Iyo ERSPAN Yakapfuura uye Yazvino yeMylinking™ Network Kuonekwa

Chishandiso chakajairika chekutarisa network uye kugadzirisa matambudziko nhasi Chinja Port Analyzer (SPAN), inozivikanwawo sePort mirroring. Izvo zvinotitendera kutarisa network traffic mu bypass kunze kwebhendi modhi pasina kukanganisa masevhisi pane mhenyu network, uye inotumira kopi yeinotariswa traffic kune yemuno kana kure zvishandiso, zvinosanganisira Sniffer, IDS, kana mamwe marudzi etiweki ekuongorora maturusi.

Zvimwe zvinonyanya kushandiswa ndezvekuti:

• Kugadzirisa matambudziko etiweki nekutevera kutonga / data mafuremu;

• Ongorora latency uye jitter nekutarisa VoIP packets;

• Ongorora latency nekutarisa kupindirana kwetiweki;

• Ziva zvinokanganisa nekutarisa network traffic.

SPAN Traffic inogona kutariswa munharaunda kune mamwe madoko pane imwechete sosi mudziyo, kana kuremerwa kune mamwe maturusi etiweki ari padyo neLayer 2 yemudziyo sosi (RSPAN).

Nhasi tichataura nezve Remote Internet traffic monitoring tekinoroji inonzi ERSPAN (Encapsulated Remote Switch Port Analyzer) inogona kufambiswa pazvikamu zvitatu zveIP. Uku kuwedzeredzwa kweSPAN kune Encapsulated Remote.

Basic operation principles of ERSPAN

Chekutanga, ngatitarisei maitiro eERSPAN:

• Ikopi yepakiti kubva pachiteshi chengarava inotumirwa kuseva yekuenda kuti icheneswe kuburikidza neGeneric Routing Encapsulation (GRE). Nzvimbo chaiyo yeseva haina kuganhurirwa.

• Nerubatsiro rweMushandisi Inotsanangurwa Munda (UDF) chimiro chechip, chero kubviswa kwe1 kusvika ku126 bytes kunoitwa zvichibva paBase domain kuburikidza nenyanzvi-chikamu chakawedzerwa runyorwa, uye mazwi akakosha emusangano anofananidzwa kuti aone kuona. yechikamu, senge TCP nzira nhatu kubata maoko uye RDMA chikamu;

• Kutsigira kuisa sampling rate;

• Inotsigira packet interception urefu (Packet Slicing), kuderedza kudzvanywa pane yakanangwa server.

Nezvimiro izvi, unogona kuona kuti sei ERSPAN chiri chishandiso chakakosha chekutarisa network mukati me data data nhasi.

Mabasa makuru eERSPAN anogona kupfupikiswa muzvikamu zviviri:

• Session Visibility: Shandisa ERSPAN kuunganidza zvese zvakagadzirwa TCP uye Remote Direct Memory Access (RDMA) maseshini kuseri-yekupedzisira server kuti iratidzike;

• Network troubleshooting: Inobata network traffic kuti iongorore kukanganisa kana dambudziko retiweki raitika.

Kuti uite izvi, iyo sosi yetiweki mudziyo inoda kusefa traffic yekufarira kumushandisi kubva kune yakakura data rwizi, ita kopi, uye incapsulate yega kopi furemu mu "superframe mudziyo" wakasarudzika unotakura ruzivo rwakakwana kuti ugone. kufambiswa nenzira kwayo kumudziyo unogamuchira. Zvakare, gonesa iyo yekugamuchira chishandiso kuburitsa uye kudzoreredza zvizere iyo yekutanga inotariswa traffic.

Iyo yekugamuchira mudziyo inogona kuve imwe sevha inotsigira decapsulating ERSPAN mapaketi.

Kuvhara ERSPAN mapaketi

Iyo ERSPAN Type uye Package Format Ongororo

ERSPAN mapakeji akavharidzirwa achishandisa GRE uye anotumirwa kune chero IP addressable kwainoenda pamusoro peEthernet. ERSPAN parizvino iri kunyanya kushandiswa paIPv4 network, uye IPv6 rutsigiro ruchadiwa mune ramangwana.

