Uyini umehluko phakathi kwe-NetFlow ne-IPFIX Yokuqapha Ukugeleza Kwenethiwekhi?

I-NetFlow ne-IPFIX womabili ubuchwepheshe obusetshenziselwa ukuqapha nokuhlaziya ukugeleza kwenethiwekhi. Banikeza imininingwane ngamaphethini wethrafikhi yenethiwekhi, esiza ekuthuthukisweni kokusebenza, ukuxazulula izinkinga, nokuhlaziya ukuphepha.

I-NetFlow:

Iyini i-NetFlow?

I-NetFlowyisixazululo sokuqala sokuqapha ukugeleza, esasungulwa yiCisco ngasekupheleni kwawo-1990. Kukhona izinguqulo eziningana ezahlukene, kodwa ukusetshenziswa okuningi kusekelwe ku-NetFlow v5 noma i-NetFlow v9. Nakuba inguqulo ngayinye inamakhono ahlukene, ukusebenza okuyisisekelo kuhlala kufana:

Okokuqala, irutha, iswishi, i-firewall, noma olunye uhlobo lwedivayisi luzothwebula ulwazi “ngokugeleza” kwenethiwekhi - ngokuyisisekelo isethi yamaphakethe abelana ngesethi evamile yezici ezifana nomthombo nekheli okuyiwa kulo, umthombo, nembobo yendawo, nephrothokholi. uhlobo. Ngemuva kokuthi ukugeleza kuthule noma sekudlule isikhathi esichazwe ngaphambilini, idivayisi izothekelisa amarekhodi okugeleza ebhizinisini elaziwa ngokuthi “umqoqi wokugeleza”.

Okokugcina, "i-flow analyzer" yenza umqondo walawo marekhodi, ihlinzeka ngemininingwane ngendlela yokubonwayo, izibalo, nokubika okuningiliziwe komlando nesikhathi sangempela. Empeleni, abaqoqi nabahlaziyi bavame ukuba yibhizinisi elilodwa, ngokuvamile elihlanganiswe libe yisisombululo esikhulu sokuqapha ukusebenza kwenethiwekhi.

I-NetFlow isebenza ngesisekelo esiqinile. Lapho umshini weklayenti ufinyelela kuseva, i-NetFlow izoqala ukuthwebula futhi ihlanganise imethadatha kusukela ekugelezeni. Ngemuva kokuthi iseshini inqanyuliwe, i-NetFlow izothekelisa irekhodi elilodwa eliphelele kumqoqi.

Yize isasetshenziswa kakhulu, iNetFlow v5 inenani lemikhawulo. Izinkambu ezithunyelwe zilungisiwe, ukuqapha kusekelwa kuphela lapho kubhekwa khona, futhi ubuchwepheshe besimanje njenge-IPv6, MPLS, ne-VXLAN abusekelwe. I-NetFlow v9, futhi ebizwa ngokuthi i-Flexible NetFlow (FNF), ibhekana neminye yale mikhawulo, ivumela abasebenzisi ukuthi bakhe izifanekiso ezenziwe ngokwezifiso futhi bangeze ukusekela kobuchwepheshe obusha.

Abathengisi abaningi futhi banokusebenzisa kwabo okuphathelene ne-NetFlow, okufana ne-jFlow evela kuJuniper kanye ne-NetStream evela kuHuawei. Yize ukucushwa kungase kuhluke ngandlela thile, lokhu kuqaliswa kuvame ukukhiqiza amarekhodi okugeleza ahambisana nabaqoqi be-NetFlow nabahlaziyi.

Izici ezibalulekile ze-NetFlow:

~ I-Flow Data: I-NetFlow ikhiqiza amarekhodi okugeleza afaka imininingwane efana namakheli e-IP womthombo nendawo, izimbobo, izitembu zesikhathi, ukubalwa kwephakethe nebhayithi, nezinhlobo zephrothokholi.

~ Ukuqapha Traffic: I-NetFlow inikeza ukubonakala kumaphethini wethrafikhi yenethiwekhi, okuvumela abalawuli ukuthi bakhombe izinhlelo zokusebenza eziphezulu, izindawo zokugcina, nemithombo yethrafikhi.

~Ukutholwa Okungaqondakali: Ngokuhlaziya idatha yokugeleza, i-NetFlow ingathola okudidayo njengokusebenzisa umkhawulokudonsa oweqile, ukuminyana kwenethiwekhi, noma amaphethini ethrafikhi angajwayelekile.

~ Ukuhlaziywa Kwezokuphepha: I-NetFlow ingasetshenziselwa ukuthola nokuphenya izehlakalo zokuphepha, njengokuhlaselwa kwe-distributed denial-of-service (DDoS) noma imizamo yokufinyelela engagunyaziwe.

Izinguqulo ze-NetFlow: I-NetFlow iye yavela ngokuhamba kwesikhathi, futhi izinguqulo ezihlukene sezikhishiwe. Ezinye izinguqulo eziphawulekayo zifaka i-NetFlow v5, i-NetFlow v9, ne-Flexible NetFlow. Inguqulo ngayinye yethula izithuthukisi kanye namakhono engeziwe.

