Net Optics Smart Filtering Appliance Uživatelský manuál

Procházejte online nebo si stáhněte Uživatelský manuál pro Sítě Net Optics Smart Filtering Appliance. Net Optics Smart Filtering Appliance User's Manual Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk

Shrnutí obsahu

Strany 1 - User Guide

User Guide"Smart Filtering" ApplianceDoc. PUBDIRU Rev. 2, 9/08www.netoptics.com12BAA BIDSAnalyzer 2Analyzer 1RMON 1 RMON 2Forensic*** Conde

Strany 2

6*** Condential - DO NOT Distribute ***DirectorTypical ApplicationThe following diagram shows a typical application using Director to implement a com

Strany 3 - Contents

7*** Condential - DO NOT Distribute ***DirectorIn this installation, Director has ten additional Span ports and one in-line link that are available f

Strany 4

8*** Condential - DO NOT Distribute ***DirectorIn-line Monitoring of 10 Gigabit Links To create an in-line link on a 10 Gigabit network segment, use

Strany 5 - Introduction

9*** Condential - DO NOT Distribute ***DirectorDirector Front PanelThe features of the Director front panel are shown in the following diagram.www.ne

Strany 6 - Key Features

10*** Condential - DO NOT Distribute ***DirectorDirector Rear PanelThe features of the Director rear panel are shown in the following diagram.Managem

Strany 7 - About this Guide

11*** Condential - DO NOT Distribute ***DirectorChapter 2 Installing DirectorThis chapter describes how to install and connect Director devices. The

Strany 8 - Director Architecture

12*** Condential - DO NOT Distribute ***DirectorPlan the InstallationBefore you begin the installation of your Director device, determine the followi

Strany 9 - Director Management

13*** Condential - DO NOT Distribute ***DirectorInstall Director Network ModulesIf the Director Network Modules (DNMs) are not already installed when

Strany 10 - Typical Application

14*** Condential - DO NOT Distribute ***DirectorConnect Power to DirectorFor power fault protection, Director is equipped with redundant power connec

Strany 11

15*** Condential - DO NOT Distribute ***DirectorLaunch terminal emulation software and set communication parameters to:2. 115200 baud8 data bits No p

Strany 12 - Monitoring tools

PLEASE READ THESE LEGAL NOTICES CAREFULLY.By using a Net Optics Director device you agree to the terms and conditions of usage set forth by Net Optics

Strany 13 - Director Front Panel

16*** Condential - DO NOT Distribute ***DirectorEnter 4. netoptics as the password. For security, the password is not displayed as you type it. The

Strany 14 - Director Rear Panel

17*** Condential - DO NOT Distribute ***DirectorCongure Director using the CLIYou should be logged into the Director CLI. The factory-set default va

Strany 15 - Installing Director

18*** Condential - DO NOT Distribute ***DirectorAssign a New Director IP Address, Netmask, and Gateway IP AddressIf you are using the local RS-232 se

Strany 16 - Plan the Installation

19*** Condential - DO NOT Distribute ***DirectorTip! ________________________________________________________________________________________________

Strany 17 - Slot 1 Slot 2

20*** Condential - DO NOT Distribute ***DirectorUsing the CLI Help CommandTo view CLI help information:Enter 1. Help at the "Net Optics:"

Strany 18 - Connect Power to Director

21*** Condential - DO NOT Distribute ***DirectorUsing the CLI Command History BufferYou can save a lot of typing by using the command history buffer

Strany 19 - Shell login Figure 13:

22*** Condential - DO NOT Distribute ***DirectorConnect Span Ports to DirectorTo connect Director to the network using Span ports, be sure that at le

Strany 20 - Log into the CLI

23*** Condential - DO NOT Distribute ***DirectorConnect Director With In-line Network LinksTo connect Director to the network using an in-line instal

Strany 21 - CLI Interface

24*** Condential - DO NOT Distribute ***Directorwww.netoptics.com™Director12BA16273851049A BIn-Line10/100/1000101001000LINKACTIn-LineGigaBit1 2 3 4 5

Strany 22

25*** Condential - DO NOT Distribute ***DirectorChapter 3 Conguring Filters Using the CLIThis chapter describes how to use the CLI to determine whic

Strany 23

Director*** Condential - DO NOT Distribute ***ContentsChapter 1 Introduction ...

Strany 24

26*** Condential - DO NOT Distribute ***DirectorWhen you dene a lter, you specify and action to be taken when the lter conditions are met. The act

Strany 25

27*** Condential - DO NOT Distribute ***DirectorNetwork Port 1Network Port 2Monitor Port 3+lter add in_ports=n1.1,n1.2 action=redir redir_ports=m.3T

Strany 26 - Port numbers in purple

28*** Condential - DO NOT Distribute ***DirectorCreate FiltersFilters process a trafc stream by selecting packets based on criteria in the packet he

Strany 27 - A B A B A B

29*** Condential - DO NOT Distribute ***Directorip_dst IP destination address• ip_dst_mask IP source address mask• ip_proto IP protocol• l4_src_po

Strany 28 - Check the Installation

30*** Condential - DO NOT Distribute ***DirectorMonitor Port 1Network Port 5lter add in_ports=n1.5 ip_proto=6 action=redir redir_ports=m.1lter add

Strany 29 - Chapter 3

31*** Condential - DO NOT Distribute ***DirectorWork with congurable 10 Gigabit portsThe two congurable 10 Gigabit XFP ports on the front panel are

Strany 30 - Monitor Port 1Network Port 3

32*** Condential - DO NOT Distribute ***Directorlter add in_ports=n1.11 action=redir redir_ports=t.2lter add in_ports=n1.1-n1.4 action=redir redir_

Strany 31 - Network Port 11

33*** Condential - DO NOT Distribute ***DirectorUnderstand lter interactionsIt is important to understand that Director uses Content Addressable Mem

Strany 32 - Create Filters

34*** Condential - DO NOT Distribute ***DirectorHave we achieved our goal of sending all the TCP trafc to Monitor Port 2? Not quite. What happens wh

Strany 33 - Create Complex Filters

35*** Condential - DO NOT Distribute ***DirectorNote: _______________________________________________________________________________________________

Strany 34 - View lters

Director*** Condential - DO NOT Distribute ***Create Complex Filters ...29View lters

Strany 35

36*** Condential - DO NOT Distribute ***DirectorUnderstand pending and active ltersTo understand the actions of lter commands such as ltercommit,

Strany 36

37*** Condential - DO NOT Distribute ***DirectorPending lter listAddress Filter1 n1.1 ip_proto=UDP action=drop2 n1.1 m.1CAMAddress Filter1 n1.1 ip_p

Strany 37 - Understand lter interactions

38*** Condential - DO NOT Distribute ***DirectorBe aware of these similar pairs of commands:lterdiscard• clears the pending lter list, while lt

Strany 38

39*** Condential - DO NOT Distribute ***DirectorChapter 4 Daisy-chaining Multiple Director ChassisThis chapter describes how to expand the capacity o

Strany 39 - 2 n1.1 m.1

40*** Condential - DO NOT Distribute ***DirectorAppendix A Director SpecicationsSpecications, chassisMechanicalDimensions: 1.6” high x 15.65” deep

Strany 40

41*** Condential - DO NOT Distribute ***DirectorSpecications, DNMCopper Interface(12) RJ45 Network Ports 10/100/1000Mbps(6) In-line links or (12) Sp

Strany 41

42*** Condential - DO NOT Distribute ***DirectorAppendix B Command Line InterfaceTip! _______________________________________________________________

Strany 42

43*** Condential - DO NOT Distribute ***DirectorCommand Sub-Command Parameters Example and descriptionlter add ipv6=< y | n >in_ports=<netw

Strany 43 - Chapter 4

44*** Condential - DO NOT Distribute ***DirectorCommand Sub-Command Parameters Example and descriptionlter (continued)list ipv6=< y | n > lte

Strany 44 - Director Specications

45*** Condential - DO NOT Distribute ***DirectorCommand Sub-Command Parameters Example and descriptionpasswd passwd Interactively changes the passwor

Strany 45 - Available Models

1*** Condential - DO NOT Distribute ***DirectorChapter 1 IntroductionNet Optics Director is a key component for building a comprehensive, consolidate

Strany 46 - Command Line Interface

46*** Condential - DO NOT Distribute ***DirectorCommand Sub-Command Parameters Example and descriptionsysip commit sysip commitActivates pending chan

Strany 47

47*** Condential - DO NOT Distribute ***DirectorCommand Sub-Command Parameters Example and descriptionuserThis command is only available at root leve

Strany 48

48*** Condential - DO NOT Distribute ***DirectorFilter parametersSwitches and lters are dened using the lteraddandlterinscommands. The lter

Strany 49

49*** Condential - DO NOT Distribute ***DirectorAppendix C Protocol NumbersThe ofcial Assigned Internet Protocol Numbers list is maintained by the I

Strany 50

50*** Condential - DO NOT Distribute ***DirectorNum Keyword Protocol55 MOBILE IP Mobility56 TLSP Transport Layer Security Protocol using Kryptonet ke

Strany 51

51*** Condential - DO NOT Distribute ***DirectorNum Keyword Protocol115 L2TP Layer Two Tunneling Protocol116 DDX D-II Data Exchange (DDX)117 IATP Int

Strany 52 - Filter parameters

52*** Condential - DO NOT Distribute ***DirectorLimitations on Warranty and LiabilityNet Optics offers a limited warranty for all its products. IN NO

Strany 53 - Protocol Numbers

© 2008 by Net Optics, Inc. All Rights Reserved.www.netoptics.com

Strany 54

2*** Condential - DO NOT Distribute ***DirectorKey FeaturesEase of UseTap, aggregation, regeneration, matrix switch, and lter functions in a single

Strany 55

3*** Condential - DO NOT Distribute ***DirectorAbout this GuidePlease read this entire guide before installing Director. This guide applies to the fo

Strany 56

4*** Condential - DO NOT Distribute ***DirectorDirector ArchitectureThe following diagram shows a schematic view of the architecture of the Director

Strany 57

5*** Condential - DO NOT Distribute ***DirectorThe inputs are divided into three groups: two DNMs plus the 10GbE ports. In-line DNM models support 6

Komentáře k této Příručce

Žádné komentáře