+7 (916) 741 5495
support@netams.com

    ïðîäóêòû è óñëóãè     î êîìïàíèè     ïðîåêòû     áèëëèíã     êîíòàêòû english   

Âíèìàíèå! Ýòî äîêóìåíòàöèÿ ê âåðñèè 3.4. Äëÿ âåðñèè 4.0 ñìîòðèòå çäåñü

Äîêóìåíòàöèÿ

Releases

Áàçà çíàíèé

Ïðèìåðû êîíôèãóðàöèè

 

Ïðîòîêîëèðîâàíèå çàïðîøåííûõ ññûëîê (URL)


Ïîääåðæêà ýòîé äîëãîæäàííîé âîçìîæíîñòè ïîÿâèëàñü â NeTAMS 3.3.3

×òî ïðîòîêîëèðóåòñÿ

Ïðè ðàáîòå ðÿäà ñåðâèñîâ data-source (êðîìå netflow) åñòü âîçìîæíîñòü "çàãëÿíóòü" âîâíóòðü IP-ïàêåòà è ïðîàíàëèçèðîâàòü ïðîòîêîëû "âûøå" ÷åì TCP/IP. Òàê, ê ïðèìåðó, ïîëüçîâàòåëüñêèé çàïðîñ ê âåá-ñàéòó ïðîèñõîäèò ñîãëàñíî ñïåöèôèêàöèè ïðîòîêîëà HTTP/1.1. Ïðè äîëæíîì àíàëèçå ïðîõîäÿùèõ ïàêåòîâ ñðåäñòâàìè NeTAMS ñòàëî âîçìîæíûì "çàïîìèíàòü" çàïðàøèâàåìóþ ññûëêó è ñîõðàíÿòü åå â òàáëèöå monitor.  êîìïëåêòå ïîñòàâêè NeTAMS èäåò "íåäîðàçâèòûé" ñêðèïò, ïîçâîëÿþùèé êàê-òî ïðîñìàòðèâàòü ñîáðàííóþ èíôîðìàöèþ.

Êàê âêëþ÷èòü

  1. Ñîáðàòü è ïîñòàâèòü íîâóþ âåðñèþ NeTAMS
    Ñêà÷àòü êàê îáû÷íî äèñòðèáóòèâ, ðàñïàêîâàòü, ñêîìïèëèðîâàòü, óñòàíîâèòü. Ïðè êîìïèëÿöèè ïî óìîë÷àíèþ ñáîðêà áóäåò âåñòèñü ñ êëþ÷îì -DLAYER7_FILTER. Íå çàáóäüòå óñòàíîâèòü íîâûå CGI-ñêðèïòû, îñîáåííî monitor.cgi.

  2. Íàñòðîèòü ñåðâèñ data-source
    Ïðîïèøèòå â êîíôèãóðàöèþ íóæíîãî ñåðâèñà íîâûé ïàðàìåòð: layer7-detect urls

  3. Ñîçäàòü íîâóþ ïîëèòèêó ó÷åòà
    Â êîíôèãóðàöèè ñåðâèñà processor äîáàâüòå îïèñàíèå íîâîé ïîëèòèêè:
    policy name urls target layer7-detect
    
  4. Óêàçàòü ïîëèòèêó ó÷åòà äëÿ òåõ þíèòîâ, êîòîðûå íàäî îòñëåæèâàòü
     êîíôèãóðàöèè ñåðâèñà processor äëÿ íóæíûõ þíèòîâ äîáàâüòå íîâóþ ïîëèòèêó ó÷åòà:
    unit host name pupkin ip 172.16.1.3 acct-policy urls
    
    èëè, äëÿ âñåõ þíèòîâ
    default acct-policy urls
    
  5. Íàñòðîèòü ñåðâèñ ìîíèòîðèíãà
    Êàê îïèñàíî â ýòîì äîêóìåíòå. Äîïîëíèòåëüíûõ äåéñòâèé íå òðåáóåòñÿ. Ñïåöèàëüíî óêàçûâàòü þíèòû, êîòîðûå õî÷åòñÿ ìîíèòîðèòü íà layer7, íå òðåáóåòñÿ. Åñëè æå âàñ èíòåðåñóåò ïîëíûé ìîíèòîðèíã êàêîãî-òî þíèòà (ïî-ñòàðîìó), òîãäà òàêîé þíèò óêàçûâàòü âñå æå íåîáõîäèìî.

  6. (Îïöèîíàëüíî) îáíîâèòü SQL-òàáëèöó ñåðâèñà monitor
    Åñëè âû èñïîëüçîâàëè ìîíèòîðèíã ðàíåå (òàáëèöà monitor óæå ñóùåñòâóåò), åå íåîáõîäèìî îáíîâèòü:
    mysql netams
    alter table monitor add column layer7 varchar(80);
    

  7. Çàïóñòèòü NeTAMS

Ïðîâåðêà ðàáîòû

Ðàáîòîñïîñîáíîñòü ìåõàíèçìà ìîíèòîðèíãà ññûëîê ìîæíî ïðîâåðèòü êîìàíäàìè:
#netamsctl show ds     
host: localhost port: 20001 login: anton password: aaa
cmd: show ds 
 Data-source ID=1 type LIBPCAP source xl1:0 loop 82356480 average 35 mcsec
    Perf: average skew delay 2676 mcsec, PPS: 1060, BPS: 904985
    IP tree: 258 nodes [12] + 4 dlinks [1024] + 254 unodes [20] = 12272 bytes
    Flows: 1644/2507 act/inact entries (796992 bytes), 3332872 flows sent
    HASH: size=65536, 1644 flows hashed, 1622 nodes used, max chain= 2
    FIFO: 0/1871 used/ready messages, each 152, total 284392 bytes
    Libpcap xl1 : EN10MB: 83735013 packets received, 488394 dropped

Ýòà êîìàíäà ïîêàçûâàåò, ÷òî data-source äåéñòâèòåëüíî ïîëó÷àåò òðàôèê è âûäàåò ñåðâèñó processor èíôîðìàöèþ î ïðîøåäøèõ ïîòîêàõ.
#netamsctl show monitor
host: localhost port: 20001 login: anton password: aaa
cmd: show monitor 
service monitor 1
Monitoring to storage: 1
Units: 
Packets monitored: 1985769
Ýòà êîìàíäà ïîêàçûâàåò, ÷òî ñåðâèñ ìîíèòîðèíãà ïîëó÷àåò èíôîðìàöèþ î ïîòîêàõ è ïèøåò åå â áàçó.
debug ds_ip
debug monitor
Ïîêàæåò, îïðåäåëÿþòñÿ ëè ññûëêè â ïðîõîäÿùåì òðàôèêå è èäåò ëè ïðèñâîåíèå àòðèáóòà LAYER7 èíôîðìàöèè î ïîòîêàõ.
mysql netams
select count(*) from monitor where layer7 != NULL;
Ïîêàçûâàåò, ñêîëüêî ñòðîê ñîáðàëîñü â òàáëèöå ìîíèòîðèíãà ñ èíôîðìàöèåé î ññûëêàõ.

Ïðîáëåìû

  • Ìîíèòîðèíã â SQL áàçó àêòèâíî ïîæèðàåò äèñêîâîå ïðîñòðàíñòâî! Íàïðèìåð, çà íåäåëþ ðàáîòû ïðîãðàììû, ïðè îáùåì êîëè÷åñòâå ïðîøåäøåãî òðàôèêà ïîðÿäêà 40 ãèãàáàéò (82 ìèëëèîíà ïàêåòîâ), â òàáëèöå ìîíèòîðèíãà îáðàçîâàëîñü 2 ìèëëèîíà çàïèñåé). Ðàçìåð SQL-òàáëèöû è èíäåêñà ñîñòàâëÿåò 240 ìåãàáàéò.
  • Ñòàòèñòèêà ïî òðàôèêó äëÿ çàïèñàííûõ â ìîíèòîðèíãå ññûëîê îòíîñèòñÿ íå ñ ñêà÷åííîé èíôîðìàöèè, à ê çàïðîñàì íà ñêà÷èâàíèå. Ò.å. íå íàäî îáðàùàòü íà öèôðû áîëüøîãî âíèìàíèÿ. Ê ñîæàëåíèþ, ýòî îáóñëîâëåííî íåññèìèòðè÷íîñòüþ õýø-ôóíêöèè ïðåîáðàçîâàíèÿ äàííûõ IP-çàãîëîâêà â èíäåêñ ïîòîêà, ò.å. òðàôèê "çàïðîñà" è "îòâåòà" ïîïàäåò â ðàçíûå ïîòîêè è äëèíà "îòâåòà", ò.å. ôàêòè÷åñêè ñêà÷åííîé ïî äàííîìó çàïðîñó èíôîðìàöèè, â òàáëèöå ìîíèòîðèíãà íå ó÷òåòñÿ. Èçìåíèòü òàêîå ïîâåäåíèå òåõíè÷åñêè î÷åíü íåïðîñòî.

Îòîáðàæåíèå ñòàòèñòèêè

Îòîáðàæåíèåì ñòàòèñòèêè çàíèìàåòñÿ ñêðèïò monitor.cgi, âõîäÿùé ñ äèñòðèáóòèâ. Êàê èì ïîëüçîâàòüñÿ - î÷åâèäíî èç åãî èíòåðôåéñà. Ïàðà ñêðèíøîòîâ:






[an error occurred while processing this directive]