IPFIX:

Iyini i-IPFIX?

Izinga le-IETF elavela ekuqaleni kwawo-2000, i-Internet Protocol Flow Information Export (IPFIX) ifana kakhulu ne-NetFlow. Eqinisweni, i-NetFlow v9 isebenze njengesisekelo se-IPFIX. Umehluko omkhulu phakathi kwalokhu okubili ukuthi i-IPFIX iyindinganiso evulekile, futhi isekelwa abathengisi abaningi benethiwekhi ngaphandle kweCisco. Ngaphandle kwezinkambu ezimbalwa ezengeziwe ezingezwe ku-IPFIX, amafomethi acishe afane. Eqinisweni, i-IPFIX kwesinye isikhathi ibizwa nangokuthi "NetFlow v10".

Ngenxa yokufana kwayo ne-NetFlow, i-IPFIX ijabulela ukwesekwa okubanzi phakathi kwezixazululo zokuqapha inethiwekhi kanye nemishini yenethiwekhi.

I-IPFIX (I-Internet Protocol Flow Information Export) iyiphrothokholi evulelekile eyakhiwe i-Internet Engineering Task Force (IETF). Isekelwe ekucacisweni kwe-NetFlow Version 9 futhi inikeza ifomethi emisiwe yokuthekelisa amarekhodi agelezayo kusuka kumadivayisi enethiwekhi.

I-IPFIX yakhela phezu kwemiqondo ye-NetFlow futhi iyandise ukuze inikeze ukuguquguquka okwengeziwe nokusebenzisana kubathengisi abahlukene namadivayisi. Yethula umqondo wezifanekiso, okuvumela incazelo eguquguqukayo yesakhiwo serekhodi eligelezayo nokuqukethwe. Lokhu kuvumela ukufakwa kwezinkambu zangokwezifiso, ukusekelwa kwezivumelwano ezintsha, nokwandiswa.

Izici ezibalulekile ze-IPFIX:

~ Indlela Esekelwe Isifanekiso: I-IPFIX isebenzisa izifanekiso ukuchaza isakhiwo nokuqukethwe kwamarekhodi agelezayo, enikeza ukuguquguquka ekuhlanganiseni izinkambu zedatha ezahlukene kanye nolwazi oluqondene nephrothokholi.

~ Ukusebenzisana: I-IPFIX iyindinganiso evulekile, eqinisekisa amandla okuqapha ukugeleza okungaguquki kubo bonke abathengisi benethiwekhi abahlukene namadivayisi.

~ Ukusekela kwe-IPv6: I-IPFIX isekela i-IPv6, iyenze ifaneleke ukuqapha nokuhlaziya ithrafikhi kumanethiwekhi e-IPv6.

~Ukuvikeleka Okuthuthukisiwe: I-IPFIX ihlanganisa izici zokuphepha ezifana nokubethela kwe-Transport Layer Security (TLS) nokuhlola ubuqotho bomlayezo ukuze kuvikelwe ubumfihlo nobuqotho bokugeleza kwedatha ngesikhathi sokudlulisa.

I-IPFIX isekelwa kabanzi ngabathengisi bemishini yenethiwekhi abahlukahlukene, okwenza kube ukukhetha okungathathi hlangothi nokwamukelwa kabanzi kokuqapha ukugeleza kwenethiwekhi.

 

Ngakho-ke, yini umehluko phakathi kwe-NetFlow ne-IPFIX?

Impendulo elula ukuthi i-NetFlow iyiphrothokholi yokuphathelene neCisco eyethulwa cishe ngo-1996 futhi i-IPFIX ingumzalwane wayo osezingeni eligunyaziwe.

Womabili amaphrothokholi asebenza ngenjongo efanayo: ukunika amandla onjiniyela benethiwekhi nabalawuli ukuthi baqoqe futhi bahlaziye ukugeleza kwethrafikhi ye-IP yezinga lenethiwekhi. I-Cisco ithuthukise i-NetFlow ukuze izishintshi zayo namarutha akwazi ukukhipha lolu lwazi olubalulekile. Ngokunikezwa amandla egiya leCisco, iNetFlow yasheshe yaba indinganiso ye-de-facto yokuhlaziywa kwethrafikhi yenethiwekhi. Kodwa-ke, izimbangi zemboni zabona ukuthi ukusebenzisa iphrothokholi yobunikazi elawulwa imbangi yayo enkulu kwakungewona umqondo omuhle futhi yingakho i-IETF ihole umzamo wokulinganisa umthetho olandelwayo wokuhlaziywa kwethrafikhi, okuyi-IPFIX.

I-IPFIX isuselwe enguqulweni ye-NetFlow 9 futhi yethulwa ekuqaleni ngo-2005 kodwa kwathatha inani leminyaka ukuthola ukutholwa kwemboni. Kuleli qophelo, lezi zivumelwano ezimbili ziyafana futhi yize igama elithi NetFlow lisadlange kakhulu ukusetshenziswa okuningi (yize kungezona zonke) kuyahambisana nezinga le-IPFIX.

