éåžžãHabrã®èŠèŽè ã¯ããã¹ããã¥ãŒã¹ã奜ããããäºåã«æºåãããäŒè©±èšç»ãç«ãŠãããšã«ããŸããã äŒè©±ã§èšãããå 容ãšã¯ãããã«ç°ãªããŸãããå ±æããããã¹ãŠã®æçšãªæ å ±ãå«ãŸããŠããŸãã
補åã«æ £ããŠããªã人ã®ããã«ãç§ãã¡ã®ãµã€ããšGitHubãããžã§ã¯ãããå§ããããšããå§ãããŸãã
ããããã£ã¹ããœãããŠã§ã¢éçºpodCast 58ã®äŒè©±ã®ããã¹ãã
ããªãèªèº«ã«ã€ããŠã®ããã€ãã®èšè
ç§ã®ååã¯Pavel Odintsovã§ããDDoSæ»æãæ€åºããFastNetMonãããžã§ã¯ãã®èè ã§ãã çŸåšãç§ã¯ãã³ãã³ã«äœãã§ãããäž»ã«ãããã¯ãŒã¯é¢é£ã·ã¹ãã ã®èšèšãšããã°ã©ãã³ã°ã«é¢é£ããåé¡ãæ±ã£ãŠããŸãã
æšæºçãªè³ªåã¯ãã©ã®ããã«ITã«åå ¥ããã®ã§ããïŒ ã©ãããããã£ãŠããã®ïŒ
ITã«å ¥ãã®ã¯å¶ç¶ã§ã¯ãããŸããã圌ã¯ç¶èŠªããæè¡ãžã®æã现éšãžã®æ³šæãç¹å®ã®åé¡ã«éäžããèœåãæ¯èŠªããåãç¶ããŸããã
ç§ã®å¹Œå°æã¯äž»ã«ãã¯ãã¯ã¹èªã®å±±ã®äžã§éãããŸãã-éå°å¹Žãã©ãžãªã§ã¯ãèªåã§ããœã³ã³ãçµã¿ç«ãŠãæ¹æ³ãéåžžã«é »ç¹ã«èª¬æãããŠããŸããã åœæã¯ãã¡ããç§ã®èœåãè¶ ããŠããŸããããããã§ãèå³ãçããæé ãªäŸ¡æ Œã®ã³ã³ãã¥ãŒã¿ãŒïŒ32Mb RAMãæèŒããCeleron 266ïŒã®ç»å Žã«ãããããããéèªãèªãã§å®éã«ãã¹ãŠãè©Šãããšãå¯èœã«ãªããŸããïŒ
ãã®åŸãããŸããŸãªæ¬ãéèªïŒäž»ã«PC Worldãæã«ã¯HackerïŒãèªãã§ãIRCãã£ããïŒããã«ã¡ã¯RusnetãšDalNetïŒïŒã«åº§ã£ãŠãã€ã³ã¿ãŒãããã§æè¡ææžãå匷ããŸããã 33kã®é床ã§ã
ãã°ããããŠãç§ã®è¡ããµãã©ã«æé ãªäŸ¡æ Œã®GPRSãšè¡æã€ã³ã¿ãŒããããããã€ããŒãçŸãããããããã®ç¬éããç§ã®å°éçãªç·Žç¿ãå§ãŸããŸããã ããã¯ãã¹ãŠãICQãä»ããç¥ãåããããPerlã§ç°¡åãªã¹ã¯ãªãããæžãããã«äŸé Œããããããæãããšããäºå®ããå§ãŸããŸããã ãã®ãããžã§ã¯ãã«å ããŠãWindowsã§éçºããã®ã¯ããªãé£ãããLinuxã«åãæ¿ãããšãã決å®ãäžããããšããç解ãåŸãããŸããã
æéãçµã€ã«ã€ããŠãç§ã®è¶£å³ã¯PerlãšLinuxã®äž¡æ¹ã«ã€ããŠããªãèªä¿¡ã®ããç¥èã«å€ãããPerlããã°ã©ããŒãšããŠREG.RU Domain Registrarã«å°±è·ããŸããã ãããå®éã«ã¯ãããã°ã©ãã³ã°ã ãã§ãªããLinuxã«é¢é£ããå€ãã®ã¿ã¹ã¯ã«åŸäºããŠããŸããã
æ»æã®çš®é¡ããµãã¿ã€ããšã¯äœããæ»æãéåžžã©ã®ããã«çºçããããã©ã®ããã«çµç¹åãããŠããã®ãããªãå¿ èŠãªã®ãã«ã€ããŠã®ããã€ãã®èšè
ããããã£ã¹ãã®ã¡ã€ã³ãããã¯ã¯FastNetMonãããžã§ã¯ãã§ããããããã®ã³ã³ããã¹ãã§èª¬æããŸãã å€ãã®DoS / DDoSæ»æãããããã¹ãŠã®çš®é¡ãããŠãŒã¶ãŒãä¿è·ããã¿ã¹ã¯ãèšå®ããŠããŸããã
