路由器作为局域网内主机访问外网的网关,现要求通过NetStream功能使用采样器对路由器上GigabitEthernet3/0/1入方向的流量进行统计,再将统计的信息输出到Netstream服务器上。具体应用需求如下:
在接口GigabitEthernet3/0/1的入方向上配置固定采样,每1001个报文中抽取一个报文进行NetStream统计。
本举例是在Release 0007P06版本上进行配置和验证的。
当配置NetStream流镜像不带sampler参数时,缺省按1000:1进行采样;如果带sampler参数,则按配置的采样器的采样率进行采样,但该采样器的采样率取值不能低于1000。
(1) 创建Sampler采样器。
创建一个名为samplerin的采样器,采用固定采样方式,设置采样率为1001,即1001个报文中采样1个报文。
<Device> system-view
[Device] sampler samplerin mode fixed packet-interval 1001
(2) 使能路由器NetStream功能。
配置GigabitEthernet3/0/1 IP地址。
[Device] interface gigabitethernet 3/0/1
[Device-GigabitEthernet3/0/1] ip address 192.168.0.1 24
[Device-GigabitEthernet3/0/1] quit
配置GigabitEthernet3/0/2 IP地址。
[Device] interface gigabitethernet 3/0/2
[Device-GigabitEthernet3/0/2] ip address 10.0.0.1 24
[Device-GigabitEthernet3/0/2] quit
配置GigabitEthernet3/0/3 IP地址。
[Device] interface gigabitethernet 3/0/3
[Device-GigabitEthernet3/0/3] ip address 192.168.1.1 24
[Device-GigabitEthernet3/0/3] quit
在全局开启NetStream功能。
<Device> system-view
[Device] ip netstream
配置QoS策略,将接口GigabitEthernet3/0/1的入方向的IPv4流量镜像到3号槽NetStream业务板并调用采样器samplerin。
[Device] acl number 3000
[Device-acl-adv-3000] rule 0 permit ip
[Device-acl-adv-3000] quit
[Device] traffic classifier ns_ipv4
[Device-classifier-ns_ipv4] if-match acl 3000
[Device-classifier-ns_ipv4] quit
[Device] traffic behavior ns_ipv4_in
[Device-behavior-ns_ipv4] mirror-to slot 3 sampler samplerin
[Device-behavior-ns_ipv4] quit
[Device] qos policy ns_ipv4_in
[Device-qospolicy-ns_ipv4] classifier ns_ipv4 behavior ns_ipv4_in
[Device-qospolicy-ns_ipv4] quit
配置GigabitEthernet3/0/1,在此接口入方向上应用QoS策略ns_ipv4_in。
[Device] interface GigabitEthernet 3/0/1
[Device-GigabitEthernet3/0/1] qos apply policy ns_ipv4_in inbound
[Device-GigabitEthernet3/0/1] quit
配置NetStream普通流统计信息输出的目的地址为192.168.1.2和目的UDP端口号为5000。
[Device] ip netstream export host 192.168.1.2 5000
(1) 通过display sampler查看采样器的配置信息。
[Device] display sampler
Sampler name: samplerin
Mode: fixed; Packet-interval: 1001
(2) 路由器运行一段时间后,查看NetStream普通流的统计信息。
通过display ip netstream cache命令来查看NetStream流缓存区的配置和状态的详细信息。
[H3C]display ip netstream cache verbose
IP NetStream cache information:
Active flow timeout : 30 min
Inactive flow timeout : 30 sec
Max number of entries : 819200
IP active flow entries : 1
MPLS active flow entries : 0
L2 active flow entries : 0
IPL2 active flow entries : 0
IP flow entries counted : 22
MPLS flow entries counted : 0
L2 flow entries counted : 0
IPL2 flow entries counted : 0
Last statistics resetting time : 06/30/2014 at 16:02:43
IP packet size distribution (300 packets in total):
1-32 64 96 128 160 192 224 256 288 320 352 384 416 448 480
.000 .000 1.00 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000
512 544 576 1024 1536 2048 2560 3072 3584 4096 4608 >4608
.000 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000
Protocol Total Packets Flows Packets Active(sec) Idle(sec)
Flows /sec /sec /flow /flow /flow
---------------------------------------------------------------------------
ICMP 22 0 0 13 1 30
Type DstIP(Port) SrcIP(Port) Pro ToS If(Direct) Pkts
DstMAC(VLAN) SrcMAC(VLAN)
TopLblType(IP/MASK) Lbl-Exp-S-List
---------------------------------------------------------------------------
IP 10.0.0.2(2048) 192.168.0.2(0) 1 0 GE3/0/1(I) 5
TCPFlag: 0
DstMask: 32 SrcMask: 32 NextHop: 10.0.0.2
DstAS: 0 SrcAS: 0 BGPNextHop: 0.0.0.0
InVRF: 0
SamplerMode: 1 SamplerInt: 1001
Active: 0 Bytes/Pkt: 84
通过display ip netstream export命令来查看NetStream统计输出报文的信息。
[Device] display ip netstream export
IP export information:
Flow source interface : Not specified
Flow destination VPN instance : Not specified
Flow destination IP address (UDP) : 192.168.1.2 (5000)
Version 5 exported flow number : 0
Version 5 exported UDP datagram number (failed) : 0 (0)
Version 9 exported flow number : 1
Version 9 exported UDP datagram number (failed) : 0 (0)
IPL2 export information:
Flow source interface : Not specified
Flow destination VPN instance : Not specified
Flow destination IP address (UDP) : 192.168.1.2 (5000)
Version 9 exported flow number : 0
Version 9 exported UDP datagram number (failed) : 0 (0)
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作