Kune yakajairwa encapsulation chimiro che ERSAPN, chinotevera chionioni packet kubatwa kweICMP mapaketi:

encapsulation chimiro che ERSAPN

Iyo ERSPAN protocol yakagadziridzwa kwenguva yakareba, uye nekuvandudzwa kwehunyanzvi hwayo, shanduro dzakati wandei dzakagadzirwa, dzinodaidzwa kuti "ERSPAN Types". Mhando dzakasiyana dzine akasiyana furemu musoro mafomati.

Inotsanangurwa mune yekutanga Shanduro ndima yeERSPAN musoro:

ERSPAN musoro wevhezheni

Pamusoro pezvo, iyo Protocol Type ndima mumusoro weGRE inoratidzawo iyo yemukati ERSPAN Type. Iyo Protocol Type ndima 0x88BE inoratidza ERSPAN Type II, uye 0x22EB inoratidza ERSPAN Type III.

1. Type I

Iyo ERSPAN furemu yeType I inovhara IP uye GRE yakananga pamusoro weiyo yekutanga girazi furemu. Iyi encapsulation inowedzera makumi matatu nemasere mabheti pamusoro peiyo yekutanga furemu: 14(MAC) + 20 (IP) + 4(GRE). Kubatsira kweiyo fomati ndeyekuti ine compact header size uye inoderedza mutengo wekutapurirana. Nekudaro, nekuti inoseta GRE Mureza uye Shanduro minda ku0, haina kutakura chero minda yakawedzerwa uye Type I haishandiswe zvakanyanya, saka hapana chikonzero chekuwedzera zvimwe.

Iyo GRE yemusoro fomati yeType I yakaita seinotevera:

GRE musoro wefomati I

2. Type II

MuType II, iyo C, R, K, S, S, Recur, Mireza, uye Shanduro minda mumusoro weGRE ese ari 0 kunze kwe S ndima. Naizvozvo, iyo Sequence Nhamba munda inoratidzwa mune iyo GRE musoro weType II. Ndokureva kuti, Type II inogona kuve nechokwadi chekugashira GRE mapaketi, kuitira kuti nhamba huru yekunze-ye-kurongeka GRE mapaketi haigone kurongwa nekuda kwekukanganisa kwenetiweki.

Iyo GRE yemusoro fomati yeType II yakaita seiyi:

GRE musoro wefomati II

Pamusoro pezvo, iyo ERSPAN Type II furemu fomati inowedzera 8-byte ERSPAN musoro pakati peGRE musoro uye yekutanga girazi furemu.

Iyo ERSPAN header fomati yeType II yakaita seiyi:

ERSPAN musoro wefomati II

Chekupedzisira, nekukasira kutevedzera yekutanga mufananidzo furemu, ndiyo yakajairwa 4-byte Ethernet cyclic redundancy cheki (CRC) kodhi.

CRC

Zvakakosha kucherechedza kuti mukushandiswa, girazi regirazi harina FCS ndima yepakutanga furemu, panzvimbo iyo itsva CRC kukosha inoverengwa zvakare zvichienderana neERSPAN yose. Izvi zvinoreva kuti chishandiso chekugamuchira hachigone kuonesa iyo CRC kurongeka kweiyo yekutanga furemu, uye isu tinogona kungofunga kuti mafraremu asina kuodzwa chete anotaridzwa.

3. Rudzi rwechitatu

Rudzi rwechitatu runounza musoro wakakura uye unoshanduka-shanduka kugadzirisa mamiriro anowedzera uye akasiyana ekutarisa network, kusanganisira asi kwete kugumira kune network manejimendi, intrusion kuona, kuita uye kunonoka kuongorora, nezvimwe. Aya mapikicha anofanirwa kuziva ese ekutanga maparamendi egirazi furemu uye anosanganisira ayo asipo mune yekutanga furemu pachayo.

Iyo ERSPAN Type III inoumbwa musoro inosanganisira inosungirwa 12-byte musoro uye inosarudzika 8-byte chikuva-chaiwo musoro muduku.

Iyo ERSPAN header fomati yeRudzi III yakaita seiyi:

ERSPAN musoro wefomati III

Zvekare, mushure meiyo yekutanga girazi furemu ndeye 4-byte CRC.

