亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? flow-tools-examples.sgml

?? netflow,抓包
?? SGML
字號:
<!DOCTYPE refentry PUBLIC "-//Davenport//DTD DocBook V3.0//EN"><refentry><refmeta><refentrytitle><application>flow-tools-examples</application></refentrytitle><manvolnum>1</manvolnum></refmeta><refnamediv><refname><application>flow-tools-examples</application></refname><refpurpose>Example usage of flow-tools.</refpurpose></refnamediv><refsect1><title>EXAMPLE - Configuring Cisco IOS Router</title><informalexample><para>NetFlow is configured on each input interface, then global commands areused to specify the export destination.  To ensure a consistant sourceaddress address Loopback0 is configured as the export source.<programlisting>ip cef distributedip flow-export version 5 origin-asip flow-export destination 10.0.0.100 5004ip flow-export source Loopback0interface Loopback0 ip address 10.1.1.1 255.255.255.255interface FastEthernet0/1/0  ip address 10.0.0.1 255.255.255.0 no ip directed-broadcast ip route-cache flow ip route-cache distributed</programlisting>Many other options exist such as aggregated NetFlow and sampled NetFlow whichare detailed at <ulink url="http://www.cisco.com"></ulink>.</para></informalexample></refsect1><refsect1><title>EXAMPLE - Configuring Cisco CatIOS Switch</title><informalexample><para>Some Cisco Catalyst switches support a different implementation of NetFlowthat is performed on the supervisor.  With the cache based forwarding modelwhich is implemented in the Catalyst 55xx with Route Switch Module (RSM)and NetFlow Feature Card (NFFC), the RSM processes the first flow and theremaining packets in the flow are forwarded by the Supervisor.  This isalso implemented in the early versions of the 65xx with MSFC.  Thedeterministic forwarding model used in the 65xx with MSFC2 do not useNetFlow to determine the forwarding path, the flow cache is only usedfor statistics as in the current IOS implementations.  In all of of the above configurations flow exports arrive from both the RSM/MSFC andthe Supervisor engines as distinct streams.  In the worst cast the RSMexports in version 5 and the Supervisor exports in version 7.Fortunately flow-capture and flow-receive can sort all this out by processing flows from both sources and converting them to a common export format.</para><para>The router side running IOS is configured identically to the examplegiven above.  The CatIOS NetFlow Data Export configuration follows:</para><para><programlisting>set mls flow fullset mls nde version 7set mls nde 10.0.0.1 9800set mls nde enable</programlisting></para><para>When the 65xx is running in Native mode, from a users perspective the switch is only running IOS.</para><para>More detailed examples can be found on Cisco's web site <ulink url="http://www.cisco.com"></ulink>.</para></informalexample></refsect1><refsect1><title>EXAMPLE - Configuring Juniper Router</title><informalexample><para>Juniper supports flow exports by the routing engine sampling packetheaders and aggregating them into flows.  Packet sampling is done by defining a firewall filter to accept and sample all traffic, applying that rule to the interface, then configuring the samplingforwarding option.<programlisting>interfaces {    ge-0/3/0 {        unit 0 {            family inet {                filter {                    input all;                    output all;                }                address 10.0.0.1/24;            }        }    }firewall {    filter all {        term all {            then {                sample;                accept;            }        }    }}forwarding-options {    sampling {        input {            family inet {                rate 100;            }        }        output {            cflowd 10.0.0.100 {                port 9800;                version 5;            }        }    }}</programlisting></para><para>Other options exist such as aggregated flows which are detailed at <ulink url="http://www.juniper.net"></ulink>.