ãŸããL3 / L4ãããã³ã«ã䜿çšããããªã¥ãŒã¡ããªãã¯æ»æã«çŠç¹ãåœãŠãŠããŸãã
ãããã®æ»æã¯ããµãŒãã¹ã®æ£ããæ©èœãäžæããããã«ããã£ãã«å®¹éãŸãã¯æ©åšã®æ§èœã䜿ãæããããšãç®çãšããŠããŸãã
å€ãã®å Žåãããã¯ç¹å®ã®ãµã€ãã«å¯Ÿããæ»æã§ãããç¹å®ã®ãªãã¬ãŒã¿ãŒãŸãã¯äŒç€Ÿå šäœã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«å¯Ÿããæ»æãããå ŽåããããŸããããã¯ã¯ããã«å±éºã§ãã
çŸåšã®çš®é¡ã®æ»æã«ã€ããŠèª¬æãããšããã£ãã«å®¹éã«å¯Ÿããæ»æã«äœ¿çšãããäž»ãªçš®é¡ã¯ãNTPãSSDPãSNMPãDNSå¢å¹ ã§ãã 圌ãã®æ¬è³ªã¯éåžžã«åçŽã§ãããã«ãŒã«ãã£ãŠå¶åŸ¡ãããäžéãã¹ãã䜿çšããŸãããã®ãã¹ãã¯ããã®ã¿ã€ãã®æ»æã«å¯ŸããŠè匱ãªãµãŒãã¹ãåããæ°åïŒå Žåã«ãã£ãŠã¯æ°åäžïŒã®ã€ã³ã¿ãŒãããããŒãã«èªåã®ã¢ãã¬ã¹ã®ä»£ããã«è¢«å®³è ã®ã¢ãã¬ã¹ã䜿çšããŠåœã®ãªã¯ãšã¹ããéä¿¡ããŸã ãããã®èŠæ±ãåä¿¡ããåŸããããã®ïŒå€ãã®å Žåãéåžžã«æ£åœãªïŒãµãŒãã¹ã¯å¿çãçæããæå®ããã被害è ããŒããžã®å€§éã®èŠæ±ã§å¿çãããããç¡å¹ã«ããŸãã
ãããã®æ»æã«å ããŠãã¹ããŒãã£ã³ã°ã䜿çšããæ»æã«æ³šç®ãã䟡å€ããããŸããå€ãã®å Žåããã¹ãã£ã³ã°ãããã€ããŒãšããŒã¿ã»ã³ã¿ãŒã®èª€ã£ãŠæ§æãããæ©åšããŸãã¯éåžå Žã§ãã®ãµãŒãã¹ãæäŸããç¹å¥ãªãã¹ãã£ã³ã°ãµãŒãã¹ã䜿çšããŠå®è¡ãããŸãã 圌ããšæŠãããšã¯ããå°é£ã§ãã圌ãã¯éåžžã«æŽç·ŽãããŠããå¯èœæ§ããããŸãã
ãã®ãããªæ»æã«å¯ŸåŠããæ¹æ³ã¯äœã§ããïŒ å¯èœãªè§£æ±ºç
ãããã®ãã£ãã«æ¯æžæ»æã«å¯ŸåŠããããã®å žåçãªã·ããªãªã¯ãããªãæ²ããã§ãã éåžžããµã€ããVPSããŸãã¯ãµãŒããŒã®ææè ã§ã¯ãªããããŒã¿ã»ã³ã¿ãŒãŸãã¯ãã¹ãã£ã³ã°äŒç€Ÿã®ã·ã¹ãã ããã³ãããã¯ãŒã¯ç®¡çè ãçŽé¢ããŸãã
äŒç€Ÿã«ãã©ãã£ãã¯ã®ééçãªç£èŠãä¿èšŒããæ段ããªãå Žåãæåã®ã¹ãããã¯ããã¹ãŠãååšããäœãèµ·ãã£ãã®ããæ確ã§ãªãå Žåã«ãããã¯ã«äŒŒããã®ã«ãªããŸãã
éåžžãããã«ç¶ããŠãéåžžtcpdumpã䜿çšããã«ãŒã¿ãŒããµãŒããŒãã¹ã€ããããŸãã¯ç¹å®ã®ãã³ããŒã®çµã¿èŸŒã¿ãœãªã¥ãŒã·ã§ã³ãããã©ãã£ãã¯ãã¿ãŒã³ããã£ããã£ããããšããŸãã
ãã³ãããã»ãšãã©åžžã«ãããã¯ãŒã¯äžã®ç¹å®ã®IPã¢ãã¬ã¹ã«æ»æããããç¹å®ã®ãã¿ãŒã³ãç¹å®ã§ããããšããããããŸãïŒããšãã°ãæ»æã¯ããŒã53ããã®UDPãã±ãã-æããDNSå¢å¹ ããŒã«ãŒã«ãã£ãŠå®è¡ãããŸãïŒã
