Flow-Based Monitoring - Dell Force10 Z9000 Configuration Manual

Ftos configuration guide for z9000 system
Hide thumbs Also See for Force10 Z9000:
Table of Contents

Advertisement

Flow-based Monitoring

Flow-based Monitoring
Flow-based monitoring conserves bandwidth by monitoring only specified traffic instead all traffic on the
interface. This feature is particularly useful when looking for malicious traffic. It is available for Layer 2
and Layer 3 ingress and egress traffic. You may specify traffic using standard or extended access-lists.
To configure flow-based monitoring:
Step
Task
4
Enable flow-based monitoring for a monitoring session.
5
Define in an access-list rules that include the keyword
monitor. FTOS only considers for port monitoring traffic
matching rules with the keyword monitor.
See
Chapter 6, Access Control Lists
6
Apply the ACL to the monitored port. See
Access Control Lists
View an access-list that you applied to an interface using the command
from EXEC Privilege mode, as shown in
Figure 32-8. Configuring Flow-based Monitoring
FTOS(conf)#monitor session 0
FTOS(conf-mon-sess-0)#flow-based enable
FTOS(conf)#ip access-list
FTOS(config-ext-nacl)#seq 5 permit icmp any any count bytes
FTOS(config-ext-nacl)#seq 10 permit ip 102.1.1.0/24 any count bytes
FTOS(config-ext-nacl)#seq 15 deny udp any any count bytes
FTOS(config-ext-nacl)#seq 20 deny tcp any any count bytes
FTOS(config-ext-nacl)#exit
FTOS(conf)#interface gig 1/1
FTOS(conf-if-gi-1/1)#ip access-group
FTOS(conf-if-gi-1/1)#show config
!
interface GigabitEthernet 1/1
ip address 10.11.1.254/24
ip access-group testflow in
shutdown
FTOS(conf-if-gi-1/1)#exit
FTOS(conf)#do show ip accounting access-list testflow
!
Extended Ingress IP access list testflow on GigabitEthernet 1/1
Total cam count 4
seq 5 permit icmp any any monitor count bytes (0 packets 0 bytes)
seq 10 permit ip 102.1.1.0/24 any monitor count bytes (0 packets 0 bytes)
seq 15 deny udp any any count bytes (0 packets 0 bytes)
seq 20 deny tcp any any count bytes (0 packets 0 bytes)
FTOS(conf)#do show monitor session 0
SessionID
---------
|
Port Monitoring
698
is supported only on platform
(ACLs).
Chapter 6,
(ACLs).
Figure 32-8.
ext testflow
testflow in
Source
Destination
------
-----------
e
Command Syntax
flow-based enable
ip access-list
ip access-group
access-list
show ip accounting access-list
monitor
monitor
Direction
Mode
---------
----
Command Mode
MONITOR SESSION
CONFIGURATION
INTERFACE
Type
----

Advertisement

Table of Contents
loading

Table of Contents