</para></informalexample></refsect1><refsect1><title>EXAMPLE - Network topology and <filename>flow.acl</filename></title><informalexample><para>The network topology and flow.acl will be used for many of the examplesthat follow.  Flows are collected and stored in <filename>/flows/R</filename>.<screen>                       ISP-A       ISP-B                         +           +                          +         +            IP=10.1.2.1/24 +       + IP=10.1.1.1/24                 ifIndex=2  +     +  ifIndex=1       interface=serial1/1   +   +   interface=serial0/0                             -----                             | R | Campus Router                             -----                             +   +           IP=10.1.4.1/24   +     +   IP=10.1.3.1/24                ifIndex=4  +       +  ifIndex=3    interface=Ethernet1/1 +         + interface=Ethernet0/0                         +           +                       Sales      Marketing</screen><programlisting>ip access-list standard sales permit 10.1.4.0 0.0.0.255ip access-list standard not_sales deny 10.1.4.0 0.0.0.255ip access-list standard marketing permit 10.1.3.0 0.0.0.255ip access-list standard not_marketing deny 10.1.3.0 0.0.0.255ip access-list standard campus permit 10.1.4.0 0.0.0.255ip access-list standard campus permit 10.1.3.0 0.0.0.255ip access-list standard not_campus deny 10.1.4.0 0.0.0.255ip access-list standard not_campus deny 10.1.3.0 0.0.0.255ip access-list standard evil_hacket permit host 10.6.6.6ip access-list standard spoofer permit host 10.9.9.9ip access-list standard multicast 224.0.0.0 15.255.255.255</programlisting></para></informalexample></refsect1><refsect1><title>EXAMPLE - Finding spoofed addresses</title><informalexample><para>A common problem on the Internet is the use of "spoofed" (addressesthat are not assigned to an organization) for use in DoS attacks or compromising servers that rely on the source IP address for authentication.</para><para>Display all flow records that originate from the campus and are sentto the Internet but are not using legal addresses.</para><para><command>flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-print</command></para><para>Summary of the destinations of the internally spoofed addresses sorted by octets.</para><para><command>flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-stat -f8 -S2</command></para><para>Summary of the sources of the internally spoofed addresses sorted by flows.</para><para><command>flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-stat -f9 -S1</command></para><para>Summary of the internally spoofed sources and destination pairs sorted by packets.</para><para><command>flow-cat /flows/R | flow-filter -Snot_campus -I1,2 | flow-stat -f10 -S4</command></para><para>Display all flow records that originate external to the campus that havecampus addresses.  Many times these can be attackers trying to exploit hostbased authentication mechanisms like unix r* commands.  Another commonsource is mobile clients which send packets with their campus addressesbefore obtaining a valid IP.</para><para><command>flow-cat /flows/R | flow-filter -Scampus -i1,2 | flow-print</command></para><para>Summary of the destinations of the externally spoofed addresses sorted by octets.</para><para><command>flow-cat /flows/R | flow-filter -Scampus -i1,2 | flow-stat -f8 -S2</command></para></informalexample></refsect1><refsect1><title>EXAMPLE - Locate hosts using or running services</title><informalexample><para>Find all SMTP servers active during the collection periodthat have established connections to the Internet.  Summarize sortedby octets.</para><para><command>flow-cat /flows/R | flow-filter -I1,2 -P25 | flow-stat -f9 -S2</command></para><para>Find all outbound NNTP connections to the Internet.  Summarize with sourceand destination IP sorted by octets.