CRC

Sezvinoonekwa kubva mumusoro fomati yeRudzi III, mukuwedzera pakuchengeta Ver, VLAN, COS, T uye Session ID minda pahwaro hweType II, akawanda akakosha minda anowedzerwa, akadai se:

• BSO: inoshandiswa kuratidza kuremerwa kwemafuremu edata anotakurwa kuburikidza neERSPAN. 00 ifuremu yakanaka, 11 ifuremu yakaipa, 01 ifuremu pfupi, 11 ifuremu hombe;

• Chitambi chenguva: chinotengeswa kunze kubva pawachi yehardware yakawiriraniswa nehurongwa hwenguva. Iyi 32-bit ndima inotsigira angangoita zana mamicroseconds eTimestamp granularity;

• Rudzi rweFremu (P) uye Rudzi rweFremu (FT) : yekutanga inoshandiswa kudoma kana ERSPAN inotakura Ethernet protocol mafuremu (PDU mafuremu), uye yekupedzisira ndiyo inoshandiswa kutaura kana ERSPAN inotakura Ethernet mafuremu kana IP mapakeji.

• HW ID: chiziviso chakasiyana cheinjini yeERSPAN mukati mehurongwa;

• Gra (Timestamp Granularity) : Inotsanangura Granularity yeTimestamp. Semuyenzaniso, 00B inomiririra 100 microsecond Granularity, 01B 100 nanosecond Granularity, 10B IEEE 1588 Granularity, uye 11B inoda mapuratifomu-madiki-musoro kuti awane yakakwirira Granularity.

• Platf ID vs. Platform Specific Info: Platf Specific Info minda ine mafomati akasiyana uye zviri mukati zvichienderana nePlatf ID kukosha.

Port ID Index

Izvo zvinofanirwa kucherechedzwa kuti akasiyana misoro minda inotsigirwa pamusoro inogona kushandiswa mune yakajairwa ERSPAN maapplication, kunyangwe girazi rekukanganisa mafuremu kana BPDU mafuremu, uchichengetedza yekutanga Trunk package uye VLAN ID. Pamusoro pezvo, ruzivo rwechisimbiso chenguva uye mamwe masimu eruzivo anogona kuwedzerwa kune yega yega ERSPAN furemu panguva yegirazi.

Ne ERSPAN's own feature headers, tinokwanisa kuwana ongororo yakakwenenzverwa yetiweki traffic, tobva taisa inoenderana ACL muERSPAN process kuti ienderane netiweki traffic yatiri kufarira.

ERSPAN Inoshandisa RDMA Session Kuonekwa

Ngatitorei muenzaniso wekushandisa ERSPAN tekinoroji kuwana RDMA chikamu chekuona mune yeRDMA mamiriro:

RDMA: Remote Direct Memory Access inogonesa network adapter ye server A kuverenga nekunyora Memory ye server B nekushandisa akangwara network interface makadhi (ics) uye switch, kuwana yakakwira bandwidth, yakaderera latency, uye yakaderera zviwanikwa kushandiswa. Inoshandiswa zvakanyanya mune yakakura data uye yakakwirira-inoshanda yakagoverwa ekuchengetedza mamiriro.

RoCEv2: RDMA pamusoro peConverged Ethernet Version 2. Iyo RDMA data yakavharirwa muUDP Header. Nhamba yechiteshi chekufambisa ndeye 4791.

Kushanda kwezuva nezuva uye kugadzirisa kweRDMA kunoda kuunganidza data rakawanda, iro rinoshandiswa kuunganidza zuva rega rega remazinga emvura mitsara uye maaramu asina kujairika, pamwe nehwaro hwekutsvaga matambudziko asina kujairika. Yakasanganiswa neERSPAN, data hombe inogona kutorwa nekukurumidza kuti iwane microsecond yekufambisa yemhando data uye protocol yekudyidzana mamiriro ekuchinja chip. Kuburikidza nehuwandu hwe data uye ongororo, RDMA yekupedzisira-kusvika-kumagumo yekufambisa kwemhando yekuongorora uye kufanotaura kunogona kuwanikwa.

Kuti uwane kuona kwechikamu cheRDAM, tinoda ERSPAN kuti ienderane nemazwi akakosha eiyo RDMA yekudyidzana zvikamu kana uchitarisa traffic, uye isu tinofanirwa kushandisa iyo nyanzvi yakawedzera runyorwa.

Nyanzvi-nhanho yakawedzera runyorwa inoenderana nemunda tsananguro:

Iyo UDF ine minda mishanu: UDF keyword, base field, offset field, value field, uye mask field. Yakaganhurirwa nekuwanda kwekupinda kwehardware, huwandu hwesere maUDF hunogona kushandiswa. Imwe UDF inogona kuenderana nepamusoro pemabhayiti maviri.

