Datacom FVS-1044 Скачать руководство пользователя страница 72

FLOWcontrol™

72

© 2010 Datacom Systems Inc

VERSA

stream

The 

Refresh Filter List

 button re-reads the filter file stored in the program

directory. This function is useful if new filters have been created by the Filter
Management element and the new filters are desired to be applied. In order to
make available to the Filter Configuration tab the new filters, the 

Refresh Filter

List

 button must be pressed. 

The checkboxes 

 and 

 are used to select those ports

which match the Egress/Ingress filter types. Pre-Aggregation Filters are
considered to be Ingress Filters. The 

 checkbox is used to

indicate that all filters should be set to 

PASS-ALL

. This checkbox is useful when

resetting all filters to a known state. Selection of this check box DOES NOT
automatically set all filters to 

PASS-ALL

. Once the check box is checked,

selection of the 

Apply

 button is required. 

7.2.6 Event Log

The 

Event Log

 tab allows the user to quickly monitor any actions or events that

have occurred with the connected Filtered SINGLEstream™ or Filtered
VERSAstream™. Each entry in the Event Log captures the time of the event, the
user who made the change, the IP address of the Filtered product device and a
brief description of the event itself. 

This information allows the user to track any changes that may have been made
to the connected Filtered product. The Event Log will also alert the user to any
operating errors that may have been encountered during the normal operation of
the Filtered product.

To direct the Event Log (Syslog) entries to an external destination (Syslog
Server),the Syslog options must be defined from the (Utilities > Options)
window. (see: 

Options

 )

Retrieve

 requests the event log at any given time as determined by the user. 

Clear Event Log

 will clear the event log on the hardware platform as well as

clear the log on screen. This function is only available to an Administrator
enabled account.

32

Содержание FVS-1044

Страница 1: ...Datacom Systems Inc Access Your Network TM May 2010 541 0114 U B 00 FVS 1080 Data Access Switch USERguide FVS 1044 Data Access Switch 2010 Datacom Systems Inc ...

Страница 2: ...This page intentionally left blank ...

Страница 3: ...security sensors With less data to work with through filtering network devices can run faster and more efficiently which can reduce or eliminate the possiblity of port oversubscription The Filtered VERSAstream product provides you with unprecedented flexibility and filtering capability for your network monitoring needs offering a complete view of the traffic and easily lets security and analysis t...

Страница 4: ...e publisher and the author make no claim to these trademarks While every precaution has been taken in the preparation of this document the publisher and the author assume no responsibility for errors or omissions or for damages resulting from the use of information contained in this document or from the use of programs and source code that may accompany it In no event shall the publisher and the a...

Страница 5: ...cations 14 4 FVS 1080 Specifications 15 Section 3 Hardware 15 1 Power 15 2 Any to Any Ports 16 3 Management Port 16 4 Serial USB 16 5 Rear Panel 17 Section 4 Initial Configuration 17 1 SERIAL Port Configuration 17 2 IP Address 19 3 Small Form Factor Plug Module 19 1 Installation Prerequisites 19 2 Safety Guidelines 20 3 Installing the SFP Module 20 4 Removing the SFP Module 21 Section 5 Hardware I...

Страница 6: ...resh 31 8 Restart 31 9 Agent Add Modify Properties Form 32 3 Utilities 34 4 Tabs 34 5 Help 34 1 About 34 2 FLOWcontrol Help 35 3 Web Site 35 4 Tutorials 35 2 Agent List 36 2 Filter Management 37 1 Saved Filters Panel 38 2 Filter Specifics Panel 39 1 Include Exclude Definition 39 2 Include VLAN Tunneling Frames 40 3 Rule Definition 41 4 Combinatorial Logic 44 5 MAC Address Filter 44 6 VLAN ID Filte...

Страница 7: ... Filtered SINGLEstream Summary 62 2 Filtered VERSAstream Summary 62 2 Counter Resets 63 3 Summary Expanded 64 4 Port Configuration 66 5 Aggregation Configuration 67 1 Example Filtered SINGLEstream 69 2 Example Filtered VERSAstream 71 5 Filter Configuration 72 6 Event Log 73 Section 8 Appendix 1 Command Line Interface CLI 73 1 Basic Functionality 73 2 Basic Command Set 73 1 HELP 74 2 CLEAR LOG CL L...