ãã®åŸãéåžžãBGPãã©ãã¯ããŒã«ã¯ãäžäœã®ãªãã¬ãŒã¿ãŒã®ã¬ãã«ã§ã¹ããªã¢ã¹ãã©ãã£ãã¯ãé®æããããã«æ»æãããŠãããã¹ãã®ã¢ããŠã³ã¹ãšããŠã¢ããŠã³ã¹ãããŸãã åæã«ãäŒç€Ÿã®ãããã¯ãŒã¯ãååã«å€§ããã容éãšBGP Flow SpecããµããŒãããææ°ã®èšåãååã«ããå Žåããã¹ãå šäœããããã¯ããã®ã§ã¯ãªããåœã®ãã©ãã£ãã¯ãé®æããŠãµãŒãã¹ã®æ©èœãç¶æããããšãã§ããŸãã
ãã®ãããªæ»æã«å¯Ÿããå¯èœãªä¿è·ã®1ã€ã¯ããã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°ã»ã³ã¿ãŒãã®äœ¿çšã§ããããã®äœ¿çšã«ã¯å€ãã®åé¡ã䌎ããŸããç¹ã«ã誰ãããŸã ã©ã®ãã©ãã£ãã¯ããã€ãã£ã«ã¿ãªã³ã°ã»ã³ã¿ãŒã«è»¢éãããã決å®ããå¿ èŠããããŸãã
FastNetMonã®ç®æšã¯ãæ»æã®äºå®ãç¹å®ãããã®çš®é¡ãç¹å®ãã察çãå±éããããšããããã¹ãŠã®æé ãå®å šã«èªååããããšã ãã§ãã éåžžã人éã®ä»å ¥ããŸã£ãããªããŠã5ç§ããããããŸããã ãã¡ãããã¯ã©ã€ã¢ã³ããä¿è·ã®ããã«ãã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°ã»ã³ã¿ãŒã䜿çšããå Žåã®ãªãã·ã§ã³ããµããŒãããŸããFastNetMonã¯ãæ»æã®å Žåã«ããã䜿çšããŠãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ã»ã³ã¿ãŒã«åãæ¿ããããšãã§ããŸãã
ã©ã®ããã«ããŠã¢ã€ãã¢ãæžããŸãããïŒ
ãã®ã¢ã€ãã¢ã¯ããã¹ãã£ã³ã°æ¥çã§åããŠãããšãã«çãŸããŸãããåã®æ®µèœã§èª¬æããã¿ã¹ã¯ãæåã§äœååããŸãã¯äœçŸåã解決ããªããã°ãªããããã®ãã³ã«æ»æã®çš®é¡ãå€å¥ãããã®åãæ»æãæåã§æéããããã§ãã
以åã®å®è£ /代æ¿æ段ã¯äœã§ãããïŒ
äž»èŠãªãšã³ãžãã¢ãšããŠãç§ã®ã¿ã¹ã¯ã«ã¯ãã¿ã¹ã¯ã«é©åããŠäºç®ã«é©åãããœãªã¥ãŒã·ã§ã³ãèŠã€ããããšã»ã©ããœãªã¥ãŒã·ã§ã³ãæžãããšã¯å«ãŸããŸããã§ããã
å€ãã®ãœãªã¥ãŒã·ã§ã³ãè©ŠãããŸãããããããã®æ±ºå®ã®äž»ãªèŠå ã¯äŸ¡æ Œã§ãã-ããã¯çµ¶å¯Ÿã«èããããããããã¯ãŒã¯æ©åšã®å šäœã®ã³ã¹ãããã10åé«ãã£ããããå®è£ ãå®å šã«äžåœã«ãªããŸããã
DDoSã«å¯Ÿããä¿è·ã¯ä»¥åã©ã®ããã«è§£æ±ºãããŸãããïŒ
æåã§ãå€éå€åäžã®ç®¡çè ãžã®é»è©±ã§:)
ã·ã¹ãã ã®åç
FNMã®åºç€ãšãªãéèŠãªååã¯ããã©ãã£ãã¯ã®ãããå€ã®æŠå¿µã§ãã ãããå€ã¯ããããã¯ãŒã¯å ã®ããŒãã«åºå ¥ããããã©ãã£ãã¯ã®éïŒã¡ã¬ãããããããŒç§ãŸãã¯ãã±ãã/ç§ïŒã§ããããã®åŸãã©ãã£ãã¯ã¯ç°åžžãšèŠãªããããããã¯ãŒã¯ã«è åšãäžããŸãã ãããã®å Žåãããããã¯ç°ãªãå€ã§ãããå€ãã®å Žåãåããããã¯ãŒã¯å ã®ç°ãªãããŒãã§ãç°ãªãå€ã§ãã
ãã®ãããå€ã«éããåŸãããŒãã®ç¡æ¡ä»¶ã®ããããã³ã°ãå®è¡ãããããç¹å®ã®ããŒãã®ãã¹ãŠã®ãã©ãã£ãã¯ããã£ããã£ããã³åæãããŠãæ»æã®ã¿ãŒã²ãããšã¹ããªã¢ã¹ãã±ããã®ãã©ã¡ãŒã¿ãŒã決å®ãããŸãã
å éšããã€ã¹