</para><para><command>flow-cat /flows/R | flow-filter -I1,2 -P119 | flow-stat -f10 -S3</command></para><para>Find all inbound NNTP connections to the Internet.  Summarize with sourceand destination IP sorted by octets.</para><para><command>flow-cat /flows/R | flow-filter -i1,2 -P119 | flow-stat -f10 -S3</command></para></informalexample></refsect1><refsect1><title>EXAMPLE - Multicast usage</title><informalexample><para>Summarize Multicast S,G where sources are on campus.</para><para><command>flow-cat /flows/R | flow-filter -Dmulticast -I1,2 | flow-stat -f10 -S3</command></para><para>Summarize Multicast S,G where sources are off campus.</para><para><command>flow-cat /flows/R | flow-filter -Dmulticast -i1,2 | flow-stat -f10 -S3</command></para></informalexample></refsect1><refsect1><title>EXAMPLE - Find scanners</title><informalexample><para>Find SMTP scanners with flow-dscan.  This will also find SMTP clients whichtry to contact many servers.  This behavior is characterized by a recent Microsoft worm.</para><para><literallayout><command>touch dscan.suppress.src dscan.suppress.dst</command><command>flow-cat /flows/R | flow-filter -P25 | flow-dscan -b</command></literallayout></para></informalexample></refsect1><refsect1><title>AUTHOR</title><para><author><firstname>Mark</firstname><surname>Fullmer</surname></author><email>maf@splintered.net</email></para></refsect1><refsect1><title>SEE ALSO</title><para><application>flow-tools</application>(1)</para></refsect1></refentry>

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
精品一区二区三区久久久| 亚洲图片一区二区| 亚洲高清免费一级二级三级| 国产精品1区2区3区在线观看| 91久久人澡人人添人人爽欧美 | 中文字幕国产精品一区二区| 一区二区在线观看免费视频播放| 国产精品国产三级国产专播品爱网| 国产精品卡一卡二| 六月丁香婷婷色狠狠久久| 欧美三级电影精品| 亚洲女女做受ⅹxx高潮| 亚洲国产aⅴ天堂久久| 99热精品国产| 亚洲欧美在线高清| 成人av动漫在线| 久久影院午夜片一区| 日韩国产在线观看一区| 欧美日韩一区久久| 亚洲成av人片| 日韩一区二区电影在线| 免费在线观看一区二区三区| 日韩一二三区不卡| 紧缚捆绑精品一区二区| 精品国产一区a| 91麻豆视频网站| 国产精品美女视频| 99精品桃花视频在线观看| 亚洲资源中文字幕| 欧美不卡在线视频| 风间由美性色一区二区三区| 亚洲欧美自拍偷拍| 日韩欧美中文字幕一区| 国产精品1024| 最新日韩在线视频| 在线播放/欧美激情| 国产在线精品一区在线观看麻豆| 欧美v日韩v国产v| 97se亚洲国产综合在线| 丝袜亚洲另类欧美| 久久久综合网站| 在线视频综合导航| 激情久久五月天| 亚洲国产精品久久久久秋霞影院 | 国产精品网站一区| 欧美高清性hdvideosex| 成人免费视频一区| 青青草97国产精品免费观看| 国产精品久久久久久久第一福利| 欧美一区二区三区公司| 色成年激情久久综合| 午夜精品aaa| 亚洲女同ⅹxx女同tv| 久久久国产一区二区三区四区小说| 91视频国产观看| 东方欧美亚洲色图在线| 日本中文字幕一区二区视频| 国产精品成人一区二区三区夜夜夜 | 91香蕉视频污在线| 国产精品电影一区二区| 国产毛片精品一区| 18欧美亚洲精品| 亚洲视频你懂的| 最新久久zyz资源站| 亚洲国产精品精华液ab| 国产精品网站导航| 久久久久久久久久久久久夜| 亚洲精品一区二区三区蜜桃下载| 欧美撒尿777hd撒尿| 色综合久久天天综合网| 国产一区视频在线看| 国产精品一区免费在线观看| 国产精品18久久久久久久网站| 国产精品自拍毛片| 波多野结衣视频一区| 99久免费精品视频在线观看 | 欧美一区二区黄| 日韩小视频在线观看专区| 日韩一区二区三区四区| 久久久高清一区二区三区| 337p粉嫩大胆色噜噜噜噜亚洲| 欧美国产欧美综合| 亚洲激情图片一区| 久久99久久久欧美国产| 国产黄色精品网站| 欧美视频完全免费看| 久久伊人蜜桃av一区二区| 国产欧美精品区一区二区三区 | 色爱区综合激月婷婷| 欧美亚洲综合色| 精品电影一区二区| 久久精品综合网| 亚洲国产精品一区二区尤物区| 免费高清成人在线| 成人一道本在线| 欧美一级二级在线观看| 中文字幕中文字幕一区二区| 视频一区二区不卡| 91一区二区三区在线观看| 2021久久国产精品不只是精品| 国产精品久久久久久亚洲毛片 | 欧美激情资源网| 免费美女久久99| 成人97人人超碰人人99| 亚洲精品一区二区精华| 日本不卡高清视频| 欧美日韩视频在线一区二区 | 九九视频精品免费| 日韩欧美国产麻豆| 婷婷丁香激情综合| 欧美色图片你懂的| 欧美另类videos死尸| 在线综合亚洲欧美在线视频| 国产精品久久99| caoporn国产精品| 精品精品国产高清a毛片牛牛 | 国产成人亚洲精品狼色在线| 欧美私人免费视频| 亚洲一区二区综合| 欧美精品一二三区| 蜜臀99久久精品久久久久久软件| 欧美一三区三区四区免费在线看| 一区二区三区丝袜| 91精品欧美综合在线观看最新| 日韩电影在线观看一区| 91麻豆精品国产91久久久久| 日韩黄色小视频| 精品成人一区二区三区| 风间由美一区二区av101 | 久久蜜桃av一区二区天堂| 国产aⅴ综合色| 亚洲精品一二三| 欧美va在线播放| 99久久国产免费看| 视频在线在亚洲| 久久精品一二三| 色婷婷精品久久二区二区蜜臂av | 日韩精品中文字幕在线不卡尤物 | 日韩毛片精品高清免费| 精品毛片乱码1区2区3区| 欧美日韩精品欧美日韩精品一| 国产成人鲁色资源国产91色综| 亚洲r级在线视频| 18成人在线视频| 亚洲色图视频免费播放| 久久九九国产精品| 精品999在线播放| 日韩三级av在线播放| 欧美日本在线视频| 欧美体内she精高潮| 在线亚洲一区二区| 欧美三级日韩三级国产三级| 成人动漫一区二区三区| 国产伦精一区二区三区| 国产精品99久久久久久久女警| 久久99国产精品免费网站| 久久成人av少妇免费| 国产精选一区二区三区| 福利一区福利二区| 99久久er热在这里只有精品66| 99精品黄色片免费大全| 日本高清不卡一区| 日韩欧美电影在线| 欧美国产精品久久| 一个色在线综合| 日本不卡不码高清免费观看| 国产精品自拍在线| 麻豆免费看一区二区三区| 青青草国产成人av片免费| 国产在线日韩欧美| 91免费看视频| 精品播放一区二区| 最近中文字幕一区二区三区| 午夜视黄欧洲亚洲| 国产aⅴ综合色| 欧美日韩国产一二三| 欧美国产精品一区二区| 亚洲bt欧美bt精品777| 国产a精品视频| 精品国产免费一区二区三区四区 | 免费一级片91| 99在线热播精品免费| 日韩一区二区免费高清| 综合中文字幕亚洲| 国产在线视频一区二区| 欧美日韩高清影院| 亚洲免费观看高清| 国产福利一区二区三区视频 | 菠萝蜜视频在线观看一区| 日韩精品中文字幕一区二区三区| 亚洲日本在线视频观看| 国产精品原创巨作av| 久久久久久99精品| 精品一区二区在线免费观看| 色婷婷综合中文久久一本| 中文在线一区二区| 成人激情av网| 中文字幕乱码亚洲精品一区 | 日日夜夜精品视频天天综合网| 一本大道久久精品懂色aⅴ|