亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? flow-tools-examples.html

?? netflow,抓包
?? HTML
字號:
<HTML><HEAD><TITLE>flow-tools-examples</TITLE><METANAME="GENERATOR"CONTENT="Modular DocBook HTML Stylesheet Version 1.71"></HEAD><BODYCLASS="REFENTRY"BGCOLOR="#FFFFFF"TEXT="#000000"LINK="#0000FF"VLINK="#840084"ALINK="#0000FF"><H1><ANAME="AEN1"><SPANCLASS="APPLICATION">flow-tools-examples</SPAN></A></H1><DIVCLASS="REFNAMEDIV"><ANAME="AEN6"></A><H2>Name</H2><SPANCLASS="APPLICATION">flow-tools-examples</SPAN>&nbsp;--&nbsp;Example usage of flow-tools.</DIV><DIVCLASS="REFSECT1"><ANAME="AEN10"></A><H2>EXAMPLE - Configuring Cisco IOS Router</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN12"></A><P></P><P>NetFlow is configured on each input interface, then global commands areused to specify the export destination.  To ensure a consistant sourceaddress address Loopback0 is configured as the export source.<PRECLASS="PROGRAMLISTING">ip cef distributedip flow-export version 5 origin-asip flow-export destination 10.0.0.100 5004ip flow-export source Loopback0interface Loopback0 ip address 10.1.1.1 255.255.255.255interface FastEthernet0/1/0  ip address 10.0.0.1 255.255.255.0 no ip directed-broadcast ip route-cache flow ip route-cache distributed&#13;</PRE>Many other options exist such as aggregated NetFlow and sampled NetFlow whichare detailed at <AHREF="http://www.cisco.com"TARGET="_top">http://www.cisco.com</A>.</P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN16"></A><H2>EXAMPLE - Configuring Cisco CatIOS Switch</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN18"></A><P></P><P>Some Cisco Catalyst switches support a different implementation of NetFlowthat is performed on the supervisor.  With the cache based forwarding modelwhich is implemented in the Catalyst 55xx with Route Switch Module (RSM)and NetFlow Feature Card (NFFC), the RSM processes the first flow and theremaining packets in the flow are forwarded by the Supervisor.  This isalso implemented in the early versions of the 65xx with MSFC.  Thedeterministic forwarding model used in the 65xx with MSFC2 do not useNetFlow to determine the forwarding path, the flow cache is only usedfor statistics as in the current IOS implementations.  In all of of the above configurations flow exports arrive from both the RSM/MSFC andthe Supervisor engines as distinct streams.  In the worst cast the RSMexports in version 5 and the Supervisor exports in version 7.Fortunately flow-capture and flow-receive can sort all this out by processing flows from both sources and converting them to a common export format.</P><P>The router side running IOS is configured identically to the examplegiven above.  The CatIOS NetFlow Data Export configuration follows:</P><P><PRECLASS="PROGRAMLISTING">set mls flow fullset mls nde version 7set mls nde 10.0.0.1 9800set mls nde enable</PRE></P><P>When the 65xx is running in Native mode, from a users perspective the switch is only running IOS.</P><P>More detailed examples can be found on Cisco's web site <AHREF="http://www.cisco.com"TARGET="_top">http://www.cisco.com</A>.