Страница 8: ...ET PORT SE PO 80 18 SET NTP SE NTP 81 19 SET PING SE PG 81 20 SET SSH SE SH 81 21 SET SYSLOG SE SY 81 22 SET TELNET SE TT 82 23 SET TFTP SE TP 82 24 SET TIME SE TI 82 25 REBOOT 83 26 REBOOT management 83 27 EXIT 84 Section 9 Appendix 2 Sample Filter Setup 88 Section 10 Customer Service 88 1 World Wide Web 88 2 Warranty 89 3 Limits of Liability 89 4 Force Majeure ...

Страница 9: ...oducts you agree to the terms set forth No licenses express or implied are granted with respect to the technology described and Datacom Systems Inc retains all rights with respect to the technology described herein If applicable you may return the product to the place of purchase for a full refund 1 3 Trademark Attribution Access Your Network DS3 ACTIVEtap DS3switch DURAstream ETHERNETtap Empoweri...

Страница 10: ...sceptibility This equipment completed the Product Safety Review and meets the Low Voltage Directive 98 68 EEC requirements to the standards of EN 60950 Safety of Information Technology Equipment The RoHS compliant logo indicates that this electronic product does not exceed the limit requirements of toxic hazardous substances or elements as set forth in Directive 2002 95 EC of the European Parliame...

Страница 11: ...uct line gives you access to your network without creating bottlenecks by providing the capability to monitor aggregate and filter network traffic to an analysis device or sensor Aggregation combines two or more streams of network traffic into one link Aggregated network traffic may overload or oversubscribe an analysis device Filtering unwanted network traffic reduces the potential for oversubscr...

Страница 12: ...ports to any monitoring ports Many to Any architecture combines traffic from up to four of the input ports providing visibility into multiple network segments with one monitoring tool One to Many architecture allows sending multiple copies of data from the input port to multiple monitoring devices Aggregate and reassembly full duplex conversations from multiple trunk links redundant networks Ether...

Страница 13: ...e LX or SX Management Port front RJ45 10 100 Mbs Full Duplex Serial Port front USB type A style Power Input 120 240VAC 50 60Hz 0 6A 0 3A Dimensions H x W x D includes mount bracket 1 75 x 19 00 x 12 00 inch 4 44 x 48 26 x 30 48 cm Weight 7 0 lbs shipping 14 0 lbs 3 175 kg shipping 6 3 kg Operating Temperature 32º to 104 F 0º to 40 C Storage Temperature 22º to 149 F 30º to 65 C Humidity Less than 9...

Страница 14: ...bs Full Duplex Serial Port front USB type A style Power Input 120 240VAC 50 60Hz 0 6A 0 3A Dimensions H x W x D includes mount bracket 1 75 x 19 00 x 12 00 inch 4 44 x 48 26 x 30 48 cm Weight 7 0 lbs shipping 14 0 lbs 3 175 kg shipping 6 3 kg Operating Temperature 32º to 104 F 0º to 40 C Storage Temperature 22º to 149 F 30º to 65 C Humidity Less than 95 C non condensing Warranty One 1 year see War...

Страница 15: ...ower as a single point of failure The power sockets are located on the rear The POWER 1 and 2 front panel LEDs illuminate green when power is available at both of the two rear power sockets indicating power 1 and 2 respectively are on Either LED not illuminated indicates immediate investigation is recommended if both power sources are being used and a power led is not illuminated to insure redunda...

Страница 16: ...ct the Management PC to set the IP address for the first time 3 5 Rear Panel Two AC input power sockets are provided on the rear panel The POWER 1 and 2 front panel LEDs illuminate green when power is available at both of the two rear power sockets indicating power 1 and 2 respectively are on Either front panel LED not illuminated indicates immediate investigation is recommended if both power sour...

Страница 17: ...ange the IP address to match your network NOTE If your FVS already has an IP address for your network you may proceed to the Small Form Factor Plug Module section Step 1 First connect your terminal emulator application PC and FVS using the provided Datacom Systems DRL434 6 R cable Connect the DB9 Female pin end to the serial port on your PC and connect the USB style Type A end to the SERIAL port o...

Страница 18: ...typing SET IP ppp ppp ppp ppp sss sss sss sss ggg ggg ggg ggg where ppp ppp ppp ppp corresponds to a valid IP address where sss sss sss sss corresponds to a valid SUBNET for your network and where ggg ggg ggg ggg corresponds to a valid GATEWAY for your network Press the Enter key to continue Step 8 Review and verify the network address settings are correct and enter y to confirm changes updating e...

