80 likes | 110 Views
IPFIX Architecture. draft-ietf-ipfix-arch-01.txt Ganesh Sadasivan / Nevil Brownlee. Flow Definition.
E N D
IPFIX Architecture draft-ietf-ipfix-arch-01.txt Ganesh Sadasivan / Nevil Brownlee
Flow Definition A flow is defined as a set of IP packets passing an observation point in a network during a certain time interval. All packets that belong to a particular flow have a set of common properties derived from the data contained in the packet and from the packet treatment at the observation point. A 'flow' is a set of IP packets, or encapsulated IP packets,passing an observation point in the network during a certain time interval.
Terminology • In sync with draft-ietf-ipfix-reqs-10.txt for most of the definitions • Some extra definitions: • Collector:The device which hosts one or more collecting processes. • Flow Recording Process: The flows generated from the metering device(s) in an Observation Domain MAY be collected into one or more database before exporting. This is an optional block.
Architecture Diagrams • Reference Model • A typical IPFIX device – shows the association between various components within an IPFIX device • Logical Blocks and Functional flow within an IPFIX device
New Sections • IPFIX Protocol • List of rule categories • List of functions • Encoding Control Information • Encoding Flow Data Information • Exporting Control Information • Export Error Handling
New Sections (Contd.) • Selected IPFIX Protocol • Brief overview of Netflow V9 • IPFIX Specific DoS attack
Need More Inputs • Encoding Control Information (network order or host order etc.) • Encoding Flow Data Information – need clearer guidelines • Export Models • Anonymization of IPFIX export packets • IPFIX Specific DoS attack (sec. 13.3.3) • No section on exporter overloading