ä»æ¥ã¯ããžã¥ãããŒMXã·ãªãŒãºã«ãŒã¿ãŒã§ã®ãã©ãã£ãã¯ãã©ãŒãªã³ã°ã«ã€ããŠèª¬æããŸãã CiscoãHuaweiããŸãã¯Aristaã«ããåãæ¿ãã®åŸãJunOSã§ã®SPANããã³RSPANã®æ§æã¯éåžžã«è€éã«èŠããŸãããè€éãªïŒäžèŠïŒæ§æã¯ããã©ãã£ãã¯ãã©ãŒãªã³ã°ã®åéã§MXãã©ãããã©ãŒã ã®å·šå€§ãªæ©èœãé ããŸãã ãžã¥ãããŒã®ã¢ãããŒãã¯äžèŠè€éã§ãããèšå®ãããããã¯ã¹ããå¥ã®ããã¯ã¹ã«ã³ããŒã¢ã³ãããŒã¹ãããã«ãäœãè¡ãããŠããã®ãããããŠãã®çç±ãç解ããã°ãã·ã³ãã«ã§ç解ãããããªããŸãã JunOSã®ã€ããªãã®ãŒã§ã¯ããã©ãŒãªã³ã°ã®ç®çã§ãã£ã«ã¿ãŒããŒã¹ã®è»¢éïŒFBFïŒã䜿çšããããšãæšå¥šããŠããŸããããã«ãããè€éãªãã©ãã£ãã¯ãã©ãŒãªã³ã°ã¹ããŒã ã®å®è£
ã«æè»æ§ãããããããŸãã
ããã§ã¯å§ããŸãããã ãã©ãŒãªã³ã°ã®äŸãããã€ãèŠãŠãããŸãã
1.ããŒã«ã«ããŒãéãã©ãŒãªã³ã°
2.è€æ°ã®ã³ã³ã·ã¥ãŒããŒãžã®ãã©ãŒãªã³ã°
3.ãªã¢ãŒããã¹ããžã®ãã©ãŒãªã³ã°
4.è€æ°ã®ã³ã³ã·ã¥ãŒããŒã®éžæçãã©ãŒãªã³ã°
5. L2ãã©ãã£ãã¯ã®ããŒã«ã«ãã©ãŒãªã³ã°
6. L2ãã©ãã£ãã¯ããªã¢ãŒããµãŒããŒã«ãã©ãŒãªã³ã°ãã
7. 1ã€ã®FPCã§3ã€ä»¥äžã®ãã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ã䜿çšãã
ããã§ã¯ãé çªã«å§ããŸãããã
ããŒãããããŒããžã®ããŒã«ã«ãã©ãŒãªã³ã°ããã¹ããã³ãã¯åžžã«å€åããŸã-æ¶è²»è
ãè¿œå ããåä¿¡ãããã©ãã£ãã¯ã®ã³ããŒã«å¿ããŠåžæãå€æŽããŸãã æåã®æ®µéã§ã¯ããã¹ããã³ãã¯æ¬¡ã®ããã«ãªããŸãã
泚ïŒæåã¯ãã©ãã£ãã¯ãžã§ãã¬ãŒã¿ãŒã䜿çšãããã£ãã®ã§ããããã©ãã£ãã¯ã¢ãã©ã€ã¶ãŒã§ãã£ããã£ãããhping3 tcp / udp / icmpã«ãã£ãŠçæããããã±ããïŒã¢ãã©ã€ã¶ãŒã¯ããŒãäžã®ubuntuãµãŒããŒ14.04ãæã€ãã¹ãã®ã¿ã䜿çšããããïŒã¯ãããŒãããã®ã«ãŠã³ã¿ãŒãããèŠèŠçã§ãããšå€æããŸããppsïŒããšãã°ãéä¿¡ããŒã¿ãšåä¿¡ããŒã¿ã®é¢é£æ§ãæ¯èŒã§ããŸãïŒã ãã®æ©èœã䜿çšããå Žåã¯ãè² è·ãã¹ãäžã«ã«ãŠã³ã¿ãŒã䜿çšããŠãã«ãŒã¿ãŒã®ããã©ãŒãã³ã¹ã確èªããå¿
èŠããããŸãã ãã ããä»®æ³MXã§ã¯ãããã©ãŒãã³ã¹ããã§ãã¯ããŠãæå³ããããŸããããã¹ãŠåãããã«ããã¹ãŠãä»®æ³åãµãŒããŒã®æ©èœã«äŸåããŸãã
Server-1ïŒ11.0.0.1ïŒãšServer-2ïŒ12.0.0.1ïŒã®éã«äœããã®ãã©ãã£ãã¯äº€æããããšããŸãã Analyzer-1ãµãŒããŒã®ææè
ã¯ãããã2ã€ã®ãµãŒããŒéã§æ£ç¢ºã«è»¢éãããå
容ã確èªãããããServer-1ãšServer-2éã®ãã¹ãŠã®ãã©ãã£ãã¯ã®ã³ããŒãAnalyzer-1ã«éä¿¡ããããã«æ§æããå¿
èŠããããŸããã€ãŸããããŒã«ã«ãã©ãŒãªã³ã°ãè¡ããŸãã ããã§ã¯å§ããŸãããã
çè«çã«ã¯ãããã¯æ¬¡ã®ããã«æ©èœããŸããçä¿¡ãã©ãã£ãã¯ã®ãã©ã¡ãŒã¿ãŒïŒãã©ãã£ãã¯ããã©ãŒãªã³ã°ããé »åºŠïŒãšãã©ãã£ãã¯ããã€ãºãã³ã°ããããŒããŸãã¯çºä¿¡ããŒããæå®ãããã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ãäœæããŸãã äœæããã€ã³ã¹ã¿ã³ã¹ã«ãã©ãã£ãã¯ãèªå°ããã«ã¯ããã©ãã£ãã¯ã®ã³ããŒãåé€ããã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããå¿
èŠãªã€ã³ã¹ã¿ã³ã¹ã§ãã©ãã£ãã¯ãã©ããããç¹å¥ãªãã£ã«ã¿ãŒãåãå¿
èŠããããŸãã ã€ãŸããããã¯ããžã¥ãããŒã®èŠ³ç¹ããèŠããšãå€å
žçãªããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ã¹ããŒã ããŸãã¯ãã£ã«ã¿ãŒããŒã¹ã«ãŒãã£ã³ã°ã§ãã çè«ãç解ããã®ã§ãä»ããç·Žç¿ããŸãããããã®ãããªãã©ãŒãªã³ã°ã¹ããŒã ãçµã¿ç«ãŠãå¿
èŠããããŸãã
æåã«ã[転éãªãã·ã§ã³ã®ããŒããã©ãŒãªã³ã°ã®ç·šé]éå±€ã«ã€ã³ã¹ã¿ã³ã¹ãäœæããå¿
èŠããããŸããããã䜿çšããŠããã©ãã£ãã¯ããã©ãŒãªã³ã°ããŸãã
[edit forwarding-options port-mirroring] bormoglotx@RZN-PE-1# show instance { SPAN-1 { input { rate 1; run-length 0; } family inet { output { interface ge-0/0/1.0 { next-hop 169.254.0.1; } } } }
ã€ã³ã¹ã¿ã³ã¹æ§æã¯2ã€ã®éšåã§æ§æãããŸãã æåã«å
¥åã»ã¯ã·ã§ã³ãæ±ããŸã-ãæ³åã®ãšããããããã¯çä¿¡ãã©ãã£ãã¯ã®ãã©ã¡ãŒã¿ãŒã§ããããã©ãŒãªã³ã°ããå¿
èŠããããŸãã ããã§ã¯ãé床ãšã©ã³ã¬ã³ã°ã¹ã®ãã©ã¡ãŒã¿ãŒãéèŠã§ãã æåã®ãã©ã¡ãŒã¿ãŒã¯ããã±ããããã©ãŒãªã³ã°ãããé »åºŠïŒããªã¬ãŒãããªã¬ãŒãããïŒãæ
åœãã2çªç®ã®ãã©ã¡ãŒã¿ãŒã¯ãã¬ãŒãããªã¬ãŒãããªã¬ãŒãããåŸããã©ãŒãªã³ã°ããããã±ããæ°ãæ
åœããŸãã
ãã®å Žåãã¬ãŒãã¯1ã«èšå®ãããŸããã€ãŸããåãã±ããããã©ãŒãªã³ã°ãããŸãã ã©ã³ã¬ã³ã°ã¹ã¯0ã«èšå®ãããŸããããã¯ãã¬ãŒãã1ã®å Žåããã®ååšã¯äœã®åœ¹å²ãæãããªãããã§ãã
å®å
šãæãããã«ããããã®ãã©ã¡ãŒã¿ãŒã®æå³ãããå
·äœçãªäŸã§åæããŸãã ã¬ãŒããã©ã¡ãŒã¿ãŒã¯ãã©ãã£ãã¯ãã©ãŒãªã³ã°ã®é »åºŠãèšå®ããŸããã¬ãŒãã5ã§ãããšä»®å®ããŸããã€ãŸããããªã¬ãŒã¯5çªç®ã®ãã±ããããšã«èµ·åããŸããã€ãŸãã5çªç®ã®ãã±ããããšã«ãã©ãŒãªã³ã°ãããŸãã ããã§ãã©ã³ã¬ã³ã°ã¹ã4ã«èšå®ãããŠãããšããŸããããã¯ã5çªç®ã®ãã±ããããšã«ããã«4ã€ã®ãã±ããããã©ãŒãªã³ã°ãããããšã瀺ããŠããŸãã ã€ãŸãã5çªç®ã®ãã±ããã®ããªã¬ãŒãæåã«æ©èœããŸããããã®ãã±ããã¯ãã©ãŒãªã³ã°ããããã§ã«ãã©ãŒãªã³ã°ããããã±ããã«ç¶ã4ã€ã®ãã±ããããã©ãŒãªã³ã°ãããŸãã ãã®çµæã5çªç®ã®ãã±ããããšã«ãã©ãŒãªã³ã°ãããããã«4ã€ã®ãã±ãããç¶ãããšã«ãªããŸã-åèš100ïŒ
ã®ãã©ãã£ãã¯ã ãããã®ãã©ã¡ãŒã¿ãŒãå€æŽããããšã«ãããããšãã°ã100ãã±ããã®ãã¡10ãã±ããããšã«ãã©ãŒãªã³ã°ããããšãã§ããŸãïŒããã¯ããã©ãŒãªã³ã°ããããµã³ããªã³ã°ã«å¿
èŠã§ããåäœåçã¯åãã§ãïŒã
ã±ãŒã¹ã«æ»ããšãåããã±ãŒãžãæ¢ã«ãã©ãŒãªã³ã°ããŠãããããåã«run-lengthãã©ã¡ãŒã¿ãŒãå¿
èŠãšãããããã©ã«ãå€ã®ãŒãã®ãŸãŸã«ããŸãã
ãã©ãŒãªã³ã°ããããã©ãã£ãã¯ã®å²åãèšç®ããã«ã¯ãåŒ
ïŒ
=ïŒïŒrun-length + 1ïŒ/ rateïŒ* 100ïŒã䜿çšã§ããŸãã ã©ã³ã¬ã³ã°ã¹1ããã³ã¬ãŒã1ã®ãã©ã¡ãŒã¿ãŒã䜿çšãããšããã©ãã£ãã¯ã®200ïŒ
ã®ãã©ãŒãªã³ã°ãååŸã§ããŸããããšãã°ãã¬ãŒã1ããã³ã©ã³ã¬ã³ã°ã¹4-500ïŒ
ã®ãã©ãã£ãã¯ãååŸã§ããŸãã ç§ã¯ããªããæ²ããŸããããåãã§ããŸã-ãã©ãã£ãã¯ã®100ïŒ
以äžã¯ãã©ãŒãªã³ã°ãããŸãã-ãžã¥ãããŒãããã¯ãŒã¯ã¹ã¯è«ççãªä»¥äžã®ãã±ãããå¢å ãããŸããã ãããŠãåããã©ãã£ãã¯ã®ã³ããŒã2ã€äœæããå¿
èŠãããå Žåãã·ããªãªãæãä»ãããšãã§ããŸããã§ããïŒèª°ããç¥ã£ãŠãããªããã³ã¡ã³ããæžããŠãã ããïŒã
ãã1ã€ã®éèŠãªãã©ã¡ãŒã¿ãŒã¯ãmaximum-packet-lengthã§ãã ããã¯ããã©ãŒãªã³ã°ãããæ倧ãã±ãããµã€ãºã§ãã ããšãã°ã128ã«èšå®ããå Žåã128ãã€ãïŒããšãã°ã1514ïŒãè¶
ãããã±ãããåä¿¡ãããšãæåã®128ãã€ããã«ãããããŠã³ã³ã·ã¥ãŒããŒã«éä¿¡ãããŸãã ãã±ããã®æ®ãã¯åã«ç Žæ£ãããŸãã ããã¯ãããããŒã®ã¿ããµãŒããŒã«éä¿¡ããå¿
èŠãããããã€ããŒããäžèŠãªå Žåã«äŸ¿å©ã§ãã ipv4ã«20æªæºãèšå®ããããšã¯æšå¥šãããŸããã
ããã§ã¯ãåºåãã©ã¡ãŒã¿ãŒã«ç§»ããŸãããã ããã§ãäžè¬çãªã±ãŒã¹ã§ã¯ããã©ãã£ãã¯ããã©ãŒãªã³ã°ããã€ã³ã¿ãŒãã§ã€ã¹ãæå®ããå¿
èŠããããŸãã p2pã€ã³ã¿ãŒãã§ãŒã¹ã ããããå Žåãä»ã«äœãæå®ããå¿
èŠã¯ãããŸãã-ãã¹ãŠãé£ã¶ã§ãããã ããããç§ãã¡å
šå¡ãèŠããŠããããã«ãã€ãŒãµãããã¯p2pããé ãïŒæ£ç¢ºã«ã¯csma / cdã§ãïŒãã€ã³ã¿ãŒãã§ã€ã¹ã«å ããŠããã©ãã£ãã¯ãç®çãšãããã¹ãã¢ãã¬ã¹ïŒIPãšMACââã®äž¡æ¹ïŒãæå®ããå¿
èŠããããŸãïŒãã ããåŸã§èª¬æããŸãïŒ ïŒ æ¢åã®ã¢ãã¬ã¹ãšã®äº€å·®ãåé¿ããããã«ããªã³ã¯ããŒã«ã«ã¢ãã¬ã¹ç¯å²ããã¢ãã¬ã¹ãéžæããŸãã-ä»»æã®ã¢ãã¬ã¹æå®ãè¡ãããšãã§ããŸãããããã¯ãã¯ãããžãŒã®åäœæ¹æ³ããŸã£ããå€æŽããŸããã ã€ãŒãµãããã§ã¯ããããã¹ãã«ãã±ãããéä¿¡ããããã«ãã«ãŒã¿ãŒã¯ARPã䜿çšããŠãã®ãã¹ãã®MACã¢ãã¬ã¹ãèŠã€ããå¿
èŠããããŸãã ç§ã®å Žåãå®å
ãµãŒããŒã®åŽã«ã¯äœãèšå®ãããŠããŸãã-ãã ã®ç©ºã®ã€ã³ã¿ãŒãã§ãŒã¹ã§ãããã«ãŒã¿ãŒã¯ç¡é§ã«ãªã¢ãŒããã¹ãã®ã¢ãã¬ã¹ã解決ããããšããŸãã åœç¶ããã¹ãŠã®ãã©ãŒãªã³ã°ã¯ããã§çµäºããŸãã ãã®ç¶æ³ã«ãªãã«ã¯ïŒ ç¬åµçãªãã®ã¯ãã¹ãŠã·ã³ãã«ã§ã-éçARPã¬ã³ãŒããäœæãããŸãã
bormoglotx@RZN-PE-1# show interfaces ge-0/0/1 description Analyzer-1; unit 0 { family inet { address 169.254.0.0/31 { arp 169.254.0.1 mac 02:00:00:00:00:01; } } }
ãã®çµæãã€ã³ã¿ãŒãã§ã€ã¹ã«ãã®ãããªãšã³ããªãã§ããŸãã
[edit] bormoglotx@RZN-PE-1# run show arp interface ge-0/0/1.0 MAC Address Address Name Interface Flags 02:00:00:00:00:01 169.254.0.1 169.254.0.1 ge-0/0/1.0 permanent
ããã§ãç§ã¯ãã£ãšè©³ãã説æããããšæããŸãã çè«çã«ã¯ããµãŒããŒã«èšå®ãããå®éã®ã¢ãã¬ã¹ã«ãã©ãã£ãã¯ãéä¿¡ã§ããŸãããæãåçŽã§æãæè»ãªã¢ãããŒãã¯ãæ¶ç©ºã®IPã¢ãã¬ã¹ãšARPãšã³ããªããã©ãã£ãã¯ã®ã³ã³ã·ã¥ãŒãåŽã«äœæããããšã§ãã IP / MACã¢ãã¬ã¹ã¯ãæçµçã«ããã¯ã¹ã«æããªãã©ãã£ãã¯ãéä¿¡ãããŸãããç解ããã«ãå®éã«æå®ããããã¹ãããããã©ãã-äž»ãªããšã¯ããŒããã¢ããããŠããããšã§ãã ãã©ãŒãªã³ã°ã§éçARPèšé²ã䜿çšããããšã«ã¯å€§ããªå©ç¹ããããŸã-éçARPèšé²ã¯æéåãã«ãªãããã«ãŒã¿ãŒã¯ARPãµãŒããŒã«èŠæ±ãéä¿¡ããŸããïŒåé€ããããã©ãã£ãã¯ã®ãã³ãã«é¥ãå¯èœæ§ããããããŸãè¯ããããŸããïŒã
ããã§ããã©ãã£ãã¯ããã©ãŒãªã³ã°ããããã«ãäœæããã€ã³ã¹ã¿ã³ã¹ã«äœããã®åœ¢ã§ã©ããããå¿
èŠããããŸãã ãããè¡ãã«ã¯ããã£ã«ã¿ãŒããŒã¹è»¢éã䜿çšããŸãã ãã£ã«ã¿ãŒãäœæããèå³ã®ããã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšããŸãïŒ
[edit] bormoglotx@RZN-PE-1# show firewall family inet filter MIRROR>>>SPAN-1 term MIRROR { then port-mirror-instance SPAN-1; } [edit] bormoglotx@RZN-PE-1# show interfaces ge-0/0/3 description Server-1; unit 0 { family inet { filter { input MIRROR>>>SPAN-1; output MIRROR>>>SPAN-1; } address 11.0.0.254/24; } }
çä¿¡ãã©ãã£ãã¯ãšçºä¿¡ãã©ãã£ãã¯ã®äž¡æ¹ãåéããå¿
èŠããããããäž¡æ¹åã«ãã£ã«ã¿ãŒãæããŸãã
å®è·µã瀺ãããã«ããã®ãã£ã«ã¿ãŒã¯ãµãŒããŒèªäœã®éã®ãã©ãã£ãã¯ã®ééããããã¯ããŸããããã®ãããåãå
¥ãã¢ã¯ã·ã§ã³ãèšè¿°ããå¿
èŠã¯ãããŸããããå€ãã®å Žåãããããä¿è·ããããã«è¿œå ãããŸãã
ããã§ããã©ãŒãªã³ã°ã»ãã·ã§ã³ã®ç¶æ
ã確èªã§ããŸãã
bormoglotx@RZN-PE-1> show forwarding-options port-mirroring Instance Name: SPAN-1 Instance Id: 2 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop inet up ge-0/0/1.0 169.254.0.1
ã©ãããè·å Žã§ãã©ãŒãªã³ã°ã Server-1ããServer-2ã«5ã€ã®ããã±ãŒãžãå®è¡ããŠãAnalyzer-1ã¢ãã©ã€ã¶ãŒã§äœããã£ããã§ããããèŠãŠã¿ãŸãããã
bormoglotx@Server-1:~$ sudo hping3 -S -c 5 12.0.0.1 -d 40 -I eth1 HPING 12.0.0.1 (eth1 12.0.0.1): S set, 40 headers + 40 data bytes len=40 ip=12.0.0.1 ttl=63 DF id=34108 sport=0 flags=RA seq=0 win=0 rtt=3.4 ms len=40 ip=12.0.0.1 ttl=63 DF id=34121 sport=0 flags=RA seq=1 win=0 rtt=3.5 ms len=40 ip=12.0.0.1 ttl=63 DF id=34229 sport=0 flags=RA seq=2 win=0 rtt=3.5 ms len=40 ip=12.0.0.1 ttl=63 DF id=34471 sport=0 flags=RA seq=3 win=0 rtt=3.5 ms len=40 ip=12.0.0.1 ttl=63 DF id=34635 sport=0 flags=RA seq=4 win=0 rtt=3.5 ms
次ã«ããµãŒããŒAnalyzer-1ã§ãã³ãã§ãããã®ãèŠãŠã¿ãŸãããã
bormoglotx@Analyzer-1:~$ sudo tcpdump -i eth1 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes ^C 0 packets captured 0 packets received by filter 0 packets dropped by kernel
ãã¹ãŠãããã»ã©ãã©è²ã§ã¯ãããŸãããçµè«ã¯ããžã¥ãããŒãããã¯ãŒã¯ã¹ãäžèšã®çµè«ã§ç§ãã¡ã«ãã¹ãŠã倧äžå€«ã ãšå ±åããããå®éã«ã¯äœãç§ãã¡ã«ãšã£ãŠããŸããããªãããšã瀺ããŠããŸãã å®éã«ã¯ãèªåèªèº«ããã©ãŒãªã³ã°ããããã®ã€ã³ã¹ã¿ã³ã¹ãäœæããããšãã§ããŸãïŒãããè¡ããŸããïŒããããã©ã«ãã®ã€ã³ã¹ã¿ã³ã¹ã䜿çšããŸãïŒããã¯ã¹å
šäœçšã§ãïŒã ã€ã³ã¹ã¿ã³ã¹ãèªåã§äœæããå Žåããã©ãŒãªã³ã°ãè¡ãFPCã«ãã®ã€ã³ã¹ã¿ã³ã¹ãé¢é£ä»ããå¿
èŠããããŸãïŒããŒããè€æ°ã®FPCã«ããå Žåãè€æ°ã®FPCã«é¢é£ä»ããããšãæå³ããŸãïŒã Juniperã«æ»ããFPCæ§æã§äœæããã€ã³ã¹ã¿ã³ã¹ã瀺ããŸãããã ãªãããã«çŠç¹ãåãããã®ã§ããïŒ äºå®ã圌èªèº«ããã®åé¡ã«äœåºŠãééãããã£ãããäœã§ããããç解ã§ããŸããã§ãã-çµå±ã®ãšãããçµè«ã¯ãã¹ãŠãããŸããã£ãŠãããšèšããŸãã
[edit] bormoglotx@RZN-PE-1# show | compare [edit] + chassis { + fpc 0 { + port-mirror-instance SPAN-1; + } + }
次ã«ããã©ãŒãæ©èœãããã©ãããããäžåºŠç¢ºèªããŸãã
bormoglotx@Server-1:~$ sudo hping3 -S -c 5 12.0.0.1 -d 40 -I eth1 HPING 12.0.0.1 (eth1 12.0.0.1): S set, 40 headers + 40 data bytes len=40 ip=12.0.0.1 ttl=63 DF id=43901 sport=0 flags=RA seq=0 win=0 rtt=4.4 ms len=40 ip=12.0.0.1 ttl=63 DF id=44117 sport=0 flags=RA seq=1 win=0 rtt=3.4 ms len=40 ip=12.0.0.1 ttl=63 DF id=44217 sport=0 flags=RA seq=2 win=0 rtt=3.4 ms len=40 ip=12.0.0.1 ttl=63 DF id=44412 sport=0 flags=RA seq=3 win=0 rtt=3.7 ms len=40 ip=12.0.0.1 ttl=63 DF id=44416 sport=0 flags=RA seq=4 win=0 rtt=3.5 ms
bormoglotx@Analyzer-1:~$ sudo tcpdump -i eth1 -B 4096 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 14:48:43.641475 IP 11.0.0.1.2237 > 12.0.0.1.0: Flags [S], seq 1075183755:1075183795, win 512, length 40 14:48:43.642024 IP 12.0.0.1.0 > 11.0.0.1.2237: Flags [R.], seq 0, ack 1075183796, win 0, length 0 14:48:44.641981 IP 11.0.0.1.2238 > 12.0.0.1.0: Flags [S], seq 1410214066:1410214106, win 512, length 40 14:48:44.642818 IP 12.0.0.1.0 > 11.0.0.1.2238: Flags [R.], seq 0, ack 1410214107, win 0, length 0 14:48:45.642022 IP 11.0.0.1.2239 > 12.0.0.1.0: Flags [S], seq 1858880488:1858880528, win 512, length 40 14:48:45.642873 IP 12.0.0.1.0 > 11.0.0.1.2239: Flags [R.], seq 0, ack 1858880529, win 0, length 0 14:48:46.642127 IP 11.0.0.1.2240 > 12.0.0.1.0: Flags [S], seq 1472273281:1472273321, win 512, length 40 14:48:46.642947 IP 12.0.0.1.0 > 11.0.0.1.2240: Flags [R.], seq 0, ack 1472273322, win 0, length 0 14:48:47.642017 IP 11.0.0.1.2241 > 12.0.0.1.0: Flags [S], seq 1810623498:1810623538, win 512, length 40 14:48:47.642601 IP 12.0.0.1.0 > 11.0.0.1.2241: Flags [R.], seq 0, ack 1810623539, win 0, length 0 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
ãã®çµæããµãŒããŒ1ãšãµãŒããŒ2ã®éã®ãã©ãã£ãã¯äº€æå
šäœãã¢ãã©ã€ã¶ãŒã«èœã¡ãŸããã
次ã«ãã¹ããŒã ãå€æŽãããã¢ãã©ã€ã¶ãŒ2ãè¿œå ãããŸãããã¢ãã©ã€ã¶ãŒ2ã§ã¯ããµãŒããŒ1ãšãµãŒããŒ2ã®éã®ãã¹ãŠã®ãã©ãã£ãã¯ãåä¿¡ããããšãã§ããŸãã
è€æ°ã®æ¶è²»è
ãžã®ãã©ãŒãªã³ã°ãã®çµæãå¥ã®ã¿ã¹ã¯ããããŸãã次ã®ãããªæ°ãããã©ãŒãªã³ã°ã¹ããŒã ãå®è£
ããå¿
èŠããããŸãã
è€éãªããšã¯ãªãããã§ããAnalyzer-2ã®æ¹åã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããã€ã³ã¹ã¿ã³ã¹ãšåžœåã«è¿œå ããŸãã
[edit] bormoglotx@RZN-PE-1# show interfaces ge-0/0/2 description Analyzer-2; unit 0 { family inet { address 169.254.0.2/31 { arp 169.254.0.3 mac 02:00:00:00:00:01; } } } [edit] bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN-1 input { rate 1; run-length 0; } family inet { output { interface ge-0/0/1.0 { next-hop 169.254.0.1; } interface ge-0/0/2.0 { next-hop 169.254.0.3; } } }
ãããããã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ã®åºåéå±€ã«å¥ã®ããŒããè¿œå ããããšãããšãã³ãããæã«ãšã©ãŒãçºçããŸãã
[edit] bormoglotx@RZN-PE-1# commit check [edit forwarding-options port-mirroring instance SPAN-1 family inet output] Port-mirroring configuration error Port-mirroring out of multiple nexthops is not allowed on this platform error: configuration check-out failed
äžèŠãããšããã²ã©ããã¬ãŒãº-ãã©ãããã©ãŒã ã®å¶éã«ããããã©ãŒåããããã©ãã£ãã¯ã«å¯Ÿãã2ã€ã®æ¬¡ã®åžæãäžåºŠã«èšå®ããããšãã§ããŸããã ãããããã¯ã¹ããããã°ã«ãŒãã䜿çšããå Žåããã®å¶éã¯éåžžã«ç°¡åã§ãã
ãã¯ã¹ããããã°ã«ãŒããäœã§ãããã¯ãã§ã«æ確ã«ãªã£ãŠãããšæããŸããååã¯ãããè¡šããŠããŸãã Juniper MXã¯æ倧30ã®ãã¯ã¹ããããã°ã«ãŒãããµããŒãããåã°ã«ãŒãã¯æ倧16ã®ãã¯ã¹ããããã°ã«ãŒããæã€ããšãã§ããŸãã ãã ããããã«å ããŠãåãã¯ã¹ããããã°ã«ãŒãã§ããã¯ã¹ãããããµãã°ã«ãŒããäœæã§ããŸãã 1ã€ã®ãã¯ã¹ããããã°ã«ãŒãã«ã¯ãå°ãªããšã2ã€ã®ãã¯ã¹ãããããå¿
èŠã§ããããã§ãªãå ŽåãJunOSã¯ã³ããããèš±å¯ããŸããã
次ã«ãæ§æã«ç§»ãã次ãããã°ã«ãŒããäœæããŸãã
[edit] bormoglotx@RZN-PE-1# show forwarding-options next-hop-group Analyzer-servers group-type inet; interface ge-0/0/1.0 { next-hop 169.254.0.1; } interface ge-0/0/2.0 { next-hop 169.254.0.3; }
ãããŠããã®ã°ã«ãŒããåºåã®ãã¯ã¹ãããããšããŠç€ºããŸãã
[edit] bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN-1 input { rate 1; run-length 0; } family inet { output { next-hop-group Analyzer-servers; } }
æ®ãã®æ§æã¯å€æŽãããŸããã
æ€èšŒã«é²ã¿ãŸãã æåã«ããã¯ã¹ããããã°ã«ãŒãã®ç¶æ
ã確èªããŸãã
bormoglotx@RZN-PE-1> show forwarding-options next-hop-group detail Next-hop-group: Analyzer-servers Type: inet State: up Number of members configured : 2 Number of members that are up : 2 Number of subgroups configured : 0 Number of subgroups that are up : 0 Members Interfaces: State ge-0/0/1.0 next-hop 169.254.0.1 up ge-0/0/2.0 next-hop 169.254.0.3 up
ãã¹ãŠãã°ã«ãŒãã§æ£åžžã«åäœããŠããŸã-åäœããŠããŸãïŒå°ãªããšã1ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãã¢ããããŠããå Žåãã°ã«ãŒãã¯ã¢ããã«ãªããŸãïŒã 次ã«ããã©ãŒãªã³ã°ã»ãã·ã§ã³ã®ç¶æ
ã確èªããŸãã
bormoglotx@RZN-PE-1> show forwarding-options port-mirroring SPAN-1 Instance Name: SPAN-1 Instance Id: 2 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop inet up Analyzer-servers