Страница 19: ...unit NOTE You can install and remove SFP modules with power on to the system however it is strongly recommended that you do not install or remove the SFP module with fiber or copper cables attached to it Disconnect all cables before removing or installing a SFP module CAUTION Prevent system problems use only Datacom Systems Inc supplied SFP modules 4 3 2 Safety Guidelines Before handling a SFP mod...

Страница 20: ...until completed Step 3 Attach the appropriate network cable to the LC type or RJ45 type connector on the SFP module For fiber optic SFP modules you can use either simplex or duplex connectors For simplex connectors two cables are required one cable for transmit Rx and a second cable for receive Rx For duplex connectors only one cable that has both Tx and Rx connectors is required 4 3 4 Removing th...

Страница 21: ...ternal power source is required to power the unit use of a second independent external power source is strongly recommended to assure uninterrupted monitoring Furthermore connecting to a second different external power source circuit than the first AC power source eliminates power as a single point of failure 5 2 Management Connection This section shows the MANAGEMENT port 100 Mbs fixed full duple...

Страница 22: ...orm Factor Pluggable section Installing the SFP Module on how to install the SFP module Step 1 Connect a network or monitoring cable to an Any to Any port socket and the other side of this cable to the network or monitoring tool NIC port as appropriate Step 2 Continue repeating Step 1 for any remaining Any to Any port socket you want connected from the FVS 1080 Between the connectors are LEDs that...

Страница 23: ...23 2010 Datacom Systems Inc FVS Application VERSA stream 6 FVS Application This section depicts a simple application using the Filtered VERSAstream FVS 1080 solution FVS 1080 Functional ...

Страница 24: ...ty of port oversubscribing Using the built in technologies of link aggregation regeneration and filtering you can quickly and easily load balance both your network and your network tools and eliminate bottlenecks Aggregation lets you load balance your network with confidence The Filtered Product will combine one or more full duplex streams of data from one or more network segments reassemble the c...

Страница 25: ...these Datacom Systems Inc Filter Products FSS 1000BT FVS 1044 SS 1204LR 10G F VS 1204 10G F FSS 1000LX FVS 1080 SS 1204SR 10G F VS 1206LR 10G F FSS 1000SX SS 1206LR 10G F VS 1206SR 10G F FSS 2000BT SS 1206SR 10G F VS 1214 10G F FSS 2000LX SS 1214LX 10G F FSS 2000SX SS 1214SR 10G F FSS 2000BT LX SS 1214SX 10G F FSS 2000BT SX Also FLOWcontrol supports these Fluke Networks Filtered Products FTAP 1000...

Страница 26: ...th the installation of new applications If presented with a Security Warning click through to continue the installation process To install the FLOWcontrol software on your computer 1 Insert the FLOWcontrol CD into your computer s CD ROM drive The installation InstallShield Wizard program should start automatically If it does not start locate your CD ROM drive in Windows Explorer and double click t...

Страница 27: ...shed using the factory default 192 168 1 1 IP address 7 2 1 FLOWcontrol Main Screen The Main Screen is shown here when FLOWcontrol is run the first time From the Main screen the user is able to connect to a Filtered Product to create a new Agent use an existing Agent or modify the properties of an existing Agent After subsequent runs of FLOWcontrol a short delay may be experienced while FLOWcontro...

Страница 28: ...s Consoles will remain Multiple connected agents can be maintained within FLOWcontrol If the Filter Management tab is selected when File Exit is executed a sequence of dialog boxes will appear asking for confirmation to close any other Agents that may be connected This first figure represents the unconnected Main Screen This second figure represents the Main Screen with a single Agent connected to...

Страница 29: ...ection will attempt to authenticate to the selected agent If no agent is selected a message box will be presented indicating that an agent must be selected If the agent is a telnet Agent a TELNET Communications Console will automatically open If the agent is a normal FLOWcontrol agent a dialog box will appear requesting authentication information for the selected agent The Username field of the di...

Страница 30: ...s are populated also based on the product properties In FLOWcontrol it is possible to connect to multiple agents simultaneously However when a connection has been established the newly connected agent s product tab is selected 7 2 1 1 2 2 Disconnect Agent Disconnect menu selection will perform the same functionality as the File Exit menu option Please refer to that section to determine the functio...

Страница 31: ...om the Agent menu From this form the Agent Location and Connection can be managed In addition the filtered product found at a specified Connection can be determined Selection of the button on the form attempts to communicate and determine what filtered product responds Although this capability is provided an agent may be specified without determining the product Whenever an actual connection is ma...