• UDF keyword: UDF1... UDF8 Ine keywords masere eUDF matching domain

• Nzvimbo yepasi: inoratidza nzvimbo yekutanga yeUDF inofananidzira ndima. Zvinotevera

L4_header (inoshanda kuRG-S6520-64CQ)

L5_header (yeRG-S6510-48VS8Cq)

• Offset: inoratidza kumisa kunoenderana nenzvimbo yepasi. Kukosha kunotangira pa0 kusvika pa126

• Munda wekukosha: kukosha kwekufananidza. Inogona kushandiswa pamwe chete nendima yemasiki kugadzirisa iyo chaiyo kukosha kuti ienderane. Iyo inoshanda bhiti mabhayiti maviri

• Mask field: mask, inoshanda zvishoma mabhayiti maviri

(Wedzera: Kana mapindiro akawanda achishandiswa mundima imwe chete yeUDF yekuenzanisa, nzvimbo dzegadziko nedzekubvisa dzinofanira kufanana.)

Iwo maviri mapaketi akakosha ane hukama neiyo RDMA chikamu chimiro ndeye Congestion Notification Packet (CNP) uye Negative Kubvuma (NAK):

Iyo yekutanga inogadzirwa neiyo RDMA inogamuchira mushure mekugamuchira iyo ECN meseji inotumirwa neshanduko (apo iyo eout Buffer inosvika pachikumbaridzo), iyo ine ruzivo nezve kuyerera kana QP ichikonzera kusangana. Iyo yekupedzisira inoshandiswa kuratidza iyo RDMA kufambisa ine meseji yekurasikirwa kwepaketi.

Ngatitarisei nzira yekufananidza aya mameseji maviri uchishandisa iyo nyanzvi-chikamu chakawedzera runyorwa:

RDMA CNP

nyanzvi yekuwana-rondedzero yakawedzerwa rdma

bvumidza udp chero chero chero eq 4791udf 1 l4_header 8 0x8100 0xFF00(Inoenderana neRG-S6520-64CQ)

bvumidza udp chero chero chero eq 4791udf 1 l5_header 0 0x8100 0xFF00(Kufananidza RG-S6510-48VS8CQ)

RDMA CNP 2

nyanzvi yekuwana-rondedzero yakawedzerwa rdma

bvumidza udp chero chero chero eq 4791udf 1 l4_header 8 0x1100 0xFF00 udf 2 l4_header 20 0x6000 0xFF00(Inoenderana neRG-S6520-64CQ)

bvumidza udp chero chero chero eq 4791udf 1 l5_header 0 0x1100 0xFF00 udf 2 l5_header 12 0x6000 0xFF00(Kufananidza RG-S6510-48VS8CQ)

Senhanho yekupedzisira, unogona kuona iyo RDMA chikamu nekumisikidza iyo nyanzvi yekuwedzera rondedzero mune yakakodzera ERSPAN maitiro.

Nyora kwekupedzisira

ERSPAN ndechimwe chezvishandiso zvinonyanya kukosha mune yanhasi yakakura data center network, iri kuramba ichinetsa netiweki traffic, uye netiweki iri kuwedzera kuomarara mashandiro uye kugadzirisa zvinodiwa.

Nekuwedzera kuri kuita dhigirii reO&M otomatiki, matekinoroji akadai seNetconf, RESTconf, uye gRPC anozivikanwa pakati pevadzidzi veO&M mune network otomatiki O&M. Kushandisa gRPC seyo pasi peprotocol yekutumira kumashure girazi traffic inewo zvakawanda zvakanaka. Semuyenzaniso, zvichibva paHTTP/2 protocol, inogona kutsigira kutenderera kusunda meshini pasi pekubatana kwakafanana. NeProtoBuf encoding, saizi yeruzivo yakaderedzwa nehafu kana ichienzaniswa nefomati yeJSON, ichiita kuti data rifambiswe nekukurumidza uye zvakanyanya. Chimbofungidzira, kana iwe ukashandisa ERSPAN kuratidza inofarira hova uye wozotumira kune yekuongorora server pane gRPC, ichavandudza zvakanyanya kugona uye kugona kwetiweki otomatiki kushanda uye kugadzirisa?


Nguva yekutumira: May-10-2022