Professional Documents
Culture Documents
NBAR and NetFlow 2003 Ccmigration - 09186a00801da7de
NBAR and NetFlow 2003 Ccmigration - 09186a00801da7de
APPLICATION RECOGNITION
ITD PRODUCT MANAGEMENT
NOVEMBER 2003
NetFlow and NBAR, November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 1
Overview of NetFlow and
Network-Based Application Recognition
• NetFlow
Pioneering IP accounting technology
Invented and patented by Cisco
IETF export standard
NetFlow and NBAR, November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 2
NetFlow and NBAR Benefit Footprints
Enterprise Enterprise Service Provider Service Provider Core
Backbone Premise Edge Aggregation Edge
NetFlow
• User (IP) monitoring • Attack mitigation
• Application monitoring • Billing
• Traffic analysis • AS Peer monitoring
• Attack Mitigation • Traffic engineering
• Chargeback Billing • Network Planning
NBAR
• Application classification
• Precise Quality of Service (QoS) treatment
• Application statistics for bandwidth provisioning
Top-n views
Threshold settings
• Mapping applications to an SP’s service offering
NetFlow and NBAR, November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 3
NetFlow and NBAR Benefit Footprints
Enterprise Enterprise Service Provider Service Provider Core
Backbone Premise Edge Aggregation Edge
NetFlow
• Cisco • Cisco Catalyst 5000, 6500 Series • Cisco Catalyst 4500, • Cisco 10000 and 12000
Catalyst 4500, HW Acceleration 5000, 6500 Series; Series Internet Routers
5000, 6500, • Cisco Catalyst 4500 Series ASIC Cisco 7600 Series ASIC ASIC
7600 Series • Cisco 7100, 7200, 7300, 75000 • Cisco 7100, 7200, 7300, • Cisco Catalyst 5000 and
ASIC 75000 Series 6500 Series; Cisco 7600
Series
• Cisco AS5300,AS5400, AS5800 • Cisco AS5300 and Series ASIC
Series AS5800 Series • Cisco 7500 Series
• Cisco 830, 1400, 1700, 2600, 3600, • Cisco MGX8000 Series
and 3700 Series
NBAR
• Cisco • Cisco Catalyst 6500 and 7600 • Cisco Catalyst 6500 and Cisco Catalyst 6500 and
Catalyst Series 7600 Series 7600 Series
6500 and FlexWAN, MWAM
FlexWAN, MWAM FlexWAN, MWAM Planned ASIC
7600 Series Planned ASIC Planned ASIC
MSFC • Cisco 7500 Series
• Cisco 7100, 7200, and 7500 Series • Cisco 7100, 7200, and
Planned • Cisco 830, 1400, 1700, 2600, 3600, 7500 Series
ASIC
NetFlow and NBAR, November 2003and 3700© Series
2003 Cisco Systems, Inc. All rights reserved. 4
NetFlow and NBAR: Main Objectives and
Benefits
NBAR
NBAR
NetFlow NBAR
NetFlow and NBAR, November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 7
NetFlow and NBAR Differentiation
Link Layer
Interface
Header
NetFlow NetFlow and NBAR both
TOS
Protocol
leverage Layer 3 and 4
IP
Source
Header Information
Header
IP Address
Destination NetFlow
IP Address • Monitors data in Layers 2 thru 4
• Determines applications by port
Source
TCP/UDP Port • Utilizes a 7-tuple for flow
Header Destination
Port NBAR
• Examines data from Layers 3
through 7
• Uses Layers 3 & 4 plus packet
Data Deep Packet inspection for classification
Packet
(Payload) NBAR • Stateful inspection of dynamic-
Inspection
port traffic
NetFlow and NBAR, November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 8
NetFlow and NBAR useful for Security
NetFlow and NBAR, November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 9
Summary of Benefits
NetFlow NBAR
NetFlow and NBAR, November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 10
NetFlow and NBAR,
November 2003 © 2003 Cisco Systems, Inc. All rights reserved. 11