å éšã§ã¯ãFastNetMonã¯å ¥åçšã®ã»ãŒãã¹ãŠã®åœ¢åŒã§ãã©ãã£ãã¯ãåä¿¡ããã³ã³ãã€ãŒã§ãã
ä»ãæã ã¯ãµããŒãããŠããŸãïŒ
- sFlow v4
- sFlow v5
- Netflow v5
- Netflow v9
- IPFIX
- ã¹ãã³
- é¡
- Pf_ring
- ãããããã
- ã¹ããã¹ã€ãã
ãã®åŸããã³ããŒåºæã®åœ¢åŒããããã©ãã£ãã¯ã¯å éšã®ãŠãããŒãµã«è¡šçŸã«å€æãããŸãã
ãã®åŸããããã¯ãŒã¯å ã®ããŒãããšã«ããããã³ã«ã®ç²åºŠïŒTCPãUDPãICMPïŒããã©ã°ã®ç²åºŠïŒTCP SYNãªã©ïŒãŸãã¯IPãªãã·ã§ã³ïŒæçåïŒãããã³é床ãäžãããšããã«åå¥ã®è¿œè·¡ãµãããã»ã¹ã¬ã³ãŒãã䜿çšããŠãå€ãã®ã«ãŠã³ã¿ãŒãäœæãããŸãåäœæéãããã®ç¹å®ã®ãã©ãã£ãã¯ã«ãŠã³ã¿ãŒããŠãŒã¶ãŒå®çŸ©ã®ãããå€ãè¶ ããŸããã
ãããããã®åŸãæ»æã®çš®é¡ã確ç«ããæãé©åãªå¯Ÿçãéžæããããã®çµ±èšçææ³ã§ããDPIãé¢äžããå°ããªéæ³ãå§ãŸããŸãã
ãããŠæåŸã«ãã¹ã¯ãªãããåŒã³åºãããããBGPã¢ããŠã³ã¹ãçæãããŠãBGP Flow Specã䜿çšããŠãã¹ãŠã®ãã©ãã£ãã¯ãå®å šã«ãããã¯ããããããŸãã¯åœã®ãã©ãã£ãã¯ã®ã¿ããããã¯ãããŸãã
å€éšAPI
ã»ãšãã©ã®å ŽåãAPIã®éåžžã®ç解ã§ã¯ãããŸããã
FastNetMonã¯ãInfluxDBã®Graphiteã«æ å ±ããšã¯ã¹ããŒãããŠããã©ãã£ãã¯ãèŠèŠåã§ããŸãã
æ å ±ãåä¿¡ããã«ã¯ãsFlowãIPFIXãNetFlowãªã©ã®ããªãæšæºåããããããã³ã«ã䜿çšãããã³ããŒãããããæ£ããå®è£ ããŠããã°ãèªåçã«ãµããŒããä¿èšŒããŸãã
ãã©ã°ã€ã³ã·ã¹ãã
圌女ã¯ãäžçãéåžžã«è€éã§ããã1ã€ã®ãããã³ã«ïŒåœæã¯ãã©ãŒ/ãã©ãŒã€ã³ã¿ãŒãã§ã€ã¹ããã®ãã©ãã£ãã¯ãã£ããã£ïŒãå®è¡ã§ããªãã£ãããšãç解ããåŸãsFlowãNetflowãããã³4ã€ç®ãè¿œå ããŠãæ·±å»ãªãªãã¡ã¯ã¿ãªã³ã°ãå®æœããåãã©ãã£ãã¯ãã£ããã£ã¢ãžã¥ãŒã«ãå€éšAPIãåºå®ãããåå¥ã®ã©ã€ãã©ãªã«å³éã«åé¢ããŸããã 誰ã§ãç°¡åã«ãã©ãã£ãã¯ãã¬ã¡ããªãåé€ããç¬èªã®ç¹å¥ãªæ¹æ³ãå®è£ ãããã©ã°ã€ã³ãéçºã§ããŸãã
ããã¥ã¡ã³ã
ããã¯æ¬åœã«çãç¹ã§ãã å€ãã®ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãã«ã€ããŠãã»ãŒééããªãã§ãããã éåžžãããã¥ã¡ã³ããäœæããæéã¯ãããŸããããä»åŸåç §ããæã詳现ãªåçãæäŸããããã«ãGitHubãšãã¥ãŒã¹ã¬ã¿ãŒã«é¢ãããã¹ãŠã®ãªã¯ãšã¹ããæ éã«æ€èšããããåªããŠããŸãã æ®å¿µãªããããããžã§ã¯ãã®å段éã説æããå æ¬çãªããã¥ã¡ã³ãã¯ãããŸããã
ãã¹ãäž
ãããžã§ã¯ãã®é·å¹Žã«ããã£ãŠãã»ãŒæ°çŸã®ç°ãªãããã€ã¹ã¢ãã«ã«å¯ŸããŠéåžžã«å€ãã®pcapãã³ããèç©ããŠããŸããã ããŒãµãŒã«å€æŽãå ããå Žåãå éšãã¹ãã·ã¹ãã ã§ãããã䜿çšããŸãã