ãã¹ãŠé 調ã§ãããåã«èŠãããã«ãããã¯ãã¹ãŠãæ£ããè¡ãããã¹ãŠãããŸããããšããæå³ã§ã¯ãããŸããã ãããã£ãŠã2ã€ã®ãµãŒããŒãžã®ãã©ãã£ãã¯ããã©ãŒãªã³ã°ããããã©ããã確èªããŸãã
bormoglotx@Server-1:~$ sudo hping3 -S -c 5 12.0.0.1 -d 40 -I eth1 HPING 12.0.0.1 (eth1 12.0.0.1): S set, 40 headers + 40 data bytes len=40 ip=12.0.0.1 ttl=63 DF id=64150 sport=0 flags=RA seq=0 win=0 rtt=3.4 ms len=40 ip=12.0.0.1 ttl=63 DF id=64222 sport=0 flags=RA seq=1 win=0 rtt=3.5 ms len=40 ip=12.0.0.1 ttl=63 DF id=64457 sport=0 flags=RA seq=2 win=0 rtt=3.7 ms len=40 ip=12.0.0.1 ttl=63 DF id=64593 sport=0 flags=RA seq=3 win=0 rtt=3.5 ms len=40 ip=12.0.0.1 ttl=63 DF id=64801 sport=0 flags=RA seq=4 win=0 rtt=3.4 ms
Analyzer-1ã®ãã©ãã£ãã¯ïŒ
bormoglotx@Analyzer-1:~$ sudo tcpdump -i eth1 -B 4096 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 15:09:36.837983 IP 11.0.0.1.2304 > 12.0.0.1.0: Flags [S], seq 1255230673:1255230713, win 512, length 40 15:09:36.839367 IP 12.0.0.1.0 > 11.0.0.1.2304: Flags [R.], seq 0, ack 1255230714, win 0, length 0 15:09:37.838115 IP 11.0.0.1.2305 > 12.0.0.1.0: Flags [S], seq 2135769685:2135769725, win 512, length 40 15:09:37.839054 IP 12.0.0.1.0 > 11.0.0.1.2305: Flags [R.], seq 0, ack 2135769726, win 0, length 0 15:09:38.838528 IP 11.0.0.1.2306 > 12.0.0.1.0: Flags [S], seq 1139555126:1139555166, win 512, length 40 15:09:38.839369 IP 12.0.0.1.0 > 11.0.0.1.2306: Flags [R.], seq 0, ack 1139555167, win 0, length 0 15:09:39.838328 IP 11.0.0.1.2307 > 12.0.0.1.0: Flags [S], seq 1181209811:1181209851, win 512, length 40 15:09:39.838924 IP 12.0.0.1.0 > 11.0.0.1.2307: Flags [R.], seq 0, ack 1181209852, win 0, length 0 15:09:40.838335 IP 11.0.0.1.2308 > 12.0.0.1.0: Flags [S], seq 1554756347:1554756387, win 512, length 40 15:09:40.838901 IP 12.0.0.1.0 > 11.0.0.1.2308: Flags [R.], seq 0, ack 1554756388, win 0, length 0 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
ãŸããAnalyzer-2ã®ãã©ãã£ãã¯ã®åæ§ã®ã³ããŒïŒ
bormoglotx@Analyzer-2:~$ sudo tcpdump -i eth1 -B 4096 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 15:09:35.125093 IP 11.0.0.1.2304 > 12.0.0.1.0: Flags [S], seq 1255230673:1255230713, win 512, length 40 15:09:35.126394 IP 12.0.0.1.0 > 11.0.0.1.2304: Flags [R.], seq 0, ack 1255230714, win 0, length 0 15:09:36.125044 IP 11.0.0.1.2305 > 12.0.0.1.0: Flags [S], seq 2135769685:2135769725, win 512, length 40 15:09:36.126107 IP 12.0.0.1.0 > 11.0.0.1.2305: Flags [R.], seq 0, ack 2135769726, win 0, length 0 15:09:37.125552 IP 11.0.0.1.2306 > 12.0.0.1.0: Flags [S], seq 1139555126:1139555166, win 512, length 40 15:09:37.126418 IP 12.0.0.1.0 > 11.0.0.1.2306: Flags [R.], seq 0, ack 1139555167, win 0, length 0 15:09:38.125374 IP 11.0.0.1.2307 > 12.0.0.1.0: Flags [S], seq 1181209811:1181209851, win 512, length 40 15:09:38.125930 IP 12.0.0.1.0 > 11.0.0.1.2307: Flags [R.], seq 0, ack 1181209852, win 0, length 0 15:09:39.125320 IP 11.0.0.1.2308 > 12.0.0.1.0: Flags [S], seq 1554756347:1554756387, win 512, length 40 15:09:39.125844 IP 12.0.0.1.0 > 11.0.0.1.2308: Flags [R.], seq 0, ack 1554756388, win 0, length 0 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
ãã°ããã-ã¿ã¹ã¯ã¯å®äºãããã©ãã£ãã¯ã¯å¿
èŠãªå Žæã«æµããŸã-äž¡æ¹ã®æ¶è²»è
ã¯ãèŠæ±ããããã©ãã£ãã¯ã®ã³ããŒãåãåããŸãã
ãããããããã¯ãŒã¯ã¯éæ¹ããªãããŒã¹ã§çºå±ããŠãããåœç€Ÿã¯ãŒã«ãªãŒãŒã·ã§ã³ãšSORMã«ãéãspareãã¿ãŸããã ããã§ãå¥ã®ãµãŒããŒãAnalyzer-3ãã§ããŸãããããããã©ãã£ãã¯ã®ã³ããŒãåä¿¡ããå¿
èŠããããŸãã ããããåé¡ã¯ããã®ãµãŒããŒãRZN-PE-1ã«ããŒã«ã«ã§ã¯ãªããRZN-PE-2ã«æ¥ç¶ãããŠããããšã§ãã
ãªã¢ãŒããã¹ããã©ãŒãªã³ã°äžèšã®ãã¹ãŠã®èŠ³ç¹ããããã©ãŒãªã³ã°ã¹ããŒã ãå床ããçŽãå¿
èŠããããŸããããã¯æ¬¡ã®ããã«ãªããŸãã
Analyzer-3ãµãŒããŒã¯RZN-PE-2ã®èåŸã«ããããããã®åé¡ã解決ããããã«ä»¥åã«äœ¿çšããæ¹æ³ã¯æ©èœããŸããã äž»ãªåé¡ã¯ããã©ãã£ãã¯ããã©ãŒãªã³ã°ããæ¹æ³ã§ã¯ãªãããã®æ¢ã«ãã©ãŒãªã³ã°ããããã©ãã£ãã¯ãRZN-PE-2ã®èåŸã«ããAnalyzer-3ãµãŒããŒã«ãã©ãã°ãããããã¯ãŒã¯ã«å¯ŸããŠééçã«ããæ¹æ³ã§ããåŸã§åç
§ïŒã ãããè¡ãã«ã¯ããžã¥ãããŒã®æ©åšã§greãã³ãã«ã䜿çšããã®ãäžè¬çã§ãã ããã¯ããªã¢ãŒããã¹ããžã®ãã³ãã«ãäœæãããã©ãŒåããããã¹ãŠã®ãã©ãã£ãã¯ããã®ãã³ãã«ã«ãŸãšããŠããµãŒããŒãŸãã¯å®å
ãµãŒããŒãçµç«¯ããã«ãŒã¿ãŒã«çŽæ¥éä¿¡ãããšããèãæ¹ã§ãã greãã³ãã«ã䜿çšããã«ã¯2ã€ã®ãªãã·ã§ã³ããããŸãã
ãªãã·ã§ã³1 ãã©ãŒãªã³ã°ãå®è¡ããã«ãŒã¿ãŒã§ãgreãã³ãã«ãæ§æããããã©ãã£ãã¯ãåä¿¡ãããµãŒããŒã®å®å
ã¢ãã¬ã¹ãå®å
ãšããŠæå®ãããŸãã åœç¶ããã®ãµãŒããŒãé
眮ãããŠãããããã¯ãŒã¯ïŒãã®å Žåã¯Analyzer-3ïŒã¯ãäœããã®ã«ãŒãã£ã³ã°ãããã³ã«ïŒBGPãŸãã¯IGP-éèŠã§ã¯ãããŸããïŒãä»ããŠèªèãããŠããå¿
èŠããããŸãã åé¡ã¯ããã®ãããªã·ããªãªã§ã¯ããµãŒããŒãžã®ãã©ãã£ãã¯ãgreããããŒãšãšãã«æ³šãããããšã§ãã ææ°ã®ãã©ãã£ãã¯åæããã³ç£èŠã·ã¹ãã ã§ã¯ãããã¯åé¡ã«ãªããŸãããgreã¯IPSecã§ã¯ãªãããã©ãã£ãã¯ã¯æå·åãããŸããã ã€ãŸããã¹ã±ãŒã«ã®çåŽãå®è£
ã®å®¹æãããã1ã€-è¿œå ã®èŠåºãã§ãã ãããããããã€ãã®ã·ããªãªã§ã¯ãäœåãªããããŒã®ååšã¯åãå
¥ããããªãããããªãã·ã§ã³2ã䜿çšããå¿
èŠããããŸãã
ãªãã·ã§ã³2 ãã©ãŒãªã³ã°ãå®è¡ããã«ãŒã¿ãŒãšããã©ãã£ãã¯ãåä¿¡ãããµãŒããŒãçµäºããã«ãŒã¿ãŒã®éã§ãgreãã³ãã«ãäžæããŸãïŒéåžžãããã¯ã«ãŒãããã¯ã§è¡ãããŸãïŒã ãœãŒã¹ããã®ãã©ãŒãªã³ã°ãå®è¡ããã«ãŒã¿ãŒåŽã§ã¯ããã¹ãŠããªãã·ã§ã³1ãšåãã§ãããåä¿¡åŽã§ã¯ãgreãã³ãã«ããåä¿¡ãããã©ãã£ãã¯ãã¢ãã©ã€ã¶ãŒã«ãã©ãŒãªã³ã°ããã«ãŒã¿ãŒã®ã€ã³ã¹ã¿ã³ã¹ãæ§æããå¿
èŠããããŸãã ã€ãŸãã1ã€ã®ãã©ãŒã«ã€ããŠããœãŒã¹ã§ãã©ãŒãªã³ã°ã®1ã€ã®ã€ã³ã¹ã¿ã³ã¹ã䜿çšãããã©ãã£ãã¯ã®åä¿¡è
ã§2ã€ç®ã®ã€ã³ã¹ã¿ã³ã¹ã䜿çšããå¿
èŠãããããšãããããŸããããã«ãããã¹ããŒã ã倧å¹
ã«è€éã«ãªããŸãã ãããäžæ¹ã§ããã®ã·ããªãªã§ã¯ãçŽç²ãªãã©ãã£ãã¯ãäœåãªgreããããŒãªãã§ãµãŒããŒã«æµããŸãã ããã«ããã®ã¹ããŒã ãå®è£
ãããšãã¯ãå³å¯ã«éµå®ããå¿
èŠãããã«ãŒã«ããããŸã-ãã³ãã«ãšã³ããã€ã³ãgreãçµäºããã«ãŒã¿ãŒã«ã¯ããã©ãŒãã©ãã£ãã¯ã®åä¿¡è
ïŒã€ãŸããå
ã®ãã©ãŒãã±ããã®åä¿¡è
ïŒãšããŠç€ºããããã¹ããžã®ã«ãŒãããããŸããã ãã®æ¡ä»¶ãæºããããªãå Žåãéè€ãã±ãããåä¿¡ããŸãããã©ãã£ãã¯ã¯greãã³ãã«ããé£ã³åºããæå®ããããŒãã«ãã©ââãŒãªã³ã°ãããããšã«å ããŠãéåžžã®ipãã±ããã®ããã«ã«ãŒãã£ã³ã°ãããŸãã ãããŠãã«ãŒã¿ãŒãå®å
ãã¹ããžã®ã«ãŒããç¥ã£ãŠããå Žåããã©ãã£ãã¯ã¯ããã«éä¿¡ãããŸãã ãããåé¿ããã«ã¯ãgreã€ã³ã¿ãŒãã§ã€ã¹ãä»®æ³ã«ãŒã¿ãŒã¿ã€ãã®å¥ã®ã€ã³ã¹ã¿ã³ã¹ã«æµžæŒ¬ããå¿
èŠããããŸããã以äžã§èª¬æããä»ã®æ¹æ³ããããŸãã 誰ããèå³ãæã£ãŠããå Žåãæ§æãåé¡ã®æ¬è³ªãããã³ãã¿ãã¬ã®äžã§ãããæã¡è² ããæ¹æ³ïŒ
greåé¡ã«ãããã©ãŒãªã³ã°ãœãŒã¹ã®ãµãŒããŒåŽã®greãã³ãã«ã®æ§æïŒ
bormoglotx@RZN-PE-1# show interfaces gr-0/0/0 description RSPAN; unit 0 { tunnel { source 62.0.0.1; destination 62.0.0.2; } family inet { address 169.254.100.1/31; } }
ãã³ãã«ã®å®å
ã¢ãã¬ã¹ã®ã¿ãå€æŽãããŸãã-RZN-PE-2ã«ãŒãããã¯ã«ãªããŸããã
RZN-PE-2ã§ã¯ãæåã«RZN-PE-1ãžã®greãã³ãã«ãäœæããå¿
èŠããããŸãã
bormoglotx@RZN-PE-2> show configuration interfaces gr-0/0/0 description SPAN; unit 0 { tunnel { source 62.0.0.2; destination 62.0.0.1; } family inet { filter { input MIRROR-RSPAN-GE0/0/1; } } }
ãã®ã€ã³ã¿ãŒãã§ã€ã¹ãããã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ã«ãã©ãã£ãã¯ãéä¿¡ããã«ã¯ã次ã®ããã«ãã£ã«ã¿ãŒããããå¿
èŠããããŸãã
bormoglotx@RZN-PE-2> show configuration firewall family inet filter MIRROR-RSPAN-GE0/0/1 term MIRROR { then port-mirror-instance RSAPN; }
æåŸã«ãã€ã³ã¹ã¿ã³ã¹èªäœãäœæãããããfpcã«ãã€ã³ãããŠããã©ãã£ãã¯ãéä¿¡ãããã€ã³ã¿ãŒãã§ã€ã¹ãäœæããŸãã
bormoglotx@RZN-PE-2> show configuration forwarding-options port-mirroring instance RSAPN input { rate 1; } family inet { output { interface ge-0/0/1.0 { next-hop 169.254.100.1; } } } bormoglotx@RZN-PE-2> show configuration chassis fpc 0 { pic 0 { tunnel-services { bandwidth 10g; } } port-mirror-instance RSAPN; } bormoglotx@RZN-PE-2> show configuration interfaces ge-0/0/1 description Analyzer-3; unit 0 { family inet { address 169.254.100.0/31 { arp 169.254.100.1 mac 02:00:00:19:21:68; } } }
