IPFIX

IPFIX(Internet Protocol Flow Information Export)는 스위치 또는 라우터를 통한 트래픽 플로우를 모니터하는 회계 기술입니다. 트래픽을 해석하여 사용되는 클라이언트, 서버, 프로토콜 및 포트를 판별합니다. 또한 바이트 및 패킷 수를 계수하고 해당 데이터를 IPFIX 콜렉터로 보냅니다. IBM® Security Network Protection XGS 5000, 차세대 침입 보호 시스템 (IPS) 은 IPFIX 플로우 형식으로 플로우 트래픽을 전송하는 디바이스의 예입니다.

IPFIX 데이터를 전송하는 프로세스를 NetFlow 데이터 내보내기 (NDE) 라고도 하지만 IPFIX는 NetFlow v9보다 더 많은 플로우 정보와 심층적인 인사이트를 제공합니다.

IBM QRadar 는 IPFIX 콜렉터로 작동하도록 NDE를 허용합니다. IPFIX는 UDP(User Datagram Protocol)를 사용하여 NDE를 전달합니다. IPFIX 전달 디바이스에서 NDE를 전송하면 IPFIX 레코드를 제거할 수 있습니다.

IPFIX 플로우 소스 구성

IPFIX의 외부 플로우 소스를 구성할 때 다음 태스크를 수행해야 합니다.
  • NetFlow 플로우 소스를 추가하십시오.
    참고: QRadar 시스템에 기본 NetFlow 플로우 소스가 포함될 수 있습니다. 이 경우 QRadar 는 기본 NetFlow 플로우 소스를 사용하여 IPFIX 플로우를 처리할 수 있습니다.

    시스템에 기본 NetFlow 플로우 소스가 포함되어 있는지 확인하려면 관리 탭에서 플로우 소스를 선택하십시오. default_Netflow가 플로우 소스 목록에 나열되어 있는 경우, IPFIX가 이미 구성된 것입니다.

  • 적절한 방화벽 룰이 구성되어 있는지 확인하십시오.

    플로우 콜렉터 구성에서 외부 플로우 소스 모니터링 포트 매개변수를 변경하는 경우 방화벽 액세스 구성도 업데이트해야 합니다.

  • 플로우 콜렉터에 대해 적절한 포트가 구성되어 있는지 확인하십시오.

IPFIX 플로우 소스 템플리트

IPFIX 소스의 IPFIX 템플리트에 다음 IANA 나열 정보 요소가 포함되어 있는지 확인하십시오.
  • protocolIdentifier(4)
  • sourceIPv4Address(8)
  • destinationIPv4Address(12)
  • sourceTransportPort(7)
  • destinationTransportPort(11)
  • octetDeltaCount(1) 또는 postOctetDeltaCount(23)
  • packetDeltaCount(2) 또는 postPacketDeltaCount(24)
  • tcpControlBits(6)(TCP 플로우만 해당).
  • flowStartSeconds(150) 또는 flowStartMilliseconds(152) 또는 flowStartDeltaMicroseconds(158)
  • flowEndSeconds(151) 또는 flowEndMilliseconds(153) 또는 flowEndDeltaMicroseconds(159)

지원되는 필드

다음 목록에는 IPFIX 플로우 소스에 지원되는 몇 가지 필드 유형이 표시되어 있습니다.

7.4.3 QRadar에 표시되지 않는 추가 IPFIX 필드에 대한 지원을 추가하기 위해 /api/ariel/taggedfields API를 사용하여 태그 지정된 새 필드를 작성할 수 있습니다.
VLAN 필드
IPFIX에는 다음 VLAN 필드가 지원됩니다.
  • vlanId(IANA 요소 ID 58)
  • postVlanId(IANA 요소 ID 59)
  • dot1qVlanId(IANA 요소 ID 243)
  • dot1qPriority(IANA 요소 ID 244)
  • dot1qCustomerVlanId(IANA 요소 ID 245)
  • dot1qCustomerPriority(IANA 요소 ID 246)
  • postDot1qVlanId(IANA 요소 ID 254)
  • postDot1qCustomerVlanId(IANA 요소 ID 255)
  • dot1qDEI(IANA 요소 ID 388)
  • dot1qCustomerDEI(IANA 요소 ID 389)
MAC 주소 필드
IPFIX에는 다음 MAC 주소 필드가 지원됩니다.
  • sourceMacAddress(IANA 요소 ID 56)
  • postDestinationMacAddress(IANA 요소 ID 57)
  • DestinationMacAddress(IANA 요소 ID 80)
  • postSourceMacAddress(IANA 요소 ID 81)
NAT(Network Address Translation) 필드
NAT(Network Address Translation) 및 NAPT(Network Address Port Translation)에 대해 다음 필드가 지원됩니다.
  • postNATSourceIPv4Address(IANA 요소 ID 225)
  • postNATDestinationIPv4Address(IANA 요소 ID 226)
  • postNAPTSourceTransportPort(IANA 요소 ID 227)
  • postNAPTDestinationTransportPort(IANA 요소 ID 228)
MPLS 필드
IPFIX에는 다음 MPLS 필드가 지원됩니다.
  • mplsTopLabelType(IANA 요소 46)
  • mplsTopLabelIPv4Address(IANA 요소 47)
  • mplsTopLabelStackSection(IANA 요소 70)
  • mplsLabelStackSection2(IANA 요소 71)
  • mplsLabelStackSection3(IANA 요소 72)
  • mplsLabelStackSection4(IANA 요소 73)
  • mplsLabelStackSection5(IANA 요소 74)
  • mplsLabelStackSection6(IANA 요소 75)
  • mplsLabelStackSection7(IANA 요소 76)
  • mplsLabelStackSection8(IANA 요소 77)
  • mplsLabelStackSection9(IANA 요소 78)
  • mplsLabelStackSection10(IANA 요소 79)
  • mplsVpnRouteDistinguisher(IANA 요소 90)
  • mplsTopLabelPrefixLength(IANA 요소 91)
  • mplsTopLabelIPv6Address(IANA 요소 140)
  • mplsPayloadLength(IANA 요소 194)
  • mplsTopLabelTTL(IANA 요소 200)
  • mplsLabelStackLength(IANA 요소 201)
  • mplsLabelStackDepth(IANA 요소 202)
  • mplsTopLabelExp(IANA 요소 203)
  • postMplsTopLabelExp(IANA 요소 237)
  • pseudoWireType(IANA 요소 250)
  • pseudoWireControlWord(IANA 요소 251)
  • mplsLabelStackSection IANA 요소 316)
  • mplsPayloadPacketSection(IANA 요소 317)
  • sectionOffset(IANA 요소 409)
  • sectionExportedOctets(IANA 요소 410)