æ®å¿µãªããšã«ããããã®ãã³ãã«ã¯ã»ãšãã©ã®å Žåã顧客ã®æ©å¯æ å ±ãå«ãŸããŠããããªãŒãã³ãœãŒã¹ãšããŠå ¬éããããšã¯äžå¯èœã§ããããããã®æ å ±ã®ä¿åã«ã¯éåžžã«æ³šæããã¢ã¯ã»ã¹ã¯éåžžã«æ éã«å¶åŸ¡ãããŠããŸãã
ããã«ãéèŠã§æ¬è³ªçã«è€éãªãããã³ã«ïŒBGP Flow Specãªã©ïŒã«ã¯ããŠããããã¹ãããããŸãã
ç°ãªããã©ãããã©ãŒã ã§åäœããé©å¿
çŸåšãã»ãŒãã¹ãŠã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ããµããŒãããŠãããFreeBSDã«å ¬åŒã®ç§»æ€çããããå ¬åŒã®Debianããã±ãŒãžããŒã¹ã«è¿œå ã§ããŸãã å°ãåã«ãã©ãããããã§ãã¬ã€ãããã£ããããšããçç±ã ãã§MacOSã®ãµããŒããè¿œå ããŸãã:)
ãã©ãããã©ãŒã ã§å©çšå¯èœãªAPIã䜿çšããŠãæã移æ€æ§ã®é«ã圢åŒã§ã³ãŒããèšè¿°ããŸããããšãã°ãFreeBSDãžã®ç§»æ€ã§ã¯ãæåéã4ã€ã®é¢æ°ãå€æŽããå¿ èŠããããŸããïŒä»ã®å®æ°åã䜿çšãããŸããïŒã
äž»ãªåé¡ã¯ããµããŒããããŠããéåžžã«åºç¯ãªãã£ã¹ããªãã¥ãŒã·ã§ã³ãšããªããžããªã«å¿ èŠãªããŒãžã§ã³ã®ã©ã€ãã©ãªãé »ç¹ã«ååšããªãããšã§ãã ä»ã§ã¯ããŸãããŸã決å®ãããŠããŸãã-åãã©ãããã©ãŒã ã§ãã€ã³ã¹ããŒã«æã«ãœãŒã¹ã³ãŒãããäŸåé¢ä¿ãåéãããŸãã ããã¯å¥œãã§ã¯ãããŸããããæ®å¿µãªããããµããŒããããŠããã»ãŒ20ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ãã€ããªãããžã§ã¯ããçµã¿ç«ãŠãããšã¯ãç§ãã¡ã«ãšã£ãŠäžå¯èœãªäœæ¥ã§ãã è©ŠããŠã¿ãŸããããããªããããããŸãã-éåžžã«è€éãªã·ã¹ãã ã§ããããšãå€æããŸããã
ã©ã®ãã¯ãããžãŒïŒèšèªããã¬ãŒã ã¯ãŒã¯ãã¢ãžã¥ãŒã«ïŒã«åºã¥ããŠæ§ç¯ãããŠããã®ãããããŠãªãéžã°ããã®ã
C ++ãããžã§ã¯ãã®äž»èŠèšèªã STLããœãªã¥ãŒã·ã§ã³ãæäŸããŠããªãå ŽåãSTLãšBoostãéåžžã«ç©æ¥µçã«äœ¿çšããŠããŸãã ãããžã§ã¯ãã®ä»æ§ãšãªãŒãã³ãã©ãŒã ã§å©çšå¯èœãªéçºã®æ°ãå°ãªããããã³ãŒãã«ã¯å€éšäŸåé¢ä¿ã¯ããŸããããŸãããæãå¿ èŠãªã³ãã¯ã¿ãŸãã¯ããŒã¿ããŒã¹ã³ãã¯ã¿ã®ã¿ã§ãã
ãã ããExaBGPãInfluxDBãGraphiteãGrafanaãGoBGPãªã©ã®å€éšãããžã§ã¯ããç©æ¥µçã«äœ¿çšããŠããã©ãã£ãã¯ã®èŠèŠåãå€éšãšã®å¯Ÿè©±ãæäŸããŠããŸãã
ãã®ãããžã§ã¯ããŸãã¯çµ±åãããžã§ã¯ããéžæããäž»ãªåºæºã®1ã€ã¯ãAPIã®å¯çšæ§ãšéçºè ã®äœ¿ããããã§ãã
ããšãã°ãQuaggaãBirdãªã©ã®BGPãããžã§ã¯ãã¯ãçµ±åã®æ©äŒãéåžžã«ä¹ããããã人æ°ãããã«ãããããããç§ãã¡ã«ã¯é©ããŠããŸããã§ããã
ãã©ãŒã«ããã¬ã©ã³ã¹ãã¹ã±ãŒãªã³ã°ãããã³ã·ã¹ãã ããã©ãŒãã³ã¹ã«ã€ããŠäœãèšããŸããïŒ ãããã®åé¡ã¯ã©ã®ããã«è§£æ±ºãããŸããïŒ
