SlideShare a Scribd company logo
Monitoring Dual-
Stack Networks
Vance Shipley
CTO, Wavenet
Cisco Router Configuration
Setting up SNMPv3 authentication:
snmp-server group zabbix v3 auth
snmp-server user zabbix zabbix v3 auth md5 mypassphrase
Testing with Net-SNMP
Configure authentication in a host specific
configuration file (~/.snmp/hosts/hqr.conf):
defVersion 3
defSecurityLevel authNoPriv
defSecurityName zabbix
defAuthType MD5
defAuthPassphrase mypassphrase
Testing with Net-SNMP
Get the system name:
$ snmpget hqr sysName.0
SNMPv2-MIB::sysName.0 = STRING: HQR
Internet Protocol MIB (IP-MIB)
ipSystemStatsHCOutForwDatagrams OBJECT-TYPE
SYNTAX Counter64
MAX-ACCESS read-only
STATUS current
DESCRIPTION
"The number of datagrams for which this entity
was not their final IP destination and for which
it was successful in finding a path to their
final destination."
http://tools.ietf.org/html/rfc4293#page-34
Internet Protocol MIB (IP-MIB)
Get the number of forwarded datagrams:
$ snmpget hqr ipSystemStatsHCOutForwDatagrams.ipv4
IP-MIB::ipSystemStatsHCOutForwDatagrams.ipv4 = Counter64:
19993419
$ snmpget hqr ipSystemStatsHCOutForwDatagrams.ipv6
IP-MIB::ipSystemStatsHCOutForwDatagrams.ipv6 = Counter64:
285
Interfaces MIB (IF-MIB)
Walk the interface table:
$ snmpwalk hqr ifDescr
IF-MIB::ifDescr.1 = STRING: Embedded-Service-Engine0/0
IF-MIB::ifDescr.2 = STRING: GigabitEthernet0/0
IF-MIB::ifDescr.3 = STRING: GigabitEthernet0/1
IF-MIB::ifDescr.4 = STRING: Serial0/0/0
IF-MIB::ifDescr.5 = STRING: Null0
http://tools.ietf.org/html/rfc2863#page-30
Internet Protocol MIB (IP-MIB)
ipIfStatsHCInForwDatagrams OBJECT-TYPE
SYNTAX Counter64
MAX-ACCESS read-only
STATUS current
DESCRIPTION
"The number of input datagrams for which this
entity was not their final IP destination and
for which this entity attempted to find a
route to forward them to that final
destination.”
http://tools.ietf.org/html/rfc4293#page-47
Internet Protocol MIB (IP-MIB)
Query received IP datagrams on interface
GigabitEthernet0/0 (index 2):
$ snmpget hqr ipIfStatsHCInReceives.ipv4.2
IP-MIB::ipIfStatsHCInReceives.ipv4.2 =
Counter64: 106157
$ snmpget hqr ipIfStatsHCInReceives.ipv6.2
IP-MIB::ipIfStatsHCInReceives.ipv6.2 =
Counter64: 1040
Network Monitoring with Zabbix
✓ Open Source
✓ Graphical User Interface
✓ SNMP, IPMI, JMX Agents
✓ Notification Triggers
✓ Historical Database
✓ Graphing
Zabbix: Latest Data View
✓ Items gather data from
a host for a particular
metric
✓ Each item has it’s own
schedule for collection
(i.e. every 60s, 24h)
✓ Quick Graphing
Zabbix: Configure SNMP Item
✓ Net-SNMP Integration
✓ Graphical Configuration
✓ Flexible Intervals
✓ Store As-Is or Delta
✓ History Storage Period
✓ Trend Storage Period
✓ Templates & Cloning
Zabbix: Create Custom Graph
IP Datagrams Forwarded (Hour)
Average of IP
datagrams
forwarded through
router:
IPv4: 80%
IPv6: 20%
IP Datagrams Received (Hour)
Average of IP
datagrams received
by router:
IPv4: 66%
IPv6: 34%
IP Bytes Received (Hour)
Average of bytes
received in IP
datagrams:
IPv4: 49%
IPv6: 51%
IP Datagrams Sent/Received (Hour)
IP Datagrams Sent/Received (Week)
vances@globalwavenet.com
Questions?