</P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN26"></A><H2>EXAMPLE - Configuring Juniper Router</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN28"></A><P></P><P>Juniper supports flow exports by the routing engine sampling packetheaders and aggregating them into flows.  Packet sampling is done by defining a firewall filter to accept and sample all traffic, applying that rule to the interface, then configuring the samplingforwarding option.<PRECLASS="PROGRAMLISTING">interfaces {    ge-0/3/0 {        unit 0 {            family inet {                filter {                    input all;                    output all;                }                address 10.0.0.1/24;            }        }    }firewall {    filter all {        term all {            then {                sample;                accept;            }        }    }}forwarding-options {    sampling {        input {            family inet {                rate 100;            }        }        output {            cflowd 10.0.0.100 {                port 9800;                version 5;            }        }    }}</PRE></P><P>Other options exist such as aggregated flows which are detailed at <AHREF="http://www.juniper.net"TARGET="_top">http://www.juniper.net</A>.</P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN33"></A><H2>EXAMPLE - Network topology and <TTCLASS="FILENAME">flow.acl</TT></H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN36"></A><P></P><P>The network topology and flow.acl will be used for many of the examplesthat follow.  Flows are collected and stored in <TTCLASS="FILENAME">/flows/R</TT>.<PRECLASS="SCREEN">&#13;                       ISP-A       ISP-B                         +           +                          +         +            IP=10.1.2.1/24 +       + IP=10.1.1.1/24                 ifIndex=2  +     +  ifIndex=1       interface=serial1/1   +   +   interface=serial0/0                             -----                             | R | Campus Router                             -----                             +   +           IP=10.1.4.1/24   +     +   IP=10.1.3.1/24                ifIndex=4  +       +  ifIndex=3    interface=Ethernet1/1 +         + interface=Ethernet0/0                         +           +                       Sales      Marketing&#13;</PRE><PRECLASS="PROGRAMLISTING">ip access-list standard sales permit 10.1.4.0 0.0.0.255ip access-list standard not_sales deny 10.1.4.0 0.0.0.255ip access-list standard marketing permit 10.1.3.0 0.0.0.255ip access-list standard not_marketing deny 10.1.3.0 0.0.0.255ip access-list standard campus permit 10.1.4.0 0.0.0.255ip access-list standard campus permit 10.1.3.0 0.0.0.255ip access-list standard not_campus deny 10.1.4.0 0.0.0.255ip access-list standard not_campus deny 10.1.3.0 0.0.0.255ip access-list standard evil_hacket permit host 10.6.6.6ip access-list standard spoofer permit host 10.9.9.9ip access-list standard multicast 224.0.0.0 15.255.255.255</PRE></P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN41"></A><H2>EXAMPLE - Finding spoofed addresses</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN43"></A><P></P><P>A common problem on the Internet is the use of "spoofed" (addressesthat are not assigned to an organization) for use in DoS attacks or compromising servers that rely on the source IP address for authentication.