åºæ¬çã«ãé«å¯çšæ§ã®åé¡ã¯ã¢ãŒããã¯ãã£ã¬ãã«ã§è§£æ±ºãããŸããããã¯ãBGPãæ¬è³ªçã«éåžžã«åé·ã§ããããã®é¢ã§åªåããå¿ èŠããªãããã§ãã éåžžãFastNetMonã¯ããããã¯ãŒã¯äžã§å©çšå¯èœãªå°ãªããšã2ã€ã®ç¬ç«ããã«ãŒã¿ãŒã§æ»æãåããŠããããŒããéç¥ããŸãã
FastNetMonã®ãã©ãŒã«ããã¬ã©ã³ã¹ã確ä¿ããã«ã¯ãéåžžããããã¯ãŒã¯ãã©ãã£ãã¯ã2çªç®ã®ã€ã³ã¹ã¿ã³ã¹ã«åçŽã«è€è£œãïŒéåžžãã«ãŒã¿ãŒãšã¹ã€ãããããããµããŒãããããã«ãµã³ããªã±ãŒã¿ãŒãåžžã«äœ¿çšã§ããŸãïŒããã©ãŒã«ããã¬ã©ã³ã¹ãæäŸããŸã.1ã€ã®ã€ã³ã¹ã¿ã³ã¹ã倱ãããå Žåã2çªç®ã®ã€ã³ã¹ã¿ã³ã¹ãã¿ã¹ã¯ãå®äºããŠãã©ãã£ãã¯ããããã¯ããŸãã
è² è·ã®ã¹ã±ãŒãªã³ã°ã«é¢ããŠã¯ãã»ãŒ1.4Tbã®ãã©ãã£ãã¯ã§ãããã¯ãŒã¯ã«å±éããçµéšãããããã®ãããªæ°å€ã¯NetFlow v9ã³ã¬ã¯ã¿ãŒã«åºã¥ããŠéæãããã¹ã«ãŒããããåäžãããå€ãã®æ©äŒããŸã ãããŸããã
ããã§ååã§ãªãå Žåã¯ããã€ã§ãä»»æã®åºæºã«åŸã£ãŠãã©ãã£ãã¯ãåå²ããè¿œå ã®FastNetMonã€ã³ã¹ã¿ã³ã¹ãã€ã³ã¹ããŒã«ã§ããŸãã
ãªããªãŒãã³ãœãŒã¹ãªã®ã§ããïŒ
ãããžã§ã¯ãã¯æåã®ã¹ãããããéããŠããããã1åã®ã³ãããã§æ°åäžè¡ã®ã³ãŒããèªã¿èŸŒãŸããç¬éã¯ãããŸãããæåããé²åããã©ãããšãã§ããŸãã
ããããäžè¬ã«äœææã«çåã¯ãããŸããã§ãããç®æšã¯ãç¹å®ã®ãããã€ããŒã®ç¹å®ã®ã±ãŒã¹ã§åé¡ã解決ããã ãã§ãªãã詳现ã«ç«ã¡å ¥ããã«äžè¬åããã圢åŒã§åé¡ã解決ãããããžã§ã¯ããäœæããããšã§ããã
ãããã£ãŠãå¯äžã®æ¹æ³ããããŸãã-ãªãŒãã³ãœãŒã¹ïŒ ããã§ãªããã°ãç¹å®ã®é åã§éåžžã«å°ããªã¿ã¹ã¯ã1ã€è§£æ±ºãããçãå°éåããããœãªã¥ãŒã·ã§ã³ãèŠã€ãããŸãã
ãããžã§ã¯ãããªãŒãã³ãœãŒã¹ã§å ¬éããããšã«ã¯ã©ã®ãããªå©ç¹ããããŸããïŒ ãã¡ãããããã¯å€§ããªåœ±é¿ã§ãã ããªãã®ãœãªã¥ãŒã·ã§ã³ããã¥ãŒããå«ã103ãåœã§äœ¿çšãããŠããããšãããããšãã€ã³ã¹ãã¬ãŒã·ã§ã³ãåŸãŸã:)
ãªãŒãã³ãœãŒã¹ãããžã§ã¯ããšã¯ããŒãºãåæ¥éçºã®éãã¯äœã§ããïŒ
ãã¯ããŒãºãããªãŒãã³ãœãŒã¹ãããžã§ã¯ãããããã¯ããŒãºããœãŒã¹ã®éåžžã«ããªãŒãã³ããªåçšãããžã§ã¯ãããããŸãã
ããã§éèŠãªã®ã¯ããããžã§ã¯ãã®å²åŠã»ã©ã³ãŒãã®ãªãŒãã³æ§ã§ã¯ãªããããå€æŽãæ¹åã«å¯ŸããŠããªãŒãã³ã§ãã
å€ãã®äººã«ãšã£ãŠããªãŒãã³ãœãŒã¹ã¯ã補é æ¥è ã®æ°ããçµå¶é£ãã©ã€ã»ã³ã¹ããªã·ãŒãå€æŽããªãããšãäŒç€Ÿãç Žç£ããªãããšããããŠãµããŒãã圹ã«ç«ããªãå Žåããã€ã§ãèªåã§ãããææ¡ãããããããæ¹åããå°é家ãèŠã€ããããšãã§ãããšããå°æ¥ã®èªä¿¡ã®ä¿èšŒã§ãã
å€æ°ã®ã¹ãã€ãŠã§ã¢ã¹ãã£ã³ãã«ãèãããšããªãŒãã³ãœãŒã¹ã¯ããã«é åçã«èŠããŸãã ã³ãŒãã®åç §ãšç¬ç«ããæ€èšŒã®å¯èœæ§ã«ãããåžžã«ã»ãã¥ãªãã£ã®ä¿èšŒã確èªã§ããŸãã
ãããžã§ã¯ããåãå·»ãã³ãã¥ããã£ã¯ããããžã§ã¯ãã®çãæ¹ãšçºå±ã®ä»æ¹ã§ãã å€éšè²¢ç®ã¯ãããã§ããïŒ æ°æ©èœãšãã°ã®ãªã¯ãšã¹ãã
ãããžã§ã¯ããžã®äž»ãªè²¢ç®ã¯ããã€ãã®æ¹åã«åããããŠããŸãã
- ããŸããŸãªãã³ããŒãšã®çµ±åïŒA-10ãããã¯ãŒã¯ãã©ããŠã§ã¢ã
- MikrotikïŒã
- æ¢åã®ãŠãŒã¶ãŒããã®æ°ããæ©èœã®ãªã¯ãšã¹ã
- ãŠãŒã¹ã±ãŒã¹ã®è©³çŽ°ãªèª¬æ-ããã¯éåžžã«éèŠã§ã
- ãããžã§ã¯ãã®éçºã«é¢ããæ å ±
- å¯èœãªéãå€æ§ãªãããã¯ãŒã¯ããã€ã¹ã§ã®ãã¹ã
- ãããŠããããžã®ãœãããŠã§ã¢
- ããŸããŸãªãã£ã¹ããªãã¥ãŒã·ã§ã³ïŒAltLinuxãFreeBSDãDebianïŒãžã®çµ±å
- æ®å¿µãªããããããžã§ã¯ãã®ã³ã¢ïŒæ»æãšåæãæ€åºããããã®ã¢ãžã¥ãŒã«ïŒãžã®çŽæ¥çãªè²¢ç®ã¯éåžžã«å°ãªãããã®æ¹åã§ã®éçºã®å€§éšåã¯åç¬ã§è¡ãããŸãã
ãããžã§ã¯ãã®ãããªãçºå±ã®èšç»
äž»ãªç®æšã¯ããããžã§ã¯ãã®éçºãå éããã³ã¢ã·ã¹ãã èªäœã®éçºã«ããå€ãã®éçºè ãåŒãä»ããããšã§ãã
çŸåšãæ»æè ã¯éåžžã«éãåããŠãããæ°ããè åšã«å¯Ÿæããããã®å¯Ÿçã®éçºã«ã€ããŠããã®ã¯éåžžã«å°é£ã§ãããç§ãã¡ã¯è©Šã¿ãŠããŸãã
ãã®èšç»ã®å®è£ ã®äžç°ãšããŠãæ°ãæåã«FastNetMon Advancedã®åçšããŒãžã§ã³ããªãªãŒã¹ããŸãããããã¯ã倧äŒæ¥ãTIER-2ã¯ã©ã¹ä»¥äžã®å€§èŠæš¡ãããã¯ãŒã¯ã«äžå¯æ¬ ãªå€ãã®å©ç¹ãå®è£ ããŠããŸãã ãããã¯äž»ã«ã倧èŠæš¡ãããã¯ãŒã¯ã«ãããå±éãéçšã®ç°¡çŽ åãããã³ããæè»ãªç®¡çã«é¢ãããã®ã§ãã ãããžã§ã¯ãã®äž»èŠãªã³ã¢ã¯ãäž¡æ¹ã®è£œåã§åããã®ã䜿çšãããŸãã
, Ì, ? :)
顧客ããã®æ°ããæ©èœã«å¯Ÿããå€ãã®ãªã¯ãšã¹ããèŠããšãããªãã®æã¯ãã ã€ããã§å®çŸããŸãïŒãããžã§ã¯ãã®æåã®æ®µéã§ã¯ãããã ãã®äŸ¡å€ããããŸãïŒæ確ã§ãªãå Žåã誰ãããããžã§ã¯ããå¿ èŠãšãã圌ãã®ããããããæ±ããããŸãã
ãããããããã-ããã¯æã åæ¢ãããæ®éçã«ãããè¡ãæ¹æ³ïŒããããããŠä»ã«èª°ããããå¿ èŠãšããã®ãïŒããšãã質åãèªåãã䟡å€ããããŸããå€ãã®å Žåãã¢ãŒããã¯ãã£ã§å¿ èŠãªå€æŽãçèããã¢ã€ãã¢ãæ£ããããšã確èªããããã«ãæ°é±éèŠæ±ããããã«åçµããã®ã«åœ¹ç«ã¡ãŸã-ãããŠãã®åŸã«ã®ã¿éçºãé²ããŸãã
ããã«ãæã åæ¢ããŠãç¹å®ã®ãµãã·ã¹ãã ã®ã³ãŒãã泚ææ·±ãèŠãŠãçµ±äžãŸãã¯æ¹åã§ããå Žæãæ¢ããŠã¿ã䟡å€ããããŸãã