Server-1ãšServer-2ã®éã§pingãå®è¡ãããã©ãŒãªã³ã°ãããŠããããšã確èªããŸãã
bormoglotx@Server-1:~$ ping 12.0.0.1 -I eth1 PING 12.0.0.1 (12.0.0.1) from 11.0.0.1 eth1: 56(84) bytes of data. 64 bytes from 12.0.0.1: icmp_seq=1 ttl=63 time=1.44 ms 64 bytes from 12.0.0.1: icmp_seq=1 ttl=60 time=3.24 ms (DUP!) ⊠... 64 bytes from 12.0.0.1: icmp_seq=1 ttl=3 time=34.7 ms (DUP!) ^C
åºåããéè€ã®äžéšãåé€ããŸããããéè€ã®æ°ã確èªã§ããŸã-1ã€ã®æå¹ãªããã±ãŒãžãš41ã®ãã€ã¯ã ãã©ãã£ãã¯ã¢ãã©ã€ã¶ãŒã§ã¯ãåãç»åãèªç¶ã«è¡šç€ºãããŸãã
bormoglotx@Analyzer-3:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 11:52:13.275451 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1601, seq 1, length 64 11:52:13.275462 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1601, seq 1, length 64 11:52:13.276703 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1601, seq 1, length 64 ⊠âŠ
ãã©ãŒãªã³ã°ã«å ããŠãã«ãŒã¿ãŒã¯ãå®å
ã¢ãã¬ã¹ãžã®ã«ãŒããç¥ã£ãŠãããããgreãã³ãã«ããåä¿¡ãããã±ããã転éããŸãããããä¿®æ£ããã«ã¯ãä»®æ³ã«ãŒã¿ãŒã¿ã€ãã§ã€ã³ã¹ã¿ã³ã¹ãäœæããgreã€ã³ã¿ãŒãã§ã€ã¹ãšãã©ãã£ãã¯ããã©ãŒãªã³ã°ããã€ã³ã¿ãŒãã§ã€ã¹ãè¿œå ããŸãã [edit] bormoglotx@RZN-PE-2# show routing-instances RSPAN-VR description "for RSPAN use only"; instance-type virtual-router; interface gr-0/0/0.0; interface ge-0/0/1.0;
pingãå床å®è¡ããåç·ã®åäœã確èªããŸããè€è£œãµãŒããŒã¯è¡šç€ºãããªããªããŸããã bormoglotx@Server-1:~$ ping 12.0.0.1 -I eth1 PING 12.0.0.1 (12.0.0.1) from 11.0.0.1 eth1: 56(84) bytes of data. 64 bytes from 12.0.0.1: icmp_seq=1 ttl=63 time=2.56 ms 64 bytes from 12.0.0.1: icmp_seq=2 ttl=63 time=8.13 ms 64 bytes from 12.0.0.1: icmp_seq=3 ttl=63 time=1.33 ms 64 bytes from 12.0.0.1: icmp_seq=4 ttl=63 time=2.09 ms 64 bytes from 12.0.0.1: icmp_seq=5 ttl=63 time=2.30 ms ^C
ãŸããéè€ããªãããšã¯ãAnalyzer-3ã¢ãã©ã€ã¶ãŒã®ãã³ãã蚌æããŠããŸãã bormoglotx@Analyzer-3:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 11:59:12.605205 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1602, seq 1, length 64 11:59:12.605350 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1602, seq 1, length 64 11:59:13.611070 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1602, seq 2, length 64 11:59:13.612356 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1602, seq 2, length 64 11:59:14.606350 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1602, seq 3, length 64 11:59:14.606739 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1602, seq 3, length 64 11:59:15.612423 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1602, seq 4, length 64 11:59:15.612488 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1602, seq 4, length 64 11:59:16.614228 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1602, seq 5, length 64 11:59:16.614588 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1602, seq 5, length 64 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
RZN-PE-2, . .
, discard ( discard, reject, Juniper icmp , )
bormoglotx@RZN-PE-2# show firewall family inet filter MIRROR-RSPAN-GE0/0/1 term MIRROR { then { port-mirror-instance RSAPN; discard; } }
, :
bormoglotx@Server-1:~$ ping 12.0.0.1 -I eth1 PING 12.0.0.1 (12.0.0.1) from 11.0.0.1 eth1: 56(84) bytes of data. 64 bytes from 12.0.0.1: icmp_seq=1 ttl=63 time=2.68 ms 64 bytes from 12.0.0.1: icmp_seq=2 ttl=63 time=1.22 ms 64 bytes from 12.0.0.1: icmp_seq=3 ttl=63 time=1.96 ms 64 bytes from 12.0.0.1: icmp_seq=4 ttl=63 time=2.30 ms 64 bytes from 12.0.0.1: icmp_seq=5 ttl=63 time=1.96 ms ^C
:
bormoglotx@Analyzer-3:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 12:03:11.934805 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1604, seq 1, length 64 12:03:11.934834 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1604, seq 1, length 64 12:03:12.982685 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1604, seq 2, length 64 12:03:12.982716 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1604, seq 2, length 64 12:03:13.935027 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1604, seq 3, length 64 12:03:13.935607 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1604, seq 3, length 64 12:03:14.936859 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1604, seq 4, length 64 12:03:14.937654 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1604, seq 4, length 64 12:03:15.937650 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1604, seq 5, length 64 12:03:15.938375 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1604, seq 5, length 64 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
RZN-PE-2. next-hop ( , , , JunOS ), gre , next-hop :
bormoglotx@RZN-PE-2> show configuration interfaces gr-0/0/0 description SPAN; unit 0 { tunnel { source 62.0.0.2; destination 62.0.0.1; } family inet { filter { input MIRROR-RSPAN-GE0/0/1; } } } bormoglotx@RZN-PE-2> show configuration firewall family inet filter MIRROR-RSPAN-GE0/0/1 term MIRROR { then next-hop-group Analyzer-3; }
Next-hop :
bormoglotx@RZN-PE-2> show forwarding-options next-hop-group Analyzer-3 detail Next-hop-group: Analyzer-3 Type: inet State: up Number of members configured : 2 Number of members that are up : 1 Number of subgroups configured : 0 Number of subgroups that are up : 0 Members Interfaces: State ge-0/0/1.0 next-hop 169.254.100.1 up ge-0/0/100.0 down
:
bormoglotx@Server-1:~$ ping 12.0.0.1 -I eth1 -c 5 PING 12.0.0.1 (12.0.0.1) from 11.0.0.1 eth1: 56(84) bytes of data. 64 bytes from 12.0.0.1: icmp_seq=1 ttl=63 time=3.38 ms 64 bytes from 12.0.0.1: icmp_seq=2 ttl=63 time=2.17 ms 64 bytes from 12.0.0.1: icmp_seq=3 ttl=63 time=2.14 ms 64 bytes from 12.0.0.1: icmp_seq=4 ttl=63 time=2.06 ms 64 bytes from 12.0.0.1: icmp_seq=5 ttl=63 time=1.89 ms
, , :
bormoglotx@Analyzer-3:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 12:19:28.306816 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1609, seq 1, length 64 12:19:28.306840 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1609, seq 1, length 64 12:19:29.306887 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1609, seq 2, length 64 12:19:29.307273 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1609, seq 2, length 64 12:19:30.308323 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1609, seq 3, length 64 12:19:30.308455 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1609, seq 3, length 64 12:19:31.309897 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1609, seq 4, length 64 12:19:31.310117 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1609, seq 4, length 64 12:19:32.313234 IP 11.0.0.1 > 12.0.0.1: ICMP echo request, id 1609, seq 5, length 64 12:19:32.313271 IP 12.0.0.1 > 11.0.0.1: ICMP echo reply, id 1609, seq 5, length 64 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
â . â .
