Flow monitoring

From GEANT2-JRA1 Wiki

Contents

Flow Monitoring

Objectives

Goal: to identify and implement IP traffic flow monitoring tools within perfSONAR framework.

Testbed

Collector tools evaluation

perfSONAR flow monitoring MP and MAs

The following flow monitoring MP and MAs are available:

Overview of JRA1 flow monitoring MP and MAs

The MP and MAs have each there own specific use and intended user groups:

Flow Subscription MP
This MP enables users to subscribe to a stream of flow information packets as if they were coming directly from the selected routers. Useful if they want to use there own collector and processing tools.
Intended users: researchers, grid users
Flow RRD MA
The Flow RRD MA uses RRD files to store information like total number of packets, total number of flows, flows per protocol, and flows per well known TCP or UDP port.
Intended users: NOCs
Flow Selection and Aggregation MA
This MA acts like a wrapper around nfdump allowing nfdump style queries on stored logfiles.
Intended users: security people, ordinary users
Stager MA
The Stager MA enables you to retrieve all reports that are supported by stager.
Intended users: NOCs, grid users, organization executives

Flow Monitoring information and documents

Work in progress

  • AAI issues in netflow implementation

References

Conference calls and meetings

List of netflow tools

Here is the list of the netlow collector tool:

  • flow-tools:collection of scripts to perform elementary operation on flow records (storing, filtering, replaying, some statistical analysis). Used as a backend for many visualization tools, like flowscan.
  • NERD: Network Emergency Responder & Detector -NERD- is a security monitoring tool that collects and processes NetFlow data.
  • Stager: a generic tool for storage, aggregation and presentation of network statistics. Stager consist of a web application for data presentation, and a perl back-end for data storage and aggregation. The current version of Stager include backend modules to collect and aggregate data for NetFlow, MPing and SNMP.
  • nfdump tool collects and processes netflow data on the command line. Nfsen) tool is a graphical web based front end for the nfdump.
  • IPFlow: a netflow collector developed by UTC (University of Technology of Compiegne, France), mainly for its internal use.
  • FTAS: Flow Based Traffic Analysis System developed by (Cesnet)
  • FLOWD: a small, fast and secure netflow collector.
  • ntop: a network traffic probe that shows the network usage, supports netflow
  • cflowd : flow analysis tool for analyzing NetFlow
  • NetflowMet: a version of the Unix NeTraMet. It's an RTFM meter which takes its data from a Cisco router using Cisco's NetFlow data.

Some other netflow related tools:

  • FlowMon probe is a passive monitoring device that is able to supply statistics about IP flows in NetFlow v5 and v9 formats.

Some netflow related documents and useful links

Contact

Partners involved in netflow monitoring are CARNet, GARR, Uninett and SURFnet. Main contact is Hans Trompert. Or you can send a message to the Flow Monitoring mailing list gn2-jra1-flowmon at surfnet.nl.

Personal tools