Nali ithebula elifingqa umehluko phakathi kwe-NetFlow ne-IPFIX:

Isici I-NetFlow IPFIX
Umsuka Ubuchwepheshe bobunikazi obuthuthukiswe ngabakwaCisco Iphrothokholi esezingeni lomkhakha esuselwe ku-NetFlow Version 9
Ukumisa I-Cisco-specific technology Vula izinga elichazwe yi-IETF ku-RFC 7011
Ukuvumelana nezimo Izinguqulo ezithuthukisiwe ezinezici ezithile Ukuvumelana nezimo okukhulu nokusebenzisana phakathi kwabathengisi
Ifomethi Yedatha Amaphakethe anosayizi ongashintshi Indlela esuselwe kusifanekiso yamafomethi erekhodi okugeleza enziwa ngendlela oyifisayo
Ukusekela Isifanekiso Ayisekelwe Izifanekiso ezinamandla zokufakwa kwenkambu evumelana nezimo
Ukusekelwa komthengisi Ikakhulukazi amadivayisi e-Cisco Ukusekelwa okubanzi kubo bonke abathengisi benethiwekhi
Ukunwebeka Ukwenza ngokwezifiso okukhawulelwe Ukufakwa kwezinkambu zangokwezifiso kanye nedatha eqondene nohlelo lokusebenza
Umehluko Wephrothokholi Izinguquko ezithile ze-Cisco Usekelo lwe-IPv6 yomdabu, izinketho ezithuthukisiwe zerekhodi lokugeleza
Izici Zokuvikela Izici zokuphepha ezinomkhawulo Ukubethela kwe-Transport Layer Security (TLS), ubuqotho bomlayezo

Ukuqapha Ukugeleza Kwenethiwekhiiqoqo, ukuhlaziya, nokuqapha ithrafikhi enqamula inethiwekhi ethile noma ingxenye yenethiwekhi. Izinjongo zingahluka kusukela ekuxazululeni izinkinga zokuxhuma ukuya ekuhleleni ukwabiwa komkhawulokudonsa wesikhathi esizayo. Ukuqapha ukuhamba nokusampula kwephakethe kungaba wusizo ekuhlonzeni nasekulungiseni izinkinga zokuphepha.

Ukuqapha okugelezayo kunikeza amaqembu enethiwekhi umbono omuhle wokuthi inethiwekhi isebenza kanjani, ihlinzeka ngemininingwane mayelana nokusetshenziswa kukonke, ukusetshenziswa kohlelo lokusebenza, izingqinamba ezingaba khona, okudidayo okungase kubonise izinsongo zokuphepha, nokuningi. Kunamazinga amaningana ahlukene namafomethi asetshenziswa ekuqapheni ukugeleza kwenethiwekhi, okuhlanganisa i-NetFlow, i-sFlow, ne-Internet Protocol Flow Information Export (IPFIX). Ngayinye isebenza ngendlela ethe ukuhluka kancane, kodwa zonke zihlukile ekuboneni isibuko sembobo kanye nokuhlolwa kwephakethe okujulile ngoba akuthathi okuqukethwe kwephakethe ngalinye elidlula echwebeni noma ngeswishi. Kodwa-ke, ukuqapha ukugeleza kunikeza ulwazi olwengeziwe kune-SNMP, ngokuvamile ekhawulelwe kwizibalo ezibanzi ezifana nokusetshenziswa kwephakethe kanye nomkhawulokudonsa.

Amathuluzi Okugeleza Kwenethiwekhi Kuqhathaniswa

Isici I-NetFlow v5 I-NetFlow v9 sFlow IPFIX
Vula noma Ubunikazi Ubunikazi Ubunikazi Vula Vula
Kususelwa kusampula noma ukugeleza Ngokuyinhloko Flow Ngokusekelwe; Imodi eyisampula iyatholakala Ngokuyinhloko Flow Ngokusekelwe; Imodi eyisampula iyatholakala Isampula Ngokuyinhloko Flow Ngokusekelwe; Imodi eyisampula iyatholakala
Ulwazi Luthunjiwe Imethadatha nolwazi lwezibalo, okuhlanganisa amabhayithi adlulisiwe, izinto zokubala zesikhombimsebenzisi nokunye Imethadatha nolwazi lwezibalo, okuhlanganisa amabhayithi adlulisiwe, izinto zokubala zesikhombimsebenzisi nokunye Izihloko Zephakethe Eliphelele, Ukulayisha Kwephakethe Lengxenye Imethadatha nolwazi lwezibalo, okuhlanganisa amabhayithi adlulisiwe, izinto zokubala zesikhombimsebenzisi nokunye
I-Ingress/Egress Monitoring I-Ingress Kuphela I-Ingress kanye ne-Egress I-Ingress kanye ne-Egress I-Ingress kanye ne-Egress
IPv6/VLAN/MPLS Support No Yebo Yebo Yebo

Isikhathi sokuthumela: Mar-18-2024