Академический Документы
Профессиональный Документы
Культура Документы
2012
kgrigori@cisco.com
25 2012
2011 Cisco and/or its affiliates. All rights reserved.
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
,
,
,
,
,
,
SLA
2011 Cisco and/or its affiliates. All rights reserved.
-
,
,
!
ping?
show ip route?
traceroute?
show interface?
WAN-
,
,
..
,
.
ISR-G2: 15.2(2)T1
ASR1K: XE 3.4S
AVC
AVC
Performance
Monitoring
Appliance
Email
Servers
Web
Servers
DPI
Branch
Office
1200
ISR G2
ASR 1000
AVC
on
ASR1K
Email
Servers
Management
Management
Data Center
Web
Servers
Data Center
Branch
Office
AVC
on
ISR G2
(HQoS,
PfR, WAAS)
, ,
WAN,
Internet
Cisco
IOS PA
FNF
ISR G2
ASR1K
ISR G2
ASR1K
BW
Transaction
Time
WebEx
3 Mb
150 ms
Citrix
10 Mb
500 ms
FNFv9
ISR G2
ASR1K
High
Med
Low
Reporting Tools
DPI engine
(NBAR2)
L7
2011 Cisco and/or its affiliates. All rights reserved.
Reporting
Tool
:
QoS PfR
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
TCP/UDP
(,
)
,
Stateful inspection
TCP/UDP
(, , )
IPv6 IPv6
transition
10
SCE
IOS NBAR
+150
+1200
IPv6
API
NBAR2
NBAR2
(DPI)
( SCE)
NBAR
1200 -
http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6558/ps6616/product_bull
etin_c25-627831.html
2011 Cisco and/or its affiliates. All rights reserved.
11
Categories
Sub-Categories
Application-Group
P2P-technology
Tunnel
Encrypted
file-sharing
browsing
net-admin
other
internet-privacy
instant-messaging
email
newsgroup
voice-and-video
business-and-productivity-tools
industrial-protocols
gaming
obsolete
trojan
layer3-over-ip
location-based-services
layer2-non-ip
client-server
other
routing-protocol
tunneling-protocols
network-management
voice-video-chat-collaboration
authentication-services
database
naming-services
terminal
streaming
p2p-networking
p2p-file-transfer
control-and-signaling
inter-process-rpc
remote-access-terminal
network-protocol
commercial-media-distribution
rich-media-http-content
license-manager
epayement
storage
backup-systems
one-click-hosting
ftp-group
other
ipsec-group
imap-group
irc-group
kerberos-group
ldap-group
sqlsvr-group
netbios-group
nntp-group
pop3-group
snmp-group
tftp-group
fasttrack-group
gnutella-group
skinny-group
edonkey-emule-group
bittorrent-group
smtp-group
windows-live-messanger-group
yahoo-messenger-group
flash-group
skype-group
corba-group
n
y
unassigned
n
y
unassigned
n
y
unassigned
12
Netflow v9
Top-N
NBAR
interface GigabitEthernet0/0/2
ip nbar protocol-discovery
ASR-1000#sh ip nbar protocol-discovery top-n
GigabitEthernet0/0/2
[snip]
Protocol
Output
-----
------
Packet Count
Packet Count
Byte Count
Byte Count
secure-http
youtube
bittorrent
Input
1352704
413286
2042671577
28254387
3395000
18000
15000000
208000
584678
330847
640511303
76683682
2357000
196000
8847000
353000
139631
66440
207492818
3869014
1296000
17000
3575000
80000
37186
82432
11025469
113101301
81000
248000
84000
2465000
13
IPv4/IPv6
MC/BR
Internet
BR
WAN1
(IP-VPN)
class-map match-any peer2peer
match protocol kazaa2
match protocol gnutella
?
match protocol fastrack
BR
Native IPv6
BR
IPv4
HQ
?
?
MC/BR
policy-map limit-p2p
class
peer2peer
WAN2
(IPVPN, DMVPN)
bandwidth
percent 10
MC/BR
BR
interface Serial1
service-policy input limit-p2p
MC/BR
14
Category, sub-category, p2p, tunnel
filesharing
FTP, CIFS, Bittorrent ..
MC/BR
Internet
class-map my-class2
class-map my-class2
match protocol attribute category filesharing
match protocol attribute category filesharing
match not class-map excluded-apps
WAN1
(IP-VPN)
MC/BR
FTP, CIFS
class-map match-any excluded-apps
match protocol ftp
match protocol cifs
BR
Native IPv6
BR
MC/BR
IPv4
HQ
email
outlook, gmail, hotmail,
yahoo-mail, ..
BR
WAN2
(IPVPN, DMVPN)
class-map my-class1
match protocol attribute category email
BR
MC/BR
15
ip nbar pdlm
<path_to_pdlm_file>
PDLM
(bittorrent.pdlm ,
citrix.pdlm ..)
NBAR2
PDLM
PDLM
ip nbar protocol-pack
<path_to_protocol_pack>
PDLM
Protocol Pack
16
custom protocol-> www.cisco.com
PDLM-
custom protocol MQC
http://www.cisco.com/en/US/tech/tk543/tk757/technologies_tech_note09186a0080094ac5.shtml
17
, , ..:
Bit rate (bps), , ..
CISCO-NBARPROTOCOL-DISCOVERY-MIB
Flexible NetFlow ( QoS) Performance
Agent (PA)
18
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
19
X
DSCP=EF
,
DSCP = EF
RTP
Voice
DSCP=EF
Fast1/0
Desk1
2011 Cisco and/or its affiliates. All rights reserved.
20
Metadata
Prot
L4
Src
L4
Dst
Application
Vendor
Dial From
Dial To
Caller ID
10.1.1.2
20.1.1.2
UDP
2000
4000
VideoConference
(Audio)
Cisco
83922564
85268229
Ivan
Ivanov
Metadata DB
1.
Metadata
QoS
Metadata
10.1.1.2
2.
Metadata
3.
Metadata DB
IP Dst
Metadata DB
IP Src
20.1.1.2
21
MC/BR
Metadata Signaling
WAN1
(IP-VPN)
MC/BR
BR
BR
HQ
class-map my-class
match metadata global-session-id <>
match metadata end-point [model | vendor | version]
BR
MC/BR
WAN2
(IPVPN, DMVPN)
BR
MC/BR
22
MSP
BR
MC/BR
Metadata
MC/BR
WAN1
(IP-VPN)
BR
BR
HQ
MC/BR
NBAR
IP Src
10.1.1.1
IP Dst
125.1.1.1
Prot
90
L4 Src
4080
L4 Dst
1234
Metadata
Application
Vendor
telepresence
Cisco
rtp
telepresencevideo
Dial
From
1001
Dial
To
2002
User
Bob
23
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
24
Link Layer
Header
NetFlow
Interface
ToS
NetFlow
Protocol
IP Header
TCP/UDP
Header
Source
IP Address
Destination
IP Address
Source
Port
L2-L4
7
: , ,
, ..
NBAR
Destination
Port
L3-L7
L3-L4 +
Data
Packet
Deep Packet
(Payload)
Inspection
NBAR
25
SrcIf
Fa1/0
Fa1/0
Fa1/0
Fa1/0
NetFlow
SrcIPadd
173.100.21.2
173.100.3.2
173.100.20.2
173.100.6.2
DstIf
Fa0/0
Fa0/0
Fa0/0
Fa0/0
DstIPadd
10.0.227.12
10.0.227.12
10.0.227.12
10.0.227.12
Export
Flow Monitor 1
DstIPadd
10.0.227.12
10.0.227.12
10.0.227.12
10.0.227.12
Protocol
11
6
11
6
TOS
80
40
80
40
Export
Export
Export
Flow Monitor 2
Protocol
11
6
11
6
TOS
80
40
80
40
Flgs
10
0
10
0
Flow Monitor 3
SrcIf
Fa1/0
Fa1/0
Fa1/0
Fa1/0
SrcIPadd
173.100.21.2
173.100.3.2
173.100.20.2
173.100.6.2
DstIf
Fa0/0
Fa0/0
Fa0/0
Fa0/0
26
News
app_record
match ipv4 source
address
match ipv4 destination address
match ..
Source IP
collect application name
#2
10.1.1.1
Destination IP
173.194.34.134
Destination IP
72.163.4.161
Source Port
20457
Source Port
30307
Destination Port
23
Destination Port
80
Layer 3 protocol
Layer 3 protocol
TOS byte
TOS byte
Ingress Interface
Ethernet 0
Ingress Interface
Ethernet 0
Src. IP
Src. IP
Dest. IP
Dest. IP
10.1.1.1
10.1.1.1
173.194.34.13
4.
173.194.34.134
10.1.1.1
72.163.4.161
Src. Port
Src.
Port
20457
20457
30307
NetFlow
Dest.
Dest.
Port
Port
80
23
Layer 3
Layer 3
Prot.
Prot.
6
6
TOS
TOS
Byte
Byte
0
0
Ingress Intf.
Ingress Intf.
Ethernet 0
Ethernet 0
HTTP
80
Ethernet 0
Youtube
App
Name
Times
tamps
Bytes
Packets
Flow entry
(, , ..)
27
Exporter
Flow Record
int s3/0
ip flow monitor my-monitor input
Flow Monitor
28
flow
record ( Netflow)
NBAR
IPv4/IPv6
Flow class-id ,
, collector
(, Plixer)
2011 Cisco and/or its affiliates. All rights reserved.
APP NAME
========
nbar ssh
nbar telnet
NBAR my-app
DSCP Class-id
==== ========
0x20 Management
0x20 Management
0x22
29
NEW
3.7.0S
show flow mon <app_mon> cache
IPV4 SRC ADDR
===============
10.0.1.1
APP NAME
=============
nbar http
Hostname
===============
www.google.com
URL
===========
/news
News
HTTP_record
match ipv4 source address
match ipv4 destination address
match application name
match application http hostname
match application http URL
30
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
31
(Media Monitoring)
30%
(Performance Agent)
40%
-
, , ?
(Flexible Netflow NBAR/NBAR2)
HTTP HTTP
32
ISR G2:
ASR1K:
SLA?
WAN
Branch
NFv9
(
, Top N)
WAN
NBAR/NBAR2
Netflow v9 (IPFIX
)
WAAS Express
WAAS
33
Clients
Client
Network
Server
Network
IOS PA
Application
Servers
, WAN )
IOS PA ISR end-user
(NAM)
2011 Cisco and/or its affiliates. All rights reserved.
34
Client Side
Un-optimized
WAN Side
Optimized
Server Side
Un-Optimized
WAN
IOS PA
SPAN
or FA
FA
Pass-through
NAM 5.1
WAAS
TCP- 3 ,
WAAS-, original optimized bytes
Application Response Time (ART) : transaction time, network delay response time
NAM
2011 Cisco and/or its affiliates. All rights reserved.
35
IOS PA
Client
Server
SYN
(RT)
SND
SYN-ACK
CND
Response Time
t(First response pkt) t(Last request pkt)
ACK
Transaction
Request 1
Time (TT)
ACK
Request
Request 1 (Cont)
RT
TT
DATA 1
DATA 2
Network
DATA 3
ACK 3
Delay (ND)
DATA 4
DATA 5
DATA 3
DATA 4
ACK 6
Retrans
mission
DATA 6
Response
Request 2
36
IOS PA
ART
Client/Server Bytes
Client/Server Packets
Input/Output Interface
IP DSCP
WAAS Express
Input/Output Bytes
(7-bucket histogram)
Number of Retransmissions
Number of Transactions
Input/Output LZ Bytes
Client/Server Bytes
Client/Server Packets
37
NBAR2
1. flow exporter
2. flow record mace
3. flow monitor mace
4. class-map
5. policy-map mace
mace_global
6. mace
enable
NBAR2
38
FNFv9
Alarm
Syslog
FNFv9
Alarm
Syslog
Voice/video
Endpoints
Management Tool
i.e. PAM
Voice/video
Endpoints
WAN
Medianet
Perf Monitoring
- jitter, loss,...
NBAR2
alert/alarm
Netflow v9
, ,
SLA
39
Router 1
Router 2
Active Probing
IPSLA Sender
IPSLA Responder
Flexible
Netflow
PerfMon
Flow Record
Flexible Netflow -
Flow Record
40
RTP
41
Flexible
Netflow
Medianet
Performance Monitor
Performance
Agent
..
?
2011 Cisco and/or its affiliates. All rights reserved.
42
IOS XE
3.8S
..