ãŸããäžéšã®ãµãã·ã¹ãã ãè€éãã®ãã¹ãŠã®å¯èœãªå¶éãè¶ ããŠãããšæããå ŽåïŒãã®å ŽåãBGP Flow Specã䜿çšããå ŽåïŒãæ éãªæ ¡æ£ã§ã¯ãã¯ãååã§ã¯ãªãããããŠããããã¹ãããã詳现ã«ã«ããŒããããšãæ€èšããå¿ èŠããããŸãã
æåããã¢ãŒããã¯ãã£ãèãããããžã§ã¯ããéçºããªããå°æ¥çã«ã©ã®ããã«ããããã©ããªãããåæã«æªç©ãæŸèæã®åŽé¢ã«å°ããªãããšãéèŠã§ããïŒ :)
åœåããã¢ãŒããã¯ãã£ã¯ãããŸããã§ãããéæãããç®æšã®æŒ ç¶ãšããç®æšã ãã§ããæåã®ã¹ãããã§ã¯ããããžã§ã¯ããæ©èœããæ¯ç§æ°åäžãã±ããã®è² è·ã«å¯ŸåŠã§ãããã©ããããæ確ã§ã¯ãããŸããã§ããïŒããã¯å€ããæåã¯æ¯ç§120,000ãã±ãããåŠçã§ããŸããã§ããïŒ
ãããã£ãŠãåã«èšã£ãããã«ãæã åæ¢ããŠãã·ã¹ãã ãã¢ãžã¥ãŒã«ã«åå²ããå¯èœæ§ã«ã€ããŠèãã䟡å€ããããŸãã
ããã¥ã¡ã³ããšãã¹ãã®éèŠæ§
å€ãã®äººãèšãããããã«ããªãŒãã³ãœãŒã¹ãããžã§ã¯ãã«ãšã£ãŠæè¯ã®ããã¥ã¡ã³ãã¯ã³ãŒãã§ãããããžã§ã¯ãã®æŽå²ã®äžã§ãã³ãŒãã泚ææ·±ã調ã¹ãŠããã®æ¹æ³ã§åœŒãã®è³ªåã«çããã®ã¯ããå°æ°ã§ãããããç§ã¯æ ¹æ¬çã«åæããŸããã
ããããããã¥ã¡ã³ãã®äžè¶³ã¯ãåžžã«ã¬ã¹ãã³ã·ãã³ãã¥ããã£ãšéçºè ã®è¿ éãªå¯Ÿå¿ã«çœ®ãæããããšãã§ããŸããäž¡æ¹èªæ ¢ã§ããŸãïŒå€ãã®å Žåã質åã¯ç¹å®ã®ãã±ããã«å°éãããã£ãšåã«è§£æ±ºãããŸã-ã³ãã¥ããã£ã¡ã³ããŒã®1人ããéçºè ã®åå ãªãã§åé¡ã«çãã解決ããããšã«æ±ºããŸãã:)
ãã¹ãã«é¢ããŠ-ç§ã®æèŠã§ã¯ããã©ã³ã¹ãç¶æããå¿ èŠããããŸããæçœãªãã®ããã¹ãã§ã«ããŒããããšã¯å®å šã«ç¡æå³ã§ã;ããã¯æçšã«è²»ããããšãã§ããæéã®ç¡é§ã§ããããããã·ã¹ãã ã®è€éããéåžžã«é«ãå ŽåããŸãã¯å€éšã·ã¹ãã ãšå¯Ÿè©±ãããšãã«é害ã®ãªã¹ã¯ãé«ãå Žåã¯ããã¹ãã絶察ã«å¿ èŠã§ãã
ãªãŒãã³ãœãŒã¹éçºã®ç€ŸäŒçåŽé¢ïŒèª€ã£ãPRãæããªè³ªåãééã
ç¹å®ã®ãã³ããŒã圌ãã®åé¡ã解決ããããã«ãç§ãã¡ã¯ãã°ãã°ãŠãŒã¶ãŒã«å©ããæ±ããã¯ãŒã«ãªç€ŸäŒçåŽé¢ãæã£ãŠããŸãã
ãã°ä¿®æ£ã®ãããã¯ã«é¢ãããããã¯ãŒã¯æ©åšã®å€ãã®ãã³ããŒã®ä»äºã®ã¢ãã«ã¯ã䜿çšäžã®å¥çŽ/æ©åšãæããªãå€éšäŒæ¥ãããããä¿®æ£ããããšã«é¢ãããã°ãåŸãæ©äŒãåã«æããªããããªãã®ã§ãã
ãã®çµæããFastNetMonã¯XXXãã³ããŒã®YYYããã€ã¹ã§ã¯åäœããŸããããšããå€æ°ã®ãã°ãçºçããŸãããæåã¯ããã³ããŒã«åé¡ããããäœãã§ããªãããšãè¬çœªããŸããã
ä»-ç§ãã¡ã¯åé¡ãå¯èœãªéã詳现ã«èª¿æ»ããŠåãåãããã®åŸã¯ã©ã€ã¢ã³ãã«äŸé ŒããŠãã°ãä¿®æ£ãããªã¯ãšã¹ããäœæããããäŸé ŒããŸããå€ãã®äººã ãåé²ããããã«ãã£ãŠåããã³ããŒã®éåžžã«å€ãã®ãŠãŒã¶ãŒã®åé¡ã解決ããŸãïŒ