More Related Content

PDF
Graph Signal Processing: an interpretable framework to link neurocognitive ar...
PDF
BUD17-302: LLVM Internals #2
DOCX
Link state routing protocol
PPTX
Quantum Cryptography
PPTX
Cryptanalysis
PDF
Packet sniffing & ARP Poisoning
PPTX
OSPF Fundamental
PDF
DPDK & Layer 4 Packet Processing
Graph Signal Processing: an interpretable framework to link neurocognitive ar...
BUD17-302: LLVM Internals #2
Link state routing protocol
Quantum Cryptography
Cryptanalysis
Packet sniffing & ARP Poisoning
OSPF Fundamental
DPDK & Layer 4 Packet Processing

What's hot (20)

PDF
CS6701 CRYPTOGRAPHY AND NETWORK SECURITY
PDF
Instruction Combine in LLVM
PPTX
Intrusion prevention system(ips)
PDF
Binary heap in data structures algorithms.pdf
PDF
Introduction to eBPF and XDP
PPT
Quantum Cryptography
PDF
netfilter and iptables
PPTX
PDF
A whirlwind tour of the LLVM optimizer
PDF
wolfSSL and TLS 1.3
PDF
Zebra SRv6 CLI on Linux Dataplane (ENOG#49)
PPTX
Quantum Cryptography
PDF
LLVM Register Allocation
PPTX
What is Network Address Translation (NAT)
PDF
2. public key cryptography and RSA
PDF
Federated Semi-Supervised Learning with Inter-Client Consistency & Disjoint L...
PPTX
Quantum Cryptography
PPTX
Paillier-ElGamal cryptosystem presentation
PPTX
Cryptography and Network Security
PDF
eBPF - Rethinking the Linux Kernel
CS6701 CRYPTOGRAPHY AND NETWORK SECURITY
Instruction Combine in LLVM
Intrusion prevention system(ips)
Binary heap in data structures algorithms.pdf
Introduction to eBPF and XDP
Quantum Cryptography
netfilter and iptables
A whirlwind tour of the LLVM optimizer
wolfSSL and TLS 1.3
Zebra SRv6 CLI on Linux Dataplane (ENOG#49)
Quantum Cryptography
LLVM Register Allocation
What is Network Address Translation (NAT)
2. public key cryptography and RSA
Federated Semi-Supervised Learning with Inter-Client Consistency & Disjoint L...
Quantum Cryptography
Paillier-ElGamal cryptosystem presentation
Cryptography and Network Security
eBPF - Rethinking the Linux Kernel
Ad

Viewers also liked (8)

PDF
BdNOG 3: A closer look at IPv4 transfers
PDF
Go with the Flow-v2
PDF
DDoS-bdNOG
PDF
IPV6 Hands on Lab
PDF
Alphorm.com Formation Cisco CCNA v3 : mise à jour
PPTX
US AUTOMOTIVE AFTERMARKET
PPT
2014.04.10 - Cloud privé powered by IBM - Aspaway - Patrice Lagorsse et Loic ...
BdNOG 3: A closer look at IPv4 transfers
Go with the Flow-v2
DDoS-bdNOG
IPV6 Hands on Lab
Alphorm.com Formation Cisco CCNA v3 : mise à jour
US AUTOMOTIVE AFTERMARKET
2014.04.10 - Cloud privé powered by IBM - Aspaway - Patrice Lagorsse et Loic ...
Ad

Similar to Monitoring Dual Stack IPv4/IPv6 Networks (20)

PPTX
Hunting for APT in network logs workshop presentation
PPTX
Hyperledger Besu 빨리 따라하기 (Private Networks)
PDF
注意看,這些Windows的Potatoes太狠了! 解析5種基於MS-RPCE的攻擊手法.pdf
PPT
snort.ppt
DOC
Juniper防火墙case信息收集表
PPTX
Incident response: Advanced Network Forensics
PPTX
Splunk Dynamic lookup
PPT
Snmp
PDF
Pentesting111111 Cheat Sheet_OSCP_2023.pdf
PDF
Building a Scalable Real-Time Fleet Management IoT Data Tracker with Kafka St...
PPTX
Multi-Layer DDoS Mitigation Strategies
PPTX
Docker summit : Docker Networking Control-plane & Data-Plane
PPTX
Docker Networking: Control plane and Data plane
PDF
Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE
KEY
Building A Sensor Network Controller
PPTX
Harmonia open iris_basic_v0.1
PPTX
DCUS17 : Docker networking deep dive
PPTX
Training open stack networking -neutron
PPTX
Threat hunting on the wire
PPTX
Seamless migration from nova network to neutron in e bay production
Hunting for APT in network logs workshop presentation
Hyperledger Besu 빨리 따라하기 (Private Networks)
注意看,這些Windows的Potatoes太狠了! 解析5種基於MS-RPCE的攻擊手法.pdf
snort.ppt
Juniper防火墙case信息收集表
Incident response: Advanced Network Forensics
Splunk Dynamic lookup
Snmp
Pentesting111111 Cheat Sheet_OSCP_2023.pdf
Building a Scalable Real-Time Fleet Management IoT Data Tracker with Kafka St...
Multi-Layer DDoS Mitigation Strategies
Docker summit : Docker Networking Control-plane & Data-Plane
Docker Networking: Control plane and Data plane
Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE
Building A Sensor Network Controller
Harmonia open iris_basic_v0.1
DCUS17 : Docker networking deep dive
Training open stack networking -neutron
Threat hunting on the wire
Seamless migration from nova network to neutron in e bay production

Recently uploaded (20)

PPT
Ethics in Information System - Management Information System
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PDF
Introduction to the IoT system, how the IoT system works
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PPTX
Mathew Digital SEO Checklist Guidlines 2025
PDF
Paper PDF World Game (s) Great Redesign.pdf
PPT
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
PDF
WebRTC in SignalWire - troubleshooting media negotiation
PDF
Unit-1 introduction to cyber security discuss about how to secure a system
PDF
Decoding a Decade: 10 Years of Applied CTI Discipline
PPTX
artificial intelligence overview of it and more
PDF
Slides PDF The World Game (s) Eco Economic Epochs.pdf
PPTX
Internet___Basics___Styled_ presentation
PPTX
innovation process that make everything different.pptx
PPTX
Funds Management Learning Material for Beg
PPTX
presentation_pfe-universite-molay-seltan.pptx
Ethics in Information System - Management Information System
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
Module 1 - Cyber Law and Ethics 101.pptx
Introduction to the IoT system, how the IoT system works
INTERNET------BASICS-------UPDATED PPT PRESENTATION
Introuction about ICD -10 and ICD-11 PPT.pptx
SASE Traffic Flow - ZTNA Connector-1.pdf
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
Mathew Digital SEO Checklist Guidlines 2025
Paper PDF World Game (s) Great Redesign.pdf
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
WebRTC in SignalWire - troubleshooting media negotiation
Unit-1 introduction to cyber security discuss about how to secure a system
Decoding a Decade: 10 Years of Applied CTI Discipline
artificial intelligence overview of it and more
Slides PDF The World Game (s) Eco Economic Epochs.pdf
Internet___Basics___Styled_ presentation
innovation process that make everything different.pptx
Funds Management Learning Material for Beg
presentation_pfe-universite-molay-seltan.pptx

Monitoring Dual Stack IPv4/IPv6 Networks

  • 2. Cisco Router Configuration Setting up SNMPv3 authentication: snmp-server group zabbix v3 auth snmp-server user zabbix zabbix v3 auth md5 mypassphrase
  • 3. Testing with Net-SNMP Configure authentication in a host specific configuration file (~/.snmp/hosts/hqr.conf): defVersion 3 defSecurityLevel authNoPriv defSecurityName zabbix defAuthType MD5 defAuthPassphrase mypassphrase
  • 4. Testing with Net-SNMP Get the system name: $ snmpget hqr sysName.0 SNMPv2-MIB::sysName.0 = STRING: HQR
  • 5. Internet Protocol MIB (IP-MIB) ipSystemStatsHCOutForwDatagrams OBJECT-TYPE SYNTAX Counter64 MAX-ACCESS read-only STATUS current DESCRIPTION "The number of datagrams for which this entity was not their final IP destination and for which it was successful in finding a path to their final destination." http://tools.ietf.org/html/rfc4293#page-34
  • 6. Internet Protocol MIB (IP-MIB) Get the number of forwarded datagrams: $ snmpget hqr ipSystemStatsHCOutForwDatagrams.ipv4 IP-MIB::ipSystemStatsHCOutForwDatagrams.ipv4 = Counter64: 19993419 $ snmpget hqr ipSystemStatsHCOutForwDatagrams.ipv6 IP-MIB::ipSystemStatsHCOutForwDatagrams.ipv6 = Counter64: 285
  • 7. Interfaces MIB (IF-MIB) Walk the interface table: $ snmpwalk hqr ifDescr IF-MIB::ifDescr.1 = STRING: Embedded-Service-Engine0/0 IF-MIB::ifDescr.2 = STRING: GigabitEthernet0/0 IF-MIB::ifDescr.3 = STRING: GigabitEthernet0/1 IF-MIB::ifDescr.4 = STRING: Serial0/0/0 IF-MIB::ifDescr.5 = STRING: Null0 http://tools.ietf.org/html/rfc2863#page-30
  • 8. Internet Protocol MIB (IP-MIB) ipIfStatsHCInForwDatagrams OBJECT-TYPE SYNTAX Counter64 MAX-ACCESS read-only STATUS current DESCRIPTION "The number of input datagrams for which this entity was not their final IP destination and for which this entity attempted to find a route to forward them to that final destination.” http://tools.ietf.org/html/rfc4293#page-47
  • 9. Internet Protocol MIB (IP-MIB) Query received IP datagrams on interface GigabitEthernet0/0 (index 2): $ snmpget hqr ipIfStatsHCInReceives.ipv4.2 IP-MIB::ipIfStatsHCInReceives.ipv4.2 = Counter64: 106157 $ snmpget hqr ipIfStatsHCInReceives.ipv6.2 IP-MIB::ipIfStatsHCInReceives.ipv6.2 = Counter64: 1040
  • 10. Network Monitoring with Zabbix ✓ Open Source ✓ Graphical User Interface ✓ SNMP, IPMI, JMX Agents ✓ Notification Triggers ✓ Historical Database ✓ Graphing
  • 11. Zabbix: Latest Data View ✓ Items gather data from a host for a particular metric ✓ Each item has it’s own schedule for collection (i.e. every 60s, 24h) ✓ Quick Graphing
  • 12. Zabbix: Configure SNMP Item ✓ Net-SNMP Integration ✓ Graphical Configuration ✓ Flexible Intervals ✓ Store As-Is or Delta ✓ History Storage Period ✓ Trend Storage Period ✓ Templates & Cloning
  • 14. IP Datagrams Forwarded (Hour) Average of IP datagrams forwarded through router: IPv4: 80% IPv6: 20%
  • 15. IP Datagrams Received (Hour) Average of IP datagrams received by router: IPv4: 66% IPv6: 34%
  • 16. IP Bytes Received (Hour) Average of bytes received in IP datagrams: IPv4: 49% IPv6: 51%