Страница 32: ...ic instructions on performing this function The Utilities Options is context sensitive and will present a form with the available options under user control This form also provides the ability to set Filter File Location Filtered Product IP Address Real Time Clock SYSLOG parameters The Filter File Location option is used to share a filter file on a network location or the default installed directo...

Страница 33: ...User Account Management Screen is depicted Specifically the Username field is a text box into which the new Username should be entered In the case of a Modify or Delete of a User Account the text box will appear as a combo box from which to select the user to be operated upon this combo box is depicted as The individual tabs within the User Management form allow for customizing the security rights...

Страница 34: ... communications console or the Filter Management tab depending upon those tabs being available 7 2 1 1 5 Help The Help menu provides information regarding FLOWcontrol 7 2 1 1 5 1 About unconnected The Help About menu option will present a dialog box containing information about FLOWcontrol its element dynamic data libraries DLLs and any connected product firmware and configuration information Both...

Страница 35: ...e list is divided into Agent Groupings Within the Agent Groupings specific Locations are specified Please note that the list is alphabetically sorted Within the Locations specific Agents are designated as either a local COM port or as a network agent with an IP address specified The specific Agents are sorted showing the COM ports first then the IP Addresses are sorted by IP address From the Agent...

Страница 36: ... IPv6 IP Address Filters ADVANCED Filters MIXED Filters Frame Type and Protocol Filters built in the Advanced Wizard are considered ADVANCED Filters and will appear under this major section The Filter Management capability provides the user with off line filter management Filters can be created deleted and modified without being attached to a specific filtered product In addition a wizard is provi...

Страница 37: ...ered product from the dialog box combo box then determines the number and names of the ports on the filtered product and presents another dialog box with the list of ports from which to select Selection of a port from this list then proceeds to another dialog box asking which filter to retrieve Depending upon the product the list of filters available may vary Specifically for the Filtered SINGLEst...

Страница 38: ...oupings as depicted The six individual filter groupings consist of a unique blend of elements with specific differences based upon the filter type The individual group definitions are represented in the following six figures MAC Address Filtering VLAN ID Filtering IPv4 IP Address Filtering IPv4 PORT Number Filtering IPv6 IP Address Filtering Advanced Filtering ...

Страница 39: ...d Exclude Filter check boxes apply to all of the Filter Types 7 2 2 2 2 Include VLAN Tunneling Frames The Include VLAN Tunneling Frames check box is found in the following Filter Types VLAN ID Filter IPv4 Address Filter IPv4 PORT Filter IPv6 Address Filter This flag if checked forces the filter engine to examine an Ethernet frame to determine if the frame is a VLAN tagged frame If so the specified...

Страница 40: ...g Filter Types only MAC Address Filter IPv4 Address Filter IPv4 PORT Number Filter IPv6 Address Filter The Directional Selections include Source Destination Destination Source Bidirectional Directional Selection For the Directional Selections of Source Destination and Destination Source no special rule handling is required other than that already specified for Range Definitions However for the Bid...

Страница 41: ...s Filter 16 Rules Allowed 8 Rules Allowed 8 Rules Allowed 4 Rules Allowed 16 Rules Allowed IPv4 PORT Number Filter 16 Rules Allowed 8 Rules Allowed 8 Rules Allowed 4 Rules Allowed 16 Rules Allowed IPv6 IP Address Filter 16 Rules Allowed 8 Rules Allowed 8 Rules Allowed 4 Rules Allowed 16 Rules Allowed Advanced Filter Not Applicable Not Applicable Not Applicable Not Applicable 2 Rules Allowed 7 2 2 ...

Страница 42: ...ss is EQUAL 00 14 E2 00 00 1F OR Source MAC Address is between 22 EF 45 00 00 00 AND 22 EF 45 FF FF FF AND Destination MAC Address is between 22 EF 45 00 00 00 AND 22 EF 45 FF FF FF AND VLAN ID is between 2 AND 10 OR VLAN ID is EQUAL 100 AND Offset 14 bits 6 7 8 0x60 which corresponds to a VLAN Priority of 3 OR Offset 14 bits 6 7 8 0xE0 which corresponds to VLAN Priority of 7 ...