æåã®ãªãã·ã§ã³ã䜿çšããŸããæåã«ãgreãµãŒãã¹ïŒgr-X / X / XïŒãåŸãããã«ããã³ãã«ãµãŒãã¹ãæå¹ã«ããå¿
èŠããããŸãã bormoglotx@RZN-PE-1
ããã§ãçè«ã«æ»ãããã³ãã«ã€ã³ã¿ãŒãã§ãŒã¹ãšãªãœãŒã¹ã®äºçŽã«ã€ããŠèª¬æããŸãããã®æ§æã§ã¯ããŒãFPCã®ãŒãPICã®ãã³ãã«ãµãŒãã¹ã«10Gãå²ãåœãŠãŸããããã¯ã10Gã®PFE垯åå¹
ãåæãããããšãæå³ãããã®ã§ã¯ãããŸãã-ããã¯ããã³ãã«ãµãŒãã¹ã10G PFEã®åž¯åå¹
ãã䜿çšã§ããããããã«ãã£ãŠå æãããŠããªããªãœãŒã¹ã®äžéšãç©çããŒããã©ãã£ãã¯ã®è»¢éã«äœ¿çšã§ããããšã瀺åããŸã-ã€ãŸããPFEäžã®10Gã¯å
±æãããŸããã³ãã«ãµãŒãã¹ãšå®éã®ã€ã³ã¿ãŒãã§ã€ã¹ãããããããã¯MPCã«ãŒãäžã«ãããŸãã DPCã«ãŒãã®ã幞ããªãææè
ã§ããå ŽåïŒããšãã°ã4ããŒã¹ã®ã«ãŒããããå ŽåïŒãäžèšã®æ§æã§ã¯1ã€ã®ããŒãã倱ãããŸãïŒã€ãŸããxeããŒãã¯ã·ã¹ãã ããåçŽã«æ¶ããcliããã¢ã¯ã»ã¹ã§ããªããªããããŒãã®è¿ãã§ã©ã€ããç¹ç¯ããŸãïŒããŒãããã³ãã«ã¢ãŒãã«ãªã£ãŠããããšãäŒããŸãïŒãããã«ããããã®ã«ãŒãã§ã¯ããåç¥ã®ãšããããªãœãŒã¹ã¯å³ããäºçŽãããŠããŸããããããã®ã«ãŒãã¯å€ããå€ããªã£ãŠããããããŸã§ã®ãšãã倧éã«äœ¿çšãããŠããŸããã第äºã«ãããŒãçªå·ã«ã€ããŠã話ããããšæããŸã-1GãäºçŽãããšããŒãçªå·ã¯gr-0 / 0/10ã«ãªãã10G以äžãäºçŽãããšããŒãçªå·ã¯gr-0 / 0/0ã«ãªããŸãïŒä»¥äžã«è¡šç€ºãããŸãïŒãªãã·ã§ã³ïŒã [edit] bormoglotx@RZN-PE-1# run show interfaces terse | match "^(gr|lt|vt)-" gr-0/0/0 up up lt-0/0/0 up up vt-0/0/0 up up
TRIOãããã»ãããæèŒããã©ã€ã³ã«ãŒãã§ã¯ããã³ãã«ãµãŒãã¹çšã«äºçŽå¯èœãªæ倧垯åå¹
ã¯60Gã§ãã泚ïŒltãšvtã¯ç°ãªãã€ã³ã¿ãŒãã§ãŒã¹ã§ããããšãè¿œå ããããšæããŸããlt-è«çãã³ãã«-éåžžãè«çã·ã¹ãã ã®æ¥ç¶ãŸãã¯ã€ã³ã¹ã¿ã³ã¹ã®ã«ãŒãã£ã³ã°ãçžäºã«ç®çãšããè«çãã³ãã«-ãããã®ã€ã³ã¹ã¿ã³ã¹ãŸãã¯è«çã·ã¹ãã ãçŽæ¥ãããã³ãŒãã§æ¥ç¶ãããŠãããã®ããã«ããããã®éã®ãã©ãã£ãã¯ãé§åã§ããŸãããã ããvtã¯ä»®æ³ãã³ãã«ã§ããä»®æ³ã«ãŒãããã¯ã¯ãäœããã®ä»®æ³ãšã³ãã£ãã£ããã€ã³ãããã®ã§ã¯ãªããç¹°ãè¿ãæ€çŽ¢ããããã«pfeã§ãã©ãã£ãã¯ãã©ããããããšãç®çãšããŠããŸãïŒããšãã°ãvplsã§ïŒã
ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããåŸãgr-0 / 0/0ãèšå®ããæ©äŒããããŸãããªã¢ãŒãPEã«ãŒã¿ãŒãgreãã³ãã«ãçµäºãããåã«ãµãŒããŒåŽã«ãã©ãã£ãã¯ãéä¿¡ãããªãã·ã§ã³ãç Žæ£ãããããRZN-PE-1äžã®ãã³ãã«ã®ãœãŒã¹ã¢ãã¬ã¹ãšããŠãç¬èªã®ã«ãŒãããã¯ãæå®ããŸããããã©ãŒãªã³ã°ããããã©ãã£ãã¯ã®åä¿¡è
ãµãŒããŒã®å®å
ã¢ãã¬ã¹ãšããŠãããã«ããã®ã¢ãã¬ã¹ãå©çšå¯èœã§ããå¿
èŠããããŸããå®éã®ãšããããµãŒããŒã«ã¯ã¢ãã¬ã¹ãããå Žåãšãªãå ŽåããããŸãã以äžã«ç€ºãããã«ãèªåã§éžæããŠéçARPã¬ã³ãŒããäœæã§ããŸãã [edit] bormoglotx@RZN-PE-2# show | compare [edit interfaces] + ge-0/0/1 { + description Analyzer-3; + unit 0 { + family inet { + address 192.168.0.0/31 { + arp 192.168.0.1 mac 02:00:00:19:21:68; + } + } + } + } [edit protocols ospf area 0.0.0.0] interface ge-0/0/0.0 { ... } + interface ge-0/0/1.0 { + passive; + }
ããã«ãæ瀺ãããæ§æãããããããã«ãã€ã³ã¿ãŒãã§ã€ã¹ã¯ospfã§ããã·ããšããŠè¿œå ãããRZN-PE-1ã¯ãã®ãããã¯ãŒã¯ãžã®ã«ãŒããèªèããŸãã [edit] bormoglotx@RZN-PE-1# run show route 192.168.0.1 inet.0: 20 destinations, 20 routes (20 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 192.168.0.0/31 *[OSPF/10] 00:00:16, metric 3 > to 10.0.0.0 via ge-0/0/0.0
次ã«ãRZN-PE-1ã«greãã³ãã«ãäœæãã次ã®ãããã°ã«ãŒãã«è¿œå ããŸãã [edit] bormoglotx@RZN-PE-1# show interfaces gr-0/0/0 description RSPAN; unit 0 { tunnel { source 62.0.0.1; destination 192.168.0.1; } family inet { address 169.254.100.1/31; } } [edit] bormoglotx@RZN-PE-1# show forwarding-options next-hop-group Analyzer-servers group-type inet; interface gr-0/0/0.0; interface ge-0/0/1.0 { next-hop 169.254.0.1; } interface ge-0/0/2.0 { next-hop 169.254.0.3; }
geã€ã³ã¿ãŒãã§ã€ã¹ãšã¯ç°ãªããgreã€ã³ã¿ãŒãã§ã€ã¹ã¯p2pã§ããããããã¯ã¹ããããã¢ãã¬ã¹ãæå®ããŠãæå³ããããŸãããæå®ããããšã¯ã§ããŸããããã©ãã£ãã¯ã¯å察åŽããåŒãç¶ãéä¿¡ãããŸããããã§ã¯ããã¹ãŠãéåžžã©ããã§ã-ãã©ãŒãªã³ã°ã»ãã·ã§ã³ã®ç¶æ
ã確èªããŸãã [edit] bormoglotx@RZN-PE-1# run show forwarding-options next-hop-group detail Next-hop-group: Analyzer-servers Type: inet State: up Number of members configured : 3 Number of members that are up : 3 Number of subgroups configured : 0 Number of subgroups that are up : 0 Members Interfaces: State gr-0/0/0.0 up ge-0/0/1.0 next-hop 169.254.0.1 up ge-0/0/2.0 next-hop 169.254.0.3 up
ããŠãããã§ãªã¢ãŒããµãŒããŒäžã®ãã©ãã£ãã¯ãååŸãããŠããããšã確èªããŸãã bormoglotx@Server-1:~$ sudo hping3 -S -c 5 12.0.0.1 -d 40 -I eth1 HPING 12.0.0.1 (eth1 12.0.0.1): S set, 40 headers + 40 data bytes len=40 ip=12.0.0.1 ttl=63 DF id=53439 sport=0 flags=RA seq=0 win=0 rtt=8.2 ms len=40 ip=12.0.0.1 ttl=63 DF id=53515 sport=0 flags=RA seq=1 win=0 rtt=3.5 ms len=40 ip=12.0.0.1 ttl=63 DF id=53610 sport=0 flags=RA seq=2 win=0 rtt=3.4 ms len=40 ip=12.0.0.1 ttl=63 DF id=53734 sport=0 flags=RA seq=3 win=0 rtt=3.8 ms len=40 ip=12.0.0.1 ttl=63 DF id=53897 sport=0 flags=RA seq=4 win=0 rtt=3.3 ms
bormoglotx@Analyzer-3:~$ sudo tcpdump -i eth1 -B 4096 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 16:34:34.923370 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 11.0.0.1.2894 > 12.0.0.1.0: Flags [S], seq 1149405522:1149405562, win 512, length 40 16:34:34.926586 IP 62.0.0.1 > 192.168.0.1: GREv0, length 44: IP 12.0.0.1.0 > 11.0.0.1.2894: Flags [R.], seq 0, ack 1149405563, win 0, length 0 16:34:35.923022 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 11.0.0.1.2895 > 12.0.0.1.0: Flags [S], seq 1598018315:1598018355, win 512, length 40 16:34:35.923855 IP 62.0.0.1 > 192.168.0.1: GREv0, length 44: IP 12.0.0.1.0 > 11.0.0.1.2895: Flags [R.], seq 0, ack 1598018356, win 0, length 0 16:34:36.922903 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 11.0.0.1.2896 > 12.0.0.1.0: Flags [S], seq 592229199:592229239, win 512, length 40 16:34:36.924048 IP 62.0.0.1 > 192.168.0.1: GREv0, length 44: IP 12.0.0.1.0 > 11.0.0.1.2896: Flags [R.], seq 0, ack 592229240, win 0, length 0 16:34:37.923278 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 11.0.0.1.2897 > 12.0.0.1.0: Flags [S], seq 694611591:694611631, win 512, length 40 16:34:37.924765 IP 62.0.0.1 > 192.168.0.1: GREv0, length 44: IP 12.0.0.1.0 > 11.0.0.1.2897: Flags [R.], seq 0, ack 694611632, win 0, length 0 16:34:38.924275 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 11.0.0.1.2898 > 12.0.0.1.0: Flags [S], seq 1423363395:1423363435, win 512, length 40 16:34:38.924291 IP 62.0.0.1 > 192.168.0.1: GREv0, length 44: IP 12.0.0.1.0 > 11.0.0.1.2898: Flags [R.], seq 0, ack 1423363436, win 0, length 0 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
ããããç§ãèšã£ãããã«ãgreãã©ãã£ãã¯ã¯é²ãã§ãããããããµãŒããŒã«ãšã£ãŠåé¡ã§ãªãå Žåããã®ã¢ãããŒãã¯æãåçŽã§æãæè»ã§ããããããå€æããããã«ããã©ãŒãªã³ã°ãããåä¿¡ãµãŒããŒã®ææè
ã¯ããã©ãã£ãã¯ãå€ãããããããã¹ãŠã®ãã©ãã£ãã¯ãåä¿¡ããããšãæã¿ãŸããã Analyzer-1ãµãŒããŒã¯TCPãã©ãã£ãã¯ã®ã¿ãå¿
èŠãšããAnalyzer-2ãµãŒããŒã¯UDPãã©ãã£ãã¯ã®ã¿ãå¿
èŠãšããŸãããAnalyzer-3ãµãŒããŒã¯ãã¹ãŠã®ãã©ãã£ãã¯ãå¿
èŠãšããTCP / UDPã«éå®ãããŸãããã€ãŸãã次ã®ãããªã¹ããŒã ãå®è£
ããå¿
èŠããããŸããè€æ°ã®ã³ã³ã·ã¥ãŒããŒã®éžæçãã©ãŒãªã³ã°ããã§ã¯ããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹vt-0 / 0/0ïŒä»®æ³ã«ãŒãããã¯ïŒãå¿
èŠã§ãããŸãã¯ãlt-0 / 0/0ïŒä»®æ³ãã³ãã«ïŒã䜿çšã§ããŸãããæåã®æ¹ãããæãŸããã§ãããã®ãããéžæçãã©ãŒãªã³ã°ã®ç®çã¯æ¬¡ã®ãšããã§ã-ããŒãããã®ãã©ãã£ãã¯ã¯æåã«ä»®æ³ã«ãŒãããã¯vtããŒãã«ãã©ââãŒãªã³ã°ããã次ã«ãéžæãããã©ã¡ãŒã¿ãŒïŒãããã³ã«ãããŒããªã©ïŒã«åºã¥ããŠããã®ããŒãããç°ãªããã¯ã¹ããããã°ã«ãŒãã«åæ£ãããŸãäœãèµ·ãã£ãŠããããããããç解ããããã«ããã®ã¹ããŒã ãçµã¿ç«ãŠãŸããããæåã«ããã©ãã£ãã¯ãä»®æ³ã«ãŒãããã¯ã«ãã©ãŒãªã³ã°ãããããã«ããã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ãå€æŽããŸãã [edit] bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN-1 input { rate 1; run-length 0; } family inet { output { interface vt-0/0/0.0; no-filter-check; } }
no-filter-checkãã©ã¡ãŒã¿ãŒã¯éåžžã«éèŠã§ã-ãã®ã³ãã³ãã䜿çšãããšããã©ãã£ãã¯ããã©ãŒãªã³ã°ãããã€ã³ã¿ãŒãã§ã€ã¹ã«ãã£ã«ã¿ãŒãæ¥ç¶ã§ããŸããããã©ã«ãã§ã¯ããããã®ã€ã³ã¿ãŒãã§ãŒã¹ã§ãã£ã«ã¿ãªã³ã°ã¯ç¡å¹ã«ãªã£ãŠããŸãã次ã«ãvtã€ã³ã¿ãŒãã§ã€ã¹èªäœãäœæããŸãã [edit] bormoglotx@RZN-PE-1# show interfaces vt-0/0/0 unit 0 { description SPAN-USE; family inet; }
