Ïðîòîêîëèðîâàíèå çàïðîøåííûõ ññûëîê (URL)
Ïîääåðæêà ýòîé äîëãîæäàííîé âîçìîæíîñòè ïîÿâèëàñü â NeTAMS 3.3.3
×òî ïðîòîêîëèðóåòñÿ
Ïðè ðàáîòå ðÿäà ñåðâèñîâ data-source (êðîìå netflow) åñòü âîçìîæíîñòü "çàãëÿíóòü" âîâíóòðü IP-ïàêåòà è
ïðîàíàëèçèðîâàòü ïðîòîêîëû "âûøå" ÷åì TCP/IP. Òàê, ê ïðèìåðó, ïîëüçîâàòåëüñêèé çàïðîñ ê âåá-ñàéòó
ïðîèñõîäèò ñîãëàñíî ñïåöèôèêàöèè ïðîòîêîëà HTTP/1.1. Ïðè äîëæíîì àíàëèçå ïðîõîäÿùèõ ïàêåòîâ ñðåäñòâàìè
NeTAMS ñòàëî âîçìîæíûì "çàïîìèíàòü" çàïðàøèâàåìóþ ññûëêó è ñîõðàíÿòü åå â òàáëèöå monitor. Â êîìïëåêòå
ïîñòàâêè NeTAMS èäåò "íåäîðàçâèòûé" ñêðèïò, ïîçâîëÿþùèé êàê-òî ïðîñìàòðèâàòü ñîáðàííóþ èíôîðìàöèþ.
Êàê âêëþ÷èòü
- Ñîáðàòü è ïîñòàâèòü íîâóþ âåðñèþ NeTAMS
Ñêà÷àòü êàê îáû÷íî äèñòðèáóòèâ, ðàñïàêîâàòü, ñêîìïèëèðîâàòü, óñòàíîâèòü.
Ïðè êîìïèëÿöèè ïî óìîë÷àíèþ ñáîðêà áóäåò âåñòèñü ñ êëþ÷îì -DLAYER7_FILTER. Íå çàáóäüòå óñòàíîâèòü íîâûå
CGI-ñêðèïòû, îñîáåííî monitor.cgi.
- Íàñòðîèòü ñåðâèñ data-source
Ïðîïèøèòå â êîíôèãóðàöèþ íóæíîãî ñåðâèñà íîâûé ïàðàìåòð: layer7-detect urls
- Ñîçäàòü íîâóþ ïîëèòèêó ó÷åòà
 êîíôèãóðàöèè ñåðâèñà processor äîáàâüòå îïèñàíèå íîâîé ïîëèòèêè:
policy name urls target layer7-detect
- Óêàçàòü ïîëèòèêó ó÷åòà äëÿ òåõ þíèòîâ, êîòîðûå íàäî îòñëåæèâàòü
 êîíôèãóðàöèè ñåðâèñà processor äëÿ íóæíûõ þíèòîâ äîáàâüòå íîâóþ ïîëèòèêó ó÷åòà:
unit host name pupkin ip 172.16.1.3 acct-policy urls
èëè, äëÿ âñåõ þíèòîâ
default acct-policy urls
- Íàñòðîèòü ñåðâèñ ìîíèòîðèíãà
Êàê îïèñàíî â ýòîì äîêóìåíòå. Äîïîëíèòåëüíûõ äåéñòâèé íå òðåáóåòñÿ.
Ñïåöèàëüíî óêàçûâàòü þíèòû, êîòîðûå õî÷åòñÿ ìîíèòîðèòü íà layer7, íå òðåáóåòñÿ. Åñëè æå âàñ èíòåðåñóåò
ïîëíûé ìîíèòîðèíã êàêîãî-òî þíèòà (ïî-ñòàðîìó), òîãäà òàêîé þíèò óêàçûâàòü âñå æå íåîáõîäèìî.
