기존 eth0과 통신하도록 구성
  • 17. ACI에서 생성된 Netflow를 StealthWatch에서 확인
  • 18. SMC에서 Flow 확인 – Host List ACI EPG 또는 BD subnet 이름과 StealthWatch Host Group 연계
  • 19. SMC에서 Flow 확인 – Host List ACI EPG or BD Name = SMC Host Groups
  • 20. SMC에서 Flow 확인 – Host List ACI EPG or BD Name = SMC Host Groups ACI EP
  • 21. SMC에서 Flow 확인 – Host List ACI EPG or BD Name = SMC Host GroupsACI EP