ãã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ã¢ãã¬ã¹ããã³ã°ãããããšã¯ã§ããŸããããŸãããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§è§£æ±ºã§ããã¢ãã¬ã¹ãã¡ããªã¯å¶éãããŠããŸãã次ã®å³ããããŸã-ge-0 / 0/3ã€ã³ã¿ãŒãã§ã€ã¹ããã®ãã¹ãŠã®ãã©ãã£ãã¯ã¯vt-0 / 0 / 0.0ããŒãã«åããããŸãã次ã«ããã®ãã©ãã£ãã¯ãããŸããŸãªã³ã³ã·ã¥ãŒãã«ãã©ãŒãªã³ã°ããå¿
èŠããããŸãããããè¡ãã«ã¯ããŸãå¿
èŠãªã³ã³ã·ã¥ãŒããå«ããã¯ã¹ããããã°ã«ãŒããäœæããå¿
èŠããããŸãã [edit] bormoglotx@RZN-PE-1# show forwarding-options next-hop-group Analyzer-TCP group-type inet; interface gr-0/0/0.0; interface ge-0/0/1.0 { next-hop 169.254.0.1; } [edit] bormoglotx@RZN-PE-1# show forwarding-options next-hop-group Analyzer-UDP group-type inet; interface gr-0/0/0.0; interface ge-0/0/2.0 { next-hop 169.254.0.3; } [edit] bormoglotx@RZN-PE-1# show forwarding-options next-hop-group Analyzer-default group-type inet; interface gr-0/0/0.0; interface ge-0/0/100.0;
Analyzer-3ã§ãã©ãã£ãã¯ããã©ãŒãªã³ã°ããããã«èšèšãããgr-0 / 0/0ã€ã³ã¿ãŒãã§ã€ã¹ã¯ã3ã€ãã¹ãŠã®ã°ã«ãŒãã«è¿œå ãããŸããããã¯ããã®ãµãŒããŒãTCPãšUDPã®äž¡æ¹ã®ãã©ãã£ãã¯ãåä¿¡ããããšããäºå®ã«ãããã®ã§ããããã®ããã®å¥åã®ã°ã«ãŒããäœæããŠãã£ã«ã¿ãŒã«é©çšããããšã¯ã§ããŸãããç°ãªãã°ã«ãŒãã§åããã¯ã¹ããããã䜿çšããããšã¯çŠæ¢ãããŠããŸãããAnalyzer-defaultã°ã«ãŒãã«ã¯ãge-0 / 0 / 100.0ããŒãããããŸã-ããã¯ãã°ã«ãŒããå°ãªããšã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãæã€å¿
èŠããããããæ§æãã³ãããã§ããããã«ã°ã«ãŒãã«è¿œå ãããåœã®ããŒãã§ãã次ã«ãå¿
èŠãªåºæºã«åŸã£ãŠãã©ãã£ãã¯ãç
§åãããã¯ã¹ããããã°ã«ãŒãã«æ²¿ã£ãŠåæ£ãããã£ã«ã¿ãŒãäœæããå¿
èŠããããŸãã [edit] bormoglotx@RZN-PE-1# show firewall family inet filter MIRROR-SORTED term MIRROR-TCP { from { protocol tcp; } then next-hop-group Analyzer-TCP; } term MIRROR-UDP { from { protocol udp; } then next-hop-group Analyzer-UDP; } term MIRROR-DEFAUL { then next-hop-group Analyzer-default; }
ãããŠãvtã€ã³ã¿ãŒãã§ãŒã¹ã«åºå®ããŸãã [edit] bormoglotx@RZN-PE-1# show interfaces vt-0/0/0 unit 0 { description SPAN-USE; family inet { filter { input MIRROR-SORTED; } } }
ãã¶ã€ã³ããã§ãã¯ããŸããã¢ããç¶æ
ã®vtã€ã³ã¿ãŒãã§ã€ã¹ã§ã®ãã©ãŒãªã³ã°ïŒ bormoglotx@RZN-PE-1> show forwarding-options port-mirroring SPAN-1 Instance Name: SPAN-1 Instance Id: 2 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop inet up vt-0/0/0.0
ãã¹ãŠã®ã°ã«ãŒãã皌åäžã§ãïŒã°ã«ãŒãã皌åããã«ã¯å°ãªããšã1ã€ã®ããŒãã皌åããŠããå¿
èŠãããããšã«æ³šæããŠãã ããïŒã bormoglotx@RZN-PE-1> show forwarding-options next-hop-group detail Next-hop-group: Analyzer-TCP Type: inet State: up Number of members configured : 2 Number of members that are up : 2 Number of subgroups configured : 0 Number of subgroups that are up : 0 Members Interfaces: State gr-0/0/0.0 up ge-0/0/1.0 next-hop 169.254.0.1 up Next-hop-group: Analyzer-UDP Type: inet State: up Number of members configured : 2 Number of members that are up : 2 Number of subgroups configured : 0 Number of subgroups that are up : 0 Members Interfaces: State gr-0/0/0.0 up ge-0/0/2.0 next-hop 169.254.0.3 up Next-hop-group: Analyzer-default Type: inet State: up Number of members configured : 2 Number of members that are up : 1 Number of subgroups configured : 0 Number of subgroups that are up : 0 Members Interfaces: State gr-0/0/0.0 up ge-0/0/100.0 down
ããŠã5ã€ã®icmpãtcpãudpãã±ãããçæããã©ã®ãµãŒããŒã«å°éãããã確èªããŸãããã¹ãŠã®ã¯ã©ã€ã¢ã³ããµãŒããŒã§ãtcpdumpãåæã«æå¹ã«ããŸãã--rand-sourceã¹ã€ããã§hping3ã䜿çšããã®ã§ããã©ãã£ãã¯ã¯Server-1ã«åããããŒãã§ã®ã¿ååŸãããããããªã¿ãŒã³ãã©ãã£ãã¯ã¯è¡šç€ºãããŸããããã®ãããAnalyzer-1ã§ææãããã®ãèŠãŠãã ãããTCPã®ã¿ãååšããã¯ãã§ãã bormoglotx@Analyzer-1:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 19:58:25.457641 IP 108.215.126.169.1668 > 12.0.0.1.0: Flags [S], seq 1842749676:1842749716, win 512, length 40 19:58:26.458098 IP 230.181.170.188.1669 > 12.0.0.1.0: Flags [S], seq 1810452177:1810452217, win 512, length 40 19:58:27.459245 IP 112.6.155.46.1670 > 12.0.0.1.0: Flags [S], seq 1524555644:1524555684, win 512, length 40 19:58:28.459006 IP 50.45.169.23.1671 > 12.0.0.1.0: Flags [S], seq 1362080290:1362080330, win 512, length 40 19:58:29.459294 IP 135.146.14.177.1672 > 12.0.0.1.0: Flags [S], seq 2122009219:2122009259, win 512, length 40 ^C 5 packets captured 5 packets received by filter 0 packets dropped by kernel
次ã«ãAnalyzer-2ã§äœãçºçãããã確èªããŸãããïŒããã«ã¯UDPãã©ãã£ãã¯ã®ã¿ãååšããã¯ãã§ãïŒ bormoglotx@Analyzer-2:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 19:58:09.340702 IP 132.43.66.243.1121 > 12.0.0.1.0: UDP, length 40 19:58:10.341308 IP 205.172.124.143.1122 > 12.0.0.1.0: UDP, length 40 19:58:11.341239 IP 253.127.33.120.1123 > 12.0.0.1.0: UDP, length 40 19:58:12.341204 IP 246.68.75.25.1124 > 12.0.0.1.0: UDP, length 40 19:58:13.341819 IP 95.89.126.64.1125 > 12.0.0.1.0: UDP, length 40 ^C 5 packets captured 5 packets received by filter 0 packets dropped by kernel
ããŠãç§ã¯Analyzer-3ã«ãšã©ãŸããããã§ãã¹ãŠãé£ç¶ããŠãã£ãããããã±ããã®ç·æ°ã¯15ïŒ5 UDP / 5 TCP / 5 ICMPïŒã§ããã¯ãã§ãïŒ bormoglotx@Analyzer-3:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 19:58:11.782669 IP 62.0.0.1 > 192.168.0.1: GREv0, length 72: IP 132.43.66.243.1121 > 12.0.0.1.0: UDP, length 40 19:58:12.783508 IP 62.0.0.1 > 192.168.0.1: GREv0, length 72: IP 205.172.124.143.1122 > 12.0.0.1.0: UDP, length 40 19:58:13.783166 IP 62.0.0.1 > 192.168.0.1: GREv0, length 72: IP 253.127.33.120.1123 > 12.0.0.1.0: UDP, length 40 19:58:14.782758 IP 62.0.0.1 > 192.168.0.1: GREv0, length 72: IP 246.68.75.25.1124 > 12.0.0.1.0: UDP, length 40 19:58:15.783594 IP 62.0.0.1 > 192.168.0.1: GREv0, length 72: IP 95.89.126.64.1125 > 12.0.0.1.0: UDP, length 40 19:58:18.310249 IP 62.0.0.1 > 192.168.0.1: GREv0, length 100: IP 65.173.140.215 > 12.0.0.1: ICMP net 5.6.7.8 unreachable, length 76 19:58:19.311045 IP 62.0.0.1 > 192.168.0.1: GREv0, length 100: IP 171.91.95.222 > 12.0.0.1: ICMP net 5.6.7.8 unreachable, length 76 19:58:20.312496 IP 62.0.0.1 > 192.168.0.1: GREv0, length 100: IP 228.215.127.12 > 12.0.0.1: ICMP net 5.6.7.8 unreachable, length 76 19:58:21.311067 IP 62.0.0.1 > 192.168.0.1: GREv0, length 100: IP 214.149.191.71 > 12.0.0.1: ICMP net 5.6.7.8 unreachable, length 76 19:58:22.311398 IP 62.0.0.1 > 192.168.0.1: GREv0, length 100: IP 119.130.166.53 > 12.0.0.1: ICMP net 5.6.7.8 unreachable, length 76 19:58:26.186528 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 108.215.126.169.1668 > 12.0.0.1.0: Flags [S], seq 1842749676:1842749716, win 512, length 40 19:58:27.187385 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 230.181.170.188.1669 > 12.0.0.1.0: Flags [S], seq 1810452177:1810452217, win 512, length 40 19:58:28.188726 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 112.6.155.46.1670 > 12.0.0.1.0: Flags [S], seq 1524555644:1524555684, win 512, length 40 19:58:29.188846 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 50.45.169.23.1671 > 12.0.0.1.0: Flags [S], seq 1362080290:1362080330, win 512, length 40 19:58:30.188499 IP 62.0.0.1 > 192.168.0.1: GREv0, length 84: IP 135.146.14.177.1672 > 12.0.0.1.0: Flags [S], seq 2122009219:2122009259, win 512, length 40 ^C 15 packets captured 15 packets received by filter 0 packets dropped by kernel
ããŠãå®è£
ããªããã°ãªããªãããšã¯ãã¹ãŠè¡ãããŸãã-æå³ãããšããããã©ãã£ãã¯ã¯æ¶è²»è
ã®éã§ãã©ãŒãªã³ã°ããã³åæ£ãããŸããäžèšã®L3ãã©ãã£ãã¯ããã©ãŒãªã³ã°ããŸããããJuniper MXã·ãªãŒãºã«ãŒã¿ãŒã¯éåžžã«æè»ãªããã€ã¹ã§ãããIPãã©ãã£ãã¯ïŒinet / inet6ãã¡ããªãŒïŒã ãã§ãªããvplsãl2cktïŒCiscoã®çšèªã§ã¯xconnectïŒãªã©ã®L2ãã©ãã£ãã¯ããã©ãŒãªã³ã°ã§ããŸããL2ãã©ãã£ãã¯ã®ããŒã«ã«ãã©ãŒãªã³ã°L2CKTã«éä¿¡ãããŠãããã®ãã¹ãã€ããå¿