Страница 43: ...1 0 10 1 1 255 OR 10 2 2 0 10 2 2 255 AND Ports 16384 32767 The Advanced Filter rules are combined according to the OR function There are 2 Advanced filters available Traffic must comply with one rule in order for the filter to be applied Rule 1 OR Rule 2 Advanced Filter offsets are combined according to the AND function Traffic must comply with all applied offsets for the filter to be applied Off...

Страница 44: ... bits of offset 14 and the entire byte of offset 15 are used for the VLAN ID This corresponds to 12 bits of data which corresponds to a maximum VLAN ID of 4095 Consequently the maximum value that can be specified in the definition of a VLAN ID filter is 4095 The VLAN IDs are specified as integers The VLAN ID Filter is bound by the Rule Definition limitations 7 2 2 2 7 IPv4 IP Address Filter The IP...

Страница 45: ...mber is 2370 The IPv4 PORT Number Filter is bound by the Rule Definition limitations 7 2 2 2 9 IPv6 IP Address Filter The IPv6 IP Address Filter definition is used to specify an exact Source Address Destination Address or Source Destination Address pair In addition ranges of each of these can be specified and a directional indicator specified The directional indicator Source Destination will place...

Страница 46: ... Equals Not Equals Greater Than Less Than Greater Than or Equals Less Than or Equals The values are specified in two digit hex notation 0x which corresponds to a value that can be specified in a single byte of data As an example of an Advanced Filter if bit 5 is to be evaluated the mask should be set to 00010000 the equation set to Equals and the value set to the hex value of the mask in this case...

Страница 47: ...eck the other as the Include and Exclude Filters are mutually exclusive In the case of the Include VLAN Tunneling Frames node double clicking on the node will toggle between the checked and unchecked state The Rule Set and Rule nodes are toggled from an expanded to a collapsed state when a double click of that node is performed In addition the same functionality can be performed by clicking on the...

Страница 48: ...C Address filtering select so data entry of MAC Address Filtering Configuration grouping will be enabled and can now be completed as described in the MAC Address Wizard section of this document When completed selection of the button will proceed to the VLAN ID Filtering entry screen If the filter specification has been completed click on the button In order to enable VLAN ID filtering must be sele...

Страница 49: ...een completed click on the button In order to enable IPv4 IP Address filtering must be selected so the IPv4 IP Address Filtering Configuration grouping will be enabled Selection of the IPv4 IP Address filtering parameters can now be completed as described in the IPv4 IP Address Wizard section of this document When completed selection of the button will proceed to one of either the IPv4 Protocol Fi...

Страница 50: ...ering that has already been enabled configured is desired click on the button If the filter specification has been completed click on the button In order to enable IPv4 PORT Number filtering must be selected so the IPv4 IP PORT Number Filtering Configuration grouping will be enabled Selection of the IPv4 PORT Number filtering parameters can now be completed as described in the IPv4 PORT Number Wiz...

Страница 51: ...cification of a given filter row The button is used to cancel ALL entered filter specifications and return to the Filter Management Screen The button always takes all currently entered data and populates the information in the Filter Specifics Panel with the selected data entered in the applicable area on the screen The MAC Address filter being created is either an Include or an Exclude filter as ...

Страница 52: ...try is to be a Destination Range enter data as depicted If the MAC Address entry is to be a specific Source Destination Address pair enter data as depicted below Either the Source or Destination Ranges can be specified with appropriate screens as given below Please note that the upper Destination Address is auto filled to the lower Destination MAC Address value As noted in the Rule Definitions sec...

Страница 53: ...cation of a given filter row The button is used to cancel ALL entered filter specifications and return to the Filter Management Screen The button always takes all currently entered data and populates the information in the Filter Specifics Panel with the selected data entered in the appropriate area on the screen The VLAN ID filter being created is either an Include or an Exclude filter as determi...

Страница 54: ...ation of a particular frame for a specified ETHERtype The second rule is reserved in case evaluation of a VLAN tagged frame is required Therefore this wizard only allows for the selection of a single ETHERtype as ETHERtype 8848 MPLS is selected in the screen below The list of ETHERtypes is found in the installed directory for FLOWcontrol in a text file called Ethertypes_FC txt The button is used t...

Страница 55: ... used to cancel ALL entered filter specifications and return to the Filter Management Screen The button takes all currently entered data and populates the information in the Filter Specifics Panel with the selected data entered in the applicable area on the screen The IPv4 IP Address filter being created is either an Include or an Exclude filter as determined by selecting the or the radio button T...

Страница 56: ... ANY range definitions require ALL table entries to be treated as ranges 7 2 2 3 5 IPv4 Protocol Wizard The IPv4 Protocol Wizard enables filtering on a specific Protocol Only a single entry can be examined within a given filter as this filter type makes use of the Advanced Filtering capability which consists of only 2 rules The first rule is used for evaluation of a particular frame for a specifie...

Страница 57: ... button is only enabled when an entire row has been highlighted The button is used to copy a selected table and add the row to the end of the currently entered table The row type only is copied Specific data will still be required to be entered for a complete specification of a given filter row The button is used to cancel ALL entered filter specifications and return to the Filter Management Scree...

Страница 58: ...valid IPv4 PORT Number If the IPv4 PORT Number entry is to be a Destination Range enter data as depicted If the IPv4 PORT Number entry is to be a specific Source Destination Address pair enter data as depicted below Either the Source or Destination Ranges can be specified with appropriate screens as given below Please note that the upper Destination Address is auto filled to the lower Destination ...

Страница 59: ...rily in the functionality of the Telnet Serial client sending a script file containing a series of commands appropriate for performing upgrades is applicable Create FVS 1080 Upgrade Scripts creates upgrade scripts based upon an entered tftp or ftp server and a designated directory into which to place the files If used in conjunction with a tftp server the files should be located in the tftp server...

Страница 60: ...an result for various reasons and when the Communications Console becomes aware of a broken connection or the the interrupts the Telnet or Serial connection the becomes initiates a ping every second for a selected IP Address reports the ping status and is available only when Telnet connectivity is selected When selected becomes and the becomes disabled Selection of terminates the ongoing pings bec...

Страница 61: ...et capabilities The tree view presented may correspond to ingress or egress focused operation In the case of ingress focused orientation the top level node received data is copied routed to each of the selected subordinate nodes In the case of egress focused orientation each of the selected subordinate nodes received data is copied routed to the top level node Filter Configuration This tab allows ...

Страница 62: ... port traffic Port Mirrors or the monitor side of a stand alone network tap Data received via the Network Input Port is copied filtered and then replicated on the identified Monitor Ports Monitor Ports are used to provide network data to connected analysis devices 7 2 4 1 2 Counter Resets Individual counters within the FVS 1080 can be reset other products do not currently support this function To ...

Страница 63: ...ame noted as Local Name Port Name Expanding the Summary view the user can review the connected device available Network Port and Monitor Port properties which include but are not necessarily limited to the following Port Names o Local Names Names found on the front panel of the product o User Assigned Names Up to 16 characters in length Media Preference o Copper o Fiber SFP Handling Standard Exter...

Страница 64: ...4 1 4 Port Configuration The Port Configuration tab allows the user to view or modify the port settings for all the available ports of the connected product Port Name Media Preference Port Speed and Port Type can all be reviewed by the user Values that cannot be changed within the Port Configuration tab will be grayed out and made into read only values SINGLEstream or VERSAstream products that hav...

Страница 65: ...ports are connected to protocol analysis tools probes or security devices Be sure that the correct speed setting is used consistently across Network Taps Both the A and B ports of any Network Tap must have the same speed settings Also be sure to only send an appropriate amount of traffic to any connected monitoring device A 100BaseT network analyzer cannot handle all unfiltered traffic from both s...

Страница 66: ...e nodes in the Aggregation Configuration tree Egress Port Focused Aggregation implies that any data arriving on one of the checked subordinate nodes is copied to the top level node Example In the below Egress Port Focused case Data arriving on Port 2 Port 4 and Port 5 are all copied to Port 1 Data arriving on Port 3 Port 4 Port 5 and Port 6 are all copied to Port 2 Data arriving on Port 1 Port 2 P...

Страница 67: ...xample Reduce the chance of oversubscribing the throughput capacity of a a monitoring tool 100BaseT and 1000BaseT monitoring tools are rarely if ever capable of accepting sustained input at full line rate Sending the different data streams of the two sides of a single duplex conversation to different Monitor ports and thereby to different NIC s on a multiple port monitoring tool is a useful strate...

Страница 68: ...s By default the A and B ports of any Network Tap are routed to each other and cannot be changed or else the Network Tap would cause a break in the network The FLOWcontrol software does not allow the user to make this change The flow of network traffic in the diagram above can be replicated by the Aggregation Configuration shown Data received on Network Port 1A is sent to Network Port 1B to comple...

