IPFIX
IPFIX(Internet Protocol Flow Information Export)는 스위치 또는 라우터를 통한 트래픽 플로우를 모니터하는 회계 기술입니다. 트래픽을 해석하여 사용되는 클라이언트, 서버, 프로토콜 및 포트를 판별합니다. 또한 바이트 및 패킷 수를 계수하고 해당 데이터를 IPFIX 콜렉터로 보냅니다. IBM® Security Network Protection XGS 5000, 차세대 침입 보호 시스템 (IPS) 은 IPFIX 플로우 형식으로 플로우 트래픽을 전송하는 디바이스의 예입니다.
IPFIX 데이터를 전송하는 프로세스를 NetFlow 데이터 내보내기 (NDE) 라고도 하지만 IPFIX는 NetFlow v9보다 더 많은 플로우 정보와 심층적인 인사이트를 제공합니다.
IBM QRadar 는 IPFIX 콜렉터로 작동하도록 NDE를 허용합니다. IPFIX는 UDP(User Datagram Protocol)를 사용하여 NDE를 전달합니다. IPFIX 전달 디바이스에서 NDE를 전송하면 IPFIX 레코드를 제거할 수 있습니다.IPFIX 플로우 소스 구성
IPFIX의 외부 플로우 소스를 구성할 때 다음 태스크를
수행해야 합니다.
- NetFlow 플로우 소스를 추가하십시오.참고: QRadar 시스템에 기본 NetFlow 플로우 소스가 포함될 수 있습니다. 이 경우 QRadar 는 기본 NetFlow 플로우 소스를 사용하여 IPFIX 플로우를 처리할 수 있습니다.
시스템에 기본 NetFlow 플로우 소스가 포함되어 있는지 확인하려면 관리 탭에서 플로우 소스를 선택하십시오. default_Netflow가 플로우 소스 목록에 나열되어 있는 경우, IPFIX가 이미 구성된 것입니다.
- 적절한 방화벽 룰이 구성되어 있는지 확인하십시오.
플로우 콜렉터 구성에서 외부 플로우 소스 모니터링 포트 매개변수를 변경하는 경우 방화벽 액세스 구성도 업데이트해야 합니다.
- 플로우 콜렉터에 대해 적절한 포트가 구성되어 있는지 확인하십시오.
IPFIX 플로우 소스 템플리트
IPFIX 소스의 IPFIX 템플리트에 다음 IANA 나열 정보 요소가 포함되어
있는지 확인하십시오.
- protocolIdentifier(4)
- sourceIPv4Address(8)
- destinationIPv4Address(12)
- sourceTransportPort(7)
- destinationTransportPort(11)
- octetDeltaCount(1) 또는 postOctetDeltaCount(23)
- packetDeltaCount(2) 또는 postPacketDeltaCount(24)
- tcpControlBits(6)(TCP 플로우만 해당).
- flowStartSeconds(150) 또는 flowStartMilliseconds(152) 또는 flowStartDeltaMicroseconds(158)
- flowEndSeconds(151) 또는 flowEndMilliseconds(153) 또는 flowEndDeltaMicroseconds(159)
지원되는 필드
다음 목록에는 IPFIX 플로우 소스에 지원되는 몇 가지 필드 유형이 표시되어 있습니다.
7.4.3 QRadar에 표시되지 않는 추가 IPFIX 필드에 대한 지원을 추가하기 위해
/api/ariel/taggedfields API를 사용하여 태그 지정된 새 필드를 작성할 수 있습니다.- VLAN 필드
- IPFIX에는 다음 VLAN 필드가 지원됩니다.
- vlanId(IANA 요소 ID 58)
- postVlanId(IANA 요소 ID 59)
- dot1qVlanId(IANA 요소 ID 243)
- dot1qPriority(IANA 요소 ID 244)
- dot1qCustomerVlanId(IANA 요소 ID 245)
- dot1qCustomerPriority(IANA 요소 ID 246)
- postDot1qVlanId(IANA 요소 ID 254)
- postDot1qCustomerVlanId(IANA 요소 ID 255)
- dot1qDEI(IANA 요소 ID 388)
- dot1qCustomerDEI(IANA 요소 ID 389)
- MAC 주소 필드
- IPFIX에는 다음 MAC 주소 필드가 지원됩니다.
- sourceMacAddress(IANA 요소 ID 56)
- postDestinationMacAddress(IANA 요소 ID 57)
- DestinationMacAddress(IANA 요소 ID 80)
- postSourceMacAddress(IANA 요소 ID 81)
- NAT(Network Address Translation) 필드
- NAT(Network Address Translation) 및 NAPT(Network Address Port Translation)에 대해
다음 필드가 지원됩니다.
- postNATSourceIPv4Address(IANA 요소 ID 225)
- postNATDestinationIPv4Address(IANA 요소 ID 226)
- postNAPTSourceTransportPort(IANA 요소 ID 227)
- postNAPTDestinationTransportPort(IANA 요소 ID 228)
- MPLS 필드
- IPFIX에는 다음 MPLS 필드가 지원됩니다.
- mplsTopLabelType(IANA 요소 46)
- mplsTopLabelIPv4Address(IANA 요소 47)
- mplsTopLabelStackSection(IANA 요소 70)
- mplsLabelStackSection2(IANA 요소 71)
- mplsLabelStackSection3(IANA 요소 72)
- mplsLabelStackSection4(IANA 요소 73)
- mplsLabelStackSection5(IANA 요소 74)
- mplsLabelStackSection6(IANA 요소 75)
- mplsLabelStackSection7(IANA 요소 76)
- mplsLabelStackSection8(IANA 요소 77)
- mplsLabelStackSection9(IANA 요소 78)
- mplsLabelStackSection10(IANA 요소 79)
- mplsVpnRouteDistinguisher(IANA 요소 90)
- mplsTopLabelPrefixLength(IANA 요소 91)
- mplsTopLabelIPv6Address(IANA 요소 140)
- mplsPayloadLength(IANA 요소 194)
- mplsTopLabelTTL(IANA 요소 200)
- mplsLabelStackLength(IANA 요소 201)
- mplsLabelStackDepth(IANA 요소 202)
- mplsTopLabelExp(IANA 요소 203)
- postMplsTopLabelExp(IANA 요소 237)
- pseudoWireType(IANA 요소 250)
- pseudoWireControlWord(IANA 요소 251)
- mplsLabelStackSection IANA 요소 316)
- mplsPayloadPacketSection(IANA 요소 317)
- sectionOffset(IANA 요소 409)
- sectionExportedOctets(IANA 요소 410)