</P><P>Display all flow records that originate from the campus and are sentto the Internet but are not using legal addresses.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-print</B></P><P>Summary of the destinations of the internally spoofed addresses sorted by octets.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-stat -f8 -S2</B></P><P>Summary of the sources of the internally spoofed addresses sorted by flows.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-stat -f9 -S1</B></P><P>Summary of the internally spoofed sources and destination pairs sorted by packets.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-stat -f10 -S4</B></P><P>Display all flow records that originate external to the campus that havecampus addresses.  Many times these can be attackers trying to exploit hostbased authentication mechanisms like unix r* commands.  Another commonsource is mobile clients which send packets with their campus addressesbefore obtaining a valid IP.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Scampus -i1,2 | flow-print</B></P><P>Summary of the destinations of the externally spoofed addresses sorted by octets.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Scampus -i1,2 | flow-stat -f8 -S2</B></P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN63"></A><H2>EXAMPLE - Locate hosts using or running services</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN65"></A><P></P><P>Find all SMTP servers active during the collection periodthat have established connections to the Internet.  Summarize sortedby octets.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -I1,2 -P25 | flow-stat -f9 -S2</B></P><P>Find all outbound NNTP connections to the Internet.  Summarize with sourceand destination IP sorted by octets.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -I1,2 -P119 | flow-stat -f10 -S3</B></P><P>Find all inbound NNTP connections to the Internet.  Summarize with sourceand destination IP sorted by octets.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -i1,2 -P119 | flow-stat -f10 -S3</B></P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN75"></A><H2>EXAMPLE - Multicast usage</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN77"></A><P></P><P>Summarize Multicast S,G where sources are on campus.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Dmulticast -I1,2 | flow-stat -f10 -S3</B></P><P>Summarize Multicast S,G where sources are off campus.</P><P><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -Dmulticast -i1,2 | flow-stat -f10 -S3</B></P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN84"></A><H2>EXAMPLE - Find scanners</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN86"></A><P></P><P>Find SMTP scanners with flow-dscan.  