èŠãããæãåçŽãªã±ãŒã¹ãèããŠã¿ãŸãããïŒããã¯ãåæããã®ã«ãã©ãã£ãã¯ãã©ããããŠããã¯ã©ã€ã¢ã³ããããã«ã€ããŠãç¥ããªãã®ã§ãããã¯ç¢ºãã«è¯ãããšã§ã¯ãããŸããã顧客ïŒãã¹ããŒã ã¯åçŽã§ã-äœããã®çš®é¡ã®L2CKTãRZN-PE-1ãšRZN-PE-2ã®éã«åŒã蟌ãŸããŸããã€ãŸãããã®ãããªãã©ãŒãªã³ã°ã¹ããŒã ãå®è£
ããå¿
èŠããããŸããRZN-PE-1ãšRZN-PE-2ã®éã«L2CKTããã«ãããŸããããã確èªããŸãã bormoglotx@RZN-PE-1> show configuration protocols l2circuit neighbor 62.0.0.2 { interface ge-0/0/6.100 { virtual-circuit-id 100; } } bormoglotx@RZN-PE-1> show configuration interfaces ge-0/0/6.100 encapsulation vlan-ccc; vlan-id 100; family ccc { filter { input MIRROR-L2CKT-SPAN-1; output MIRROR-L2CKT-SPAN-1; } }
cccãã¡ããªãã€ã³ã¿ãŒãã§ã€ã¹ã«å«ãŸããŠããã®ã¯è«ççã§ã-ããã¯çµå±L2CKTã§ãããã®æ§æã§ã¯ãL2CKTãééãããã¹ãŠã®ãã©ãã£ãã¯ãåä¿¡ããå¿
èŠããããããäž¡åŽã®ãã£ã«ã¿ãŒãå¿
èŠãªã€ã³ã¿ãŒãã§ã€ã¹ã«æ¢ã«ãã³ã°ããŠããŸãããã£ã«ã¿ãŒã¯ä»¥åãšåºæ¬çã«åãã§ããã¢ãã¬ã¹ãã¡ããªãŒã®ã¿ãinetã§ã¯ãªããcccã§ãã bormoglotx@RZN-PE-1> show configuration firewall family ccc filter MIRROR-L2CKT-SPAN-1 term MIRROR { then port-mirror-instance SPAN-1; }
次ã«ããã©ãŒãªã³ã°ã«äœ¿çšãããã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ãã»ããã¢ããããŸããå
¥åã»ã¯ã·ã§ã³ã«å€æŽã¯ãããŸãã-ãã¹ãŠã¯ä»¥åãšåãã§ãããåºåã»ã¯ã·ã§ã³ã«ã¯å€§ããªéãããããŸãã bormoglotx@RZN-PE-1> show configuration forwarding-options port-mirroring instance SPAN-1 input { rate 1; run-length 0; } family ccc { output { interface ge-0/0/1.0; } }
ã¢ãã¬ã¹ãã¡ããªãå€æŽãããŸãã-çŸåšã¯cccã§ããããã«ããããã©ãã£ãã¯ã®éä¿¡å
ãšãªãã€ã³ã¿ãŒãã§ã€ã¹ã®æ§æã«å¿
ç¶çãªå€æŽãçããŸãã以åã«ép2pã€ã³ã¿ãŒãã§ã€ã¹ã§è¡ãããããã«ã次ãããã¢ãã¬ã¹ãèšå®ããããšãããšãæåããŸããã bormoglotx@RZN-PE-1# set forwarding-options port-mirroring instance SPAN-1 family ccc output interface ge-0/0/1 ? Possible completions: <[Enter]> Execute this command + apply-groups Groups from which to inherit configuration data + apply-groups-except Don't inherit configuration data from these groups no-filter-check Do not check for filters on port-mirroring interface | Pipe through a command
ç§ãã¡ã«ã¯ãã®ãããªæ©äŒã¯ãããŸããããããã£ãŠããã©ãã£ãã¯ãéä¿¡ããå¿
èŠãããã€ã³ã¿ãŒãã§ã€ã¹ã«ã¯ãããªããžãŸãã¯cccãã¡ããªãå«ããå¿
èŠããããŸãã [edit] bormoglotx@RZN-PE-1# show interfaces ge-0/0/1 description Analyzer-1; encapsulation ethernet-ccc; unit 0 { family ccc; }
cccãã¡ããªãŒã¯åœç¶äœ¿ããããã§ãããããªããžã䜿çšããå¿
èŠãããå Žåã¯ãéèŠãªãã¥ã¢ã³ã¹ãå¿ããªãã§ãã ãã-ããªããžã«ãã»ã«åãšã®ã€ã³ã¿ãŒãã§ã€ã¹ãããªããžãã¡ã€ã³ã«é
眮ããå¿
èŠããããŸãïŒãã¡ã€ã³ã®vlançªå·ããŒãã«äœ¿çšã§ãããããå®éã®vlançªå·ãéžæããŸããä»ã®ãµãŒãã¹ã®ãã©ãŒãªã³ã°äžïŒããã¹ãŠã®æºåãæŽã£ããããã©ãŒãªã³ã°ã»ãã·ã§ã³ã®ç¶æ
ã確èªããŸãã bormoglotx@RZN-PE-1> show forwarding-options port-mirroring Instance Name: SPAN-1 Instance Id: 2 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop ccc up ge-0/0/1.0
ãã¹ãŠãæ£åžžã§ã-ã»ãã·ã§ã³ã§ã¢ããããã¹ãéã§pingãå®è¡ããã¢ãã©ã€ã¶ãŒã§äœãèµ·ãããã確èªããŸãã bormoglotx@TEST-1> ping routing-instance VR-1 10.0.0.2 count 5 PING 10.0.0.2 (10.0.0.2): 56 data bytes 64 bytes from 10.0.0.2: icmp_seq=0 ttl=64 time=10.159 ms 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=11.136 ms 64 bytes from 10.0.0.2: icmp_seq=2 ttl=64 time=9.723 ms 64 bytes from 10.0.0.2: icmp_seq=3 ttl=64 time=7.754 ms 64 bytes from 10.0.0.2: icmp_seq=4 ttl=64 time=10.619 ms
åéãããã®ã¯æ¬¡ã®ãšããã§ãã bormoglotx@Analyzer-1:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 23:44:31.948237 IP 10.0.0.1 > 10.0.0.2: ICMP echo request, id 17420, seq 0, length 64 23:44:31.954408 IP 10.0.0.2 > 10.0.0.1: ICMP echo reply, id 17420, seq 0, length 64 23:44:32.955149 IP 10.0.0.1 > 10.0.0.2: ICMP echo request, id 17420, seq 1, length 64 23:44:32.964115 IP 10.0.0.2 > 10.0.0.1: ICMP echo reply, id 17420, seq 1, length 64 23:44:33.967789 IP 10.0.0.1 > 10.0.0.2: ICMP echo request, id 17420, seq 2, length 64 23:44:33.973388 IP 10.0.0.2 > 10.0.0.1: ICMP echo reply, id 17420, seq 2, length 64 23:44:34.975442 IP 10.0.0.1 > 10.0.0.2: ICMP echo request, id 17420, seq 3, length 64 23:44:34.980370 IP 10.0.0.2 > 10.0.0.1: ICMP echo reply, id 17420, seq 3, length 64 23:44:35.986900 IP 10.0.0.1 > 10.0.0.2: ICMP echo request, id 17420, seq 4, length 64 23:44:35.992213 IP 10.0.0.2 > 10.0.0.1: ICMP echo reply, id 17420, seq 4, length 64 ^C 10 packets captured 10 packets received by filter 0 packets dropped by kernel
å®éããã¹ãŠã®ãã±ãããã¢ãã©ã€ã¶ãŒã«å°éããŸãããããã§ãããè€éãªã¹ããŒã ãæ€èšããŠãã ãã-ããªããžãã¡ã€ã³ãŸãã¯ä»®æ³ã¹ã€ããã«ããã€ã³ã¿ãŒãã§ã€ã¹ã®ãã©ãŒãªã³ã°ãæ§æããå¿
èŠããããŸããåä¿¡ã¯ãäžèšã®ããã«ããŒã«ã«ããŒãã«ã³ããŒãéä¿¡ããããã®ãã©ãã£ãã¯ããªã¢ãŒãããã¯ã¹ã«ããããããŸããL2ãã©ãã£ãã¯ããªã¢ãŒããµãŒããŒã«ãã©ãŒãªã³ã°ããæåã®èãã¯ããã¹ãŠãåçŽã§ãããgreãã³ãã«ã䜿çšã§ãããšããããšã§ããããããæ®å¿µãªãããgreã¯ccc / tcc / vpls / bridgeã«ãã»ã«åããµããŒãããŠããŸããããã ããJunosã«ã¯ãããŸããŸãªæ¹æ³ã䜿çšããŠåãåé¡ã解決ã§ããããŸããŸãªããŒã«ããããæã«ã¯äœããè¡ãã®ã¯éçŸå®çãšæãããããšããããŸãããæçµçã«ã¯ãNçªç®ã®æéãšNçªç®ã®ã¹ã¢ãŒã¯ããã¥ã¢ã«ã®åŸã«ãã¹ãŠãå§ãŸããŸããããã§ãåãã§ãã次ã«ããã®ãããªè€éãªã¹ããŒã ãçµã¿ç«ãŠãŸããäœãšçç±ã説æããŸãããã®ãããä»®æ³ã¹ã€ããïŒL2CKTãŸãã¯ããªããžãã¡ã€ã³ïŒãããã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ãžã®ãã©ãã£ãã¯ããã©ãŒãªã³ã°ãããã©ãã£ãã¯ã¯äžéšã®ç©çã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯ãªããä»®æ³ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹lt-0 / 0/0ã«ãã©ãŒãªã³ã°ãããŸãããã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯ããã¯ã¹ããšã«1ã€ããããã®ãŠãããã¯ãã¢ãŠããããšåŒã°ãããã¢ã§äœæãããŸãã1ã€ã®ãŠãããã¯ãã³ãã«ã®å
¥å端ã§ã2çªç®ã®ãŠãããã¯åºåã§ãããã®çµæã1ã€ã®ãŠãããã«åé¡ããããã®ã¯ãã¹ãŠãããã«é¢é£ä»ããããŠãã2çªç®ã®ãŠãããããé£ã³åºããŸãããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãcccã«ãã»ã«åãæå¹ã«ããããããåä¿¡è
ãµãŒããŒãçµç«¯ãããªã¢ãŒãã«ãŒã¿ãŒã«L2CKTãæ§ç¯ããŸããã€ãŸããL2CKTãä»ããŠL2ãã©ãã£ãã¯ãçŽæ¥ãªã¢ãŒããµãŒããŒã«éä¿¡ããŸãããªã¢ãŒãã«ãŒã¿ãŒã®å Žåãããã¯åçŽãªL2CKTã«ãªããŸããããã§ã¯ãæ§æã«ç§»ããŸãããããµãŒããŒåŽãžã®ã€ã³ã¿ãŒãã§ãŒã¹ã¯ã¢ã¯ã»ã¹äžã§ãããä»®æ³ã¹ã€ããã«ãããŸãïŒ bormoglotx@RZN-PE-1# wildcard range show interfaces ge-0/0/[3-4] description Server-1; encapsulation ethernet-bridge; unit 0 { family bridge { filter { input MIRROR-BRIDGE-vSwitch-1; } interface-mode access; vlan-id 100; } } description Server-2; encapsulation ethernet-bridge; unit 0 { family bridge { filter { input MIRROR-BRIDGE-vSwitch-1; } interface-mode access; vlan-id 100; } } [edit] bormoglotx@RZN-PE-1# show routing-instances vSwitch-1 instance-type virtual-switch; interface ge-0/0/3.0; interface ge-0/0/4.0; bridge-domains { BD100 { vlan-id 100; } }
çä¿¡ãã©ãã£ãã¯ãSPAN-1ã€ã³ã¹ã¿ã³ã¹ã«ãã©ãŒãªã³ã°ããããã«ããã£ã«ã¿ãŒãã€ã³ã¿ãŒãã§ã€ã¹ã§ãã³ã°ããŸãããã£ã«ã¿ãŒã¯ããã¡ããªãŒãé€ãã以åã«äœ¿çšããããã®ãšå€ãããŸãã-ãã®ã·ããªãªã§ã¯ãããªããžã䜿çšãããŸãïŒ [edit] bormoglotx@RZN-PE-1# show firewall family bridge filter MIRROR-BRIDGE-vSwitch-1 term MIRROR { then port-mirror-instance SPAN-1; }
次ã«ãSPAN-1ã€ã³ã¹ã¿ã³ã¹ãäœæããŸãã [edit] bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN-1 input { rate 1; run-length 0; } family vpls { output { interface lt-0/0/0.0; } }
å°ããªãã¥ã¢ã³ã¹ããããŸããã¢ãã¬ã¹ãã¡ããªã¯ããªããžã«ãã£ãŠç€ºãããŸãããã€ã³ã¹ã¿ã³ã¹æ§æã§ã¯ãã®ãããªãã¡ããªã¯èŠã€ãããŸããããvplsã¯èŠã€ãããŸãããã®ãã¡ããªïŒVPLSïŒã¯ãvpl /ããªããžãã¡ã€ã³ããã®ãã©ãã£ãã¯ããã©ãŒãªã³ã°ããããã«äœ¿çšãããŸãã次ã«ããã©ãã£ãã¯ãéä¿¡ãããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããŸãã [edit] bormoglotx@RZN-PE-1# show interfaces lt-0/0/0 unit 0 { description RSPAN-IN; encapsulation ethernet-ccc; peer-unit 1; family ccc; } unit 1 { description RSPAN-OUT; encapsulation ethernet-ccc; peer-unit 0; family ccc; }
åã«æžããããã«ãltã€ã³ã¿ãŒãã§ãŒã¹ã¯2ã€ã®ãŠãããã§æ§æãããŠããŸã-ç§ãã¡ã®å ŽåããŠããã0ãš1ã§ãããŠããã0ã«é£ã¶ãã®ã¯ãã¹ãŠãŠããã1ãéããŸããäžè¬çã«ããŠãããã¯L3ã®ããã«ãªããŸããããšãã°ccc-ããã¯åäœããŸãã䞡端ã«cccããããŸãããŒããŠãããã§ã¯ããã©ãã£ãã¯ãccc / bridge / vplsãã¡ããªã®ã€ã³ã¹ã¿ã³ã¹ã«ãã©ãŒãªã³ã°ããå¿
èŠããããããæåã®ãŠãããã§cccã䜿çšããã®ã¯ããã®ãŠãããããL2CKTãæ§ç¯ãããããã§ãã次ã«ãRZN-PE-1ãšRZN-PE-2ã®éã«L2CKTãäœæããŸããRZN-PE-1ã®åŽé¢ããïŒ [edit] bormoglotx@RZN-PE-1# show protocols l2circuit neighbor 62.0.0.2 { interface lt-0/0/0.1 { virtual-circuit-id 1; encapsulation-type ethernet; } }
RZN-PE-2ã®åŽé¢ããïŒ bormoglotx@RZN-PE-2> show configuration protocols l2circuit neighbor 62.0.0.1 { interface ge-0/0/1.0 { virtual-circuit-id 1; encapsulation-type ethernet; } } bormoglotx@RZN-PE-2> show configuration interfaces ge-0/0/1 description Analyzer-3; encapsulation ethernet-ccc; unit 0 { family ccc; }
ããã§ããã©ã³ã±ã³ã·ã¥ã¿ã€ã³ãæ©èœããŠãããã©ããã確èªã§ããŸãããŸããL2CKTã®ç¶æ
ãèŠãŠã¿ãŸãããã [edit] bormoglotx@RZN-PE-1# run show l2circuit connections | find ^Nei Neighbor: 62.0.0.2 Interface Type St Time last up # Up trans lt-0/0/0.1(vc 1) rmt Up Sep 2 07:28:05 2017 1 Remote PE: 62.0.0.2, Negotiated control-word: Yes (Null) Incoming label: 299840, Outgoing label: 299872 Negotiated PW status TLV: No Local interface: lt-0/0/0.1, Status: Up, Encapsulation: ETHERNET Flow Label Transmit: No, Flow Label Receive: No
çŽ æŽããããL2CKTã¯ä»äºäžã次ã«ããã©ãŒãªã³ã°ã»ãã·ã§ã³ã®ç¶æ
ã確èªããŸãã [edit] bormoglotx@RZN-PE-1# run show forwarding-options port-mirroring SPAN-1 Instance Name: SPAN-1 Instance Id: 2 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop vpls up lt-0/0/0.0
ãã¹ãŠé 調ã§ããServer-1ãµãŒããŒãšServer-2ãµãŒããŒéã§pingãå®è¡ãããã©ãã£ãã¯ã¢ãã©ã€ã¶ãŒã«å°éãããã®ã確èªããŸãã bormoglotx@Server-1:~$ ping 11.0.0.2 -I 11.0.0.1 -c 5 -i 0.2 PING 11.0.0.2 (11.0.0.2) from 11.0.0.1 : 56(84) bytes of data. 64 bytes from 11.0.0.2: icmp_seq=1 ttl=64 time=3.86 ms 64 bytes from 11.0.0.2: icmp_seq=2 ttl=64 time=2.34 ms 64 bytes from 11.0.0.2: icmp_seq=3 ttl=64 time=2.30 ms 64 bytes from 11.0.0.2: icmp_seq=4 ttl=64 time=9.56 ms 64 bytes from 11.0.0.2: icmp_seq=5 ttl=64 time=1.43 ms
次ã«ãAnalyzer-3ã«ç§»åããŠãtcpdumpã®å
容ã確èªããŸãã bormoglotx@Analyzer-3:~$ sudo tcpdump -i eth1 -B 9192 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes 10:48:46.296920 IP 11.0.0.1 > 11.0.0.2: ICMP echo request, id 2000, seq 1, length 64 10:48:46.297969 IP 11.0.0.2 > 11.0.0.1: ICMP echo reply, id 2000, seq 1, length 64 10:48:46.496380 IP 11.0.0.1 > 11.0.0.2: ICMP echo request, id 2000, seq 2, length 64 10:48:46.497647 IP 11.0.0.2 > 11.0.0.1: ICMP echo reply, id 2000, seq 2, length 64 10:48:46.700540 IP 11.0.0.1 > 11.0.0.2: ICMP echo request, id 2000, seq 3, length 64 10:48:46.700547 IP 11.0.0.2 > 11.0.0.1: ICMP echo reply, id 2000, seq 3, length 64 10:48:46.897518 IP 11.0.0.1 > 11.0.0.2: ICMP echo request, id 2000, seq 4, length 64 10:48:46.907024 IP 11.0.0.2 > 11.0.0.1: ICMP echo reply, id 2000, seq 4, length 64 10:48:47.098414 IP 11.0.0.1 > 11.0.0.2: ICMP echo request, id 2000, seq 5, length 64 10:48:47.098799 IP 11.0.0.2 > 11.0.0.1: ICMP echo reply, id 2000, seq 5, length 64 10:48:51.307134 ARP, Request who-has 11.0.0.1 tell 11.0.0.2, length 46 10:48:51.307542 ARP, Reply 11.0.0.1 is-at 00:50:01:00:07:00 (oui Unknown), length 46 ^C 12 packets captured 12 packets received by filter 0 packets dropped by kernel
ããŠãpingã«å ããŠãèŠæ±/å¿çarpããã³ãã«å
¥ããŸãããããã¯ããã¹ãŠã®ãã©ãã£ãã¯ããã©ãŒãªã³ã°ãããŠããããšã蚌æããŠããŸãããããå¿
èŠãªããšã§ããçµè«ãšããŠãæ倧2ã€ã®ãã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ãåãfpcã«ãã€ã³ãã§ããããšãæžããããšãæãåºããŸãããããã3ã€ã®ã€ã³ã¹ã¿ã³ã¹ã䜿çšããå¿
èŠãããå Žåã¯ã©ãã§ããããïŒãã¡ããã2ã€ã®ãŠãŒã¶ãŒå®çŸ©ã€ã³ã¹ã¿ã³ã¹ãš1ã€ã®ããã©ã«ãã€ã³ã¹ã¿ã³ã¹ïŒ1ã€ã®ã¿ïŒã䜿çšã§ããŸãããããã¯æåã®è§£æ±ºçã§ã¯ãããŸããã次ã«ãããã©ã«ãã€ã³ã¹ã¿ã³ã¹ãæ¢ã«äœ¿çšãããŠããå Žååœç¶ãJunOSã§ã¯ãã®å¶éãåé¿ã§ããŸããååãšããŠãè¶
èªç¶çãªãã®ã¯ãããŸãã-æäœã®åçã¯åãã§ãå€æŽã¯ã€ã³ã¹ã¿ã³ã¹ã®æ§æã®ã¿ã«é¢ä¿ããŸããåãFPCã§3ã€ä»¥äžã®ãã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹ã䜿çšãããããã£ãŠãäž»ãªãã€ã³ãã¯ãè€æ°ã®ãã©ãŒãªã³ã°ã€ã³ã¹ã¿ã³ã¹éã«ãªã³ã¯ãäœæããããšã§ãããããåç
§ãã芪ã€ã³ã¹ã¿ã³ã¹ãšåã€ã³ã¹ã¿ã³ã¹ãäœæãããŸãã芪ã€ã³ã¹ã¿ã³ã¹ã§ã¯ãå
¥åãã©ã¡ãŒã¿ãŒãã€ãŸããã©ãŒãªã³ã°/ãµã³ããªã³ã°ã®é床ãæ倧ãã±ãããµã€ãºãæå®ããŸããåã€ã³ã¹ã¿ã³ã¹ã§ã¯ãåºåãã©ã¡ãŒã¿ãŒã¯ãã§ã«ç€ºãããŠããŸã-ã€ã³ã¿ãŒãã§ãŒã¹ãŸãã¯ãã¯ã¹ããããã°ã«ãŒãã§ãããå
¥åãã©ã¡ãŒã¿ãŒã¯æ§æã§æå®ããã芪ã€ã³ã¹ã¿ã³ã¹ããç¶æ¿ãããŸããæ§æããªããã°ãããã¯æããã«ç解ã§ããªãã®ã§ã次ã®ãããªãã©ãŒãªã³ã°ã¹ããŒã ããŸãšããŸãããããŸãã芪ã€ã³ã¹ã¿ã³ã¹ãäœæããSPANãšåŒã³ãŸãã bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN input { rate 1; run-length 0; }
ã€ã³ã¹ã¿ã³ã¹ã§ã¯ãçä¿¡ãã©ãŒãã©ã¡ãŒã¿ã®ã¿ãæå®ãããŸããããã«ç€ºãããšã¯ãã以äžãããŸããã次ã«ã3ã€ã®åã€ã³ã¹ã¿ã³ã¹ãäœæããŸãã [edit] bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN-1 input-parameters-instance SPAN; family inet { output { interface ge-0/0/1.0 { next-hop 169.254.0.1; } } } [edit] bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN-2 input-parameters-instance SPAN; family inet { output { interface ge-0/0/2.0 { next-hop 169.254.0.3; } } } [edit] bormoglotx@RZN-PE-1# show forwarding-options port-mirroring instance SPAN-3 input-parameters-instance SPAN; family inet { output { interface gr-0/0/0.0 { } }
ããã§ã¯ãçºä¿¡ãã©ãŒãªã³ã°ãã©ã¡ãŒã¿ãŒãæ¢ã«ç€ºããŠããŸãã芪ãšåã®ã€ã³ã¹ã¿ã³ã¹éã®ãªã³ã¯ã¯ã次ã®ã³ãã³ãã䜿çšããŠè¡ãããŸãã input-parameters-instance SPAN;
ãã®çµæãäœæãã3ã€ã®SPAN-1 / 2/3ã€ã³ã¹ã¿ã³ã¹ã¯ãã¹ãŠãSPANã€ã³ã¹ã¿ã³ã¹ããå
¥åãã©ã¡ãŒã¿ãŒãç¶æ¿ããŸããèŠããŠããããã«ãããã§ã€ã³ã¹ã¿ã³ã¹ãããã€ãïŒãŸãã¯ç°ãªãã«ãŒãã®çä¿¡ããŒãã®å Žåã¯ããã€ãïŒã«ãã€ã³ãããå¿
èŠããããŸããåã«ãèšã£ãããã«ã芪ã€ã³ã¹ã¿ã³ã¹ã®ã¿ãFPCã«ãã€ã³ãããå¿
èŠããããŸãã bormoglotx@RZN-PE-1
ããã§ã¯ããã¹ãŠãåãã§ã-ãã£ã«ã¿ãŒãäœæããçä¿¡ããŒãã«æããŸãïŒ bormoglotx@RZN-PE-1# wildcard range show interfaces ge-0/0/[3-5] description Server-1; unit 0 { family inet { filter { input MIRROR>>>SPAN-3; output MIRROR>>>SPAN-3; } address 11.0.0.254/24; } } description Server-2; unit 0 { family inet { filter { input MIRROR>>>SPAN-2; output MIRROR>>>SPAN-2; } address 12.0.0.254/24; } } description Server-3; unit 0 { family inet { filter { input MIRROR>>>SPAN-1; output MIRROR>>>SPAN-1; } address 13.0.0.254/24; } }
ãã£ã«ã¿ãŒã¯èŠªã€ã³ã¹ã¿ã³ã¹ã§ã¯ãªããåã€ã³ã¹ã¿ã³ã¹ã瀺ãããšã«æ³šæããŠãã ããã [edit] bormoglotx@RZN-PE-1# wildcard range show firewall family inet filter MIRROR>>>SPAN-[1-3] term MIRROR { then port-mirror-instance SPAN-1; } term MIRROR { then port-mirror-instance SPAN-2; } term MIRROR { then port-mirror-instance SPAN-3; }
次ã«ããã©ãŒãªã³ã°ã»ãã·ã§ã³ã®ç¶æ
ã確èªããŸãã bormoglotx@RZN-PE-1# run show forwarding-options port-mirroring Instance Name: SPAN-1 Instance Id: 3 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop inet up gr-0/0/0.0 Instance Name: SPAN-2 Instance Id: 4 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop inet up ge-0/0/2.0 169.254.0.3 Instance Name: SPAN-3 Instance Id: 5 Input parameters: Rate : 1 Run-length : 0 Maximum-packet-length : 0 Output parameters: Family State Destination Next-hop inet up ge-0/0/1.0 169.254.0.1
åºåããããã©ãã£ãã¯ãã©ãŒãªã³ã°ã»ãã·ã§ã³ãåäœäžã§ãããçä¿¡ãã©ãã£ãã¯åŠçãã©ã¡ãŒã¿ãŒã芪ã€ã³ã¹ã¿ã³ã¹ããç¶æ¿ãããŠããããšãããããŸããå®éããã®èšäºãæžããããã«äœæ¥ã®çµè«ãçŽæ¥ç€ºãããšã¯ããŸããããã®èšäºãèªãã åŸããã®ãããªã¹ããŒã ãèªåã§çµã¿ç«ãŠãŠãã®ããã©ãŒãã³ã¹ããã§ãã¯ã§ãããšæããŸããç§ãæžãããã£ããã¹ãŠãæžããããã§ããã³ã¡ã³ããè¿œå ãããå Žå-æžã蟌ã¿ãŸãããæž
èŽããããšãããããŸããã