,
2011 Cisco and/or its affiliates. All rights reserved.
43
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
44
HQ
NBAR2
IP Packet
ToS
Protocol
TCP/UDP Packet
Src
IP
Addr
Dest
IP
Addr
Src
Port
Dst
Port
Campus WAN
Aggregation
Data Packet
Sub-Port/Deep Inspection
BR
BR
Vendor
Dial From
Dial To
Caller ID
Video-Conference
(Audio)
Cisco
83922564
85268229
Albert
Albatross
Si
App
Si
Metadata
Campus
Distribution
ACL
Src IP
Dst IP
S Port
D Port
DSCP
1.1.1.1
1.1.1.2
16384
16399
46
Campus
Access
45
Committed BW
(50% of the line)
Excess BW
(50% of the line)
Application
BW
Priority
Business Critical
Committed 50%
High
Browsing
Normal
Internal
Browsing
Remaining
Normal
policy-map internal-browsing-policy
class internal-browsing
bandwidth remaining percent 60
policy-map my-network-policy
class business-critical
priority percent 50
class browsing
bandwidth remaining percent 30
service-policy internal-browsing-policy
interface Serial0/0/0
service-policy output my-network-policy
Business-Critical:
High Priority
50% committed
Remaining:
70% of Excess BW
(=35% of line)
Browsing:
Internal-Browsing: 30% of Excess BW
60% of Browsing
(=15% of the line)
46
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
48
WAN 1
High SLA
WAN 2
Med SLA
Internet
No SLA
WAN
LAN
WAN
HTTP
WAN
LAN
WAN
,
-
49
WAN- Internet
WAN 2
Med SLA
Internet
No SLA
HTTP
WAN
LAN
real-time
50
Detect high
jitter
Internet
ISP-2 (Secondary)
-
Loss > 10%
ISP1
Internet
ISP
VDI
Voice&Video
Cloud Service
ISP-1 (Primary)
WAN
Latency > 200ms; Jitter > 30ms
VDI-
Loss > 5%
- SP-A
VDI - SP-B
ISP
51
MC/BR
WAN1
(IP-VPN)
MC
BR
:
Reachability, Delay, Loss, Jitter, MOS,
Throughput, Load / $Cost
BR
HQ
MC/BR
MC/BR
BR
WAN2
(IPVPN, DMVPN)
MC/BR
BR
, ,
/
52
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
53
Cisco Prime NAM
ISR G2 SRE
Cisco Prime NAM
WAAS VB
Cisco ISR G2 NAM Blade
SPAN
Cat65xx/C76xx
NAM1/NAM2 Blades
NAM 2200 Series Appliance
ERSPAN
RSPAN
NetFlow
CEF
VACL
WAAS
PA
2011 Cisco and/or its affiliates. All rights reserved.
55
NAM
TCP
Cisco Prime Infrastructure 1.2
56
, , ..
57
Bittorrent?
58
, bittorrent
59
:
,
/,
..
60
61
NBAR2
Metadata
Flexible Netflow
Performance Monitoring
Quality of Service (QoS)
Performance Routing (PfR)
63
NBAR2
WAN, Internet edge, Datacenter edge
,
?
IOS PA
.
,
?
IOS PerfMon
.
Mediatrace.
Oracle
IOS PA
YouTube BitTorrent
NBAR2 QoS
.
64
Branch
Headend/Internet
ISR G2
ASR 1000
IOS 15.2(2)T1
IOS XE 3.4S
NBAR2
Performance Agent
Performance Monitor
Flexible Netflow
QoS
NBAR2
Performance Monitor
Flexible Netflow
QoS
Management
Cisco Prime
65
800
Advanced IP Services
1900
Data License
2900
Data License
3900
Data License
ASR1K
66
AVC
AVC ,
AVC
67
http://www.cisco.com/en/US/partner/docs/ios/ios_xe/qos/configuration/guid
e/clsfy_traffic_nbar_xe.html
Flexible Netflow - http://www.cisco.com/go/netflow
Performance Agent -
http://www.cisco.com/en/US/products/ps11671/index.html
Performance Monitor -
http://www.cisco.com/en/US/partner/docs/ios/media_monitoring/configurati
on/guide/mm_pasv_mon.html
Performance Routing - http://www.cisco.com/go/pfr
Prime NAM - http://www.cisco.com/go/nam
Prime Assurance Manager - http://www.cisco.com/go/pam
68
Cisco Expo
Linksys E900.
:
Cisco
,
:
15:00 25 16:30 26
www.ceq.com.ua
2011 Cisco and/or its affiliates. All rights reserved.
70