This will also find SMTP clients whichtry to contact many servers.  This behavior is characterized by a recent Microsoft worm.</P><P><PCLASS="LITERALLAYOUT"><BCLASS="COMMAND">touch dscan.suppress.src dscan.suppress.dst</B><br><br><BCLASS="COMMAND">flow-cat /flows/R | flow-filter -P25 | flow-dscan -b</B><br>&#13;</P></P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN92"></A><H2>AUTHOR</H2><P>Mark Fullmer<TTCLASS="EMAIL">&#60;<AHREF="mailto:maf@splintered.net">maf@splintered.net</A>&#62;</TT></P></DIV><DIVCLASS="REFSECT1"><ANAME="AEN99"></A><H2>SEE ALSO</H2><P><SPANCLASS="APPLICATION">flow-tools</SPAN>(1)</P></DIV></BODY></HTML>

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
不卡av在线免费观看| 亚洲高清不卡在线| 丰满亚洲少妇av| 2020国产成人综合网| 国产成人精品影视| 国产精品成人一区二区艾草| 92精品国产成人观看免费| 亚洲乱码国产乱码精品精98午夜 | 91麻豆精品久久久久蜜臀| 日韩成人免费电影| 久久免费美女视频| av在线这里只有精品| 亚洲国产精品久久久久秋霞影院 | 精品午夜久久福利影院| 国产性做久久久久久| 色欧美乱欧美15图片| 秋霞电影一区二区| 国产欧美视频一区二区三区| 一本一本大道香蕉久在线精品| 亚洲靠逼com| 欧美不卡一区二区三区四区| 成人综合激情网| 亚洲妇熟xx妇色黄| 久久精品视频一区二区三区| 91丨porny丨国产| 热久久久久久久| 国产精品传媒在线| 欧美一级高清片| 成人福利视频在线| 天天综合日日夜夜精品| 久久久www成人免费无遮挡大片 | 欧美日韩激情一区二区三区| 麻豆国产91在线播放| 亚洲欧美国产三级| 精品免费视频.| 日本韩国欧美在线| 国产一二精品视频| 亚洲观看高清完整版在线观看| 久久午夜国产精品| 欧美日韩免费视频| 欧美日韩一区二区在线观看视频| 国内一区二区视频| 亚洲成人免费在线观看| 国产精品久久久久aaaa樱花 | 久久综合视频网| 91黄色激情网站| 国产成人av电影在线观看| 天天综合网 天天综合色| 136国产福利精品导航| 久久欧美中文字幕| 91精品国产乱| 欧美美女直播网站| 一本一本大道香蕉久在线精品| 国产福利一区在线| 美女一区二区在线观看| 亚洲国产精品久久久久秋霞影院 | 久久国产麻豆精品| 五月天国产精品| 亚洲精品精品亚洲| 亚洲丝袜美腿综合| 国产欧美日韩在线看| 2021中文字幕一区亚洲| 91精品久久久久久久99蜜桃| 91久久线看在观草草青青| 成人精品一区二区三区四区| 亚洲精品一区二区三区精华液 | 国产精品毛片无遮挡高清| 在线91免费看| 欧美日免费三级在线| 91亚洲精品乱码久久久久久蜜桃 | 91毛片在线观看| 成人网在线播放| 成人av免费网站| 成人妖精视频yjsp地址| 激情文学综合插| 久久成人免费日本黄色| 另类小说图片综合网| 久久精品国产亚洲5555| 日本中文在线一区| 免费在线观看一区二区三区| 日韩av中文在线观看| 日韩国产成人精品| 久久黄色级2电影| 久久精品久久99精品久久| 久久精品国产精品亚洲红杏| 久久99国产精品免费| 国产精品自在在线| 国产大陆亚洲精品国产| 成人免费视频免费观看| 99久久99久久精品免费观看| 一本大道久久a久久精二百| 91福利国产精品| 91精品国产高清一区二区三区 | 欧美人妖巨大在线| 欧美电影精品一区二区| 精品国产伦理网| 亚洲国产精品激情在线观看| 一区二区三区中文字幕电影 | 日韩一级二级三级精品视频| 精品国产3级a| 国产精品蜜臀在线观看| 亚洲一线二线三线视频| 久久精品国产网站| 99久精品国产| 91精品国产综合久久久蜜臀粉嫩| 欧美精品一区二区高清在线观看| 国产精品网友自拍| 亚洲成人先锋电影| 国产精品一区二区在线播放| 91在线免费播放| 91精品午夜视频| 亚洲国产岛国毛片在线| 亚洲电影视频在线| 国产一区亚洲一区| 色噜噜久久综合| 欧美精品一区二区在线播放| 亚洲三级电影网站| 精品系列免费在线观看| 91国偷自产一区二区开放时间 | 亚洲少妇最新在线视频| 麻豆久久久久久| av在线一区二区三区| 日韩欧美在线网站| 一区二区视频在线| 男女性色大片免费观看一区二区 | 久久精品亚洲国产奇米99| 亚洲永久免费av| 另类的小说在线视频另类成人小视频在线 | 成人国产精品免费网站| 成人精品一区二区三区四区| 在线不卡一区二区| 国产精品日韩精品欧美在线| 天天影视色香欲综合网老头| 成人h版在线观看| 日韩精品一区国产麻豆| 一区二区在线免费| 成人动漫在线一区| 久久久久久久久久久黄色| 亚洲综合免费观看高清完整版在线 | 国产一区不卡视频| 51午夜精品国产| 亚洲精品成a人| 成人午夜碰碰视频| 精品国产制服丝袜高跟| 午夜精品视频在线观看| 91九色02白丝porn| 中文一区二区在线观看| 国产主播一区二区三区| 日韩欧美在线1卡| 亚洲成人7777| 国产精品三级av在线播放| 久久99热狠狠色一区二区| 成人白浆超碰人人人人| 在线不卡免费欧美| 亚洲在线观看免费| 91亚洲精品一区二区乱码| 国产精品网友自拍| 成人免费精品视频| 日本一区二区三区四区| 韩国精品一区二区| 26uuu亚洲| 国产黄色精品网站| 中文字幕免费一区| 丁香激情综合国产| 亚洲国产精品成人综合| 国产99久久久国产精品免费看| 精品美女被调教视频大全网站| 麻豆精品久久久| 精品国产a毛片| 国产九色精品成人porny| 国产剧情一区在线| 亚洲国产电影在线观看| 国产亚洲欧洲一区高清在线观看| 91精品国产91久久综合桃花 | 日韩视频中午一区| 日本女人一区二区三区| 国产精品女上位| 在线综合视频播放| 91行情网站电视在线观看高清版| 麻豆国产精品视频| 亚洲自拍都市欧美小说| 99精品久久久久久| 亚洲女人****多毛耸耸8| 色先锋资源久久综合| 亚洲一区二区高清| 欧美一级片在线观看| 看片网站欧美日韩| 中文字幕精品三区| 在线观看网站黄不卡| 五月婷婷色综合| 精品国产制服丝袜高跟| 99在线精品视频| 亚洲国产日韩a在线播放性色| 日韩欧美国产三级电影视频| 国产宾馆实践打屁股91| 亚洲欧美日韩一区二区三区在线观看| 欧美三级日韩在线| 国产一区二区三区日韩| 亚洲欧美日韩国产成人精品影院 | 亚洲制服丝袜在线|