Страница 69: ...ggregation taps to different Filtered product Monitor ports and thereby to different NIC s on a multiple port monitoring tool is a useful strategy for overcoming the inherent shortcomings of monitoring tool throughput Direct the copies of Inbound and Outbound network traffic coming from non aggregating taps or SPAN ports assuming one has different SPAN ports one set up to forward Inbound traffic o...

Страница 70: ...ical links two different SPAN ports are forwarding data copies from those links to the Network input ports for purposes of providing continuous visibility on a single monitoring tool interface a The Network input ports are receiving data copies from SPAN ports or aggregation taps that are deployed for visibility into lower utilization links at the edge of the network and that data is to be viewed ...

Страница 71: ...two sections On the left side is a list of the filters configured in the Filter Management element of FLOWcontrol The filters are grouped by type PASS ALL and PASS NONE filters are always available even if no other filters have been created in the Filter Management element of FLOWcontrol On the right side the specific hardware filters that can be configured are listed by port In order to apply a d...

Страница 72: ...ton is required 7 2 6 Event Log The Event Log tab allows the user to quickly monitor any actions or events that have occurred with the connected Filtered SINGLEstream or Filtered VERSAstream Each entry in the Event Log captures the time of the event the user who made the change the IP address of the Filtered product device and a brief description of the event itself This information allows the use...

Страница 73: ...ory buffer Connectivity Authentication Functionality Connectivity to the FVS series product is made through the Serial USB style type A or Management RJ45 port and authentication is required Base Prompt This is the text presented to the user logging in to use the CLI default values shown All Usernames and passwords are case sensitive Enter Username Administrator Enter Password admin 8 2 Basic Comm...

Страница 74: ...on SET PORT SE PO Set Management IP PORT configuration SET NTP SE NTP Set Network Time Protocol configuration SET PING SE PG Set PING Enable State SET SSH SE SH Set SSH Server State SET SYSLOG SE SY Set syslog configuration SET TELNET SE TT Set Telnet Server State SET TFTP SE TP Set TFTP Server State SET TIME SE TI Set Date and Time REBOOT Force Full System reboot REBOOT management Force Network P...

Страница 75: ... 3 17 2010 12 36 12 PM FVSApp 1949 FilterCore 77 AggregatorCore 67 EthernetCore 69 ProcessorCore 103 MANAGEMENT PORT MAC Address 00 14 E2 00 20 25 IP Address 177 175 51 114 IP Subnet 255 255 0 0 IP Gateway 177 175 50 1 IP Port 2370 Serial Baud Rate 9600 BPS SYSLOG IP 1 2 3 4 Port 514 State OFF FTP Daemon ON TFTP Daemon ON TELNET Daemon ON PING Replies ON SSH Daemon OFF 8 2 5 SHOW DAEMON SH DN This...

Страница 76: ...us NTP Client is DISABLED Status NTP GMT Offset is 4 hours Status NTP Server URL is time nist gov Status NTP Required Good Sync is 4 Status NTP Initial Polling Period 1 minutes Status NTP Regular Polling Period 480 minutes Status NTP Logging is DISABLED 8 2 8 SHOW TIME SH TI This command displays the set date and time for the product SHOW TIME SH TI example SH TI The current Time is May 14 10 37 0...

Страница 77: ...mation 8 2 11 SET BAUD SE BD This command sets the Management Port Serial Baud Rate SET BAUD SE BD example SE BD Current Management Serial Baud Rate 9600 BPS Enter new BaudRate 300 1200 2400 9600 19200 38400 57600 115200 9600 New BaudRate 9600 Enter y to confirm changes or n to cancel CHANGES WILL BE IMMEDIATE y Updating Done 8 2 12 SET FTP SE FP This command sets the File Transfer Protocol FTP da...

Страница 78: ...ows CLI combined entry for IP Subnet and Gateway but is allowed for the FVS 1044 example 2 shows CLI separate entry for IP SET IP SE IP ppp ppp ppp ppp sss sss sss sss ggg ggg ggg ggg p IP Address s Subnet g Gateway example 1 all models SE IP 177 175 51 114 255 255 0 0 177 175 50 1 Please Verify The Settings New IP 177 175 51 114 New Subnet 255 255 0 0 New Gateway 177 175 50 10 Enter y to confirm ...

Страница 79: ...n to cancel y Updating Done Please type REBOOT management or REBOOT at the command prompt to allow the new network settings to take effect 8 2 16 SET GATEWAY SE GA Separate Gateway CLI entry IS NOT ALLOWED for the FVS 1080 Separate Gateway CLI entry is allowed for the FVS 1044 This command sets the Management Port GATEWAY Initially it is highly recommended that this be done through the direct seri...

Страница 80: ... Port 44913 Enter y to confirm changes or n to cancel y Updating Done Please type REBOOT management or REBOOT at the command prompt to allow the new network settings to take effect 8 2 18 SET NTP SE NTP This command sets Network Time Protocol NTP options Enter the options required for your network SET NTP SE NTP example SE NTP Network Time Protocol Setup 1 Enable NTP Client 2 Disable NTP Client 3 ...

Страница 81: ...FF example SE SH ON SSH Daemon SET STATE TO ON Applying these settings proceed y n y Updating Done 8 2 21 SET SYSLOG SE SY This command sets SSH daemon state SET SSH SE SY ON enable OFF disable example SE SH ON Please Verify The Settings You Have Selected to ENABLE the Syslog Output Process Applying these settings proceed y n y Updating Done 8 2 22 SET TELNET SE TT This command sets TELNET Daemon ...

Страница 82: ...nd time SET TIME SE TI example SE TI Set the HW Real Time Clock Month 1 12 5 Day 1 31 7 Year 2000 2099 2010 Hour 00 23 19 Minute 00 59 42 Second 00 59 00 The RTC Clock reports MM DD YYYY 5 HH MM SS 19 42 0 8 2 25 REBOOT Elapsed time is about 2 minutes to perform a full system reboot example REBOOT REBOOT Issuing Hard Reboot Updating environment Storing log files Hard Reboot in 5 Hard Reboot in 4 H...

Страница 83: ...C92FA6 Starting AutoBoot Process Press X To Stop Autoboot 3 Press X To Stop Autoboot 2 Press X To Stop Autoboot 1 Generating Kernel Options FLEconsole ttyS0 9600 ethaddr 00 14 E2 00 20 25 ubootenv mtd5 Attempting to Direct Boot the uCLinux Kernel Reading Data from SPI FLASH Address 0x100000 to MemoryAddress 0x80000000 Total Data Size 4194304 Bytes Launching Application 0x80000000 VERSAstream Initi...

Страница 84: ...n be found in the Filtered Product Hardware USERguide in the IP Address Configuration section In a nutshell a Command Line Interface serial port connection using a terminal emulator 9 600 bits per second 8 data bits Parity none 1 stop bit Flow control none note FSSes and FVS 1044 2 400 bits per second FVS 1080 9 600 bits per second all others 115 200 bits per second is used to assign the IP addres...

Страница 85: ...s is just a label where Network Port indicates an input port and this setting does not affect packet traffic or aggregation When all selections have been completed click the Apply Selections button 5 Aggregation Configuration Determines how you are steering traffic within the FVS 1080 from data coming into the product to specific monitoring ports In this example recall that there are six input str...

Страница 86: ... an Include Filter so packets that meet this criteria will be forwarded excluding VLAN tagged frames to the monitor ports note if the source data includes VLAN tagged traffic the box for Enable Examination of VLAN encapsulated frames for all VLAN tagged frames Click the Add button Click under Lower IPv4 IP Address to enter IP Address And since this is to be a range check Enable Source Range Enter ...

Страница 87: ...ple packets are coming in on Port 1 Port 2 and Port 3 We want to apply this filter prior to those input streams being aggregated then the aggregation is going to take place and whatever packets meet this filter criteria will be sent out the monitoring Port 8 Check the three Pre Aggregation ports where the filter is to be applied double click on the filter itself and observe the filter applied on t...

Страница 88: ...he event of any such defect you can return an item of defective hardware freight prepaid to DSI during the Warranty Period and DSI will repair or replace the defective equipment and return it to you freight prepaid If DSI determines that the equipment is not defective it will return it to you freight collect DSI shall have no responsibility for any deficiency resulting from accidents misuse modifi...

Страница 89: ...ervices lost profits lost savings loss of information or data or any other special indirect consequential or incidental damages arising in any way out of the sale of use of or inability to use any DSI product or service even if DSI has been advised of the possibility of such damages 10 4 Force Majeure DSI will not be liable for any failure to perform due to unforeseen circumstances or causes beyon...

Страница 90: ...Datacom Systems Inc 9 Adler Drive East Syracuse NY 13057 TEL 315 463 9541 FAX 315 463 9557 http www datacomsystems com Datacom Systems Inc Access Your Network TM ...

Отзывы: