ExtremeWare XOS 11.1 Concepts Guide
253
14
CLEARFlow
This chapter describes the following topics:
●
Overview on page 253
●
Configuring CLEARFlow on page 253
●
Adding CLEARFlow Rules to ACLs on page 254
●
CLEARFlow Rule Examples on page 261
Overview
CLEARFlow is a broad framework for implementing security, monitoring, and anomaly detection in
ExtremeWare XOS software. Instead of simply looking at the source and destination of traffic,
CLEARFlow allows you to specify certain types of traffic that require more attention. Once certain
criteria for this traffic are met, the switch can either take an immediate, pre-determined action, or send a
copy of the traffic off-switch for analysis.
CLEARFlow is an extension to Access Control Lists (ACLs). You create ACL policy rules to count
packets of interest. CLEARFlow rules are added to the policy to monitor these ACL counter statistics.
The CLEARFlow agent monitors the counters for the situations of interest to you and your network.
You can monitor the cumulative value of a counter, the change to a counter over a sampling interval,
the ratio of two counters, or even the ratio of the changes of two counters over an interval. For example,
you can monitor the ratio between TCP SYN and TCP packets. An abnormally large ratio may indicate
a SYN attack.
If the rule conditions are met, the CLEARFlow actions configured in the rule are executed. The switch
can respond by modifying an ACL that will block, prioritize, or mirror the traffic, executing a set of CLI
commands, or sending a report using a SNMP trap or EMS log message.
NOTE
CLEARFlow is supported only on the BlackDiamond 10K Switch.
Configuring CLEARFlow
CLEARFlow is an extension to ACLs, so you must be familiar with configuring ACLs before you add
CLEARFlow rules to your ACL policies. Creating ACLs is described in detail in
Chapter 11
,
“Policies
and ACLs”
.
Chapter 11
describes how to create ACL policies, the syntax of an ACL policy file, and how
to apply ACL policies to the switch. In this current chapter, you will find information about the
CLEARFlow rules that you add to ACL policies, including the CLEARFlow rules’ syntax and behavior.
After creating the ACLs that contain CLEARFlow rules, and after applying the ACLs to the appropriate
interface, you will enable CLEARFlow on the switch. When CLEARFlow is enabled, the rules will be
evaluated by the CLEARFlow agent on the switch, and if any rules are triggered, the CLEARFlow
actions are executed.
Содержание ExtremeWare XOS 11.1
Страница 16: ...Contents ExtremeWare XOS 11 1 Concepts Guide 16...
Страница 20: ...Preface ExtremeWare XOS 11 1 Concepts Guide 20...
Страница 21: ...1 Using ExtremeWare XOS...
Страница 22: ......
Страница 78: ...Managing the ExtremeWare XOS Software ExtremeWare XOS 11 1 Concepts Guide 78...
Страница 168: ...Virtual LANs ExtremeWare XOS 11 1 Concepts Guide 168...
Страница 200: ...Policies and ACLs ExtremeWare XOS 11 1 Concepts Guide 200...
Страница 252: ...Security ExtremeWare XOS 11 1 Concepts Guide 252...
Страница 265: ...2 Using Switching and Routing Protocols...
Страница 266: ......
Страница 294: ...Ethernet Automatic Protection Switching ExtremeWare XOS 11 1 Concepts Guide 294...
Страница 354: ...Extreme Standby Router Protocol ExtremeWare XOS 11 1 Concepts Guide 354...
Страница 416: ...IP Multicast Routing ExtremeWare XOS 11 1 Concepts Guide 416...
Страница 417: ...3 Appendixes...
Страница 418: ......
Страница 432: ...Software Upgrade and Boot Options ExtremeWare XOS 11 1 Concepts Guide 432...