- (Îïöèîíàëüíî) îáíîâèòü SQL-òàáëèöó ñåðâèñà monitor
Åñëè âû èñïîëüçîâàëè ìîíèòîðèíã ðàíåå (òàáëèöà monitor óæå ñóùåñòâóåò), åå íåîáõîäèìî îáíîâèòü:
mysql netams
alter table monitor add column layer7 varchar(80);
- Çàïóñòèòü NeTAMS
Ïðîâåðêà ðàáîòû
Ðàáîòîñïîñîáíîñòü ìåõàíèçìà ìîíèòîðèíãà ññûëîê ìîæíî ïðîâåðèòü êîìàíäàìè:
#netamsctl show ds
host: localhost port: 20001 login: anton password: aaa
cmd: show ds
Data-source ID=1 type LIBPCAP source xl1:0 loop 82356480 average 35 mcsec
Perf: average skew delay 2676 mcsec, PPS: 1060, BPS: 904985
IP tree: 258 nodes [12] + 4 dlinks [1024] + 254 unodes [20] = 12272 bytes
Flows: 1644/2507 act/inact entries (796992 bytes), 3332872 flows sent
HASH: size=65536, 1644 flows hashed, 1622 nodes used, max chain= 2
FIFO: 0/1871 used/ready messages, each 152, total 284392 bytes
Libpcap xl1 : EN10MB: 83735013 packets received, 488394 dropped
Ýòà êîìàíäà ïîêàçûâàåò, ÷òî data-source äåéñòâèòåëüíî ïîëó÷àåò òðàôèê è âûäàåò
ñåðâèñó processor èíôîðìàöèþ î ïðîøåäøèõ ïîòîêàõ.
#netamsctl show monitor
host: localhost port: 20001 login: anton password: aaa
cmd: show monitor
service monitor 1
Monitoring to storage: 1
Units:
Packets monitored: 1985769
Ýòà êîìàíäà ïîêàçûâàåò, ÷òî ñåðâèñ ìîíèòîðèíãà ïîëó÷àåò èíôîðìàöèþ î ïîòîêàõ è ïèøåò åå â áàçó.
debug ds_ip
debug monitor
Ïîêàæåò, îïðåäåëÿþòñÿ ëè ññûëêè â ïðîõîäÿùåì òðàôèêå è èäåò ëè ïðèñâîåíèå àòðèáóòà LAYER7 èíôîðìàöèè î ïîòîêàõ.
mysql netams
select count(*) from monitor where layer7 != NULL;
Ïîêàçûâàåò, ñêîëüêî ñòðîê ñîáðàëîñü â òàáëèöå ìîíèòîðèíãà ñ èíôîðìàöèåé î ññûëêàõ.
Ïðîáëåìû
- Ìîíèòîðèíã â SQL áàçó àêòèâíî ïîæèðàåò äèñêîâîå ïðîñòðàíñòâî! Íàïðèìåð, çà íåäåëþ ðàáîòû ïðîãðàììû, ïðè
îáùåì êîëè÷åñòâå ïðîøåäøåãî òðàôèêà ïîðÿäêà 40 ãèãàáàéò (82 ìèëëèîíà ïàêåòîâ), â òàáëèöå ìîíèòîðèíãà îáðàçîâàëîñü 2 ìèëëèîíà çàïèñåé).
Ðàçìåð SQL-òàáëèöû è èíäåêñà ñîñòàâëÿåò 240 ìåãàáàéò.
- Ñòàòèñòèêà ïî òðàôèêó äëÿ çàïèñàííûõ â ìîíèòîðèíãå ññûëîê îòíîñèòñÿ íå ñ ñêà÷åííîé èíôîðìàöèè, à ê çàïðîñàì íà ñêà÷èâàíèå. Ò.å. íå íàäî îáðàùàòü
íà öèôðû áîëüøîãî âíèìàíèÿ. Ê ñîæàëåíèþ, ýòî îáóñëîâëåííî íåññèìèòðè÷íîñòüþ õýø-ôóíêöèè ïðåîáðàçîâàíèÿ äàííûõ IP-çàãîëîâêà â èíäåêñ ïîòîêà, ò.å. òðàôèê "çàïðîñà" è "îòâåòà" ïîïàäåò â ðàçíûå ïîòîêè è äëèíà "îòâåòà", ò.å. ôàêòè÷åñêè ñêà÷åííîé ïî äàííîìó çàïðîñó èíôîðìàöèè, â òàáëèöå ìîíèòîðèíãà íå ó÷òåòñÿ. Èçìåíèòü òàêîå ïîâåäåíèå òåõíè÷åñêè î÷åíü íåïðîñòî.
Îòîáðàæåíèå ñòàòèñòèêè
Îòîáðàæåíèåì ñòàòèñòèêè çàíèìàåòñÿ ñêðèïò monitor.cgi, âõîäÿùé ñ äèñòðèáóòèâ. Êàê èì ïîëüçîâàòüñÿ
- î÷åâèäíî èç åãî èíòåðôåéñà. Ïàðà ñêðèíøîòîâ: