User Guide
Version 8.0
Legal Notice
The information contained within this document is subject to change without notice. Arbor Networks, Inc. makes no
warranty of any kind with regard to this material, including, but not limited to, the implied warranties of merchantability
and fitness for a particular purpose. Arbor Networks, Inc. shall not be liable for errors contained herein or for any
direct or indirect, incidental, special, or consequential damages in connection with the furnishings, performance, or
use of this material.
Copyright © 1999-2016 Arbor Networks, Inc. All rights reserved. Arbor Networks, the Arbor Networks logo,
ArbOS and ATLAS are all trademarks of Arbor Networks, Inc. All other brands may be the trademarks of their
respective owners.
Document Number: SP_TMS-UG-80-2016/05
25 May, 2016
Contents
Preface
How to Use SP and TMS Documentation
Conventions Used in this Guide
Contacting the Arbor Technical Assistance Center
14
15
17
Part I: Introduction to Arbor Networks SP and TMS
Chapter 1: Introduction to Using Arbor Networks SP and TMS
Using SP to Analyze Your Network Traffic
Protecting Network Infrastructure
Using SP and TMS to Detect and Mitigate Attacks
About the SP User Interfaces
Logging In and Out
Navigating the SP Web UI
Using Selection Wizards
Using the FCAP Wizard
About the About Page
Recommended Initial Setup
Chapter 2: Introduction to SP Appliances and TMS Models
Introduction to SP and TMS Appliances
About the SP Appliance User Interface Role
Deployment Scenarios for the SP Appliance User Interface Role
About the SP Appliance Traffic and Routing Analysis Role
About the Flow Sensor Appliance
About the SP Appliance Data Storage Role
Deployment Scenarios for the SP Appliance Data Storage Role
TMS Appliance Deployment Scenarios
TMS-CGSE Deployment Scenarios
TMS-ISA Deployment Scenarios
Chapter 3: Basic Concepts
Introduction to Reference Architecture
SP on the Peering Edge
SP Deployment Guidelines
Binning and Counting Traffic
How SP Counts Traffic
Understanding Network Classification Concepts
TMS Deployment Architecture
Deploying a TMS Appliance in DNS Monitoring
Deploying TMS in Passive Monitoring of DNS Servers
Integrating VLANs into Your Network
Chapter 4: SP Licensing
About Hybrid Licensing
About Appliance-based Licensing
Applying Appliance-based Licenses from a License File
About TMS Volumetric Licensing
SP and TMS User Guide, Version 8.0
21
22
23
24
25
26
28
31
32
34
35
37
38
41
43
46
47
48
49
50
55
57
59
60
62
64
66
67
69
71
73
74
76
81
82
84
86
87
3
SP and TMS User Guide, Version 8.0
About Flexible Licensing
Uploading a Flexible License
About Flexible Licensing Enforcement
About Cloud-based Licensing
89
92
93
96
Part II: System Administration
Chapter 5: Configuring SP Appliances
About Configuring SP Appliances
Adding, Editing, and Deleting an SP Appliance
Configuring Appliance Settings for an SP Appliance
Configuring SNMP Settings for an SP Appliance
Configuring High Availability Settings
Configuring HTTPS Access Rules Settings for an SP Appliance
Configuring the ArborFlow Export Setting
Configuring SSL Certificates
Chapter 6: Configuring SP to Learn about Your Network
Defining Your Network and Configuring Network Boundaries
About Interface Classification
About the Auto-Configuration Rules
Configuring Interface Classification Rules
Configuring Address Space
Chapter 7: Configuring Monitored Network Devices
About the Configure Routers Page
Configuring Routers
Reassigning a Router to a Different Managing Appliance
Configuring Router SNMP Settings
Configuring Primary Router BGP Settings
Configuring Secondary Router BGP Settings
Configuring Router Flow Settings
Configuring Advanced Router Settings
Configuring Interfaces
Chapter 8: Configuring Managed Objects
About Managed Objects
Defining a POP Using a Profile Managed Object
About the Configure Managed Objects Page
Configuring Managed Objects
Configuring Match Settings for Managed Objects
Configuring Boundaries for Managed Objects
Configuring Threshold Alerting for Managed Objects
Configuring Profiled Router Detection for Managed Objects
Configuring Host Detection for Managed Objects
Configuring Profiled Network Detection for Managed Objects
Configuring Mitigation Settings for Managed Objects
Configuring Mitigation Settings for Customer Managed Objects
Configuring Mitigation Settings for Peer Managed Objects
Configuring Mitigation Settings for Profile Managed Objects
Configuring Cloud Signaling Settings for Managed Objects
Configuring Learning Mitigation Settings for Managed Objects
Configuring Managed Object Children
Configuring Managed Services Settings for Managed Objects
Configuring VPN Site Managed Objects
4
101
102
104
106
108
110
112
113
114
117
118
119
122
123
128
131
132
136
139
140
142
144
146
147
150
155
156
157
159
162
165
174
181
182
186
191
192
193
202
203
205
208
210
211
213
Proprietary and Confidential Information of Arbor Networks Inc.
About the VPN Sites Tab
216
Chapter 9: Configuring Other Network Resources
219
220
223
225
227
229
230
235
237
241
246
247
248
251
255
Configuring Custom Applications
About Services
About the Configure Services Page
Adding, Editing, and Deleting Services
Configuring Match Settings for Services
Configuring Boundaries for Services or Subscribers
Configuring Threshold Alerting Settings for Services
Configuring Profiled Router Detection for Services
Configuring Host Detection for Services
Configuring Profiled Network Detection for Services
Configuring Mitigation Settings for Services
Configuring Fingerprints
Configuring Subscriber Groups and Subscriber Group Settings
Configuring BGP Thresholds, Hijacking, and Traps
Chapter 10: Configuring Alert Notifications
Configuring Global Notification Settings for Alerts
About Notification Groups
Configuring Notification Groups
Configuring SP System Monitoring Alerts
About Alert Notification Rules
Configuring Alert Notification Rules
Understanding XML for Alert Notifications
Chapter 11: Configuring User Interface Settings
Configuring Global UI Settings
Configuring Ticketing
Configuring Audio Alerting
Customizing the Login Page
Configuring Menus
Configuring Name Mappings
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
About the User Accounts Page
Configuring User Accounts
Editing Your User Account
About the User Account Login Records Page
About Account Groups
Configuring Account Groups
About Capability Groups
Configuring Capability Groups
Configuring Login Options
Configuring Accounting
Configuring Authentication
Chapter 13: Configuring ATLAS Services
Active Threat Level Analysis System (ATLAS)
Configuring ATLAS Intelligence Feed (AIF)
About ATLAS Intelligence Feed (AIF) DDoS Regular Expressions (Used by TMS)
Enabling and Disabling BGP Routeview Reporting
ATLAS Visibility
Proprietary and Confidential Information of Arbor Networks Inc.
259
260
261
263
266
268
270
271
277
278
280
281
282
283
285
287
288
291
295
297
299
302
306
307
310
312
314
317
318
319
324
325
326
5
SP and TMS User Guide, Version 8.0
Chapter 14: Monitoring the System
About the My SP Dashboard
About Monitoring Cloud Signaling Status
Monitoring Your Deployment
About the Appliance Status Page
Viewing General Appliance Statistics
Viewing Web UI Statistics
Viewing Managed Services UI Statistics
Viewing TMS Appliance Statistics
Monitoring Your Arbor Networks Appliances
About the Summary Tab on the Appliance Monitoring Page
About the Per Appliance Metrics Tab on the Appliance Monitoring Page
About the Metric Comparison Tab on the Appliance Monitoring Page
Viewing ArborFlow Statistics
Monitoring Account Status
Monitoring Routers
Monitoring Interfaces
Monitoring Interface Configuration
Monitoring Interface Configuration History
Monitoring the Syslog
Viewing Flow Tuning Data
Monitoring SOAP Activity
Monitoring the UI Status
Chapter 15: System Maintenance
Maintaining SP Configurations
Managing System Backups
Deleting Alerts
Deleting Traffic Reports
Enabling Software Updates
Configuring Network Services
329
330
332
335
342
344
354
356
357
360
361
366
374
383
385
386
391
393
394
396
397
398
399
401
402
406
411
413
414
415
Part III: DDoS Detection and Mitigation
Chapter 16: About DoS Detection
Configuring Global Detection Settings
About Detection Settings for Managed Objects and Services
About Host Detection
About Shared Host Detection Settings
About the Shared Host Detection Settings Page
Configuring Shared Host Detection Settings
About Profiled Router Detection
About Profiled Network Detection
Chapter 17: About Alerts
How Alerts Work
About Alert Classes and Alert Types
About the Alert Listing Pages
About the Security Status Page
About the Activity Report
About the DoS Alert Pages
About the Fingerprint Threshold Alert Pages
About the Service Threshold Alert Pages
About the Cloud Signaling Request Alert Pages
About the BGP Instability Alert Pages
6
421
422
427
429
436
438
442
447
451
455
456
458
465
471
472
473
475
477
480
483
Proprietary and Confidential Information of Arbor Networks Inc.
Adding Annotations to an Alert
About Alert Classification
Chapter 18: About DoS Alerts
Introduction to DoS Alerts
About the Summary Tab on a DoS Alert Page
About the Traffic Details Tab on a DoS Alert Page
About the Routers Tab on a DoS Alert Page
About the Annotations Tab on a DoS Alert Page
About the Top Traffic Patterns Table
About the Alert Scratchpad
Performing a Whois Lookup for an IP Address on a DoS Alert Page
Recognizing a Potential DoS Attack
Chapter 19: Configuring TMS Models
About Configuring TMS Models
Adding, Editing, and Deleting a TMS Model
Configuring Appliance Settings for a TMS Model
Configuring SNMP Settings for a TMS Appliance or TMS-VSM
Configuring Deployment Settings for a TMS Appliance, TMS-ISA, or TMS-VSM
Configuring ArborFlow Settings for a TMS Appliance
Configuring Patch Panel Settings for a TMS Appliance or TMS-VSM
Configuring IP Forwarding Settings for a TMS Appliance
Configuring Subinterfaces for a TMS Appliance or TMS-VSM
Configuring Port Settings for a TMS Appliance or TMS-VSM
Configuring GRE Settings for a TMS Appliance or TMS-VSM
Configuring Blacklist Offloading Settings for a TMS-VSM
Configuring Advanced Settings for a TMS Model
Configuring TMS-CGSE Clusters
Configuring TMS-ISA Clusters
Configuring Diversion Settings for a TMS Cluster
Configuring TMS Groups
Chapter 20: Introduction to TMS Mitigations
About TMS Mitigations
About TMS Mitigation Countermeasures
About Blacklisting in TMS Mitigation Countermeasures
About Blacklist Offloading for TMS Models
About TMS Mitigation Templates
About the TMS Mitigation Status Page
Starting and Stopping TMS Mitigations
Configuring Global TMS Mitigation Settings
About Auto-Mitigation
Mitigating Customer Attacks in the Cloud
About Sample Packets
Using the Long-Term Statistics Page
Editing and Monitoring TMS VLANs
Chapter 21: Configuring TMS Mitigations
Configuring and Deleting TMS Mitigation Templates
Configuring and Deleting TMS Mitigations
Initiating a Mitigation from a DoS Alert
Configuring Basic Identification Settings for TMS Mitigations and Templates
Configuring Protect Settings for TMS Mitigations and Templates
Configuring TMS Appliances Settings for TMS Mitigations and Templates
Configuring Advanced Settings for TMS Mitigations and Templates
Proprietary and Confidential Information of Arbor Networks Inc.
486
488
491
492
498
507
510
513
514
517
521
522
525
526
528
531
533
535
540
542
549
550
552
554
557
560
561
563
565
567
573
574
575
580
584
587
589
596
597
600
604
608
611
612
613
614
618
622
623
626
630
632
7
SP and TMS User Guide, Version 8.0
About Filter Lists for TMS Mitigations and Templates
Configuring Filter Lists for TMS Mitigations and Templates
Selecting Learning Mitigation Datasets
Chapter 22: Configuring Per-Packet Countermeasures
Configuring the Black/White Lists Countermeasure
Configuring the DNS Authentication Countermeasure
Configuring the IP Address Filter Lists Countermeasure
Configuring the Packet Header Filtering Countermeasure
Configuring the IP Location Filter Lists Countermeasure
Configuring the IP Location Policing Countermeasure
Configuring the Payload Regular Expression Countermeasure
Configuring the Per Connection Flood Protection Countermeasure
Configuring the Protocol Baselines Countermeasure
Configuring the Shaping Countermeasure
Configuring the TCP SYN Authentication Countermeasure
Configuring the Zombie Detection Countermeasure
Chapter 23: Configuring Event-Driven Countermeasures
Configuring the AIF and HTTP/URL Regular Expression Countermeasure
Configuring the DNS Malformed Countermeasure
Configuring the DNS NXDomain Rate Limiting Countermeasure
Configuring the DNS Rate Limiting Countermeasure
Configuring the DNS Regular Expression Countermeasure
Configuring the HTTP Malformed Countermeasure
Configuring the HTTP Rate Limiting Countermeasure
Configuring the SIP Malformed Countermeasure
Configuring the SIP Request Limiting Countermeasure
Configuring the SSL Negotiation Countermeasure
Configuring the TCP Connection Limiting Countermeasure
Configuring the TCP Connection Reset Countermeasure
Chapter 24: Other Ways to Mitigate Attacks
Mitigating Attacks Using SP
About the All Mitigations Page
Searching for Mitigations
Adding Annotations to a Mitigation
Mitigating Using ACL Filters
Mitigating Using Flow Specification: A Use Case
Mitigating Using Flow Specification ACLs
About the Flow Specification Mitigation Status Page
Mitigating Using Blackhole Routing
About the Blackhole Mitigation Status Page
Configuring Blackhole Nexthop Template Values
Configuring BGP Community Groups
635
637
641
643
644
648
651
653
656
658
661
664
667
669
671
676
681
682
688
690
692
696
703
706
709
711
713
717
721
725
726
727
728
731
733
735
737
742
744
748
749
750
Part IV: Traffic Reporting and Analysis
Chapter 25: Introduction to SP Reports
755
756
758
About Reporting in SP
About the Reports Pages
Chapter 26: Using Predefined Reports
Configuring Predefined Reports
Additional Information about Predefined Report Options
8
763
764
774
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 27: Using Report Dashboards
About Dashboards
About IPv6 Summary Dashboards
About the Network Dashboard
About the Application Dashboard
About the Customer Dashboard
About the Router Dashboard
About the Subscriber Dashboard
Chapter 28: Using Report Tools
Using the ASExplorer Tool
Using the Peering Evaluation Tool
About the Service Variation Analysis Tool
Using the ATLAS 2.0 Summary Report Tool
About the AIF Tab on the ATLAS Page
About the Peering Traffic Exchange Tools
About the Traffic Engineering Tools
About the Transit Research Tools
About the IPv6 Transition Report Tool
Chapter 29: Using the Explore Pages
About the Explore Pages
Using the Explore Traffic Page
Using the Explore Forensics Page
Using the Explore Forensics IPv6 Page
Using the Explore BGP Routing Table Page
Using the Explore BGP Updates Page
Using the Explore BGP Routing Instability Page
Using the Explore BGP Routing Differences Page
Using the Explore BGP VPN Routing Table Page
Using the Explore BGP VPN Updates Page
Using the Explore Routeviews BGP Routing Table Page
Using the Explore Routeviews BGP Updates Page
Using the Explore Packets Page
Chapter 30: Using Custom Reports
About the Configure Reports Page
Configuring Wizard Reports
About Classic XML Reports
Configuring Classic XML Reports
Configuring the PDF Activity Report
Using DoS XML Reports
Chapter 31: Analyzing Network Peering
Peering Evaluation: Am I Well Connected?
Determining Peering Effectiveness
Meeting Peering Commitment Requirements
Analyzing Peering Stability
Using Reports to Balance Traffic Loads
Chapter 32: Managing the Capacity of Your Network
Locating Busy Interfaces on Your Network
Using Interface Reports to Manage the Capacity of your Network
Alleviating Congestion in Your Network
Proprietary and Confidential Information of Arbor Networks Inc.
791
792
794
795
797
798
800
804
807
808
810
812
814
816
818
820
822
824
827
828
831
836
838
840
843
847
850
853
855
858
860
863
865
866
869
876
878
884
885
887
888
889
891
892
893
897
898
900
902
9
SP and TMS User Guide, Version 8.0
Part V: Managed Services
Chapter 33: SP Managed Services – A Managed DDoS Solution
Security Threats and Trends
Managed Security Service Provider Offerings
Understanding the Managed DDoS Solution
The Managed DDoS Solution Process
Managed DDoS Solution Architectures
Deployment Considerations in the Managed DDoS Solution
Chapter 34: Deploying SP and TMS as a Managed Service
Implementing a Managed Services Deployment
Configuring Managed Services Settings
About Managed Services User Accounts and Account Groups
Enabling Customers to View SP Data in the Web Services API
907
908
909
910
911
912
913
917
918
924
925
926
Appendixes
Appendix A: Using the FCAP Expression Language
Using FCAP Expressions
FCAP Filter Languages
Example FCAP Expressions
Description of FCAP Expression Language
Appendix B: XML Specifications
Formatting a Report for External Query Interfaces
About Validating XML Files
Appendix C: Auto-Configuration Heuristics
About Auto-Configuration Heuristics
How Auto-Configuration Works
Appendix D: Using Regular Expressions
SP Regular Expressions
TMS Regular Expressions
Payload Regular Expressions
HTTP Header Regular Expressions
DNS Regular Expressions
AS Regular Expressions
Appendix E: XML for Traffic Reports
Understanding the XML Report Format and Elements
Understanding the HTML, Output, and Object Elements in XML Reports
Understanding XML for Controls
Understanding the Query Element in XML Reports
Understanding XML for Graphs
Understanding XML for Charts
Appendix F: Understanding Common Traffic Identifiers
About TCP and UDP Ports and Services
About ICMP Types, Codes, and Messages
About Protocol Numbers
About TCP Flags
About Cisco DSCP Values
About Fragmentation Bitmask Menus
Identifiers for BGP Communities
10
929
930
931
934
937
945
946
947
949
950
951
953
954
955
960
962
965
966
969
970
973
975
976
980
982
985
986
989
991
992
993
994
995
Proprietary and Confidential Information of Arbor Networks Inc.
Glossary
997
Index
1007
Software License Agreement
1023
Proprietary and Confidential Information of Arbor Networks Inc.
11
SP and TMS User Guide, Version 8.0
12
Proprietary and Confidential Information of Arbor Networks Inc.
Preface
Introduction
The Arbor Networks® SP and TMS User Guide explains how to configure and use SP
appliances and software.
Audience
This information is intended for network security system administrators (or network operators)
who are responsible for configuring and managing SP on their networks. Administrators should
have fundamental knowledge of their network security policies and network configuration.
In this section
This section contains the following topics:
How to Use SP and TMS Documentation
14
Conventions Used in this Guide
15
Contacting the Arbor Technical Assistance Center
17
SP and TMS User Guide, Version 8.0
13
SP and TMS User Guide, Version 8.0
How to Use SP and TMS Documentation
Using this guide
The SP and TMS User Guide provides instructions and information about using the SP Web
user interface (UI). The instructions assume that you have completed the installation steps
outlined in the Quick Start Cards.
Additional SP and TMS documentation
See the following documentation for more information about SP and TMS appliances and this
version of the software:
Additional documentation
Available Documentation
Contents
SP and TMS Quick Start Cards
Instructions and requirements for the initial installation
and configuration of SP and TMS appliances.
SP and TMS Advanced
Configuration Guide
Instructions and information about configuring
advanced settings in SP and TMS, including those that
can only be configured using the command line
interface (CLI).
SP and TMS Help
Online help topics from the User Guide and Advanced
Configuration Guide. The Help is context-sensitive to
the SP Web UI page from which it is accessed.
SP Managed Services Customer
Guide
Instructions and information for the managed services
customers who use the SP 8.0 Web user interface.
SP API Guide
Instructions for remotely accessing SP using the REST,
SOAP, and Arbor Web Services APIs.
REST API Documentation
Online information about the REST API endpoints.
(information)
14
Information about a report or a particular feature of the
SP Web user interface (UI). This information appears
when you hover the mouse pointer over the icon.
Proprietary and Confidential Information of Arbor Networks Inc.
Preface
Conventions Used in this Guide
Introduction
This guide uses typographic conventions to make the information in procedures, commands,
and expressions easier to recognize.
Conventions for procedures
The following conventions represent the elements that you select, press, and type as you follow
procedures.
Typographic conventions for procedures
Convention
Description
Examples
Italics
A label that identifies an area
on the graphical user interface.
On the Summary page, view the
Active Alerts section.
Bold
An element on the graphical
user interface that you click or
interact with.
Type the computer’s DGGUHVV in the
IP Address box.
Select the Print check box, and
then click OK.
SMALL CAPS
A key on the keyboard.
Press ENTER.
To interrupt long outputs, press CTRL
+ C.
0RQRVSDFHG
A file name, folder name, or
path name.
Also represents computer
output.
Navigate to the
&?8VHUV?'HIDXOW?)DYRULWHV
folder.
Expand the $GGUHVVHV folder, and
then open the UHDGPHW[W file.
Monospaced
bold
Information that you must type
exactly as shown.
Type https:// followed by the ,3
DGGUHVV.
0RQRVSDFHG
LWDOLFV
A file name, folder name, path
name, or other information that
you must supply.
Type the server's ,3 DGGUHVV or
KRVWQDPH.
>
A navigation path or sequence
of commands.
Select Mitigation > Threat
Management.
Navigate to the Alerts Ongoing page
(Alerts > Ongoing).
Proprietary and Confidential Information of Arbor Networks Inc.
15
SP and TMS User Guide, Version 8.0
Conventions for commands and expressions
The following conventions show the syntax of commands and expressions. Do not type the
brackets, braces, or vertical bar in commands or expressions.
Typographic conventions for commands and expressions
16
Convention
Description
Monospaced bold
Information that you must type exactly as shown.
0RQRVSDFHG
LWDOLFV
A variable for which you must supply a value.
{ } (braces)
A set of choices for options or variables, one of which is required. For
example: {RSWLRQ | RSWLRQ}.
[ ] (square brackets)
A set of choices for options or variables, any of which is optional. For
example: [YDULDEOH | YDULDEOH].
| (vertical bar)
Separates the mutually exclusive options or variables.
Proprietary and Confidential Information of Arbor Networks Inc.
Preface
Contacting the Arbor Technical Assistance Center
Introduction
The Arbor Technical Assistance Center is your primary point of contact with Arbor Networks®
for all service and technical assistance issues.
Contact methods
You can use the following methods to contact the Arbor Technical Assistance Center:
How to contact the Arbor Technical Assistance Center
Method
Contact details
telephone
US toll free +1 877 272 6721
Worldwide +1 781 362 4301
Web
https://support.arbor.net/
Submitting documentation comments
If you have comments about the documentation, you can forward them to the Arbor Technical
Assistance Center. Please include the following information:
n Title of the guide
n
Document number (listed on the reverse side of the title page)
n
Page number
Example
SP_TMS-UG-80-2016/05
SP and TMS User Guide
Page 9
Proprietary and Confidential Information of Arbor Networks Inc.
17
SP and TMS User Guide, Version 8.0
18
Proprietary and Confidential Information of Arbor Networks Inc.
Part I:
Introduction to Arbor
Networks SP and TMS
SP and TMS User Guide, Version 8.0
20
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1:
Introduction to Using Arbor Networks SP
and TMS
Introduction
This section describes the basics of using SP and TMS to monitor and protect your network.
In this section
This section contains the following topics:
Using SP to Analyze Your Network Traffic
22
Protecting Network Infrastructure
23
Using SP and TMS to Detect and Mitigate Attacks
24
About the SP User Interfaces
25
Logging In and Out
26
Navigating the SP Web UI
28
Using Selection Wizards
31
Using the FCAP Wizard
32
About the About Page
34
Recommended Initial Setup
35
SP and TMS User Guide, Version 8.0
21
SP and TMS User Guide, Version 8.0
Using SP to Analyze Your Network Traffic
Introduction
SP is a network-wide infrastructure security platform that measures and monitors traffic. You
can use it to scale your network and customer base. SP uses both flow and deep packet
inspection (DPI) technologies and provides macro- and micro-level visibility. This visibility
allows you to identify threats and improve the performance of your network.
SP functions
SP analyzes network traffic by performing the following functions:
Network traffic analysis functionality
Function
Description
Infrastructure
Security
Detects and mitigates network-wide anomalies and security events.
Traffic and Routing
Models traffic from across the entire network. You can make informed
business decisions about routing, transit, partners, customers, and
quality of service.
Managed Services
Provide the following:
n
n
n
Services Monitoring
22
distributed denial of service (DDoS) attack detection and
mitigation
traffic reports
MPLS VPN visibility and mitigation
Monitors and reports on network services, including VoIP and HTTP.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1: Introduction to Using Arbor Networks SP and TMS
Protecting Network Infrastructure
Introduction
Infrastructure security teams can use SP to prepare for and address anomalies and threats to
their networks.
Protecting your network
Arbor, in conjunction with Cisco Systems, developed a process to assist infrastructure security
teams. The following table describes the phases of the process:
Network protection phases
Phase
Description
Preparation
You need the right team and tools to learn what “normal” traffic is on
your network. SP offers a means to gain pervasive network visibility
and recognize normal traffic patterns.
Identification
Once you know which traffic is “normal,” you must identify
abnormalities. SP models network behavior, creates a baseline, and
alerts you to network anomalies.
Classification
SP helps you to determine whether an anomaly is benign or a threat.
SP identifies DDoS and zero-day threats and determines their type,
severity, and size.
Trace Back
SP allows you to perform real-time historical analysis of all network
activity.
Reaction
SP allows you to initiate the appropriate mitigation process to stop a
threat.
Post Mortem
SP provides detailed mitigation reports that explain what happened
and how an attack was alleviated. You can leverage this knowledge
when you mitigate future attacks.
Protecting peering points
SP provides specific tools and analysis for network peering. The system can trace attack
sources to off-net locations through specific peering points that access your network. If the
attacks or events are too large, they threaten the ability to transit other traffic over the peering
link and can bring the interface or the router down. To mitigate and protect peering points, you
must reduce the traffic and stop the attack in the upstream network.
Proprietary and Confidential Information of Arbor Networks Inc.
23
SP and TMS User Guide, Version 8.0
Using SP and TMS to Detect and Mitigate Attacks
Introduction
When an attacker targets your network, your network can suffer multiple problems, including
the following:
n denial of service (DoS) attacks
n
collateral damage to network infrastructure
This topic describes how SP can help you to identify malicious traffic and network anomalies
so that you can defend your network.
How SP detects attacks
SP uses flow records, SNMP, and BGP data to build network-wide relational models of traffic.
These models create both threshold- and behavioral-based traffic baselines. SP uses the
learned and configured traffic baselines to create alerts when the system observes abnormal
traffic. Using this information, you can create the appropriate mitigation to thwart an attack.
Mitigation options
The following are several mitigation options that you can use against attacks:
Intelligent mitigation using SP Threat Management System (TMS) appliances
n
For more information about TMS appliances, see “Purpose of the TMS appliance” on
page 40.
n
Access Control List (ACL) filter generation
n
Blackhole routing using BGP
n
Juniper Flow Specification
See “Mitigating Attacks Using SP” on page 726and “About TMS Mitigations” on page 574.
For more information
Arbor’s white papers discuss detection and attack mitigation in depth. You can access white
papers from the Arbor Networks Web site under Resources:
http://www.arbornetworks.com
24
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1: Introduction to Using Arbor Networks SP and TMS
About the SP User Interfaces
Introduction
You can view data and configure settings using the Web user interface (UI) and the command
line interface (CLI).
Using the Web UI
The Web UI provides a Web view of SP. After you initially configure the leader and appliances
using the CLI, you can use the Web UI to configure system settings, view reports, and detect
and mitigate attacks.
For more information about the Web UI, see “Navigating the SP Web UI” on page 28.
Using the CLI
In addition to the initial configuration, there are some functions that you can only configure
using the CLI.
For more information about the CLI, see "Using the Command Line Interface (CLI)" in the
SP and TMS Advanced Configuration Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
25
SP and TMS User Guide, Version 8.0
Logging In and Out
Introduction
Follow the procedures in this topic to log in to and out of SP.
Note: You can use the leader appliance and any non-leader appliances that have the user
interface role to access the SP Web UI for your deployment.
Prerequisites
Before you can log in and access the Web UI for your SP appliance, you must complete all of
the initial configuration procedures listed in the SP Quick Start Cards and TMS Quick Start
Cards. You should also work through the topics in the “Configuring Your SP Deployment" and
"Securing Your Appliances" chapters in the SP and TMS Advanced Configuration Guide.
Initial login steps
To log in, follow the steps below, based on your user group:
Instructions for initial login
User group
Steps
administrator
1. Log in using the administrator name and password that Arbor
gave you.
2. Change your password for security purposes.
See “Editing Your User Account” on page 295.
3. Create user accounts.
user
1. Log in using the user name and password that your administrator
gave you.
2. Change your password for security purposes.
See “Editing Your User Account” on page 295.
Accepting the certificate
The first time you access SP, you must accept the certificate to complete the secure session
with your SP deployment. The certificate is based on Arbor Networks’ Certificate Authority
(CA).
For more information, see your Web browser’s instructions for accepting certificates.
Logging in to SP
Important: You must use a secure connection to access SP.
To log in to SP:
1. Open your Web browser.
2. Type https:// followed by the ,3 DGGUHVV of your leader appliance.
3. If applicable, select the appropriate option for accepting the site’s certificate, and then
click OK.
4. Type your XVHU QDPH and SDVVZRUG.
5. Click Login.
26
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1: Introduction to Using Arbor Networks SP and TMS
Logging out of SP
To log out of SP:
In the upper-right corner of any page in the Web UI, click Log Out.
n
Proprietary and Confidential Information of Arbor Networks Inc.
27
SP and TMS User Guide, Version 8.0
Navigating the SP Web UI
Introduction
You can navigate the SP Web UI menus and pages using a variety of navigation controls.
About the Web UI menu bar
The Web UI menu bar displays the current date and time, indicates which menu is active, and
allows you to navigate the Web UI menus and pages.
The Web UI is divided into the following menus:
Web UI menu descriptions
Menu
Description
System
Displays summary information, the state of SP appliances and other
network devices, and the system log for troubleshooting information.
Alerts
Allows you to view the alerts detected by SP.
Explore
Allows you to search and filter specific traffic data and routing table data
and view sample packets.
Reports
Allows you to view predefined reports about traffic data from different
perspectives.
Mitigation
Allows you to view and configure mitigations in SP.
Administration
Allows you to configure and maintain the SP system. It also allows you to
configure and view custom reports.
You can hover the mouse pointer over a menu item to view that item’s submenus.
Note: The menus that are available depend on a user’s account group. See “Configuring
Account Groups” on page 302.
Customizing menus
You can customize the SP Web UI so that the only information displayed is applicable to a
user’s role. See “Configuring Menus” on page 283.
About the Arbor Smart Bar
The Arbor Smart Bar is a collection of icons that can appear to the left of the Help button. The
number of icons that appear depends on the page that you are on.
28
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1: Introduction to Using Arbor Networks SP and TMS
The following icons can appear on the Arbor Smart Bar:
Arbor Smart Bar icon descriptions
Icon
Description
Hover over this icon to display the download options. The download
options that appear vary depending on the page that you are on and can
include the following:
n
PDF - Click to download the page in PDF format.
n
XML- Click to download the page in XML format.
n
CSV - Click to download a page in CSV format. The download
n
can be a CSV text file or CSV zip archive file. When the download is
a zip archive file, “zip archive” is appended to CSV.
Excel-XML - Click to download a page in Excel-XML format.
The
icon appears only if there are multiple options for downloading a
page.
Click to download a page in PDF format.
This icon appears only when the PDF format is the only download option
for a page.
Click to download and email a page as a PDF.
Sorting data tables
You can sort most tables by certain columns. The system displays column headings as links
(underlined text) to enable table sorting by column. You can recognize the way in which a
column is sorted by the up or down arrow that appears next to the column header. SP sorts
columns by default in the Web UI as follows:
n Columns that contain alphabetical lists are initially sorted in alphabetical order, from A-Z.
Click an alphabetical column header to re-sort the table by that column in reverse order (ZA).
n
Columns that contain numerical lists are initially sorted in ascending order. Click a
numerical column header to re-sort the table by that specific column in reverse (descending)
order.
Note: By default, the Importance column on alert pages is sorted first by the severity level
(high, medium, or low) and then by the maximum severity percent value.
See “About the layout of the alert listing pages” on page 465.
See "Changing How SP Sorts Alerts by Importance" in the SP and TMS Advanced
Configuration Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
29
SP and TMS User Guide, Version 8.0
Navigating multiple pages
Data is often displayed in tables that continue on multiple pages. In these cases, SP displays at
the bottom of the page the current page number in a text box followed by the total number of
pages. You can use the following links to help you navigate among multiple pages:
Page navigation descriptions
Link
Description
One arrow pointing left (<)
Displays the previous page.
Two arrows pointing left (<<)
Displays the first page.
One arrow pointing right (>)
Displays the next page.
Two arrows pointing right (>>)
Displays last page.
To navigate directly to another page, you can type its page number in the text box and then
press ENTER.
Resizing frames
To resize a frame of network objects on an administrative page so that it fits your browser
window:
n Click
(maximize) below the frame.
Frames are maximized by default in SP.
About network perspectives
On many pages, the data displayed corresponds to a different network perspective. A
perspective can be a member of one of the following categories:
n router
n
peer
n
customer
n
profile
n
VPN
n
interface
Viewing status messages
SP displays status messages in a box at the top of the Web UI page.
Select one of the following steps:
To view the status message, click
(expand) or EXPAND.
To hide the status message, click
(collapse) or COLLAPSE.
n
n
30
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1: Introduction to Using Arbor Networks SP and TMS
Using Selection Wizards
Introduction
Throughout the SP Web UI are various selection wizards that you can use to select objects. In
general, all wizards function similarly.
Using a selection wizard
To select an object using a selection wizard:
1. (Optional) From the Group list, select an option.
2. (Optional) In the Name Regexp box, type a UHJXODU H[SUHVVLRQ and then click
Filter.
See “SP Regular Expressions” on page 954.
3. Choose one of the following steps, and then click Select:
l
To add an object, select it in the Available Choices pane, and then click the down arrow
to move it to the Selected pane.
l
To delete an object, select it in the Selected pane, and then click the up arrow to move
it to the Available Choices pane.
Proprietary and Confidential Information of Arbor Networks Inc.
31
SP and TMS User Guide, Version 8.0
Using the FCAP Wizard
Introduction
The fingerprint expression language is an extended version of the standard fingerprint
expression language used by programs, such as tcpdump, to describe layer 2/3 traffic
information. The FCAP Wizard helps you to add filtering criteria to a fingerprint expression.
An Open FCAP Wizard button appears whenever you can use the wizard to configure a
fingerprint expression.
Using the FCAP wizard to configure a fingerprint expression
To configure a fingerprint expression using the FCAP Wizard:
1. Click Open FCAP Wizard.
2. Configure the settings in the FCAP Wizard window.
Note: The settings that appear in the FCAP Wizard depend on the object you are
configuring.
3. Click Add or Add to Fingerprint.
4. Click Close.
5. To add additional fingerprint expressions, repeat this procedure.
For details about the settings, see “FCAP Wizard settings” below.
FCAP Wizard settings
The FCAP Wizard contains the following settings.
Note: The settings that appear in the FCAP Wizard depend on the object you are configuring.
FCAP Wizard settings
Setting
Description
Source
addresses box
Type one or more VRXUFH &,'5 DGGUHVVHV.
Source ports box
Type one or more VRXUFH 7&3 SRUW QXPEHUV.
Destination
addresses box
Type one or more GHVWLQDWLRQ &,'5 DGGUHVVHV.
Destination ports
box
Type one or more GHVWLQDWLRQ 7&3 SRUW QXPEHUV.
Protocols box
Type one or more SURWRFRO QDPHV or SURWRFRO QXPEHUV.
Types of service
box
Type one or more W\SHV RI VHUYLFH ELWV. The ToS bits are as
follows:
n
n
n
n
32
D - Minimizes delay
T - Maximizes throughput
R - Maximizes reliability
M - Minimizes monetary cost
In some router implementations, this bit is labeled C, for cost.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1: Introduction to Using Arbor Networks SP and TMS
FCAP Wizard settings (Continued)
Setting
Description
Average packet
lengths box
Type one or more SDFNHW OHQJWKV or ranges of lengths.
TCP Flags boxes
For each type of TCP flag, select on or off.
If you do not make a selection for a TCP flag, SP ignores it.
Router list
Select a router to add to the fingerprint.
Input Interfaces
(SNMP ID) box
To select input interfaces, click Select Interfaces and then, in the
Router Interfaces window, click the name links of one or more
interfaces. The interfaces that are available depend on your selection
in the Router list.
The selected interfaces appear in the Input Interfaces (SNMP ID)
box.
Output Interfaces
(SNMP ID) box
To select output interfaces, click Select Interfaces and then, in the
Router Interfaces window, click the name links of one or more
interfaces. The interfaces that are available depend on your selection
in the Router list.
The selected interfaces appear in the Output Interfaces (SNMP ID)
box.
ICMP Type list,
ICMP Type box
Select an ICMP type from the ICMP Type list or type an ,&03 W\SH
in the ICMP Type box.
ICMP Code box
Type an ,&03 FRGH QXPEHU.
Proprietary and Confidential Information of Arbor Networks Inc.
33
SP and TMS User Guide, Version 8.0
About the About Page
Introduction
The About page displays information about the installed software and hardware, including the
version number and build numbers. It also displays the “Arbor Networks, Inc. License and Arbor
Cloud Service Agreement” and links to important information about the software.
Accessing the About page
To access the About page:
1. Log in to the SP Web UI.
2. Click About at the bottom right corner of any page.
Links on the About page
The About page includes the following links:
copyright notices and associated licensing restrictions
n
This link is near the bottom of the About page. It displays the About: Copyrights and
Software Licenses page. This page contains the copyright and software licensing
information for software that the SP software might contain.
n
support email address
The final link at the bottom of the About page displays the support email address that you
configure on the Global Settings page (Administration > User Interface > Global
Settings).
34
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 1: Introduction to Using Arbor Networks SP and TMS
Recommended Initial Setup
Introduction
Arbor recommends that you initially complete certain tasks to set up the basic components of
an SP deployment.
Task overview
You should complete the following initial tasks:
Initial setup tasks
Task
Reference
Add appliances
“About Configuring SP Appliances” on page 102
Define your network
“Defining Your Network and Configuring Network
Boundaries” on page 118
Add network devices
“Configuring Routers” on page 136
“Configuring Interfaces” on page 150
Add interface boundaries
“Viewing interface boundaries” on page 118
“About Interface Classification” on page 119
Add managed objects, services,
custom applications, and
fingerprints
“Configuring Managed Objects” on page 162
“Configuring Custom Applications” on page 220
“Adding, Editing, and Deleting Services” on page 227
“Configuring Fingerprints” on page 248
Configure Web UI preferences
“Configuring Global UI Settings” on page 278
Add user accounts
“Configuring User Accounts” on page 291
Proprietary and Confidential Information of Arbor Networks Inc.
35
SP and TMS User Guide, Version 8.0
36
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2:
Introduction to SP Appliances and TMS
Models
Introduction
This section describes SP appliances and TMS models and how to use them to monitor and
protect your network.
In this section
This section contains the following topics:
Introduction to SP and TMS Appliances
38
About the SP Appliance User Interface Role
41
Deployment Scenarios for the SP Appliance User Interface Role
43
About the SP Appliance Traffic and Routing Analysis Role
46
About the Flow Sensor Appliance
47
About the SP Appliance Data Storage Role
48
Deployment Scenarios for the SP Appliance Data Storage Role
49
TMS Appliance Deployment Scenarios
50
TMS-CGSE Deployment Scenarios
55
TMS-ISA Deployment Scenarios
57
SP and TMS User Guide, Version 8.0
37
SP and TMS User Guide, Version 8.0
Introduction to SP and TMS Appliances
Introduction
Before you configure your deployment, you should have an understanding of the different types
of Arbor Networks appliances, and how they should be used. With SP appliances, you should
also have an understanding of the different appliance types or roles.
For information about monitoring the health of your SP appliances, see “About the Appliance
Status Page” on page 342.
About SP appliance types and appliance roles
With SP appliances in appliance-based license mode, the different types of appliances have
fixed roles. With SP appliances in flexible license mode, instead of different appliance types, an
appliance is assigned a role. Prior to SP 6.0 all SP appliances were in appliance-based license
mode.
Prior to the SP 6.0 release, licensing of SP deployments was appliance-based. The SP 6.0
release introduced Flexible Licensing. With SP 6.0, you could keep all of your appliances in
appliance-based license mode or you could convert all of your appliances to flexible license
mode. SP 6.0 Patch 3 introduced hybrid licensing, which allows you to have SP appliances in
both appliance-based license mode and flexible license mode. See “About Hybrid Licensing”
on page 82.
The following table lists the SP appliance types prior to SP 6.0 and their corresponding
appliance type (appliance-based license mode) or appliance role (flexible license mode) in 6.0
or later:
Appliance types and roles
Appliance Type Prior
to 6.0
Appliance Type or Role in 6.0 or later
Collector Platform (CP)
Traffic and Routing Analysis
Portal Interface (PI)
User Interface
Business Intelligence (BI) Data Storage
Flow Sensor (FS)
Flow Sensor (appliance-based license mode only; with flexible
license mode, the Flow Sensor appliance becomes an appliance
that has the traffic and routing analysis role)
Types of appliances with hybrid licensing
With hybrid licensing, a deployment can have the following types of appliances in appliancebased license mode:
n User Interface
38
n
Traffic and Routing Analysis
n
Data Storage
n
Flow Sensor
n
Threat Management System (TMS)
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
With hybrid licensing, a deployment can have the following SP appliances in flexible license
mode:
n SP 5500
n
SP 6000
n
SP 7000
n
VM instance of SP
The purpose of an SP appliance in flexible license mode is defined by the role that it is
assigned.
Purpose of the SP appliances
The following table lists the roles of the SP appliances with a description of their purpose:
Appliance roles and purposes
Role
Purpose
Data storage
The appliance that has the data storage role serves as a home for
managed objects. See “About the SP Appliance Data Storage Role” on
page 48.
Flow Sensor
(Appliance-based license mode only) The Flow Sensor appliance
provides broader visibility to the customer and broadband network
edges and for VPN monitoring at the MPLS edge. The Flow Sensor
appliance increases the deployment scale of the Traffic and Routing
Analysis appliance when it monitors more routers and interfaces within
the SP deployment. It also improves the overall system scale to monitor
the aggregation or customer edge of the network.
When you convert an Flow Sensor appliance to flexible license mode,
the Flow Sensor appliance becomes an appliance that has the traffic
and routing analysis role. Any routers that are managed by this
appliance are assigned the Edge router type.
Traffic and routing
analysis
An appliance that has the traffic and routing analysis role provides
infrastructure security and analyzes traffic and route information.
With a small deployment (fewer than 5 appliances that have the traffic
and routing analysis role and fewer than 25 routers), the leader
function and traffic and routing analysis function can operate together
on a single appliance. When more than 5 appliances that are
monitoring routers in a deployment have the traffic and routing analysis
role, you must deploy one of the appliances to function only as a leader.
See “About the SP Appliance Traffic and Routing Analysis Role” on
page 46 and “About configuring the leader appliance” on the next
page.
User interface
An appliance that has the user interface role provides increased
performance, scalability, and availability for SP-based managed
services. This appliance can function as a leader, non-leader, and
failover appliance. An appliance that has this role increases user and
API scalability and availability of SP-based managed services. See
“About the SP Appliance User Interface Role” on page 41 and “About
configuring the leader appliance” on the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
39
SP and TMS User Guide, Version 8.0
About configuring the leader appliance
You must designate an appliance as the leader, which hosts the Web UI for your deployment,
and configure it before you configure other SP appliances. The leader appliance must be an
appliance that has the user interface role or the traffic and routing analysis role. You must
initially configure the leader and each appliance using the CLI. After you have configured the
leader and other appliances, you can edit all appliances using the Web UI.
Important: You must use the CLI to configure the IP and routing information, to configure the
leader IP address, and to start SP services on the leader appliance and the appliances that
have the traffic and routing analysis role.
For more information about the CLI, see the SP and TMS Advanced Configuration Guide and
the SP and TMS Quick Start Cards.
Purpose of the TMS appliance
The Threat Management System (TMS) appliance provides deeper visibility into the network
and acts as a traffic mitigation device, by integrating with an appliance that has the traffic and
routing analysis role. To protect the infrastructure of your network, the TMS appliance provides
the following:
n packet analysis of the application layer
40
n
enforcement of the application layer
n
alerts of attack traffic
n
reports of attack traffic
n
surgical mitigation of attack traffic
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
About the SP Appliance User Interface Role
Introduction
An appliance that has the user interface role provides fault tolerance for managed services,
increases ISP profitability, and improves customer experience.
Note: For appliances in appliance-based license mode, the different types of SP appliances
have fixed roles. For information on the relationships between appliance types and appliance
roles, see “About SP appliance types and appliance roles” on page 38.
An appliance that has the user interface role also does the following:
serves as a Web user interface (UI)
n
n
may serve as a system leader
n
may serve as a failover leader appliance for high availability
n
provides increased scalability and performance
n
provides new ISP managed services
Note: A Traffic and Routing Analysis appliance with a CP-0 license in appliance-based
license mode does not directly manage any routers, but it can be a leader and can supply a
user interface. You can convert the Traffic and Routing Analysis appliance to an appliance in
flexible license mode that has the user interface role. The appliance will then continue to
perform the same functions.
Web UI and configuration features of the user interface role
The user interface role includes the following Web UI and configuration features:
allows total parity with the leader appliance’s Web UI and access to all SP services
n
n
provides a faster Web UI appliance
n
allows for branding
n
provides simple and centralized management of user access and capabilities
n
allows you to view and/or configure status, history, account, user, AAA, DNS, and NTP
settings
n
provides interactive attack alerting, traffic visualization, and mitigation service control
High availability
In a deployment, SP automatically synchronizes in real time all important information between
the leader that has the user interface role and all the other physical or virtual appliances that
have the user interface role. This means that if the leader appliance fails over to the configured
backup leader that has the user interface role, then the backup leader is able to assume
leadership immediately with almost no data loss.
See “Configuring High Availability Settings” on page 110 and “About High Availability
Configuration” in the SP and TMS Advanced Configuration Guide.
Note: With flexible licensing on a physical appliance, you must upload the flexible license to
both the leader appliance and the backup leader appliance. You can upload the flexible license
to the leader appliance on the Deployment Status page (System > Status > Deployment
Status). To upload the flexible license to the backup leader, you must use the CLI. See
“Uploading a Flexible License” on page 92.
Proprietary and Confidential Information of Arbor Networks Inc.
41
SP and TMS User Guide, Version 8.0
Note: With cloud-based licensing, you configure the leader VM to have access to a cloud
license server and the backup leader VM automatically receives the URL configuration that it
needs to access the cloud license server. See SP and TMS Licensing Guide at
https://support.arbor.net.
Synchronization between a leader and non-leader appliances that have the user
interface role
In a deployment, the following information is automatically synchronized between a leader
appliance that has the user interface role and all other appliances that have the user interface
role:
n alert and mitigation data
n
configuration settings and configuration history
n
interface classification and interface history
n
custom menu skins
n
custom XML report templates
How an appliance that has the user interface role improves customer experience
An appliance that has the user interface role improves the user experience in the following
ways:
n allows customers to monitor all aspects of their DDoS service and initiate mitigation actions
within the boundaries prescribed by their provider
42
n
allows customers to change their own service settings without impacting other system
configurations
n
supports increased user logins and concurrent users
n
allows ISPs to monitor and report on customers’ use of services
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
Deployment Scenarios for the SP Appliance User Interface Role
Introduction
You can configure an appliance that has a user interface role as a leader, a backup leader, or a
non-leader. Different deployment scenarios for appliances that have the user interface role are
described below along with explanations about why you might use them. See “About the SP
Appliance User Interface Role” on page 41.
Note: For appliances in appliance-based license mode, the different types of SP appliances
have fixed roles. For information on the relationships between the appliance types and
appliance roles, see“About SP appliance types and appliance roles” on page 38.
Deployment scenario: single appliance that has the user interface role
In the following deployment scenario, a single appliance that has the user interface role is the
leader. In this simple deployment scenario, there is no backup leader or alternate appliance for
Web UI requests.
Note: A Traffic and Routing Analysis appliance with a CP-0 license in appliance-based
license mode does not directly manage any routers, but it can be a leader and can supply a
user interface. You can convert the Traffic and Routing Analysis appliance to an appliance in
flexible license mode that has the user interface role. The appliance will then continue to
perform the same functions.
A deployment with a single appliance that has the user interface role
Proprietary and Confidential Information of Arbor Networks Inc.
43
SP and TMS User Guide, Version 8.0
Deployment scenario: Web UI scalability
In the following deployment scenario, three appliances have the user interface role. They
collect information from all the other appliances in the deployment and are available to serve
Web UI requests. In this scenario, an appliance that has the user interface role can be a leader,
a backup leader, or a non-leader.
A Web UI scalability deployment
Deployment scenario: load balancing for Web UI scalability
In the following deployment scenario, three appliances have the user interface role and are
deployed behind a load balancer to help handle incoming sessions.
Important: In deployment scenarios like this, it is important that the load balancer maintain
per-session persistence between the Web client and the appliances that have the user
interface role.
44
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
A load balancing deployment
Deployment scenario: redundancy
In the following deployment scenario, the two appliances that have the user interface role are
designated as a leader and a backup leader. Both appliances that have the user interface role
maintain the full leader state and connectivity to the appliances that have the data storage role
or traffic and routing analysis role. When the leader fails or becomes unreachable, the backup
leader automatically becomes the leader.
Note: Because both appliances that have the user interface role maintain the full leader state,
the backup leader can be manually configured to become the leader at any time.
A redundancy deployment
Proprietary and Confidential Information of Arbor Networks Inc.
45
SP and TMS User Guide, Version 8.0
About the SP Appliance Traffic and Routing Analysis Role
Introduction
An appliance that has the traffic and routing analysis role collects, distills, and aggregates
traffic and network attack data. By using an appliance that has this role, you can control the
activities of network mitigation appliances (for example, TMS appliances). An appliance with
this role is also a flow-monitoring appliance.
Note: For appliances in appliance-based license mode, the different types of SP appliances
have fixed roles. For information on the relationships between appliance types and appliance
roles, see “About SP appliance types and appliance roles” on page 38.
If you assign the flexible license mode to a Flow Sensor appliance, the Flow Sensor appliance
becomes an appliance that has the traffic and routing analysis role. An appliance in the flexible
license mode that has the traffic and routing analysis role can manage core and edge routers.
When ArborFlow is generated
If your deployment has appliances with the data storage role, an appliance that has the traffic
and routing analysis role generates ArborFlow for matching managed objects. It then sends the
ArborFlow to the appliances that have the data storage role. ArborFlow includes identification
of application, ephemeral port parenting, and flow de-duplication (based on flow
classification). ArborFlow also includes matched managed objects, MPLS fields, and object
(router, interface) GIDs.
46
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
About the Flow Sensor Appliance
Introduction
The Flow Sensor appliance is a flow-monitoring appliance that integrates with an appliance
that has the traffic and routing analysis role. Flow Sensor appliances increase monitoring
scalability of routers and interfaces and allow you to monitor the customer edge more
effectively. Flow Sensor appliances increase the reach and effectiveness of internal DDoS
operations as well as the granularity and capability of external detection services.
Note: When you assign the flexible license mode to a Flow Sensor appliance, the Flow Sensor
appliance becomes an appliance that has the traffic and routing analysis role. Any routers that
are managed by this appliance are assigned the Edge license type. See “About the SP
Appliance Traffic and Routing Analysis Role” on the previous page.
What the Flow Sensor appliance provides
The Flow Sensor appliance does the following:
detects customer-to-customer attacks
n
n
engineers traffic at the customer edge (for example, POP-to-POP matrices, customer-tocustomer breakdowns, on-net analysis, and capacity planning)
n
offers edge-based detection services
n
offers MPLS VPN internal visibility and visibility services
The Flow Sensor appliance performs detection and stores router and interface data locally. It
generates ArborFlow for matching managed objects from routers and forwards flow to the
Traffic and Router Analysis appliance. You must have a Traffic and Router Analysis appliance
to manage the Flow Sensor appliance. The Traffic and Router Analysis appliance calculates
portions of the data for the Flow Sensor appliance.
Note: You cannot assign a TMS appliance to a Flow Sensor appliance. You can only assign
routers to Flow Sensor appliances.
About ArborFlow
The Flow Sensor appliance generates ArborFlow for matching managed objects (except for
peer managed objects) and sends it to the parent appliance that has the traffic and routing
analysis role. ArborFlow passes between appliances that have the traffic and routing analysis
role and other appliances.
A Flow Sensor appliance generates a pre-processed rich data feed to the parent appliance
that has the traffic and routing analysis role. ArborFlow includes identification of application,
ephemeral port parenting, and flow de-duplication (based on flow classification). ArborFlow
also includes matched managed objects, MPLS fields, and object (router, interface) GIDs.
Proprietary and Confidential Information of Arbor Networks Inc.
47
SP and TMS User Guide, Version 8.0
About the SP Appliance Data Storage Role
Introduction
An appliance that has the data storage role serves as a home for managed objects. Each
appliance can support up to 1,000 homed managed objects. The number of flows per second
that an appliance can support depends on the appliance model.
For redundancy, you can assign each managed object to up to three appliances that have the
data storage role. If one appliance fails, SP automatically defaults that appliance’s managed
objects to their second home.
Note: For appliances in appliance-based license mode, the different types of SP appliances
have fixed roles. For information on the relationships between the appliance types and
appliance roles, see “About SP appliance types and appliance roles” on page 38.
What the data storage role provides
Adding an appliance that has the data storage role to an SP deployment provides the following
features:
n a new platform for in-cloud computation and data processing
n
scale in the number of managed objects
n
managed object level real-time redundancy and fault tolerance
n
reduction in the computational and storage load on the rest of the system
Note: For objects homed on an appliance that has the data storage role, that appliance
automatically performs managed object alerting.
Note: Managed services managed objects cannot be assigned to a different home from their
parent objects.
See “Deployment Scenarios for the SP Appliance Data Storage Role” on the facing page.
Use case
Network engineers can use appliances that have the data storage role to monitor the following
network entities:
n applications
48
n
peers
n
customers
n
routers
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
Deployment Scenarios for the SP Appliance Data Storage Role
Introduction
An SP appliance that has the data storage role allows ISPs to make more informed business
decisions by providing better overall scalability and performance. See “About the SP Appliance
Data Storage Role” on the previous page.
Note: For appliances in appliance-based license mode, the different types of SP appliances
have fixed roles. For information on the relationships between the appliance types and
appliance roles, see “About SP appliance types and appliance roles” on page 38.
Deployment scenario: data availability
Managed objects can be homed on multiple appliances that have the data storage role. When
this is done, the managed object data is sent to multiple appliances for data redundancy. This
automatically and transparently covers gaps in data in cases of hardware failures or loss of
network connectivity to an appliance that has the data storage role.
A data availability deployment
Deployment scenario: data scalability
You can increase the number of managed objects in a deployment by adding appliances that
have the data storage role. Managed object scalability is useful internally for monitoring more
customers, peers, and VPNs and is useful externally to support in-cloud DDoS services.
A data scalability deployment
Proprietary and Confidential Information of Arbor Networks Inc.
49
SP and TMS User Guide, Version 8.0
TMS Appliance Deployment Scenarios
Introduction
TMS appliances allow you to mitigate attacks by using countermeasures, reports, and alerts.
TMS appliances also allow network operators to monitor critical applications and network
services to ensure service availability and to provide an early warning of network attacks.
TMS appliances can stop basic Denial of Service (DoS) attacks and protect critical services by
performing the following tasks:
n monitoring key performance statistics to help ensure that services are running as optimally
as possible
n
performing deep packet inspection of critical applications such as HTTP and DNS
n
performing surgical mitigation that identifies and removes only the attack traffic and does
not interrupt the flow of legitimate traffic
n
providing reports that display the observed, dropped, and passed clean traffic data that is
involved in mitigations
How SP and TMS work together
When SP detects an anomalous event, it directs traffic through the TMS appliance so that it
can validate the traffic and respond to the attack. The TMS appliance and SP pass baseline
data and traffic data between them to ensure accurate mitigation of malicious traffic.
You do not need to predefine network elements to ensure protection against attacks. The TMS
appliance protects any destination of an IP route.
Types of TMS appliances
Arbor offers several types of TMS appliances. All TMS appliances provide the same packet
inspection, application intelligence, and mitigation capabilities. They differ in bandwidth
capacity, available hardware interfaces, stacking options, and power options.
All TMS appliances can be deployed in the following ways:
BGP diversion
n
See “Deployment scenario: diversion mode using BGP ” on the facing page.
n
Flow specification diversion
See “Deployment scenario: diversion mode using flow specification” on page 52.
n
Diversion mode with a physical interface in promiscuous mode
See “Deployment scenario: diversion mode with a physical interface in promiscuous mode”
on page 53.
n
Inline
See “Deployment scenario: inline mode” on page 53.
n
SPAN port
See “Deployment scenario: SPAN port mode” on page 54.
50
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
Deployment scenario: diversion mode using BGP
In a BGP diversion deployment, the traffic is routed as described in the following table:
BGP diversion mode stages
Stage
Description
1
SP redirects (diverts) the traffic through the TMS appliance.
The redirection is accomplished by using BGP, which defines a port on the
TMS appliance as the nexthop destination for the incoming traffic.
2
The TMS appliance inspects the traffic data and performs a mitigation that is
based on the configured countermeasures.
3
The TMS appliance sends the traffic through a GRE tunnel or VLAN to the
reinjection router (nexthop router).
4
The reinjection router sends the traffic to the original destination.
The reinjected traffic always follows the reinjection path to ensure loop-free
routing to the traffic's destination.
TMS deployment BGP diversion
The TMS appliance does not inspect or route the return path traffic or the traffic that the
destination sends in response to the source. Instead, it uses asymmetric routing to send that
traffic back to the originator.
Proprietary and Confidential Information of Arbor Networks Inc.
51
SP and TMS User Guide, Version 8.0
Deployment scenario: diversion mode using flow specification
In a flow specification diversion deployment, the traffic is routed as described in the following
table:
Flow specification diversion mode stages
Stage
Description
1
SP redirects (diverts) the traffic through the TMS appliance.
The redirection is accomplished by using a flowspec redirect announcement via
BGP, which specifies a route target associated with a dirty VRF (Virtual
Routing and Forwarding) to which the attack traffic is forwarded. This dirty VRF,
which is on the public side of the TMS appliance, contains a default route
which forwards all attack traffic to the nearest TMS appliance.
The redirection is more granular than with BGP diversion because flow
specification allows a variety of traffic characteristics to be considered when
choosing to redirect traffic, including ports and source address.
2
The TMS appliance inspects the traffic data and performs a mitigation that is
based on the configured countermeasures.
3
The TMS appliance sends the traffic directly to a nexthop router.
4
The connected router uses the GRT (Global Routing Table) to send the traffic
to the original destination.
The reinjected traffic always follows the reinjection path to ensure loop-free
routing to the traffic's destination. The reinjection router must be a router which
does not have the flowspec announcements in its routing table, which also
avoids routing loops.
TMS deployment: flow specification diversion
52
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
Deployment scenario: diversion mode with a physical interface in promiscuous mode
In a diversion deployment with a physical interface in promiscuous mode, the incoming traffic is
not diverted from its original path. Instead, a copy of the traffic is sent (diverted) to the TMS
appliance for analysis and mitigation. The TMS appliance inspects and mitigates the copied
traffic. The TMS appliance then drops all of the traffic from the interface and sends Arborflow
to the leader appliance.
A TMS appliance deployment with a physical interface in promiscuous mode is like SPAN port
mode except that the attack traffic is mitigated. You can put an interface into promiscuous
mode to learn how the settings of a mitigation impact the traffic, without dropping any of the
traffic.
To enable promiscuous mode on a physical interface of a TMS appliance, you use the CLI, and
the TMS appliance must be in the diversion mode. See “Enabling and Disabling Promiscuous
Mode on a Physical Interface of a TMS Appliance” in the SP and TMS Advanced
Configuration Guide.
TMS deployment: diversion mode with an interface in promiscuous mode
Deployment scenario: inline mode
The inline deployment scenario is the simplest way to deploy a TMS appliance. It requires only
physical connections in the protected path; no IP addressing or network configuration is
needed.
In an inline deployment, the TMS appliance acts as a physical connection between two end
points. All traffic that traverses the network flows through the appliance. Application
performance statistics are reported most accurately in this mode because the TMS appliance
measures both inbound and outbound traffic directly through the network link.
TMS deployment: inline
Proprietary and Confidential Information of Arbor Networks Inc.
53
SP and TMS User Guide, Version 8.0
The inline deployment scenario is useful in the following environments:
where the routers are not capable of producing flow
n
For example, if a TMS appliance is deployed in front of a server data center, the router
upstream of the TMS appliance might not be BGP capable, or it might be administered by a
different unit or company.
n
where a customer cannot be mitigated through the cloud because the border and customer
aggregation edges have collapsed to a single layer
The inline scenario can serve as a method for dedicating a system to the customer link.
As with any inline device, if the TMS appliance fails, then the client network goes down.
However, some TMS appliance models are bypass capable.
Deployment scenario: SPAN port mode
In a SPAN port deployment, the incoming traffic is not diverted from its original path. Instead, a
copy of the traffic is sent (diverted) to the TMS appliance for analysis. The TMS appliance
inspects the copied traffic and then sends Arborflow to the leader appliance.
No traffic filtering or attack mitigation occurs in this deployment scenario. However, this type of
deployment is useful for analyzing your application performance.
TMS deployment: SPAN port
A SPAN port deployment can easily be converted to an inline or diversion deployment.
54
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
TMS-CGSE Deployment Scenarios
Introduction
After you install and configure the TMS-CGSE software on a CGSE (Carrier Grade Services
Engine) module in a CRS-1 or CRS-3 router, you can then use SP to mitigate attacks with
TMS-CGSE.
For information about configuring a TMS-CGSE, see TMS-CGSE Configuration Guide,
available from Cisco.
TMS-CGSEs allow you to mitigate attacks by using countermeasures and alerts. TMS-CGSEs
also allow network operators to monitor critical applications and network services to ensure
service availability and to provide an early warning of network attacks.
TMS-CGSEs can stop basic Denial of Service (DoS) attacks and protect critical services by
performing surgical mitigation that identifies and removes only the attack traffic and does not
interrupt the flow of legitimate traffic.
Note: A Traffic and Routing Analysis appliance in appliance-based license mode that has a
CP-0 license does not support the use of TMS-CGSEs.
How SP and TMS-CGSE work together
When SP detects an anomalous event, it directs traffic through the TMS-CGSE so that it can
validate the traffic and respond to the attack. The TMS-CGSE and SP pass baseline and
traffic data to each other to ensure accurate mitigation of malicious traffic.
You do not need to predefine network elements to ensure protection against attacks. The
TMS-CGSE protects any destination of an IP route.
Deployment scenario: BGP diversion
In the BGP diversion deployment scenario, the CRS-1 or CRS-3 that contains the
TMS-CGSEs can be deployed in the direct packet processing path. When an attack is
detected, traffic to the attacked destination prefix is then diverted to the TMS-CGSE clusters.
In a TMS-CGSE BGP diversion deployment, the following process occurs:
1. The SP appliance that has the traffic and routing analysis role collects and analyzes the
flow records sent from the entire network.
2. SP redirects (diverts) the attack traffic through the TMS-CGSE clusters on the CRS-1 or
CRS-3 router.
The redirection is accomplished by using BGP, which defines a port on the TMS-CGSE
clusters as the nexthop destination for the incoming traffic.
3. The TMS-CGSE clusters inspect the traffic data and perform a mitigation that is based on
the configured countermeasures.
4. The TMS-CGSE clusters send the traffic through a GRE tunnel to the reinjection router
(nexthop router).
The GRE tunnel endpoint is the CRS-1 or CRS-3 chassis and not the TMS-CGSE.
5. The reinjection router sends the traffic to the original destination.
Proprietary and Confidential Information of Arbor Networks Inc.
55
SP and TMS User Guide, Version 8.0
Deployment scenario: flow specification diversion
In the flow specification diversion deployment scenario, the traffic is diverted to a router that
supports flow specification. The traffic is then forwarded to a CRS-1 or CRS-3 router that
contains the TMS-CGSEs.
Note: The CRS-1 and CRS-3 routers do not support flowspec.
In the flowspec diversion scenario, the following process occurs:
1. The SP appliance that has the traffic and routing analysis role collects and analyzes the
flow records sent from the entire network.
2. The SP appliance that has the traffic and routing analysis role learns and sends
information about the attacked prefixes to the TMS-CGSE clusters on the CRS-1 or
CRS-3.
3. A BGP flow specification route for the attack prefixes is announced to a router that
supports flow specification to divert malicious traffic to a VRF (Virtual Routing and
Forwarding) through which it will reach the CRS router and the TMS-CGSEs for
mitigation.
Flow specification diversion is more granular than BGP diversion because it allows a
variety of traffic characteristics to be considered when choosing to redirect traffic,
including ports and source address.
4. The CRS router may advertise the flow specification route to one or more peering routers,
which then advertise the updates to all of their peers.
5. The inbound suspected attack traffic is routed to the router that supports flow
specification and is then sent to the CRS router and the TMS-CGSE clusters.
6. The TMS-CGSE clusters drop the attack packets and then forward the cleaned packets
back to the peering router.
Since this return path is not part of the incoming VRF, the traffic is then forwarded
normally.
56
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 2: Introduction to SP Appliances and TMS Models
TMS-ISA Deployment Scenarios
Introduction
TMS-ISAs allow you to mitigate attacks by using countermeasures and alerts. TMS-ISAs also
allow network operators to monitor critical applications and network services to ensure service
availability and to provide an early warning of network attacks.
TMS-ISAs can stop basic Denial of Service (DoS) attacks and protect critical services by
performing surgical mitigation that identifies and removes only the attack traffic and does not
interrupt the flow of legitimate traffic.
How SP and TMS-ISA work together
When SP detects an anomalous event, it directs traffic through the TMS-ISA so that it can
validate the traffic and respond to the attack. The TMS-ISA and SP pass baseline and traffic
data to each other to ensure accurate mitigation of malicious traffic.
You do not need to predefine network elements to ensure protection against attacks. The
TMS-ISA protects any destination of an IP route.
Deployment scenario: PE diversion with reinjection
In the Provider Edge (PE) diversion with reinjection deployment scenario, the Alcatel 7750 SR
that contains the TMS-ISAs can be deployed in the direct packet processing path. When an
attack is detected, traffic to the attacked destination prefix is then diverted to the TMS-ISA
clusters.
In the PE diversion with reinjection deployment scenario, the following process occurs:
1. The SP appliance that has the traffic and routing analysis role collects and analyzes the
flow records sent from the entire network.
2. The SP appliance that has the traffic and routing analysis role learns and sends
information about the attacked prefixes to the TMS-ISA clusters on the Alcatel 7750 SR.
3. The TMS-ISA clusters inform the Alcatel 7750 SR about attack prefixes for which traffic
should be forwarded to the TMS-ISA clusters to start a mitigation.
4. The Alcatel 7750 SR advertises the updated routes to the peering router, which then
advertises the updates to all of its peers.
5. The inbound suspected attack traffic is routed to the peering router and then sent to the
TMS-ISA clusters for mitigation.
6. The TMS-ISAs drop the attack packets and then forward the cleaned packets back to the
peering router.
Deployment scenario: flow specification diversion
In the flow specification diversion deployment scenario, the Alcatel 7750 SR that contains the
TMS-ISAs can be deployed in the direct packet processing path. When an attack is detected,
the attacked destination prefix is then diverted to the TMS-ISA clusters.
In the flow specification deployment scenario, the following process occurs:
1. The SP appliance that has the traffic and routing analysis role collects and analyzes the
flow records sent from the entire network.
2. The SP appliance that has the traffic and routing analysis role learns and sends
information about the attacked prefixes to the TMS-ISA clusters on the Alcatel 7750.
Proprietary and Confidential Information of Arbor Networks Inc.
57
SP and TMS User Guide, Version 8.0
3. A BGP flow specification route for the attack prefixes is announced to the Alcatel 7750 to
divert malicious traffic to a VRF (Virtual Routing and Forwarding) through which it reaches
a TMS-ISA for a mitigation.
Flow specification diversion is more granular than BGP diversion because it allows a
variety of traffic characteristics to be considered when choosing to redirect traffic,
including ports and source address.
4. The Alcatel 7750 may advertise the flow specification route to one or more peering
routers, which then advertise the updates to all of their peers.
5. The inbound suspected attack traffic is routed to the peering router and then sent to the
TMS-ISA clusters for mitigation.
6. The TMS-ISAs drop the attack packets and then forward the cleaned packets back to the
peering router.
Since this return path is not part of the incoming VRF, the traffic is then forwarded
normally.
58
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3:
Basic Concepts
Introduction
This section defines standard terms and concepts to help you use this guide and deploy SP in
your network.
In this section
This section contains the following topics:
Introduction to Reference Architecture
60
SP on the Peering Edge
62
SP Deployment Guidelines
64
Binning and Counting Traffic
66
How SP Counts Traffic
67
Understanding Network Classification Concepts
69
TMS Deployment Architecture
71
Deploying a TMS Appliance in DNS Monitoring
73
Deploying TMS in Passive Monitoring of DNS Servers
74
Integrating VLANs into Your Network
76
SP and TMS User Guide, Version 8.0
59
SP and TMS User Guide, Version 8.0
Introduction to Reference Architecture
Introduction
This topic provides the context that you need to make decisions about the best placement of
the SP components within your general network architecture.
About the reference architecture
The following figure is an example of a generic network architecture that illustrates the
concepts used throughout this guide:
Reference network architecture
About network layers
The network includes distinct layers, such as:
peering layer or peering edge
n
n
core routers
n
aggregation edge or provider edge
n
host centers
In this guide, we separate these functions and describe them as separate infrastructures for
clarity. However, in many networks, these functions collapse into single systems (for example,
when you pair core and peering connections on the same router).
60
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
About the peering edge
The peering edge consists of all the network routers that are used to connect to other networks
from a different autonomous system (AS). These other networks may be a service provider,
enterprise, university, or other entity that operates its own network. The peering edge describes
all entry and exit points for a given network.
A router on the peering edge establishes one or more external Border Gateway Protocol
(eBGP) sessions between itself and routers within the peer autonomous systems. Each
network has a unique autonomous system number (ASN) that designates its unique
administrative control. The eBGP connections carry Network Layer Reachability Information
(NLRI) between the two autonomous systems so that each system knows how to reach IP
addresses within the other. Each system can then give the reachability information to other
BGP peers. Therefore, internal Border Gateway Protocol (iBGP) sessions are maintained
within the same AS so that they can give NLRI information to internal routers. This informs the
routers about when to use a particular exit point in the network.
Proprietary and Confidential Information of Arbor Networks Inc.
61
SP and TMS User Guide, Version 8.0
SP on the Peering Edge
Introduction
When you deploy SP on the peering edge, you gain the following:
network visibility of peer traffic
n
n
the ability to analyze peer relationships
n
potential peer opportunities through traffic analysis
n
capacity planning of peer interfaces
n
visibility into traffic that crosses the network boundary
SP provides you with details about significant DoS events. The system detects and mitigates
network threats through external sources. Through detection and the mitigation of threats, SP
also provides you with detailed information about DoS events.
When you deploy SP on the peering edge of your network, you can monitor your network for
traffic or network threats that might impede network infrastructure or a downstream network
resource. SP ensures proper coverage of all peering routers and their interfaces and provides
minute-by-minute detection for each peered link and router.
Understanding large capacity routers on the network core
Traditionally, the network core includes large capacity routers connected to high speed links
that interconnect with the major Points of Presence (POP). This is still true in today’s networks,
but the core router can also provide other functions, such as the following:
n external peering
n
customer aggregation
n
MPLS Label Switch Router (LSR)
n
MPLS Provider Edge Router (PER)
For information about MPLS, see "Configuring Juniper Routers to Send Flow Monitoring to SP"
in the SP and TMS Advanced Configuration Guide.
For example, the core routers provide the traditional connectivity between POPs and
interconnect through the highest speed links. These routers maintain iBGP sessions with the
peering routers, each other, and edge routers. Optionally, they can also provide iBGP route
reflection for regions of the network.
SP on the network core
When deployed in the network core, appliances that have the traffic and routing analysis role
help to maintain the network, plan for changes, and protect critical infrastructure. Within the
core of the network, SP can model intra-POP traffic for capacity planning, can provide traffic
accounting per interface or groups of interfaces, and can provide customer-to-customer or
POP-to-POP traffic analysis.
SP detects DoS anomalies to ensure that flash crowds or anomalous traffic do not threaten
critical network infrastructure. SP allows for a greater granularity of detection and superior
traffic trace-back to sources or distributed sources that contribute to traffic anomalies. When
you extend SP into the network core, it provides greater aggregation and traceback of widely
distributed attacks. This enables you to have greater insight into the extent of a threat.
62
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
Understanding the aggregation edge
The aggregation edge is the set of routers that directly connects to service provider customers.
These routers maintain connectivity for customers to the Internet or to provider-based VPNs.
They also provide access to network services such as DNS, VoIP, application hosting, and
others.
Traditionally, aggregation edge routers are deployed in a service provider's POP, and they are
used to connect customers to the network core. These routers often provide bandwidth
aggregation for many customer links to a few high-speed uplinks to the core network, with
some amount of over subscription. When used with MPLS VPNs, these routers are referred to
as Provider Edge (PE) routers.
SP on the aggregation edge
SP provides value on the aggregation edge by doing the following:
detecting network anomalies directly on the customer interface
n
n
reporting on network usage at the aggregation layer for capacity planning
n
providing extensive MPLS VPN and QoS visibility
n
providing unprecedented MPLS visibility
n
displaying individual customer views for use in Managed Services applications
These services can provide you a new stream of revenue through a deployment to the network
edge.
Proprietary and Confidential Information of Arbor Networks Inc.
63
SP and TMS User Guide, Version 8.0
SP Deployment Guidelines
Introduction
SP uses BGP for reachability information, SNMP for context, and flow records to build a model
of the network. Each of these data feeds provides unique information about the network and
the way in which traffic flows through it. You should position SP to ensure that your network is
protected from DoS events and to help you make critical decisions about your network.
About BGP peering for SP
SP derives much of its value from being able to cross-reference traffic statistics learned from
flow records with BGP-learned network routes. Traffic and routing analysis, based on this
mechanism, allows SP to differentiate and map patterns of network traffic, based on
dynamically learned routing criteria. This creates a rich and unique data set.
Arbor Networks SP uses BGP for the following purposes:
Purposes of using BGP
Purpose
Why It Is Useful
dynamic object
creation
The ability to define a customer, resource, or set of resources using
BGP expressions ensures that SP dynamically learns any changes
that occur to these resources over time.
provide network
reachability
information
The AS Path, community, and nexthop information provided, along
with BGP prefixes, allows SP to measure and report on where traffic
is going and coming from. This allows network administrators to make
more informed route-management and peering-analysis decisions.
active mitigation
BGP is used in blackhole routing, in sink hole routing, and for
intelligent mitigation using the TMS as a method to divert traffic from
its normal network trajectory.
The accuracy and usefulness of this data depends on the accuracy and reliability of the
network's routing data for monitored routers. In particular, the BGP route data for a given router
should represent as closely as possible the internal forwarding table of that router.
Note: Arbor recommends that you configure the SP system as an iBGP Route Reflector Client
(RRC) with each of the routers that SP peers with. If this is not possible or practical, you have
two other options. You can configure the system with a route-reflected session with a central
route reflector. You can also configure the system with another network router that has a
representative routing table for the router being monitored. Depending on how much routing
asymmetry is present in the network, it might be more accurate to have a separate routereflected session with each router that the system monitors.
About SNMP data for SP
SP polls the routers to provide contextual information about the data that the system receives
through BGP and flow records. SNMP provides interface level information, such as interface
index to interface description mappings. These mappings present the infrastructure of the
physical network infrastructure in a readable way.
64
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
When SNMP polls the network routers, it provides a correlated data feed about router health
with the BGP state and flow data. This correlation ensures that you can understand any
network event that impacts a router's normal operation. Thus, you ensure that router memory,
software, and hardware operate as expected.
Considering NetFlow, cFlowd, and sFlow
SP supports all of the common flow statistical formats that export from the major router
vendors. Flow records include information about the network and transport layers of a stream of
traffic and can come in unsampled (every network flow is accounted for in a flow record) or
sampled (one in n network flows are accounted for in flow records) formats. Sampled traffic
reduces the need to process every packet on the network while still providing statistically
accurate visibility into traffic patterns, the population of applications, and the source and
destination relationships within a network.
Most flow technologies only support flow generation on the ingress of router interfaces. The
flow record incorporates both the ingress and egress interfaces on the router through which
the traffic flows. Therefore, when you enable flow export on all ingress interfaces on a router,
you get a complete picture of traffic that traverses or terminates on the router.
For definitions of the different flow types, see “About flow types” on page 69.
For more information, see "Configuring Flow and SNMP on Routers" in the SP and TMS
Advanced Configuration Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
65
SP and TMS User Guide, Version 8.0
Binning and Counting Traffic
Introduction
SP uses the routers in your network to bin and count network traffic.
About data types
SP appliances collect the following types of data from the routers in your network:
Flow (NetFlow, NetStream, cFlowd, JFlow, sFlow, and IPFIX)
n
n
BGP
n
SNMP
Supported devices and vendors
SP supports specific devices and data types from the following vendors:
Cisco (NetFlow)
n
n
Juniper (cFlowd, IPFIX, and JFlow)
n
Huawei (NetStream)
n
Alaxala (sFlow and NetFlow)
n
Foundry (sFlow)
n
Force10 (sFlow)
n
Alcatel (cFlowd)
Contact your Arbor Networks Support Engineer (SE) or see the SP Release Notes for more
information about the supported devices and data types.
Building data with flow
Flow provides SP with layer 1-4 information for the flows that traverse a network. SP extracts
the data it needs from the flow packets and bins the data to custom databases. The raw flow is
further sampled and kept by the system for a limited period of time for reference before being
discarded.
Building data with SNMP
SP polls the monitored routers that use SNMP versions 1, 2(c), or 3. SNMP gathers contextual
information, such as interface descriptions and speed information, but it also gauges report
accuracy. You can use the Web UI to compare the flow records and SNMP counters per
interface in real time.
Building data with BGP
In addition to gathering flow information, SP peers with routers in the network to collect BGP
information. SP correlates the BGP routing information from each router with the flow records
received from that router. SP then uses this information to determine how much traffic is going
through BGP peers, communities, prefixes, ASNs (both original and transit), AS Paths,
nexthops, and a variety of other BGP attributes.
66
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
How SP Counts Traffic
Introduction
SP uses boundary-based counting to ensure accuracy while eliminating the double-counting
of flows. It aggregates information across multiple boundary interfaces and routers to track
traffic in and out of the network, each router, or user configured managed objects. Every object
the system tracks has a boundary on which the system counts data.
About network boundaries
The following are the types of network boundaries in SP:
Network boundary type descriptions
Type
Description
global
Includes all of the interfaces that connect the network to external BGP
peers. This is a system default boundary.
managed object
Includes all of the interfaces that connect an object to the network.
You must configure managed object boundaries.
For more information about configuring managed object boundaries, see “Viewing interface
boundaries” on page 118.
About global boundaries
SP uses global boundaries to define all of the entry and exit points to the network that it
monitors. It uses a number of algorithms to determine which monitored interfaces connect to
external BGP ASNs, and it labels these interfaces as “external.” SP considers in and out traffic
on these external interfaces for managed objects that use the global boundary.
Example: You can configure a global managed object for the DNS servers in your network.
The system counts traffic to this managed object across the global boundary to determine how
much DNS server traffic travels in and out of the network.
About customer and profile boundaries
Customer and profile managed objects count traffic in the same way. You can define boundary
interfaces for customer and profile managed objects. Boundary interfaces connect the profile
or the customer to the network. If you define a managed object with a set of boundary
interfaces, SP counts traffic for that object across the boundary interfaces.
If you do not define a boundary interface, the system considers the object to be a global
managed object. Therefore, it counts traffic across the network BGP border, which is defined
by the interfaces that you classify as external.
About peer interfaces
Peers are a type of managed object that describes a BGP AS that is directly connected to the
monitored network. SP counts peer traffic relative to the peer. SP counts traffic as “in” when
traffic enters the peer (for example, the traffic exits an external interface toward the peer). SP
counts peer traffic as “out” when traffic leaves the peer (for example, the traffic enters an
external interface from the peer).
Proprietary and Confidential Information of Arbor Networks Inc.
67
SP and TMS User Guide, Version 8.0
Peer in and out traffic is the reverse of network in and out traffic. Traffic that is “in” for the
network peering interface is considered “out” for the peer, and traffic that is “out” for the
network peering interface is “in” for the peer.
About VPN boundaries
VPN managed objects track traffic that is part of an RFC 4364 MPLS VPN and are measured
at the Peering Edge (PE) routers, where the traffic enters the VPN. A VPN managed object is
defined by one or more boundary interfaces that you define. A VPN managed object can
contain one or more VPN sites.
VPN site managed objects consist of one or more CIDR blocks and are counted only along the
interfaces that are defined for the parent VPN managed object. SP matches the flows that
cross the parent VPN boundary interfaces against these CIDR blocks to get per-VPN site traffic
as well as VPN site by site traffic.
68
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
Understanding Network Classification Concepts
Introduction
This topic describes the different terminology that is used by SP and how traffic is classified.
About flow types
The following table describes each of the flow types and what they mean:
Flow definitions
Flow Type
Definition
Ingress and Egress
Describes flows with respect to a network boundary.
In and Out
Describes flow with respect to a managed object.
Input and Output
Describes flow with respect to an interface.
Src and Dst
Describes the source IP address and the destination IP address of a
flow.
About off-net traffic
In addition to network ingress and egress, SP also counts how much traffic goes off-net. Offnet is an important consideration because the service provider must either pay for it (for
example, transit traffic) or use its resources to support it (for example, settlement-free peering).
Off-net traffic enters the network from a non-customer or exits the network to a non-customer.
An off-net flow must match a BGP route.
An ingress or egress flow is “off-net” if one of the following statements is true:
The flow is ingress, and the source address matches a BGP route that includes at least one
external ASN that is not a customer managed object (for example, a customer defined by a
peer AS).
n
n
The flow is egress, and the destination address matches a BGP route that includes at least
one external ASN that is not a customer managed object (for example, a customer defined
by a peer AS).
However, an ingress or egress flow is not considered off-net if one of the following statements
is true:
n The flow is ingress to the BGP border, and the flow is sourced by a customer managed
object (for example, a customer defined by a peer AS).
n
The flow is egress to the BGP border, and the flow is destined to a customer managed
object (for example, a customer defined by a peer AS).
About on-net traffic
On-net traffic enters the network from a customer or leaves the network to a customer. Service
providers gain money from this arrangement, in contrast to off-net traffic. In some cases, traffic
to a customer does not leave the network because the provider physically hosts the customer
in the network. In other cases, the customer might have its own AS. In that case, traffic to or
from the customer travels over external interfaces to another AS.
Proprietary and Confidential Information of Arbor Networks Inc.
69
SP and TMS User Guide, Version 8.0
An ingress or egress flow is “on-net” if one of the following statements is true:
The flow is ingress to the BGP border, and the flow is sourced by a customer managed
object (for example, a customer defined by a peer AS).
n
n
The flow is egress to the BGP border, and the flow is destined to a customer managed
object (for example, a customer defined by a peer AS).
About the backbone
The backbone carries traffic between peering and customer aggregation layers of the network.
The backbone generally represents a cost to the SP customer so the bandwidth along this layer
needs to be optimized as much as possible. SP reports for the backbone provide the means to
manage this traffic most effectively. Traffic between a given peering point and a given
customer may cross multiple backbone routers so a single flow may be counted multiple times
across the backbone.
About customer-to-customer traffic
When customers are defined with local boundary interfaces, it is possible to measure how
much traffic each customer is sending to other customers by counting along these interfaces.
This provides useful information when making backbone capacity planning decisions.
70
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
TMS Deployment Architecture
Introduction
Arbor recommends that you deploy TMS appliances in locations with proper connectivity and
visibility into the BGP control plane. With this deployment, you can control the diversion of
traffic (source to destination) to the TMS appliance.
Native path traffic
Native path traffic is traffic in the network that follows the current and unaltered routing path.
The native path is a result of the routing protocol’s best path selection process, which allows
traffic to flow in unaltered paths in the routers’ forwarding tables.
Diverted traffic
The TMS appliance diverts traffic from the native path to a new path from the network to the
TMS appliance. The new path is called the diversion path. The diverted traffic goes into the
TMS appliance, where the TMS appliance applies countermeasures to determine whether
traffic is appropriate or not. The TMS allows the legitimate traffic to pass and applies
countermeasures against the inappropriate traffic.
Reinjected traffic
The path from the TMS egress interface to the original destination of the traffic is the
reinjection path. Reinjected traffic always follows the reinjection path to ensure loop free
routing to the final destination of the traffic.
Reinjecting traffic into the network can be done through a native IP packet placed on the TMS
egress interface or through a Generic Routing Encapsulation (GRE) tunnel. When traffic is
injected into the network without encapsulation, it can be sent directly into the reinjection path
from the TMS. Putting traffic back on the network with no encapsulation requires an assurance
of loop free forwarding on reinjection. If a loop-free path cannot be ensured, then some form of
encapsulation is required.
GRE tunnels can also be built into the reinjection path to ensure traffic to the destination is
tunneled to the Provider Edge (PE) router closest to the destination. Encapsulating diverted
traffic through the reinjection path ensures that traffic is not re-forwarded into the TMS
appliance through a preferred route, creating an endless traffic loop.
Diverting traffic through BGP route announcements
In most deployments, traffic is diverted from the native path to the diversion path through a
BGP route announcement. This announcement changes the path by advertising the TMS
system as the BGP nexthop for the mitigated destination. The TMS system or SP can originate
the route change by announcing a more specific route to the network. The route change
nexthop is the diversion interface of the TMS appliance. This route change nexthop ensures
that traffic that comes from an attacking source is passed through the TMS appliance for
mitigation.
Delivering traffic to its destination
After traffic passes through the diversion and reinjection paths, it is delivered to the destination.
All return path traffic (traffic sent from the destination back to the original source) is routed
along the original native traffic path. TMS operates in this asynchronous traffic model
Proprietary and Confidential Information of Arbor Networks Inc.
71
SP and TMS User Guide, Version 8.0
throughout the duration of the mitigation.
A secure communication channel is maintained between the SP leader and the TMS appliance
throughout the mitigation. This control traffic communicates enabled mitigations, mitigation
and countermeasure filter configurations, and traffic statistics.
72
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
Deploying a TMS Appliance in DNS Monitoring
Introduction
The TMS appliance monitors and protects your DNS infrastructure. The TMS appliance uses
unique mitigation techniques to monitor and protect the DNS servers from flood attacks. This
deployment scenario describes how to deploy the TMS appliance to monitor the traffic sent to
the DNS server.
How the TMS appliance monitors your DNS traffic
The following figure illustrates how the TMS appliance monitors your DNS traffic:
TMS appliance monitoring DNS server infrastructure
You can deploy a TMS appliance to monitor your traffic that flows into the DNS server. The
TMS appliance receives traffic that is spanned from the network and sends traffic statistics to
SP. SP then calculates the baseline traffic patterns and reports the data.
Protecting DNS infrastructure
To protect DNS infrastructure, you must deploy a TMS appliance on a SPAN port to directly
monitor traffic. Also, you can deploy a TMS appliance with a diversion and a reinjection
interface. This ensures that SP routes the traffic to the TMS appliance and that the inspected
traffic passes through the TMS appliance.
Note: When you configure the interface, you do not need an IP address. If you use DNS
profiled detection, then you must configure flow. This allows the TMS appliance to report the
data to the appliance that has the traffic and routing analysis role.
Proprietary and Confidential Information of Arbor Networks Inc.
73
SP and TMS User Guide, Version 8.0
Deploying TMS in Passive Monitoring of DNS Servers
Introduction
The TMS appliance passively monitors network links to provide application-level data to SP for
analysis. You can deploy passive monitoring:
n to supplement flow collection by monitoring specific applications
n
in front of critical infrastructure or applications
Reference architecture figure
The following figure shows TMS deployed in a passive monitoring capacity:
Passive deployment model with single leg mitigation
The TMS appliance is connected to the production traffic through either:
a passive network tap device
n
n
a span/mirror/copy port on a network element
Traffic is provided in a 1:1 copy to the TMS monitoring interface. Usually, mirror/span/copy
ports provide bidirectional traffic from the interface, while network tap interfaces often only
provide unidirectional traffic per port provided. Depending on the method used to copy traffic to
the TMS appliance, you might need up to two ports to monitor both inbound and outbound
traffic from the monitored infrastructure.
How the TMS appliance processes DNS traffic
TMS appliances monitor traffic going into and out of your critical DNS servers. This provides
you with visibility into request types and volume sent to your DNS servers. The TMS appliance
consumes monitored traffic spanned from a link that connects the network to a DNS server
infrastructure. Next, the TMS packet engine analyzes the traffic and separates it by request
type. The TMS appliance sends the statistical data to the appliance that has the traffic and
routing analysis role.
74
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
Resolving domain names
Most often, other DNS systems query DNS servers to resolve a host or server in the registered
domain.
The following steps describe an example of how DNS resolution operates:
1. Client-A wants to access the Web site www.example.com.
2. Client-A asks its own DNS server (Server-A) for the correct IP address to send the request
for the Web site www.example.com.
Note: This is a request for a fully qualified domain name (FQDN).
See “Fully Qualified Domain Names (FQDN)” below.
3. Server-A looks up the address record (A-record) for the FQDN host www.example.com.
4. If Server-A finds no record for this lookup, Server-A searches for another DNS server that
can answer that specific request.
5. Finding an address for the .com server, Server-A asks who the owner is of
www.example.com.
Note: This is a registered domain request.
Note: A resolving server (one who gets answers for clients) queries another server (a
domain server) to find this address.
6. The .com server answers that example.com can be found on Server-B, who has an IP
address of 192.168.1.20.
7. Server-A asks Server-B for the address of www.example.com.
Note: Because the top level domain (TLD) server (.com) indicated that Server-B owns the
domain example.com, it knows what the address of the host www is within its domain,
example.com.
8. Server-B answers that the IP address of www.example.com is 192.168.1.50.
9. The DNS server sends the Web site request from Client-A to www.example.com
(192.168.1.50).
Fully Qualified Domain Names (FQDN)
The FQDN is made up of the following components, using the example www.example.com:
hostname—www
n
n
registered domain—.example
n
top level domain—.com
The name www.example.com describes an exact resource where the Web site should reside,
making it fully qualified.
DNS reports available through TMS passive monitoring
SP includes several reports that allow you to monitor DNS.
See “Additional information about the DNS filter ” on page 778.
Proprietary and Confidential Information of Arbor Networks Inc.
75
SP and TMS User Guide, Version 8.0
Integrating VLANs into Your Network
Introduction
This topic provides examples of integrating VLANs into your network. These deployment
scenarios are relevant to the use cases for the TMS appliance within a VLAN environment,
regardless of the speed of the ingress or egress links. In the examples below, you can expect
the links to be one Gigabit Ethernet (GE). This topic describes the following scenarios:
n TMS deployed in a VLAN
n
TMS deployed in a VLAN tagged 802.1Q environment
This topic does not describe all of the combinations of traffic architectures for ingress and
egress traffic to the TMS appliance.
Note: SP does not support any non-VLAN tagged traffic on a trunk interface.
TMS in VLAN diversion and reinjection environments
You can deploy a TMS appliance that can see ingress VLAN tags from the diverted attack
traffic, and can inject traffic into VLAN switched environments or any combination of diversion
or reinjection VLAN switched networks.
VLAN architectures provide customer broadcast and network level separatism over a common
physical infrastructure. VLANs do not provide as much security as you might assume. Networks
separate through logical interfaces, which serve as virtual gateways from one broadcast
domain to another. The network then operates like a distributed router network and shares the
same physical wire for transit.
TMS in a VLAN tagged 802.1Q environment
ISPs or enterprise customers who deploy the TMS appliances into the network require
deployments that allow the TMS appliance to read and match VLAN tags. These environments
require the TMS appliance to terminate and populate traffic from or to the network elements
with the VLAN tag assembly (according to the IEEE 802.1Q standard).
Note: Arbor uses the IEEE 802.1Q standard to configure a VLAN. This specification describes
how you partition traffic on a single physical network into VLANs by tagging each frame with
extra bytes. These bytes encode the virtual network to which the frame belongs.
You might need a single ingress or network diversion interface which supports 802.1Q. You
can route the reinjection, egress traffic from the TMS appliance back into the network natively.
The figures in this topic highlight some of the possible deployment options that are supported
for 802.1Q VLAN tags.
Note: To ensure a successful deployment, you must properly format a VLAN tag. See “About
formatting the VLAN ID” on page 79.
76
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
Figure: VLAN Diversion and reinjection deployment
The following figure illustrates a diversion and reinjection deployment. Expected users include
hosting providers, enterprise customers, service providers in metro rings, MPLS networks, and
hosted co-location centers.
Diversion and reinjection deployment
Figure: VLAN Diversion and GRE reinjection deployment
The following diagram illustrates the diversion and GRE reinjection deployment. Expected
users include service providers and hosting providers.
Diversion and GRE reinjection deployment
Note: Service providers who map MPLS LSPs to VLAN tagged sub interfaces might use
802.1Q diversion as a known interface in the MPLS mesh or a 2547 VPN.
Proprietary and Confidential Information of Arbor Networks Inc.
77
SP and TMS User Guide, Version 8.0
Differences in the TMS VLAN deployments
When you use a TMS appliance in a VLAN, the TMS appliance becomes a member of the
VLAN and owns an IP address in that VLAN.
When you use a TMS appliance in an 802.1Q trunk, the TMS appliance must have an IP
address within the specific VLANs where you have configured mitigations, to ensure that the
nexthop route change targets the TMS mitigation. However, you might see the diverted frame
on the diversion TMS interface with the entire VLAN tag.
The TMS appliance must first parse the VLAN tag and then match the tag to the mitigation that
you configured for the timeframe. SP does this by matching the VLAN ID to the configured
mitigation and matching the reinjection traffic to the network that uses the specified reinjection
technology. You need to add the 12-bit VLAN ID value in the VLAN diversion and reinjection
configuration.
See “About formatting the VLAN ID” on the facing page.
About reinjecting traffic in a VLAN deployment
You can redirect traffic to the TMS appliance through a simple diversion method. This method
redirects traffic (which does not contain an inbound VLAN tag) to the TMS appliance.
However, it requires the TMS appliance to inject traffic through a reinjection access path,
which requires the VLAN to specify a downstream VLAN customer. The reinjection deployment
diagram highlights this example.
Note: To ensure a successful deployment, you must properly format a VLAN tag. See “About
formatting the VLAN ID” on the facing page.
The following figure shows a reinjection deployment scenario. Expected users include hosting
providers, enterprise customers, service provider customers in metro rings, MPLS networks,
and hosted co-location centers.
VLAN reinjection deployment scenario
78
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 3: Basic Concepts
About formatting the VLAN ID
The egress traffic from the TMS appliance is critical to a successful deployment. When
reinjecting 802.1Q frames, the VLAN ID tag must assume the complete four octets, which are
described in the following table:
VLAN tag octet descriptions
Bits
Description
16
Tag Protocol ID (TPID)
3
Priority
1
Canonical Format Indicator (CFI)
12
VLAN ID
Proprietary and Confidential Information of Arbor Networks Inc.
79
SP and TMS User Guide, Version 8.0
80
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4:
SP Licensing
Introduction
This section describes SP Flexible Licensing and hybrid licensing.
User access
Administrators can configure the settings described in this section.
In this section
This section contains the following topics:
About Hybrid Licensing
82
About Appliance-based Licensing
84
Applying Appliance-based Licenses from a License File
86
About TMS Volumetric Licensing
87
About Flexible Licensing
89
Uploading a Flexible License
92
About Flexible Licensing Enforcement
93
About Cloud-based Licensing
96
SP and TMS User Guide, Version 8.0
81
SP and TMS User Guide, Version 8.0
About Hybrid Licensing
Introduction
With hybrid licensing, you can have SP appliances that use appliance-based licensing and
other SP appliances, including SP VMs, that use Flexible Licensing. For example, if you have
existing appliances in appliance-based license mode, you can either leave them in appliancebased license mode or convert them to flexible license mode. When you add new appliances,
you can add them in appliance-based license mode or flexible license mode. See “About
Flexible Licensing” on page 89 and “About Appliance-based Licensing” on page 84.
Hybrid licensing also allows you to add flexible-licensed capacity to your deployment for your
SP appliances in flexible license mode, while you continue to have appliances in appliancebased license mode.
Arbor recommends that you use Flexible Licensing for your SP appliances to take advantage of
deployment-wide licensed capacities rather than appliance-specific capacities. However,
hybrid licensing allows you to choose when to convert appliances from appliance-based
licensing to Flexible Licensing.
Assigning a license mode with hybrid licensing
With hybrid licensing, you assign a license mode to each SP appliance when you configure the
appliance. You can assign either the appliance-based license mode or the flexible license
mode. You can also change the license mode of an SP appliance after you initially assign the
license mode. See “Configuring Appliance Settings for an SP Appliance” on page 106.
Requirements for hybrid licensing
Hybrid licensing requires the following:
All SP appliances must have SP 6.0 Patch 3.0 or later installed.
n
Note: Hybrid licensing does not support multi-version upgrades with appliances that are
running versions of SP prior to 6.0 Patch 3.
n
A flexible license file must be installed on the leader in your SP deployment.
Contact your Arbor Networks sales representative to obtain the correct flexible license for
your deployment. See “Uploading a Flexible License” on page 92.
If the leader is a physical appliance, then you upload the flexible license on the Deployment
Status page. If you previously converted your deployment to Flexible Licensing, then you
only need to install SP 6.0 Patch 3.0 or later to enable hybrid licensing.
If the leader is a VM, then you use the CLI on the leader to access the cloud-based license
server to download a local copy of the cloud-based license. See “About Cloud-based
Licensing” on page 96.
About router license types
With hybrid licensing, your routers can have the following license types:
appliance-based
n
82
n
core
n
edge
n
unset
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
Routers that are managed by an appliance in appliance-based license mode have an
appliance-based license type. Routers that are managed by an appliance in flexible license
mode can have a core, edge, or unset license type. When you assign a router to a core or edge
license type, the router and its flows per second count toward your flexible-licensed capacity
for core or edge routers and flows per second. You can only assign a flexible license type to a
router that is managed by an appliance in flexible license mode. You assign the license type
when you configure the router. See “Configuring Routers” on page 136.
About licensed capacity enforcement with hybrid licensing
The licensed capacities in a deployment with hybrid licensing are enforced as follows:
Appliances in appliance-based license mode: capacities except for managed objects are
enforced on a per appliance basis.
n
n
Appliances in flexible license mode: capacities except for managed objects are enforced
across all flexible-licensed appliances.
n
The licensed capacity of managed objects is enforced deployment wide. The licensed
capacity is the sum of the base licensed capacity (1,000 managed objects), the
flexible-licensed capacity, and the licensed capacity of each appliance in appliance-based
license mode that has the data storage role.
For more information about licensed enforcement, see “About Flexible Licensing Enforcement”
on page 93 and “About Appliance-based Licensing” on the next page.
Examples of licensed capacities for routers
If you have core or edge routers that are managed by appliances in flexible license mode, then
the routers count toward the flexible-licensed capacity for core or edge routers in your
deployment. On the other hand, if you have routers that are managed by an appliance in
appliance-based license mode, then the routers count toward the licensed capacity for routers
for that appliance.
Example of licensed capacity for managed objects
If you have two appliances in appliance-based license mode that each have a licensed
capacity of 500 managed objects, and you have a flexible license that has a licensed capacity
of 1,000 managed objects, then your deployment has a licensed capacity of 3,000 managed
objects (1,000 base + 1,000 appliance-based + 1,000 flexible).
Proprietary and Confidential Information of Arbor Networks Inc.
83
SP and TMS User Guide, Version 8.0
About Appliance-based Licensing
Introduction
Prior to the Arbor Networks SP 6.0 release, licensing of SP deployments was appliance-based.
The SP 6.0 release introduced Flexible Licensing. With SP 6.0, you could keep all of your
appliances in appliance-based license mode or you could convert all of your appliances to
flexible license mode.
The SP 6.0 Patch 3 release introduced hybrid licensing. With hybrid licensing, a deployment
can have SP appliances that use appliance-based licensing and SP appliances that use
Flexible Licensing. See “About Hybrid Licensing” on page 82 and “About Flexible Licensing”
on page 89.
Note: The licenses for TMS appliances are always appliance-based.
About assigning the appliance-based license mode to an SP appliance
If you have not uploaded a flexible license, then each SP appliance is in appliance-based
license mode. If you have uploaded a flexible license, then you can assign a license mode to an
SP appliance. You can assign the appliance-based license mode to a new SP appliance. You
can also assign the appliance-based license mode to an SP appliance that is currently in
flexible license mode to convert its license mode. You assign the appliance-based license
mode to an appliance when you configure the appliance. See “Configuring Appliance Settings
for an SP Appliance” on page 106.
Note: If you convert an appliance that has the traffic and routing analysis role from flexible
license mode to appliance-based license mode, and you want it to be a Flow Sensor appliance,
you will have to use the CLI bootstrap command to assign the flow sensor role to the appliance.
For information about the bootstrap command, see "Reinstalling SP Appliance Software" in the
SP and TMS Advanced Configuration Guide.
About appliance-based licensing enforcement
The license of an SP appliance in appliance-based license mode determines the number of
routers that the appliance can manage. If the number of routers exceeds the licensed capacity
for the appliance, SP ignores the routers that exceed the licensed capacity.
If all of the SP appliances in your deployment use appliance-based licensing, then your
deployment's licensed capacity for managed objects is the sum of the base licensed capacity
(1,000 managed objects) and the licensed capacity of each appliance that has the data
storage role. If you are in hybrid licensing, then the licensed capacity for managed objects is
the sum of the base licensed capacity (1,000 managed objects), the flexible-licensed capacity,
and the licensed capacity of each appliance in appliance-based license mode that has the
data storage role. See “About Hybrid Licensing” on page 82.
Note: The VPN sites of a VPN managed object do not count against the managed object
license limit.
With hybrid licensing, when the number of managed objects exceeds 90% of the licensed
capacity, a license alert is triggered with an importance level of medium. The alert is raised to
an importance level of high when the number of managed objects reaches the licensed
capacity.
84
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
When the licensed capacity for managed objects in your deployment has been reached, you
can no longer add managed objects. You must either increase your licensed capacity or delete
another managed object.
Proprietary and Confidential Information of Arbor Networks Inc.
85
SP and TMS User Guide, Version 8.0
Applying Appliance-based Licenses from a License File
Introduction
For SP appliances in appliance-based license mode and TMS appliances, the Import Licenses
page (Administration > System Maintenance > Licenses) allows you to upload all
license keys from one file. The license file contains all of the appliance names, model numbers,
and license keys that you need for all appliance-based licenses in your deployment. You can
upload the license file with the license keys when you do any of the following:
n install your initial appliances
n
upgrade your appliances
n
acquire new appliances for your deployment.
You can also configure the license key for individual appliances on the Appliance tab of the
Add Appliance page or the Edit Appliance page. See “Adding, Editing, and Deleting an SP
Appliance” on page 104.
Note: Contact your Arbor Networks sales representative to obtain a license file.
Applying licenses from a license file
To apply licenses from a license file:
1. Navigate to the Import Licenses page (Administration > System Maintenance >
Licenses).
2. Click Browse.
3. Select your license file, and then click Import.
SP displays the message, “License information successfully imported.”
4. Commit your changes to SP.
See “Committing configuration changes” on page 402.
86
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
About TMS Volumetric Licensing
Introduction
Volumetric licensing is available for some TMS appliances. With a volumetric license, a TMS
appliance can run countermeasures for volumetric attacks only. As a result, a TMS appliance
with a volumetric license can mitigate volumetric attacks but not other types of attacks, such
as application-layer attacks.
Note: You can add TMS appliances with volumetric licensing to an Arbor Networks
deployment without consuming any AIF license capacity.
About deploying TMS appliances with volumetric licensing
A deployment can include TMS appliances with volumetric licensing and TMS appliances
without volumetric licensing. Appliances with volumetric licensing can still run mitigations that
include countermeasures that the volumetric license does not support. ̵However, when they do,
the unsupported countermeasures are skipped and only the volumetric countermeasures are
run. See “TMS appliances that support volumetric licensing” below.
If a mitigation has countermeasures that the volumetric license does not support, a warning
message appears when that mitigation runs on a TMS appliance with a volumetric license. The
warning message lists all unsupported countermeasures in that mitigation. See
“Countermeasures that a volumetric license supports” below.
TMS appliances that support volumetric licensing
You can configure the following TMS appliances with a volumetric license:
TMS 2310 appliance
n
n
TMS 2800 appliance
n
TMS 4000 chassis-based appliances
n
TMS 5000 chassis-based appliances
n
TMS HD1000 appliance
n
TMS-VSM
Countermeasures that a volumetric license supports
A TMS appliance with a volumetric license can run the following countermeasures:
Invalid Packets
n
n
IP Address Filter Lists
n
Black/White Filter Lists
n
Packet Header Filtering
n
IP Location Filter Lists
n
Zombie Detection
n
Per Connection Flood Protection
n
TCP Syn Authentication (does not include HTTP Authentication)
n
TCP Connection Limiting
n
TCP Connection Reset
n
Payload Regular Expression
Proprietary and Confidential Information of Arbor Networks Inc.
87
SP and TMS User Guide, Version 8.0
88
n
Shaping
n
IP Location Policing
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
About Flexible Licensing
Introduction
Prior to the Arbor Networks SP 6.0 release, licensing of SP deployments was appliance-based.
The SP 6.0 release introduced Flexible Licensing. With SP 6.0, you could keep all of your
appliances in appliance-based license mode or you could convert all of your appliances to
flexible license mode.
The SP 6.0 Patch 3 release introduced hybrid licensing. With hybrid licensing, a deployment
can have SP appliances that use appliance-based licensing and SP appliances that use
Flexible Licensing. See “About Hybrid Licensing” on page 82 and “About Appliance-based
Licensing” on page 84.
The Arbor Networks SP 7.0.3 release introduced cloud-based Flexible Licensing. With
cloud-based licensing, you can use a virtual machine (VM) for the leader and backup leader in
your SP deployment. Prior to the introduction of cloud-based licensing, you uploaded a flexible
license to your physical leader and backup leader appliances. With cloud-based Flexible
Licensing, you configure the leader VM so that it can access a URL of a cloud license server. If
you configure a backup leader VM, it automatically receives from the leader VM the URL
configuration that it needs to access the cloud license server. For additional information about
cloud-based licensing, see “About Cloud-based Licensing” on page 96.
The leader's flexible license is used by all of the SP physical or virtual appliances in the
deployment that are in flexible license mode.
Note: The licenses for TMS appliances are always appliance-based.
About uploading a flexible license
You upload a flexible license so that you can assign the flexible license mode to new
appliances or to appliances that are currently in appliance-based license mode. You can also
upload a flexible license to accommodate new flexible-licensed capacity requirements. A
flexible license also allows you to install SP software on a virtual machine. For more
information, see Running SP in a Virtual Machine, available from the Arbor Technical
Assistance Center (https://support.arbor.net).
Note: With cloud-based licensing, instead of uploading a flexible license to your leader
appliance, you access a cloud-based license server from the VM leader and the system
downloads a local copy of the cloud license. See “About Cloud-based Licensing” on page 96.
Before you upload a flexible license, contact the Arbor Technical Assistance Center (ATAC) to
obtain the correct flexible license for your deployment. You upload a flexible license on the
Deployment Status page (System > Status > Deployment Status) of the leader
appliance. See “Uploading a Flexible License” on page 92.
Important: After you download a flexible license file, you have 30 days to upload it to your
deployment before the ability to use that license file expires.
If you deployment has a physical leader appliance and a backup leader appliance, be sure to do
the following:
n When you contact ATAC to request a flexible license, inform ATAC that your deployment
has a leader appliance and a backup leader appliance.
n
After you download the flexible license from the license portal, upload the license to both
Proprietary and Confidential Information of Arbor Networks Inc.
89
SP and TMS User Guide, Version 8.0
the leader appliance and the backup leader appliance.
Note: You can upload the flexible license to a physical leader appliance on the Deployment
Status page (System > Status > Deployment Status). To upload the flexible license to
a physical backup leader, you must use the CLI. See “Uploading a Flexible License” on
page 92.
n
If you replace the leader appliance or backup leader appliance, upload a new license to the
replacement appliance.
About assigning the flexible license mode to an SP appliance
You can assign the flexible license mode to an SP appliance when you add or edit the
appliance. You can assign the flexible license mode to an SP appliance in appliance-based
license mode to convert its license mode. For information about assigning the flexible license
mode to an appliance, see “Configuring Appliance Settings for an SP Appliance” on page 106.
Note: Until you convert an SP 6000 appliance to flexible license mode, the appliance is in
appliance-based license mode and appears in the SP Web UI as a 5500 model appliance.
About flexible-licensed capacities
For all of the appliances in flexible license mode, licensed capacities are monitored and
enforced deployment-wide instead of for individual appliances. The following capacities are
licensed:
n Active users
n
AIF
n
Flows per second (core routers)
n
Flows per second (edge routers)
n
Managed objects
The licensed capacity for managed objects is the sum of the base licensed capacity (1,000
managed objects), the flexible-licensed capacity, and the licensed capacity of each
appliance in appliance-based license mode that has the data storage role.
n
Routers (core)
n
Routers (edge)
Note: With edge routers, SP does not populate peer managed object reports (reports that
appear in the Web UI at Reports > Peers). However, SP does report on peer-related
traffic for other managed objects (for example, the report at Reports > Customers >
Peers or at Reports > Applications > Peers).
About monitoring your flexible-licensed capacity
You can monitor your flexible-licensed capacity usage on the Deployment Status page
(System > Status > Deployment Status). This page has graphs that indicate when an
item is near a licensed capacity or when it has reached or exceeded a licensed capacity. The
Deployment Status table on this page displays the current usage for flexible-licensed
capacities. An asterisk is appended to the flexible-licensed capacities in this table. For
information about the Deployment Status page, see “Monitoring Your Deployment” on
page 335.
SP triggers license alerts and generates syslog messages when flexible-licensed capacities in
your deployment need your attention. For details on the alerts that are triggered, see
“Conditions that trigger a license alert for licensed capacities” on page 461. For information
90
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
about the syslog messages, see "SP Syslog Output Format BNF" in the SP and TMS
Advanced Configuration Guide.
You can also use the CLI to view more detailed information about your flexible-licensed
capacities and the actual license SKUs that you purchased. To use the CLI to view this
detailed information, log in to the leader appliance's CLI, and type services sp license
flexible show, and then press ENTER. For information about using the CLI commands, see
"Using CLI Commands" in the SP and TMS Advanced Configuration Guide.
If you need to modify your flexible-licensed capacity, contact your Arbor Networks sales
representative.
About a flexible license software subscription
When you purchase a flexible license, it comes with a one-year software subscription. With
this flexible license software subscription, the licensed capacities included in the license are
available with any version of SP that is released before the end of the one year software
subscription period. If you upgrade to a version of SP that is released after the one year
software subscription has expired, then the licensed capacities included in the software
subscription will no longer be available until you renew the software subscription.
When you renew a flexible license software subscription, the subscription is extended for
another year. After you renew a flexible license software subscription, the licensed capacities
are then available with any version of SP that is released before the end of the new software
subscription period. To renew a flexible license software subscription, contact your Arbor
Networks sales representative.
About time-based flexible licenses
With Flexible Licensing, if you have any time-based flexible licenses in your SP deployment, a
Time-Based Flexible Licenses table appears on the Deployment Status page (System >
Status > Deployment Status). Time-based flexible licenses include trial licenses for any of
the licensed capacities and AIF licenses. The table lists the licenses with the time remaining on
the license and the expiration date of the license. For AIF licenses, it lists only the license that
has the closest expiration date.
About Flexible Licensing enforcement
When a flexible-licensed capacity is reached or exceeded, SP enforces the licensed capacity
by limiting the usage of your deployment. The limitation on your deployment depends on the
flexible-licensed capacity that is reached or exceeded. For details on how Flexible Licensing is
enforced, see “About Flexible Licensing Enforcement” on page 93.
About appliance roles
With Flexible Licensing, instead of different appliance types, an SP appliance is assigned a
role. When you convert an existing SP appliance to flexible license mode, the appliance is
assigned the role that corresponds to the appliance type that it had before conversion, except
for a Flow Sensor appliance. A Flow Sensor appliance is assigned the traffic and routing
analysis role. For more information about appliance types and appliance roles, see “About SP
appliance types and appliance roles” on page 38.
Proprietary and Confidential Information of Arbor Networks Inc.
91
SP and TMS User Guide, Version 8.0
Uploading a Flexible License
Introduction
On a physical leader appliance, an Upload Flexible Licensing button appears in the
upper-right corner of the Deployment Status page. You can click this button to upload a
flexible license. See “About uploading a flexible license” on page 89.
Note: With cloud-based licensing, instead of uploading a flexible license to the leader VM, the
leader VM has access to a cloud license server. See “About Cloud-based Licensing” on
page 96.
Before you upload a flexible license, contact your Arbor Networks sales representative to
obtain the correct license key for your deployment.
Note: If you deployment has a physical leader appliance and backup leader appliance, you
must upload the flexible license to both appliances. To upload the flexible license to the backup
leader, you must use the CLI.
Important: After you download the flexible license file that you received from your Arbor
Networks sales representative, you have 30 days to upload it to your deployment before the
ability to use that license file expires.
Uploading a flexible license to your deployment in the Web Ui
To upload a flexible license to your deployment in the Web UI:
1. On the leader appliance, navigate to the Deployment Status page (System > Status >
Deployment Status).
2. In the upper-right corner of the page, click the Upload Flexible License button.
3. In the Upload Flexible License window, browse to the license file that you received from
your Arbor Networks sales representative, and then click Upload.
The Upload Flexible License window displays all of your licenses with their capacities. If
you have previously uploaded a flexible license, it displays the updated capacities and it
displays changes in capacities that resulted from uploading the new license.
4. Click Close.
After you upload a license, the flexible-licensed capacities in the Deployment Status table
are updated.
Uploading a flexible license to your deployment with the CLI
To upload a flexible license to your deployment with the CLI:
1. Copy the license file to your leader or backup leader appliance and store it in the following
directory: /base/store/files/OLFHQVHBILOH
OLFHQVHBILOH = the name of the license file
2. Log in to the leader appliance’s CLI by using the administrator name and password.
3. To import the license file, type / services sp license flexible import
disk:OLFHQVHBILOH, and then press ENTER.
OLFHQVHBILOH = the name of the license file
92
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
About Flexible Licensing Enforcement
Introduction
For appliances in flexible license mode, licensed capacities are monitored and enforced on a
deployment-wide basis for the following:
n Active users
n
AIF
n
Flows per second (core routers)
n
Flows per second (edge routers)
n
Managed objects
The licensed capacity for managed objects is the sum of the base licensed capacity (1,000
managed objects), the flexible-licensed capacity, and the licensed capacity of each
appliance in appliance-based license mode that has the data storage role.
n
Routers (core)
n
Routers (edge)
See “About Flexible Licensing” on page 89.
Overview of Flexible Licensing enforcement
SP triggers alerts and generates syslog messages when flexible-licensed capacities in your
deployment need your attention. When a flexible-licensed capacity is reached or exceeded, SP
enforces the licensed capacity by limiting the usage of your deployment. The limitation on your
deployment depends on the licensed capacity that is reached or exceeded. For information
about the license alerts, see “License Alert” on page 460.
Arbor recommends that you regularly monitor the status of your deployment of SP appliances in
flexible license mode to keep your deployment within the flexible-licensed capacities. You can
monitor the status of your deployment on the Deployment Status page (System > Status >
Deployment Status). If you need to increase your flexible-licensed capacity, contact your
Arbor Networks sales representative. See “Monitoring Your Deployment” on page 335.
Flexible-licensed capacity for active users
When the number of active users on SP appliances in flexible license mode exceeds 90% of
the flexible-licensed capacity, a license alert is triggered with an importance level of medium.
The alert is raised to an importance level of high when the number of active users reaches the
flexible-licensed capacity. When the active user limit is reached, a status message concerning
this licensing issue also appears on each page.
When the number of active users on SP appliances in flexible license mode reaches the
flexible-licensed capacity, only administrators who are in the system_admin account group are
able to log in to an appliance that is in flexible license mode. When any other user attempts to
log in to an appliance that is in flexible license mode, they will see an error message that
indicates that the flexible-licensed capacity for logged-in users has been reached. These users
will not be able to log in until other users log out or until the flexible-licensed capacity for active
users is increased. For information about the system_admin account group, see
“Pre-configured account groups” on page 301.
Proprietary and Confidential Information of Arbor Networks Inc.
93
SP and TMS User Guide, Version 8.0
Flexible-licensed capacity for routers
For routers that are managed by appliances in flexible license mode, SP monitors and enforces
the router capacity separately for core and edge routers.
Note: If you purchase flexible licenses for core routers and edge routers that are of equal
value, the core routers will have a higher fps capacity.
When the flexible-licensed capacity for core or edge routers in your deployment has been
reached, you can no longer associate new routers with a managing appliance that is in flexible
license mode. You must first either increase your flexible-licensed capacity or delete other
routers.
SP will not allow you to convert an appliance to flexible license mode if the number of core or
edge routers managed by that appliance will cause your deployment to exceed the flexiblelicensed capacity.
Flexible-licensed capacity for flows per second
For routers that are managed by appliances in flexible license mode, SP monitors and enforces
the flows per second capacity separately for core and edge routers.
When the number of flows per second deployment-wide for core or edge routers exceeds 90%
of the flexible-licensed capacity for 5 minutes, a license alert is triggered with an importance
level of medium. The alert is raised to an importance level of high when the number of flows per
second deployment-wide for core or edge routers exceeds the flexible-licensed capacity for 5
minutes.
When the flexible-licensed capacity for flows per second for core or edge routers has been
exceeded for 5 minutes, SP begins to sample the traffic on all appliances that have the traffic
and routing analysis role to bring the flows per second in line with the licensed capacity. SP
continues to drop packets that exceed the flexible-licensed capacity for flows per second until
the flows per second remains below the flexible-licensed capacity for 5 minutes. You can
increase your flexible-licensed capacity for flows per second for core or edge routers to avoid
this dropping of packets by SP.
Licensed capacity for managed objects
The licensed capacity for managed objects is the sum of the base licensed capacity (1,000
managed objects), the flexible-licensed capacity, and the licensed capacity of each appliance
in appliance-based license mode that has the data storage role.
Note: The VPN sites of a VPN managed object do not count against the managed object
license limit.
When the number of managed objects exceeds 90% of the licensed capacity, a license alert is
triggered with an importance level of medium. The alert is raised to an importance level of high
when the number of managed objects reaches the licensed capacity.
When the licensed capacity for managed objects in your deployment has been reached, you
can no longer add managed objects. You must either increase your licensed capacity or delete
one or more managed objects.
Flexible-licensed capacity for AIF
AIF licenses can have a 5G, 20G, 40G, or 100G capacity. To enable AIF, you must add an AIF
license for each TMS appliance, and the capacity of each AIF license must be equal to or
94
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
greater than the bandwidth of the TMS appliance. For example, if you have two 20G AIF
licenses, AIF would be enabled if you have two TMS appliances and each TMS appliance has
a bandwidth of 20G or less. However, AIF would not be enabled if any of the TMS appliances
has a bandwidth greater than 20G or if you have three or more TMS appliances.
When an AIF license is within 30 days of expiration, a license alert is triggered with an
importance level of medium. When the TMS appliances in your deployment exceed the AIF
licensed capacity, a license alert is triggered with an importance level of high.
When the AIF licensed capacity is exceeded, AIF is disabled for all of the TMS appliances.
Note: When you initially upload a flexible license, if you have an AIF subscription, then the
AIF subscription is moved to the flexible license and is enforced by the flexible license.
Proprietary and Confidential Information of Arbor Networks Inc.
95
SP and TMS User Guide, Version 8.0
About Cloud-based Licensing
Introduction
Cloud-based licensing allows you to use a virtual machine (VM) for the leader and backup
leader in your SP deployment. Prior to the introduction of cloud-based licensing, a physical SP
appliance was required for the leader and backup leader.
With cloud-based licensing, the leader and backup leader must be a VM. When the leader and
backup leader are VMs, you have the following options for your SP deployment:
n You can use VMs for your entire SP deployment.
n
You can have a deployment that is a combination of VMs and physical appliances.
The deployment can be a Flexible Licensing deployment where all of the appliances and
VMs are in flexible license mode. The deployment can also be a hybrid license deployment
where some of the appliances and VMs are in flexible license mode and other appliances
are in appliance-based license mode. See “About Flexible Licensing” on page 89 and
“About Appliance-based Licensing” on page 84.
For information about running SP in a virtual machine (VM), see Running SP 8.0 in a Virtual
Machine, available from the Arbor Technical Assistance Center (https://support.arbor.net).
How cloud-based licensing works
With cloud-based licensing, instead of uploading a flexible license to your leader and backup
leader appliance, you access a cloud license server from the VM leader and a local copy of the
cloud-based license is checked out to the leader. You configure the leader's access to the
cloud license server using the leader's CLI. If you configure a backup leader VM, it
automatically receives from the leader VM the URL configuration it needs to access the cloud
license server. For information about accessing the cloud license server, see SP and TMS
Licensing Guide, available from the Arbor Technical Assistance Center
(https://support.arbor.net).
After the local copy of the cloud license is downloaded, SP then tries to communicate with the
server on a regular basis throughout each day to refresh the local copy. If SP cannot
communicate with the cloud license server, the local copy of the license continues to remain
valid for 10 days. After 10 days, the local copy of the license expires, and the ability to access
and use SP is severely limited. See “How SP enforces cloud-based licensing” below.
Note: If you purchase additional licensed capacity, the updated license is automatically
obtained by the leader after Arbor updates the license. The license capacity changes appear
on the Deployment Status page after the local copy of the cloud-based license is
automatically refreshed, which can take up to three hours. You can also reload the Deployment
Status page to see the updated license information.
How SP enforces cloud-based licensing
If your local copy of the cloud-based license expires, your use of SP is limited as follows:
Flow is not processed on appliances in flexible license mode.
n
n
96
Only admin users can log in (a total of 25).
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 4: SP Licensing
How SP informs you about the status of cloud-based licensing
SP uses the following methods to inform you about the status of your cloud-based licensing:
Cloud-based licensing status locations
Method
Description
Cloud Based
License window
If the local copy of the cloud license will expire in 9 or fewer days,
then a message window appears when an SP administrator logs into
SP. This window displays one of the following types of messages:
n
n
A warning that SP was unable to refresh the local copy on the
leader and the number of days until the local copy will expire
A warning that the local copy has expired
These warnings include the following information:
n
n
n
The date and time of the last successful refresh
The date and time of the last attempted refresh
The date and time when the license expired or will expire
This window also includes a link to the Deployment Status page
where you can manually try to refresh the local copy of the cloud
license.
Cloud-based
License section on
the Deployment
Status page
An information section appears at the bottom of the Deployment
Status page. If the last attempted refresh of the local copy of the
cloud license was successful, then this section displays the date and
time of the refresh with no additional information. If the last refresh
was unsuccessful, then this section displays one of the following
types of messages:
n
A warning that SP was unable to refresh the local copy on the
leader and the number of days until the local copy will expire
n
A warning that the local copy has expired
These warnings include the following information:
n
n
n
n
An error message that can help debug cloud-based license issues,
particularly if you need to contact ATAC
The date and time of the last successful refresh
The date and time of the last attempted refresh
The date and time when the license expired or will expire
This section also includes a Refresh Local Copy of License
button. You can click this button to attempt to refresh the local copy
of the cloud license manually. See “About the Cloud-based License
section on the Deployment tab” on page 340.
Proprietary and Confidential Information of Arbor Networks Inc.
97
SP and TMS User Guide, Version 8.0
Cloud-based licensing status locations (Continued)
Method
Description
License alerts
SP generates the following license alerts for cloud-based licensing:
n
n
An alert with an importance level of medium when the copy of the
cloud license on the leader or backup leader will expire in the next
1 to 9 days. The alert includes the name of the leader or backup
leader VM.
An alert with an importance level of high when the copy of the
cloud license on the leader or backup leader will expire in less than
1 day or has already expired. The alert includes the name of the
leader or backup leader VM.
If the local copy of the cloud license has not expired, these alerts
include the number of days until it expires.
Status message
98
A status message appears at the top of the page of the SP Web UI
whenever there is a cloud-based license issue.
Proprietary and Confidential Information of Arbor Networks Inc.
Part II:
System Administration
SP and TMS User Guide, Version 8.0
100
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5:
Configuring SP Appliances
Introduction
This section describes how to complete the basic configuration of SP appliances.
User access
Administrators can perform all actions in this section. Non-administrative users cannot make
configuration changes.
In this section
This section contains the following topics:
About Configuring SP Appliances
102
Adding, Editing, and Deleting an SP Appliance
104
Configuring Appliance Settings for an SP Appliance
106
Configuring SNMP Settings for an SP Appliance
108
Configuring High Availability Settings
110
Configuring HTTPS Access Rules Settings for an SP Appliance
112
Configuring the ArborFlow Export Setting
113
Configuring SSL Certificates
114
SP and TMS User Guide, Version 8.0
101
SP and TMS User Guide, Version 8.0
About Configuring SP Appliances
Introduction
You can view and delete SP appliances on the Configure Appliances page (Administration
> Appliances). This topic describes the Configure Appliances page and the different tasks
for configuring SP appliances depending on their type of role. For similar information for TMS
models, see “About Configuring TMS Models” on page 526.
If you are replacing an SP appliance with an RMA replacement, also see “Replacing an SP
Appliance with an RMA Replacement” in the SP and TMS Advanced Configuration Guide.
For information about securing your Arbor Networks appliances, see “Securing Your Arbor
Networks Appliances in the SP and TMS Advanced Configuration Guide.
About the Configure Appliances page
The Configure Appliances page contains the following information:
Configure Appliances page details
Column
Description
Select if you want to delete a non-leader appliance.
You cannot delete the leader.
Name
The hostname, type, and description of an appliance.
License
Mode
The license mode of the appliance. If the license mode is Appliance, then
the appliance is in appliance-based license mode. If the license mode is
Flexible, then the appliance is in flexible license mode.
This column appears only if a flexible license has been uploaded. See
“Uploading a Flexible License” on page 92.
Tags
The tags that have been applied to an appliance configuration.
Tags can help you categorize and search for appliances in your deployment.
For example, if you are staging new appliances, you might tag them with
“staged.”
IP Address
The IP address of an appliance.
Configuration
Any devices that peer with or forward flow information to an appliance.
Configuration tasks for the different SP appliance types or roles
With SP appliances in appliance-based license mode, the different types of appliances have
fixed roles. With SP appliances in flexible license mode, instead of different appliance types, an
appliance is assigned a role.
The names for the appliance types and appliance roles are the same, except for the Flow
Sensor appliance. When you convert a Flow Sensor appliance from appliance-based license
mode to flexible license mode, it becomes an appliance that has the traffic and routing analysis
role. See “About SP appliance types and appliance roles” on page 38.
102
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5: Configuring SP Appliances
The following table list the different appliance roles or types with their configuration tasks:
Appliance role/type configuration task overview
Role or Type
Configuration Tasks
Data storage
1.
2.
3.
4.
Flow Sensor (appliance-based
licensing only)
1. Add/edit the appliance settings.
2. (Optional) Configure SP appliance SNMP settings.
3. (Optional) Configure ArborFlow Export settings
Traffic and routing analysis
1. Add/edit the appliance settings.
2. (Optional) Configure SP appliance SNMP settings.
User interface
1.
2.
3.
4.
5.
Add/edit the appliance settings.
(Optional) Configure SP appliance SNMP settings.
Configure high availability settings.
Configure flow settings.
Add/edit the appliance settings.
(Optional) Configure SP appliance SNMP settings.
Configure SSL certificate settings.
Configure high availability settings.
Configure HTTPS access rules.
Proprietary and Confidential Information of Arbor Networks Inc.
103
SP and TMS User Guide, Version 8.0
Adding, Editing, and Deleting an SP Appliance
Introduction
This topic describes how to configure and delete an SP appliance on the Configure Appliances
page (Administration > Appliances). For similar information for TMS models, see “Adding,
Editing, and Deleting a TMS Model” on page 528.
Adding and editing an SP appliance
To add or edit an SP appliance:
1. Verify that you have added the SP appliance to the deployment by using its CLI.
For more information about adding SP appliances, see the SP Quick Start Cards.
2. Navigate to the Configure Appliances page (Administration > Appliances).
3. Do one of the following:
l
To add a new appliance, click Add Appliance.
l
To edit an existing appliance, click a name link.
The leader appliance is automatically added during the CLI bootstrap process.
4. Configure the settings on each of the tabs that appear for your SP appliance.
See “Tabs on the Appliance pages for SP appliances” below.
For a task overview of the appliance that you are configuring, see “Configuration tasks for
the different SP appliance types or roles” on page 102.
5. Click Save, and then commit your changes.
Tabs on the Appliance pages for SP appliances
The following table lists the different tabs that can appear on the Add Appliance page and the
Edit Appliance page:
Tabs on the Appliance pages
104
Tab
Description
Appliance
Allows you to configure the settings for your SP appliance.
See “Configuring Appliance Settings for an SP Appliance” on
page 106.
SNMP
Allows you to configure optional SNMP settings for an appliance.
See “Configuring SNMP Settings for an SP Appliance” on page 108.
Arbor Flow Export
(Only Flow Sensor appliances with appliance-based licensing) Allows
you to configure a Flow Sensor appliance to ignore ArborFlow for DoS
detection.
See “Configuring the ArborFlow Export Setting” on page 113.
SSL Certificates
(Only appliances that have the user interface role) Allows you to
upload SSL certificates.
See “Configuring SSL Certificates” on page 114.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5: Configuring SP Appliances
Tabs on the Appliance pages (Continued)
Tab
Description
High Availability
(Only appliances that have the user interface role or the data storage
role) Allows you to configure either managed-object replication for an
appliance that has the data storage role or the backup leader and
failover timeout for an appliance that has the user interface role.
See “Configuring High Availability Settings” on page 110.
HTTPS Access
Rules
(Only appliances that have the user interface role) Allows you to
configure the CIDR blocks from which you want to allow HTTPS
access.
See “Configuring HTTPS Access Rules Settings for an SP Appliance”
on page 112.
For a task overview for the appliance that you are configuring, see “Configuration tasks for the
different SP appliance types or roles” on page 102.
Deleting SP appliances
To delete an SP appliance:
1. Navigate to the Configure Appliances page (Administration > Appliances).
2. Select the check boxes for the appliances that you want to delete, and then click Delete.
Proprietary and Confidential Information of Arbor Networks Inc.
105
SP and TMS User Guide, Version 8.0
Configuring Appliance Settings for an SP Appliance
Introduction
On the Add Appliance page or Edit Appliance page, you can use the Appliance tab to add or
edit basic SP appliance settings and to configure network interfaces for appliances that can
accept flow. For general information about configuring SP appliances, see “Adding, Editing,
and Deleting an SP Appliance” on page 104.
Configuring SP appliance settings
To configure SP appliance settings:
1. Navigate to the Add Appliance page or the Edit Appliance page.
See “Adding and editing an SP appliance” on page 104.
2. Click the Appliance tab and configure the appliance settings.
See “Appliance tab settings” below.
3. Click Save.
Appliance tab settings
Use the following table to configure the Appliance tab settings:
Appliance tab settings
106
Setting
Description
Name box
Type a QDPH for the appliance.
Description box
Type a GHVFULSWLRQ of the appliance.
Tags box
Type any WDJV that you want to apply to the appliance. After you
type a tag, press COMMA, TAB, or ENTER to set the tag and to
continue.
Tags can help you categorize and search for appliances in your
deployment. For example, if you are staging new appliances, you
might tag them with “staged.”
IP Address box
Type the ,3 DGGUHVV of the appliance.
Appliance list
Select the appliance role.
Note: If you select Flow Sensor, and then select Flexible as the
license mode, then Flow Sensor is changed to Traffic and
Routing Analysis. If Flexible is selected as the license mode,
then Flow Sensor is disabled in this list.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5: Configuring SP Appliances
Appliance tab settings (Continued)
Setting
Description
License Mode
options
Click Appliance or Flexible to assign the license mode for this
appliance. These options appear only if you have uploaded a flexible
license on the Deployment Status page. See “Uploading a Flexible
License” on page 92.
The option that you select determines how licensed capacities are
monitored for that appliance. If you select Appliance, then the
appliance is assigned the appliance-based license mode and the
licensed capacity for routers is monitored for that individual
appliance. If you select Flexible, then the appliance is assigned the
flexible license mode and licensed capacities are monitored on a
deployment-wide basis. See “About Appliance-based Licensing” on
page 84 and “About Flexible Licensing” on page 89.
Note: SP will not allow you to change the license mode of an
appliance if the change would cause the licensed capacity for
routers to be exceeded.
If you select Appliance, then the License Key boxes appear, and
the Manager list appears for Flow Sensor appliances.
Note: If you change the license mode of a Flow Sensor appliance
from appliance-based license mode to flexible license mode, then it
becomes an appliance that has the traffic and routing analysis role.
Any routers that are managed by this appliance are assigned the
Edge license type.
License Key boxes
(Only appliances in appliance-based license mode) Type the PRGHO
QXPEHU and OLFHQVH NH\ for the appliance.
You must type the full license key, including the model number (for
example, CP-5500-5). If your license key has an expiration value,
then type it as part of the model number (for example, CP-5500-5ex1454998000).
You can obtain the license key from Arbor Technical Assistance
Center.
Note: After you convert an SP appliance to flexible license mode,
the License Key boxes no longer appear.
Manager list
(Only Flow Sensor appliances) Select the manager appliance for
the appliance that you are adding.
Flow section
Click Enabled next to the interface or interfaces that you want to
use to accept flow.
Flow is a characterization of the network traffic. It defines the traffic
that is seen. It provides SP with information from layers 1, 3, and 4
for the flows that traverse a network.
Important: When the Flow section appears, you must enable an
interface to accept flow. The Flow section does not appear for an
appliance that has the user interface role.
Proprietary and Confidential Information of Arbor Networks Inc.
107
SP and TMS User Guide, Version 8.0
Configuring SNMP Settings for an SP Appliance
Introduction
You can use the SNMP tab to add or edit the SNMP settings when you configure an SP
appliance. SNMP settings are optional. The SNMP agent runs only when SP services run.
When you stop services or if you do not install the SP package, SNMP is not available. For
general information about configuring SP appliances, see “Adding, Editing, and Deleting an SP
Appliance” on page 104.
Configuring SP appliance SNMP settings
To configure SP appliance SNMP settings:
1. Navigate to the Add Appliance page or the Edit Appliance page.
See “Adding and editing an SP appliance” on page 104.
2. Click the SNMP tab, and configure the appliance SNMP settings.
See “SP Appliance SNMP settings” below.
3. Click Save.
SP Appliance SNMP settings
Use the following table to configure the SP appliance SNMP settings:
SP Appliance SNMP settings
108
Setting
Description
SNMP Version (v1/v2c
and v3) check boxes
Select the SNMP version that you use.
SNMP System Contact
box
Type the HPDLO DGGUHVV of the administrator.
SNMP System Location
box
Type the ORFDWLRQ of the appliance (for example, Boston).
SNMP Community String
box
(Versions 1 and 2c only) Type the FRPPXQLW\ VWULQJ.
For community string requirements, see “About SNMP
community strings” on the facing page.
SNMP Security Level list
(Version 3 only) Select the security level for SNMP v3
connections.
SNMP Authentication
Protocol list
(Version 3 only) Select the encryption hash algorithm.
SNMP Authentication
Username box
(Version 3 only) Type the XVHU QDPH for SNMP
authentication.
SNMP Authentication
Password box
(Version 3 only) Type the SDVVZRUG for SNMP
authentication.
SNMP Privacy Key box
(Version 3 only) Type the private SNMP NH\.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5: Configuring SP Appliances
About SNMP community strings
If you use SNMP version 1 or 2c, then you must set a community string so that you can access
SNMP data on the appliance. The community string can contain up to 32 characters and can
include any characters except the following:
n quotation mark (“)
n
apostrophe (‘)
n
backslash (\)
n
pipe (|)
n
tab
Proprietary and Confidential Information of Arbor Networks Inc.
109
SP and TMS User Guide, Version 8.0
Configuring High Availability Settings
Introduction
You can use the High Availability tab to add or edit the following settings when you
configure:
n Managed object replication on an appliance that has the data storage role
n
The backup leader and failover timeout on an appliance that has the user interface role
Note: With flexible licensing on a physical appliance, you must also upload the flexible
license to both the leader appliance and the backup leader appliance. You can upload the
flexible license to the leader appliance on the Deployment Status page (System > Status
> Deployment Status). To upload the flexible license to the backup leader, you must use
the CLI. See “Uploading a Flexible License” on page 92.
Note: With cloud-based licensing, you configure the leader VM so that it has access to a
cloud license server and the backup leader VM automatically receives the URL
configuration that it needs to access the cloud license server. See SP and TMS Licensing
Guide at https://support.arbor.net.
For additional information about high availability, see "About High Availability Configuration" in
the SP and TMS Advanced Configuration Guide. For additional information about configuring
high availability with a VM leader and VM backup leader, see Running SP 8.0 in a Virtual
Machine at https://support.arbor.net/.
For general information about configuring SP appliances, see “Adding, Editing, and Deleting an
SP Appliance” on page 104.
Configuring replicated managed objects on an appliance that has the data storage role
To configure replicated managed objects on an appliance that has the data storage role:
1. Navigate to the Add Appliance page or the Edit Appliance page for the appliance.
See “Adding and editing an SP appliance” on page 104.
2. Click the High Availability tab.
3. Click Edit Replicated Managed Object List.
4. Use the selection wizard to select the managed objects that you want to replicate on the
appliance.
See “Using Selection Wizards” on page 31.
5. Click Save.
Configuring high availability settings on an appliance that has the user interface role
To configure the high availability settings on an appliance that has the user interface role:
1. Navigate to the Add Appliance page or the Edit Appliance page for the appliance.
See “Adding and editing an SP appliance” on page 104.
110
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5: Configuring SP Appliances
2. Click the High Availability tab, and use the following table to configure the high
availability settings:
Setting
Description
Backup Leader
check box
Select to designate the appliance as the backup leader.
Automated
Failover Timeout
box
Type the number of PLQXWHV that you want the backup leader
to wait after losing contact with the leader before it takes over
as the leader. Leave blank to disable automated failover.
A deployment can have only one backup leader.
Tip: Type a number that is high enough to prevent the backup
leader from taking over during temporary network issues.
3. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
111
SP and TMS User Guide, Version 8.0
Configuring HTTPS Access Rules Settings for an SP Appliance
Introduction
You can use the HTTPS Access Rules tab to add or edit HTTPS access rules for an
appliance that has the user interface role. For general information about configuring SP
appliances, see “Adding, Editing, and Deleting an SP Appliance” on page 104.
Important: When you add or edit HTTPS access rules, SP overwrites any previously
configured HTTPS access rules.
Configuring HTTPS access rules settings
To configure HTTPS access rules on an appliance that has the user interface role:
1. Navigate to the Add Appliance page or the Edit Appliance page for the appliance that has
the user interface role.
See “Adding and editing an SP appliance” on page 104.
2. Click the HTTPS Access Rules tab.
3. Click Edit CIDRs, and then use the CIDR Wizard to enter the CIDR blocks from which
you want to allow HTTPS access.
4. (Optional) If you want to upload the local HTTPS access rules that are currently
configured for the appliance, click Load Local Rules.
You can load local rules once. SP removes this button after you save and commit the local
rules.
5. Click Save.
This procedure applies only to HTTPS access rules. You can configure other types of access
rules locally on each individual appliance.
112
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5: Configuring SP Appliances
Configuring the ArborFlow Export Setting
Introduction
With appliance-based licensing, when you configure an Flow Sensor appliance, you can use
the ArborFlow Export tab to prohibit the appliance from generating DoS alerts. For general
information about configuring SP appliances, see “Adding, Editing, and Deleting an SP
Appliance” on page 104.
Configuring ArborFlow on a Flow Sensor appliance
To configure ArborFlow on a Flow Sensor appliance:
1. Navigate to the Add Appliance page or the Edit Appliance page for the Flow Sensor
appliance.
See “Adding and editing an SP appliance” on page 104.
2. Click the ArborFlow Export tab.
3. Select the Ignore ArborFlow for DoS Detection check box to configure the appliance
to ignore ArborFlow when it detects DoS alerts.
4. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
113
SP and TMS User Guide, Version 8.0
Configuring SSL Certificates
Introduction
You can use SSL certificates with appliances that have the user interface role. You can use
the default certificate package that Arbor provides to new customers or use third-party SSL
certificates. If you use the default Arbor certificate package and then require a new certificate,
you can request a new certificate from Arbor or acquire a new certificate package from a
different authority.
If you use an Arbor certificate package, you must use the CLI and the following command to
install it: / system files install disk:ILOHBQDPH, where ILOHBQDPH = the name of
the package file. If you use a third-party SSL certificates, use the SSL Certificates tab to
upload the certificates.
Note: The SSL Certificates tab appears when you are configuring a user interface appliance
only if you are logged in to the leader’s Web UI. You cannot access the SSL Certificates tab
if you are logged in to the Web UI of a non-leader appliance that has the user interface role.
For general information about configuring SP appliances, see “Adding, Editing, and Deleting an
SP Appliance” on page 104.
About SSL certificates
SSL Web server certificates keep information private while in transit between your Web server
and Web browsers. You can install SSL Web server certificates from external authorities (such
as RSA or VeriSign).
Important: If you upload external certificate files, make sure they are properly formatted and
the lines are terminated with UNIX style newline characters.
Important: SP does not support password-protected certificates.
Uploading third-party SSL certificates
To upload third-party SSL certificates for an appliance that has the user interface role:
1. On the leader appliance, navigate to the Add Appliance page or the Edit Appliance page
for the appliance that has the user interface role.
See “Adding and editing an SP appliance” on page 104.
2. Click the SSL Certificates tab.
3. Click Upload Certificates From Files.
4. In the Upload SSL Certificates window, click Browse next to each of the following
certificates and select the certificate:
114
Type of
certificate
Description
SSL x509
certificate
SSL x509 provides information about the certificate such as the
certificate owner and certificate validity.
RSA Key
certificate
The RSA key provides encryption to secure the certificate.
Important: The RSA key must be in PKCS#1 compatible format.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 5: Configuring SP Appliances
Type of
certificate
CA certificate
Description
The CA certificate allows the authority to sign the certificate. Most
SSL companies provide this certificate.
5. In the Upload SSL Certificates window, click Upload.
6. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
115
SP and TMS User Guide, Version 8.0
116
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 6:
Configuring SP to Learn about Your
Network
Introduction
This section describes how to configure the settings that teach SP about your network.
User access
Administrators can perform all actions in this section. Non-administrative users cannot make
configuration changes.
In this section
This section contains the following topics:
Defining Your Network and Configuring Network Boundaries
118
About Interface Classification
119
About the Auto-Configuration Rules
122
Configuring Interface Classification Rules
123
Configuring Address Space
128
SP and TMS User Guide, Version 8.0
117
SP and TMS User Guide, Version 8.0
Defining Your Network and Configuring Network Boundaries
Introduction
You can define your network for SP and configure your network boundary on the Configure
Network page (Administration > Monitoring > Network). When you configure your
network boundary, you define the border between your network and the rest of the Internet.
This boundary is used to determine when and where traffic enters your network and, by default,
to determine configured managed objects, such as your customers. This is a core building block
for understanding traffic flow in both DoS and anomaly detection as well as in Traffic and
Routing reporting with SP.
Modeling the network
To create a model of the network, SP uses the configured local ASNs and the set of allocated
classless inter-domain route (CIDR) blocks (prefixes) to map the traffic that flows over
interfaces and flows across routers in your network. This model counts and monitors traffic that
crosses the peering edge and flows across the network core to other peers or customers
attached to the network. With this basic model, the system classifies traffic with directionality
and builds the network summary information from the data that the system collects.
How SP creates the network boundary
To determine the network boundary, SP uses the configured network model and autoconfiguration rules to classify interfaces as external, backbone, or internal. The network
boundary is the set of learned interfaces that connect to external peers in addition to any
interfaces that you manually configure as external.
For more information about auto-configuration, see “About Auto-Configuration Heuristics” on
page 950.
Defining your network for SP
Use the following table to configure the network definition settings on the Description tab:
Network definition settings
Setting
Description
Name box
Type the QDPH of your network.
Backbone ASNs
box
Type the $61V that your network includes.
ASNs can include any combination of public, private, and
confederated ASNs.
If an error message appears, you must correct the values before saving the configuration.
Viewing interface boundaries
To view interface boundaries:
1. Navigate to the Configure Network page (Administration > Monitoring > Network).
2. Click the Boundary tab.
3. Click Edit.
118
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 6: Configuring SP to Learn about Your Network
About Interface Classification
Introduction
SP automatically discovers which interfaces are on each router through SNMP polling of the
router or by detecting the interface in a flow record from the router. SP then classifies the
interfaces based on their traffic. Interface classification helps to build the picture of the traffic
that crosses the backbone (or core) of the network, customer boundaries, or important network
boundaries.
About discovering only the interfaces that match auto-classification rules
You can configure SP to discover only the interfaces that match auto-classification rules. The
interfaces that are not discovered are placed by SP into a single aggregate, untracked
interface. For example, you could configure SP to discover only business interfaces and other
mission-critical interfaces. To discover only interfaces that match an auto-classification rule,
you must select the Enable Dynamic Subscriber Interface Handling setting when you
configure the router. See “Configuring Advanced Router Settings” on page 147.
Note: You can also create an auto-configuration rule that assigns a matching interface to the
router's aggregate, untracked interface, even if another auto-configuration rule would
otherwise cause the interface to be discovered and tracked. For additional information, see
“Auto-configuration rule Action tab settings” on page 125 and the Merge with Router's
Aggregate Interface action.
Interface classifications
Interface classifications define the network boundaries and describe what is on- and off-net
traffic. SP uses the following interface classifications:
Interface classifications
Type
Description
External
The interface is connected to a peer that is external to your network.
Internal
The interface connects only to local hosts within your network.
Backbone
The interface connects to other interfaces within your network. The
interface may carry a mix of internal and external traffic.
Note: Backbone interfaces cannot be externally facing.
Mixed
The interface connects both to a peer external to your network and to a
router or local hosts within your network.
Note: SP does not auto-classify interfaces as “Mixed.” You must manually
classify “Mixed” interfaces.
Ignore
The interface’s traffic is ignored.
Note: SP does not auto-classify interfaces as “Ignore.” You must manually
classify “Ignore” interfaces.
Proprietary and Confidential Information of Arbor Networks Inc.
119
SP and TMS User Guide, Version 8.0
How auto-configuration works
Auto-configuration happens automatically every 4 hours at 2:50 hour offsets (for example,
02:50, 06:50, 10:50). The resulting data is then used to update the database every 4 hours at
3:00 hour offsets (for example, 03:00, 07:00, 11:00).
An additional process runs every 15 minutes to check for new interfaces. If new interfaces are
discovered, auto-configuration runs immediately for all interfaces. This out-of-sequence
process minimizes the loss of data when active network links are moved. If this additional
process runs, auto-configuration still runs on its normal schedule every 4 hours to ensure that
interfaces are classified according to the current traffic.
How SP uses auto-configuration rules to classify interfaces
SP automatically classifies every interface according to auto-configuration rules. You can
configure each auto-configuration rule to apply to all or a subset of routers and interfaces. In
addition, each auto-configuration rule can classify interfaces based on automatic heuristics
that use either correlated flow and BGP information or regular expression matches against
interface names and descriptions. Using auto-configuration rules, SP classifies an interface
and determines any directly connected peer ASNs for external interfaces. See “About AutoConfiguration Heuristics” on page 950 and “Configuring Interface Classification Rules” on
page 123.
How SP classifies interfaces using auto-configuration rules
The following explains how SP classifies interfaces using auto-configuration rules:
For each interface, SP checks each auto-configuration rule for a match.
n
n
For each matching rule, SP adds the interfaces to the interface boundary of any managed
objects listed in the rule.
For information about adding managed objects to a rule, see “Auto-configuration rule Action
tab settings” on page 125.
n
To set the classification of an interface, SP uses only the settings from the matching rule
with the lowest-numbered Rule Precedence.
For information about Rule Precedence and the settings that SP uses to set the
classification of an interface, see “Auto-configuration rule Action tab settings” on
page 125.
Manually running interface auto-classification
Interface auto-classification runs automatically in the background. It may also be run manually,
but you only need to run it manually when you want an immediate configuration update after a
change to an auto-configuration rule or to the physical network topology.
To manually run interface auto-classification:
1. Navigate to the Auto-Configuration Rules page (Administration > Monitoring >
Auto-Configuration Rules).
2. Select the check boxes for the rules that you want to run, and then click Run Rules Now.
To view the results, after the interface classification runs, navigate to the "Current Interface
Configuration" page (Administration > Monitoring > Current Interface
Configuration).
120
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 6: Configuring SP to Learn about Your Network
Manually setting the interface type and ASNs
You can manually set the interface type and ASNs on the Configure Interfaces page
(Administration > Monitoring > Interfaces). You would manually set an interface if it is
misconfigured by auto-configuration rules, or if it is not possible to maintain an
auto-configuration rule to configure the interface correctly. See “Configuring Interfaces” on
page 150.
Proprietary and Confidential Information of Arbor Networks Inc.
121
SP and TMS User Guide, Version 8.0
About the Auto-Configuration Rules
Introduction
You can review your current interface classification rules on the Auto-Configuration Rules
page (Administration > Monitoring > Auto-Configuration Rules) and run them
immediately. You can also add, edit, or delete rules.
See “About Interface Classification” on page 119.
Guidelines for searching on the Auto-Configuration Rules page
When you search with the Search box, use the following guidelines:
You can enter search values with or without keywords.
n
n
Search values and keywords are case-insensitive.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
See “Acceptable search keywords and values for rules” below.
Acceptable search keywords and values for rules
The following table lists the columns on the Auto-Configuration Rules page and the keywords
and values that you can use to search on that column in the Search box:
Search keywords for columns
Column to search
on
Acceptable keywords and
values
Name
n
n
n
Precedence
122
n
Examples
name:UXOH QDPH
descr:UXOH GHVFULSWLRQ
description:UXOH
GHVFULSWLRQ
n
precedence:UXOH
SUHFHGHQFH
n
n
n
name:highthreshold
descr:"Set type external"
description:"managed object
AS151"
precedence:1
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 6: Configuring SP to Learn about Your Network
Configuring Interface Classification Rules
Introduction
You can configure interface classification rules on the Auto-Configuration Rules page
(Administration > Monitoring > Auto-Configuration Rules). You can also configure
interface rules on the Boundary tab of a managed object, service, or subscriber. When you
configure interface rules, SP disables the default global boundary for interfaces. The
appliances then use these rules to match interface boundaries.
See “About Interface Classification” on page 119.
Configuring an interface classification rule
To configure an interface classification rule:
1. Do one of the following:
l
l
On the Auto-Configuration Rules page (Administration > Monitoring >
Auto-Configuration Rules), click Add Rule or click the name link of an existing rule.
In the Auto-Configuration Rules section of the Boundary tab of a managed object,
service, or subscriber group, click Add or click the name link of an existing rule.
For a managed object, see “Configuring router boundary settings for a customer, peer,
or profile managed object” on page 174
For a service, see “Adding and editing services” on page 227
For a subscriber group, see “Configuring subscriber groups” on page 251
2. On the Description tab, configure the following settings:
Setting
Description
Name box
Type the QDPH of the rule.
Description box
Type a GHVFULSWLRQ to help you identify the rule.
Rule Precedence
list
Select the priority that you want SP to place on the rule. The
lowest numbered rule is applied first.
3. On the Match tab, configure the following settings:
Setting
Description
Routers box
Choose one of the following steps:
Interface Subnet
Mask box
n
To select all routers, do nothing.
n
To select specific routers, click Select Routers, and then
use the selection wizard to select one or more routers. See
“Using Selection Wizards” on page 31.
Type the VXEQHW PDVN that you want to use for this rule.
This setting enforces the rule to match only interface IP
addresses within the specified subnet mask.
Proprietary and Confidential Information of Arbor Networks Inc.
123
SP and TMS User Guide, Version 8.0
Setting
Description
SNMP Field for
Interface Match
options
Select the SNMP field(s) to use for the interface match. SP
uses the regular expression that you enter in the Regular
Expression for Interface Match box to match against the
selected SNMP field(s). SP can match against the following
SNMP fields:
n
n
n
Description - the interface description (SNMP OID ifAlias)
Name - the interface name (SNMP OID ifDescr)
Description or Name - the interface description (SNMP
OID ifAlias) or the interface name (SNMP OID ifDescr)
Description is selected by default. If the SNMP name has
useful information, you can match against it. For example, you
might match against the interface name if it contains
information about the customer connected to the interface.
Regular
Expression for
Interface Match
box
Enter a regular expression to use to match against the SNMP
field(s) that you selected in SNMP Field for Interface
Match. When the regular expression matches the selected
SNMP field(s) of an interface, SP auto-configures the interface.
If you do not enter a regular expression, SP matches and autoconfigures all the interfaces of the selected routers.
For example, if you select Enable Dynamic Subscriber
Interface Handling when you configure the router, you can
type a regular expression that matches just your business
interfaces. Your business interfaces are then discovered on the
selected routers, while your consumer interfaces are not
discovered. See “About the Enable Dynamic Subscriber
Interface Handling setting” on page 148.
4. On the Action tab, configure the action settings.
See “Auto-configuration rule Action tab settings” on the facing page.
5. Click Save.
124
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 6: Configuring SP to Learn about Your Network
Auto-configuration rule Action tab settings
Use the following table to configure the auto-configuration rule Action tab settings:
Auto-configuration rule Action tab settings
Setting
Description
Use System
Auto-Configuration
Heuristics check box
To enable auto-configuration heuristics, select this check box.
See “About Auto-Configuration Heuristics” on page 950.
This check box is disabled if the Set Type or the Set ASNs
check boxes are selected.
Set Type options
To configure the classification type of the interfaces:
a. Select the Set Type check box.
b. Select a classification from the Set Type list. See “Interface
classifications” on page 119.
If the Set Type action is enabled and is set to Backbone,
Internal, or Ignore, then SP clears the ASNs setting for the
interface and ignores the Set ASNs action.
Set ASNS options
To associate ASNs with this rule:
a. Select the Set ASNS check box.
b. Type the $61V in the Set ASNs box.
If the Set ASNs check box is selected, but the ASN value is
blank, then SP clears the ASNs setting for the interface.
Proprietary and Confidential Information of Arbor Networks Inc.
125
SP and TMS User Guide, Version 8.0
Auto-configuration rule Action tab settings (Continued)
Setting
Description
Set Managed
Objects options
To associate one or more managed objects with this rule:
a. Select the Set Managed Objects check box.
b. From the Set Managed Objects list, select an option to set
the interface boundary type for the managed objects.
For a description of the interface boundary types, see
“Configuring Boundaries for Managed Objects” on
page 174.
c. Click Select Managed Objects, and then use the
selection wizard to select one or more managed objects. See
“Using Selection Wizards” on page 31.
If the auto-configuration rule matches an interface, then SP adds
the interface to the interface boundary of the selected managed
objects. SP also applies the interface boundary type to the
selected managed objects.
Important: If you configure an auto-configuration rule and select
a VPN managed object, then you must select Managed
object-facing for the interface boundary type to get traffic data
to appear in the VPN reports.
When you add an auto-configuration rule to a managed object,
the Set Managed Objects check box is automatically selected
and the managed object appears in the Managed Object box. If
the managed object is a VPN, then Managed object-facing is
selected as the interface boundary type. Otherwise, Simple is
selected as the interface boundary type. The interface boundary
type that is selected allows SP to determine the directionality of
the interface boundary.
High Threshold
options
To set the high threshold for the incoming or outgoing traffic of
the interface:
a. Select the High Threshold check box.
b. In the High Threshold box, type the SHUFHQWDJH RI WKH
LQWHUIDFH VSHHG to be used as the threshold.
SP triggers a threshold alert when the traffic on the interface
exceeds this threshold.
If the High Threshold check box is selected but the High
Threshold box is blank, then SP uses the threshold value that is
set on the Edit Interface page for that interface. If the interface
has no such setting, then the system defaults of 95% for high
threshold and -1 for the low threshold are used. The default of -1
disables the low threshold. See “Configuring Interfaces” on
page 150.
126
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 6: Configuring SP to Learn about Your Network
Auto-configuration rule Action tab settings (Continued)
Setting
Description
Low Threshold
options
To set the low threshold for the incoming or outgoing traffic of the
interface:
a. Select the Low Threshold check box.
b. In the Low Threshold box, type the SHUFHQWDJH RI WKH
LQWHUIDFH VSHHG to be used as the threshold.
SP triggers a threshold alert when the traffic on the interface
does not exceed this threshold.
If the Low Threshold check box is selected but the Low
Threshold box is blank, then SP uses the threshold value that is
set on the Edit Interface page for that interface. If the interface
has no such setting, then the system defaults of 95% for high
threshold and -1 for the low threshold are used. The default of -1
disables the low threshold. See “Configuring Interfaces” on
page 150.
SNMP Field for
Interface Tracking
options
Select whether to track interfaces by their name or description.
Name is selected by default. Select Description to track
dynamic interfaces by their SNMP description instead of their
SNMP name.
If the SNMP index or SNMP name of the interfaces might change
over time in your environment, then track the interfaces by their
SNMP description. The IDs that are used to track the interfaces
will then change only if the SNMP description changes.
You should select Description when the routers associated with
the rule are Broadband Network Gateway (BNG) routers. If you
also select Enable Dynamic Subscriber Interface Handling
when you configure the BNG router, then SP discovers and
tracks only the interfaces that match an auto-configuration rule.
For example, you can configure SP so that it discovers business
interfaces, but does not discover consumer interfaces. See
“About the Enable Dynamic Subscriber Interface Handling
setting” on page 148.
Merge with Router's
Aggregate Interface
check box
To assign the interface that the rule matches to the router's
aggregate, untracked interface, select this check box. This action
puts this interface into the router's aggregate interface, even if
another auto-configuration rule matches the interface and would
otherwise cause it to be discovered and tracked. This action
overrides the other auto-configuration rule.
Important: SP only creates an aggregate, untracked interface
for a router if you also select the Enable Dynamic Subscriber
Interface Handling check box on the router's Advanced tab.
See “Configuring Advanced Router Settings” on page 147.
This check box is disabled if the Use System
Auto-Configuration Heuristics check box is selected. The
other check boxes on the Action tab are cleared and disabled
when this check box is selected.
Proprietary and Confidential Information of Arbor Networks Inc.
127
SP and TMS User Guide, Version 8.0
Configuring Address Space
Introduction
You can configure different types of address space on or related to your network using the tabs
on the Configure Address Space page (Administration > Monitoring > Address Space).
About hole prefixes
A hole prefix is a more specific prefix covered by your address space that is not part of your
network. For example, if your address space is 10.0.0.0/8 but 10.0.128.0/24 has been given to
someone else, then 10.0.128.0/24 is a hole. Use hole prefixes to exclude these networks from
your address space.
Configuring IPv4 address space
Use the following table to configure the IPv4 address space settings on the IPv4 Space tab:
IPv4 address space settings
Setting
Description
Local Address Space
Prefixes box
Type the local DJJUHJDWHV for ASNs, using CIDR notation.
Type one prefix per line (for example, 10.1.1.0/24).
Local Address Space
Holes box
Type the local hole SUHIL[HV.
See “About hole prefixes” above.
About multicast traffic
Multicast traffic is traffic sent from one source address to one destination address that many
people share, called a multicast address. Multicast traffic can be beneficial because it can use
less bandwidth. The multicast address is an identifier for a group of hosts called a multicast
group. In IPv4, these addresses range from 224.0.0.0 to 239.255.255.255 (224.0.0.0/4).
If you use multicast traffic, you can enable SP to count the amount of incoming multicast traffic
through an internal object (router, interface, managed object). By default, this feature is
disabled in SP, and SP treats multicast traffic as dropped traffic.
SP does not provide information about outbound multicast traffic.
After you enable multicast traffic detection, you can view multicast data on the Multicast
reports.
See “Configuring Predefined Reports” on page 764.
Configuring multicast address space detection
To configure multicast address space detection:
1. Navigate to the Configure Address Space page (Administration > Monitoring >
Address Space).
2. Click the Multicast tab.
3. Select Classify matching traffic as multicast check box.
128
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 6: Configuring SP to Learn about Your Network
Before you enable multicast traffic recognition, verify that your routers can receive
multicast traffic.
4. Type the &,'5 EORFNV that you want SP to recognize in the Destination CIDRs box,
and then click Save.
For example, if you do not want to see internal routing protocol traffic that uses IP multicast,
exclude the CIDR block that includes the routing protocol traffic from the Destination CIDRs
list. SP will then treat internal routing protocol traffic on the network as dropped. The default
CIDR block is 224.0.0.0/4.
About dark IP space and detection
You can designate a portion of your unused IP space and internally used RFC1918 space as
dark IP space. SP considers any traffic that it sees as destined toward this space to be
malicious traffic. This includes hosts that might perform host and port scans that are directed
toward this space. A significant increase in dark IP traffic could indicate new malware, a worm,
or other threats propagating across the network. In order for SP to detect the dark IP address
space that is being used, you must enable Dark IP detection and configure the destination filter
(the source filter is optional).
Configuring dark IP address space detection
You use the Dark IP tab on the Configure Address Space page (Administration >
Monitoring > Address Space) to configure your local dark IP address space. The settings
on this tab are used to populate the Dark IP reports (Reports > Fingerprints > Dark IP).
Use the following table to configure dark IP address space detection settings on the Dark IP
tab:
Dark IP address space settings
Setting
Description
Enable Dark IP
Detection check box
Select to enable or clear to disable dark IP address space
detection.
If you disable dark IP address space detection, then you can save
and commit your changes without configuring other settings.
Source CIDRs box
(Optional) Type the VRXUFH &,'5 SUHIL[HV that you want to
designate as dark IP space.
Destination CIDRs
box
Type the GHVWLQDWLRQ &,'5 SUHIL[HV that you want to
designate as dark IP space.
Treat Source List as
Exclusive check box
Select to designate flows that have the same sources as traffic
that is not dark IP traffic.
Alert Thresholds
boxes (bps and pps)
Do one of the following:
n
n
To enable Dark IP alerts, type a YDOXH in the boxes (bps and
pps), and then select the appropriate value from the unit lists.
To disable Dark IP alerts, leave the boxes blank.
Commit your changes after configuring dark IP address space detection settings.
Proprietary and Confidential Information of Arbor Networks Inc.
129
SP and TMS User Guide, Version 8.0
Before configuring advanced address space settings
There are some settings on the Advanced tab that you should discuss with your Arbor
Networks Support Engineer (SE) before configuring. These include the Flow Export features
and the Exclude MPLS VPN Traffic feature. The Flow Export Features enable SP to ignore
interface classifications, and SP reports this traffic as flowing both into and out of the network.
The Exclude MPLS VPN Traffic feature allows you to prevent SP from counting VPN traffic
against non-VPN managed objects. If this feature is disabled, VPN traffic might count against
non-VPN managed objects that share match criteria with the VPN traffic.
Configuring advanced boundary settings
Use the following table to configure advanced boundary settings on the Advanced tab of the
Configure Address Space page (Administration > Monitoring > Address Space):
Advanced boundary settings
130
Setting
Description
Flow Export only Enabled
on External Interfaces
check box
Select if you only have flow export configured from your
external interfaces.
Flow Export only Enabled
on PE Interfaces check box
Select if you only have flow export configured from PE and
customer-facing interfaces.
Exclude MPLS VPN traffic
from non-VPN Managed
Objects check box
Select to allow SP to disassociate VPN traffic from nonVPN managed objects.
This setting is disabled by default.
Flows with at least this
number of MPLS labels
will be considered MPLS
VPN flows box
Type the QXPEHU RI ODEHOV that a flow must contain for
SP to recognize it as VPN traffic.
Determine the number of labels to include based on your
network configuration. The default setting is 2.
Start Delay box
Type the QXPEHU RI VHFRQGV you want SP to wait
between when the system starts and when it begins
collecting traffic data from the network.
This delay allows all of the BGP peering sessions with
network routers to be recognized and receive complete
routing tables.
Interface Classification
Period box
Type the QXPEHU RI VHFRQGV that you want SP to review
traffic each time interface auto-configuration runs.
Tip: Set this value high enough for the system to analyze
an appropriate number of flows for every interface that a
router monitors.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7:
Configuring Monitored Network Devices
Introduction
This section describes how to configure the network devices that SP monitors.
User access
Administrators can perform all actions in this section. Non-administrative users can view the
settings but cannot make configuration changes.
In this section
This section contains the following topics:
About the Configure Routers Page
132
Configuring Routers
136
Reassigning a Router to a Different Managing Appliance
139
Configuring Router SNMP Settings
140
Configuring Primary Router BGP Settings
142
Configuring Secondary Router BGP Settings
144
Configuring Router Flow Settings
146
Configuring Advanced Router Settings
147
Configuring Interfaces
150
SP and TMS User Guide, Version 8.0
131
SP and TMS User Guide, Version 8.0
About the Configure Routers Page
Introduction
You can view your configured routers on the Configure Routers page (Administration >
Monitoring > Routers). You can also filter the routers that are displayed on this page. For
information about configuring routers, see “Configuring Routers” on page 136.
In SP, the term “router” refers to routers in your network that export flow records or raw packet
data. SP might also BGP peer with these routers.
For information about navigating through multiple pages of routers, see “Navigating multiple
pages” on page 30.
About the Configure Routers page
The table on the Configure Routers page contains the following information:
Configure Routers page details
Column
Description
Select this check box if you want to delete a router.
Name
The configured name and description of a router.
License
Type
The type of license that applies to the router. If the router is managed by an
appliance in appliance-based license mode, then the license type is Appliancebased and the router counts toward the licensed capacity of that appliance. If
the router is managed by an appliance in flexible license mode, then the license
type is Core, Edge, or Unset. When the license type is Core or Edge, then the
router is counted toward the flexible-licensed capacity of your core routers or
edge routers.
This column appears only if a flexible license has been uploaded. See
“Uploading a Flexible License” on page 92.
Tags
The tags that have been applied to the router configuration.
Tags can help you categorize and search for routers in your deployment. For
example, you might want to tag all of your routers with the geographic locations
in which they are deployed.
Appliance
The name of the appliance that is monitoring the router that is sending flow,
SNMP, and BGP data if these are configured. If an appliance has not been
associated with a router, then nothing is displayed.
The
(in-progress) icon appears after an appliance name when the router is in
the process of being reassigned to that appliance. When the reassignment is
complete, the (done) icon appears after an appliance name until the page is
reloaded. The
(pending commit) icon appears after an appliance name when
the router has been reassigned to that appliance, and the configuration change
has been saved but not committed. If you hover the mouse pointer over either of
these icons, SP displays information about the reassignment process.
Note: A status message also appears at the top of the page when routers are
being reassigned to appliances and when the reassignment has completed.
132
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Configure Routers page details (Continued)
Column
Description
SNMP IP
The IP address that SP uses to query SNMP information.
BGP
The primary BGP session’s IP address, if BGP is configured, and the AS number
for the primary BGP session, if the AS is also configured. If BGP is not
configured or if only a secondary BGP session is configured, then nothing is
displayed.
Flow
Export IP
The IP address of the router that sends flow records to SP, if the Export IP is
configured. If the Export IP is not configured, then nothing is displayed. See
“Configuring Router Flow Settings” on page 146.
Flow
Sampling
The configured flow sampling rate for a router. If the sampling rate is not
configured, then 1/1 is displayed. If the flow is configured to use the router's
embedded sampling rate, then Embedded is displayed.
For information about how to monitor a router’s health, see “Monitoring Routers” on page 386.
About searching on the Configure Routers page
To search on the Configure Routers page, you can use any the following:
the Search box
n
See “Guidelines for searching on the Configure Routers page” below.
n
the Appliance list
The Appliance list allows you to filter by the managing appliance. You can select All or a
specific appliance. When you select an appliance, the keywords and search values for the
appliance appear in the Search box and the search is performed.
n
the "Filter by license type" links
The Appliance-based, Core, Edge, and Unset links allow you to filter by license type.
When you click a “Filter by license type” link, the keywords and search values for the license
type appear in the Search box and the search is performed. These links appear only if a
flexible license has been uploaded on the Deployment Status page. See “Uploading a
Flexible License” on page 92.
The Appliance-based link filters the list of routers to display only routers that are managed
by an appliance in the appliance-based license mode.The Core, Edge, and Unset links
filter the list of routers to display core, edge, or unset routers that are managed by an
appliance in flexible license mode.
Guidelines for searching on the Configure Routers page
When you search with the Search box, use the following guidelines:
You can enter search values with or without keywords.
n
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
Proprietary and Confidential Information of Arbor Networks Inc.
133
SP and TMS User Guide, Version 8.0
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
You can enter multiple keyword and value sets with a space between each set. This type of
search returns the routers that match all of the keyword and value sets. For example,
name:router123 descr:"router in abc" returns all the routers that have the text
string "router123" in the name of the router and the text string "router in abc" in the
description of the router.
n
See “Acceptable search keywords and values for routers” below.
Acceptable search keywords and values for routers
The following table lists the columns on the Configure Routers page and the keywords and
values that you can use to search on that column in the Search box. The Name column has
separate keywords for the name, type, and description, and the BGP column has separate
keywords for BGP and AS.
Search keywords for columns
Column
to search
on
Acceptable keywords and
values
Name
n
n
n
n
n
Tags
n
n
Appliance
n
n
n
SNMP IP
n
n
BGP
n
n
n
n
134
Examples
name:URXWHU QDPH
descr:URXWHU
GHVFULSWLRQ
description:URXWHU
GHVFULSWLRQ
type:OLFHQVH W\SH
license_type:OLFHQVH
W\SH
n
tag:URXWHU WDJ
tags:URXWHU WDJ
n
appliance:PDQDJLQJ
DSSOLDQFH
collector:PDQDJLQJ
DSSOLDQFH
device:PDQDJLQJ
DSSOLDQFH
n
snmp:6103 TXHU\ ,3
snmp_ip:6103 TXHU\ ,3
n
bgp:%*3 VHVVLRQ ,3
bgp_ip:%*3 VHVVLRQ ,3
as:UHPRWH %*3 $6 QXPEHU
bgp_as:UHPRWH %*3 $6
QXPEHU
n
n
n
n
n
n
n
n
n
n
n
n
name:router123
descr:"router in abc"
description:"router in xyz"
type:core
license_type:unset
tag:east_region
tags:midwest_region
appliance:appliance_231
collector:appliance_345
device:appliance_167
snmp:192.168.1.2
snmp_ip:192.168.1.2
bgp:192.168.1.1
bgp_ip:2001:48a8:48ff:ffff::2
as:65545
bgp_as:65545
Note: You cannot search on the prefix
"AS;" you can only search on the AS
number.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Search keywords for columns (Continued)
Column
to search
on
Flow
Export IP
Acceptable keywords and
values
n
n
n
Flow
Sampling
n
n
n
Examples
flow_ip:IORZ H[SRUW LS
flow_export:IORZ H[SRUW
LS
flow_export_ip:IORZ
H[SRUW LS
n
flow_sampling:VDPSOH
UDWH
flow_sample_rate:VDPSOH
UDWH
sample_rate:VDPSOH UDWH
n
Proprietary and Confidential Information of Arbor Networks Inc.
n
n
n
n
flow_ip:192.168.1.2
flow_export:192.168.1.2
flow_export_ip:192.168.1.2
flow_sampling:1/1000
flow_sample_rate:1/1000
sample_rate:1/1000
Note: You cannot search on the value
"Embedded."
135
SP and TMS User Guide, Version 8.0
Configuring Routers
Introduction
You can configure your routers on the Add Router page or Edit Router page. Configured
routers appear on the Configure Routers page. See “About the Configure Routers Page” on
page 132.
In SP, the term “router” refers to routers in your network that export flow records or raw packet
data. SP might also BGP peer with these routers.
Note: Reports that require you to select a peer managed object will not display traffic data
from routers monitored as edge routers.
Adding and editing routers
To add or edit a router:
1. Navigate to the Configure Routers page (Administration > Monitoring > Routers).
2. Choose one of the following steps:
l
To add a new router, click Add Router.
l
To edit an existing router, click its name link.
3. On the Add Router page or the Edit Router page, on the Router tab, configure the basic
router settings.
See “Basic router settings” on the facing page.
4. Click the following tabs and add or edit their settings:
Tab
Description
SNMP
Allows you to configure the SNMP settings for a router. See
“Configuring Router SNMP Settings” on page 140.
Primary BGP
Allows you to configure the primary BGP settings for a router. See
“Configuring Primary Router BGP Settings” on page 142.
Secondary BGP
Allows you to configure the secondary BGP settings for a router.
See “Configuring Secondary Router BGP Settings” on page 144.
Flow
Allows you to configure the flow settings for a router. See
“Configuring Router Flow Settings” on page 146.
Advanced
Allows you to configure the advanced settings for a router. See
“Configuring Advanced Router Settings” on page 147.
5. Click Save, and then commit your changes.
136
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Basic router settings
The Router tab has the following basic settings:
Basic router settings
Setting
Description
Name box
Type a QDPH for the router.
Description box
Type a GHVFULSWLRQ that will help you identify the router.
Tags box
Type the WDJV that you want to apply to this router. After you type a
tag, press COMMA, TAB, or ENTER to set the tag and to continue.
You can apply tags to router configurations. Tags can help you
categorize and search for routers in your deployment. For example,
you might want to tag all of your routers with the geographic
locations in which they are deployed.
Managing
Appliance list
Select the SP appliance that you want to manage the router. To
configure a router without a managing appliance, leave this field
blank or select None from this list. You configure a router without a
managing appliance if you are pre-staging a router.
If you change the appliance that manages a router, the baseline
and interface data that is associated with the router is copied
automatically to the new appliance when you commit this change.
See “Reassigning a Router to a Different Managing Appliance” on
page 139.
Note: A managing appliance can have a maximum of 32
configured primary and secondary BGP peering sessions.
Note: If an appliance is down, it does not appear in the Managing
Appliance list. An appliance is down if the leader appliance has
not received a heartbeat from it for at least two minutes. If an
appliance is down, it has a status of "No heartbeat" on the
Appliance Status page (System > Status > Appliance
Status).
Proprietary and Confidential Information of Arbor Networks Inc.
137
SP and TMS User Guide, Version 8.0
Basic router settings (Continued)
Setting
Description
License Type
options
Click Core or Edge to assign a license type to the router. The
license type that you select determines whether the router is
counted towards the flexible-licensed capacity of your core routers
or edge routers. If you are not ready to assign the license type, you
can leave the default setting of Unset. You might leave the default
setting of Unset when you are pre-staging the router.
These options appear only if the managing appliance is in flexible
license mode.
Assignment
History section
If other appliances have managed the router, this section appears
and lists the appliances that previously managed the router. For
each managing appliance, the list includes the date when the
router was reassigned from the appliance. The managing
appliances are listed in chronological order with the most recent
first.
When you change the appliance that manages a router, the
process of reassigning the router begins when you save and commit
this change. The appliance that previously managed the router is
added to this section, and SP displays (in-progress) after the
reassignment date until the reassignment is completed. If you hover
the mouse pointer over , SP displays information about the
reassignment.
If you change the managing appliance of a router and save the
changes, but do not commit the changes, then the appliance is
added to this section, with "Pending Commit" for the reassignment
date followed by
(pending commit). If you hover the mouse
pointer over the pending commit icon, SP displays information
about the reassignment.
138
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Reassigning a Router to a Different Managing Appliance
Introduction
You can reassign a router to a different managing appliance in the SP Web UI. For example,
you might reassign a router to a different managing appliance to relieve an overload on that
appliance. You can see the routers that an appliance is managing on the Configure Appliances
page (Administration > Appliances).
See “Configuring Routers” on page 136.
Important things to know about reassigning a router
The following are some important things to know about reassigning a router to a different
managing appliance:
n When you reassign a router to a different managing appliance, the baseline and interface
data that is associated with the router is copied automatically to the new appliance.
n
Before you reassign a router to a different managing appliance, back up all of the data on
the managing appliance.
n
During the process of reassigning a router to a different managing appliance, flows may be
lost. To avoid the loss of data, configure the router so that it sends the data to both the old
managing appliance and the new managing appliance before you reassign the router. If you
send the data to both appliances, then reports will not have gaps caused by missing flow
data.
n
If a router is reassigned to a new managing appliance and the old managing appliance is
decommissioned or is inaccessible, any data for the timeframe that the router was managed
by the old appliance will be missing from reports.
n
There are no limits to the number of times that you can reassign a router to a different
managing appliance.
n
You cannot reassign a router to an appliance in appliance-based license mode if that
appliance is already managing the maximum number of routers.
Reassigning a router to a different managing appliance
To reassign a router to a different managing appliance:
1. Navigate to the Configure Routers page (Administration > Monitoring > Routers).
2. Click the name link of the router that you want to reassign.
3. On the Router tab, from the Managing Appliance list, select the new managing
appliance.
4. Click Save, and then commit your changes.
The appliance that previously managed the router is added to the Assignment History
section, and SP displays (pending commit) after the end date until the router
reassignment is completed. On the Configure Routers page, the
(in-progress) icon
appears after the appliance name when the router is in the process of being reassigned to
that appliance. When the reassignment is complete, the
(done) icon appears after the
appliance name until the page is reloaded.
Proprietary and Confidential Information of Arbor Networks Inc.
139
SP and TMS User Guide, Version 8.0
Configuring Router SNMP Settings
Introduction
SP uses SNMP to learn interface names, descriptions, and statistics. Although SNMP settings
are optional, Arbor recommends that you configure them.
Configuring Router SNMP settings
To configure router SNMP settings:
1. Navigate to the Add Router page or the Edit Router page.
See “Adding and editing routers” on page 136.
2. Click the SNMP tab.
3. Use the following table to configure the SNMP settings on the SNMP tab that are not
specific to SNMP version 3:
Setting
Description
SNMP Version list
Select the SNMP version.
SNMP Query IP box
Type the remote ,3 DGGUHVV from which SP collects data
from the router.
SNMP Community
String box
Type the FRPPXQLW\ VWULQJ.
Poll low capacity
counters check box
Select if your router does not support sending high capacity
interface counters using SNMP version 1.
You need the community string to access SNMP data on the
router. If you do not specify a community string, then the
system defaults to “public.”
Low capacity counters can wrap quickly on high-speed
interfaces with significant traffic. This can cause SP to display
incorrect data on the System Tuning page (System >
Tuning).
Use SNMP
GETNEXT (instead
of GETBULK) check
box
(SNMP versions 2c and 3 only) Select if your router does not
correctly support the SNMP GETBULK operation for
efficiently retrieving large amounts of data.
4. Use the following table to configure SNMP settings on the SNMP tab that are specific to
SNMP version 3:
140
Setting
Description
SNMP Security Level
list
Select the security level for SNMP v3 connections.
SNMP
Authentication
Protocol list
Select the encryption hash algorithm.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Setting
Description
SNMP
Authentication
Username box
Type the XVHU QDPH for SNMP authentication.
SNMP
Authentication
Password box
Type the SDVVZRUG for SNMP authentication.
SNMP Privacy Key
box
Type the SULYDWH 6103 NH\.
SNMP Context Name
box
Type the FRQWH[W QDPH.
The context name indicates in what context this SNMP
management information exists.
5. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
141
SP and TMS User Guide, Version 8.0
Configuring Primary Router BGP Settings
Introduction
Configuring primary router BGP settings is optional; however, you must configure them if you
want to enable routing analysis.
Important: Arbor recommends that you configure each traffic device as an iBGP route
reflector client with each BGP router. If SP is not configured as a route reflector client, then it
loses some of the internal routing information and might have difficulty classifying some
interfaces.
Note: SP will reject BGP sessions from routers with a BGP holdtime setting of less than 30
seconds. If a router has a default BGP holdtime setting of less than 30 seconds, you will need
to explicitly configure this setting to 30 seconds or greater.
Configuring primary router BGP settings
To configure primary router BGP settings:
1. Navigate to the Add Router page or the Edit Router page.
See “Adding and editing routers” on page 136.
2. Click the Primary BGP tab.
3. Use the following table to configure the first two settings on the Primary BGP tab:
Setting
Description
Session Name box
Type a QDPH to help identify the BGP peering session in the SP
UI when you create a blackhole or TMS mitigation.
The default name is Primary.
Use Shared BGP
Routing Table list
If you do not want to peer with this router, select a different
router on the same SP appliance with which you want to share
a BGP routing table.
This setting allows the other router’s routing table to match
flows from the router that you are configuring. BGP routes are
not shared between appliances.
To filter the list, type any part of the name of a router that does
not include a space.
4. Use the following table to configure the settings in the BGP Session section on the
Primary BGP tab:
Setting
Description
BGP Session IP box
Type the remote ,3 DGGUHVV that you want SP to use to
create a BGP peering session with this router.
Note: A managing appliance can have a maximum of 32
configured primary and secondary BGP peering sessions.
Remote BGP AS
Number box
142
Type the $61 of the router.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Setting
Description
Local AS Number
box
Type the $61 that you want SP to use to establish a peering
session with the router.
By default, SP uses the backbone ASN as the local ASN. Arbor
recommends that you use the router’s ASN here so that SP is
the iBGP peer.
MD5 Secret box
(Optional) Type the VHFUHW that SP uses for BGP peering
between the SP appliance and the BGP routers.
You can type up to 80 alphanumeric characters, except for a
slash (/).
5. Use the following table to configure the settings in the Capabilities section on the
Primary BGP tab:
Setting
Description
Monitor Routes
check box
Select to monitor routes through BGP.
4 byte ASN check
box
Select if the router supports 4-byte ASNs.
BGP-VPN check box
Select to monitor VPNs through BGP information.
Flow Specification
check box
Select to enable traffic mitigation through flowspec or to use
this peering session for flow specification diversion
announcements with IPv4 TMS mitigations.
Ensure that this router supports flowspec before you enable
this option.
See “Appendix A: Configuring Flowspec Routers for Traffic
Mitigation” in the SP and TMS Advanced Configuration
Guide.
Monitor IPv6 check
box
Select if the router supports IPv6 BGP routes.
Announce IPv4
Mitigation Routes
check box
Select if you want this peering session to be used for BGP
diversion announcements with an IPv4 TMS mitigation.
Announce IPv6
Mitigation Routes
check box
Select if you want this peering session to be used for BGP
diversion announcements with an IPv6 TMS mitigation.
6. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
143
SP and TMS User Guide, Version 8.0
Configuring Secondary Router BGP Settings
Introduction
Configuring secondary router BGP settings is optional; however, you must configure them if
you want to enable both IPv4 and IPv6 peering sessions.
Note: The secondary router BGP session can only be used to announce TMS or Blackhole
mitigation routes. It cannot be used for other mitigation types, route analytics, or managed
object matching of BGP attributes.
Note: SP will reject BGP sessions from routers with a BGP holdtime setting of less than 30
seconds. If a router has a default BGP holdtime setting of less than 30 seconds, you will need
to explicitly configure this setting to 30 seconds or greater.
Configuring secondary router BGP settings
To configure secondary router BGP settings:
1. Navigate to the Add Router page or the Edit Router page.
See “Adding and editing routers” on page 136.
2. Click the Secondary BGP tab.
3. Use the following table to configure the first three secondary BGP settings on the
Secondary BGP tab:
Setting
Description
Session Name box
Type a QDPH to help identify the BGP peering session in the SP
UI when you create a blackhole or TMS mitigation.
The default name is Secondary.
Router ID box
Type an ,3 DGGUHVV that will be used by SP in the secondary
BGP session to differentiate itself from the primary BGP
session.
Note: This setting is usually not required. It is only required if
the secondary BGP session needs to use the same IP address
that is used for the primary BGP session.
Inhibit SP Peering
check box
144
Select if you want to prevent SP appliances from peering with
this router. The router will still be used in TMS mitigations when
a TMS appliance peers with this router.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
4. Use the following table to configure the settings in the BGP Session section on the
Secondary BGP tab:
Setting
Description
BGP Session IP box
Type the remote ,3 DGGUHVV that you want SP to use to
create a secondary BGP peering session with this router.
Note: A managing appliance can have a maximum of 32
configured primary and secondary BGP peering sessions.
Remote BGP AS
Number box
Type the $61 of the router.
Local AS Number
box
Type the $61 that you want SP to use to establish a secondary
peering session with the router.
By default, SP uses the backbone ASN as the local ASN. Arbor
recommends that you use the router’s ASN here so that SP is
the iBGP peer.
MD5 Secret box
(Optional) Type the VHFUHW that SP uses for BGP peering
between the SP appliance and the BGP routers.
You can type up to 80 alphanumeric characters, except for a
slash (/).
5. Use the following table to configure the settings in the Capabilities section on the
Secondary BGP tab:
Setting
Description
4 byte ASN check box
Select if the router supports 4-byte ASNs.
Announce IPv4
Mitigation Routes
check box
Select if you want this peering session to be used for BGP
diversion announcements with an IPv4 TMS mitigation.
Announce IPv6
Mitigation Routes
check box
Select if you want this peering session to be used for BGP
diversion announcements with an IPv6 TMS mitigation.
6. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
145
SP and TMS User Guide, Version 8.0
Configuring Router Flow Settings
Introduction
SP performs traffic analysis on flow records from the router when you configure the following
optional settings.
If you only want to perform BGP analysis for the router, then do not configure these settings.
Configuring router flow settings
To configure router flow settings:
1. Navigate to the Add Router page or the Edit Router page.
See “Adding and editing routers” on page 136.
2. Click the Flow tab.
3. Use the following table to configure flow settings on the Flow tab:
Setting
Description
Export IP box
Type the ,3 DGGUHVV of the router that sends flow records to
SP.
Important: While alerts are ongoing, do not change the order
of the addresses in this list because this can cause some
statistics to display incorrectly in the Web UI.
For rare cases with sFlow, you can enter multiple IP addresses
for many one-to-one mappings to the router. Use this feature if
you cannot configure the Agent Address on a Foundry switch.
The first address on the list indicates where the router export IP
addresses appear in the Web UI.
Use Embedded
Sampling Rate
check box
Select if you want SP to look for a flow sampling rate that is
embedded in the flow packet.
Sampling Rate box
Type the VDPSOH UDWH of the flow information sent by this
router. The default setting is 1.
Flow Down
Alerting Enabled
check box
Select to instruct the system to alert you when flow is down.
Flow Down Alert
Timeout box
Type the QXPEHU RI VHFRQGV that you want the system to
wait before it sends a Flow Down alert. The default setting is
120 seconds.
Important: If you select the “Use Embedded Sampling Rate”
check box and some or all flow from this router does not
populate the embedded sampling rate field, then SP applies the
default sampling rate (1).
4. Click Save, and then commit your changes.
146
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Configuring Advanced Router Settings
Introduction
The Advanced tab on the Add Router or Edit Router page allows you to configure optional
advanced router settings.
Important: Only modify these settings if you are instructed to by your Arbor Networks Support
Engineer.
Configuring advanced router settings
To configure advanced router settings:
1. Navigate to the Add Router page or the Edit Router page.
See “Adding and editing routers” on page 136.
2. Click the Advanced tab and configure the advanced settings.
See “Advanced router settings” below.
3. Click Save and then commit your changes.
Advanced router settings
Use the following table to configure the advanced router settings:
Advanced router settings
Setting
Description
Fallback
Algorithm list
Select an algorithm to classify interfaces during auto-configuration
that either report no traffic or have no associated BGP information.
You can select one of the following fallback algorithms:
n
n
n
Internal (the default) to classify interfaces as internal.
External to classify interfaces as external.
use_bgp_and_local to classify each observed flow, based on
learned BGP information and the configured IP address space.
See “Interface classifications” on page 119.
Originator ID box
Type the 2,' that this router uses for iBGP peering.
Reflected
Routers May Be
External check
box
Select if you use the default router option and if you want the system
to auto-classify the interfaces on this router as external.
Important: Users usually configure this setting for lab trials or
deployment within the backbone core or aggregation edge. The
auto-configuration rules for this router allow SP to treat an internal
router as a BGP backbone edge router.
SNMP Scaling
check box
Select to allow the system to adjust the reported traffic differences
that it sees between traffic flow information and SNMP reported
traffic levels.
Monitor eSeries
ArborFlow appid
check box
(e100 only) Select if you want SP to detect applications in the
ArborFlow that the e100 sends.
Proprietary and Confidential Information of Arbor Networks Inc.
147
SP and TMS User Guide, Version 8.0
Advanced router settings (Continued)
Setting
Description
TCP Flags
Missing check box
Select if you do not want the system to use TCP flag information from
flows coming from this router.
Select this check box if you use Cisco Catalyst 6500 and 7600
series routers. Otherwise, SP might generate false TCP flag-based
alerts due to the missing TCP flags.
Enable Dynamic
Subscriber
Interface
Handling check
box
Select if you want SP to discover and track only the interfaces that
match an auto-configuration rule. The interfaces that are not
discovered are placed by SP into a single aggregate, untracked
interface. See “About the Enable Dynamic Subscriber Interface
Handling setting” below.
Note: You can also create an auto-configuration rule that assigns a
matching interface to the router's aggregate, untracked interface,
even if another auto-configuration rule would otherwise cause the
interface to be discovered and tracked. For additional information, see
“Auto-configuration rule Action tab settings” on page 125 and the
Merge with Router's Aggregate Interface action.
About the Enable Dynamic Subscriber Interface Handling setting
The Enable Dynamic Subscriber Interface Handling setting can reduce the number of
interfaces that SP tracks and for which it polls SNMP counters from the router. Consequently,
it can improve SP scale because the untracked interfaces do not count against the monitored
interface limit of the appliance. It can also avoid possible performance problems on the router
that would be caused by frequent polling of large numbers of interfaces.
This setting changes how SP discovers interfaces on a router, as follows:
Flow-based discovery of interfaces is turned off.
n
n
Flow-based classification of interfaces using the system auto-configuration heuristics is
disabled.
Auto-configuration heuristics is a setting that can be selected when configuring an
auto-configuration rule.
n
SNMP-based discovery of interfaces occurs only when an auto-classification rule matches
the interface.
See “Configuring an interface classification rule” on page 123.
n
All interfaces on the router that are not discovered by an auto-classification rule are part of
a single aggregate, untracked interface.
You can view and edit this interface on the Interfaces page (Administration >
Monitoring > Interfaces).
Important: Arbor recommends that you do not change the name of the untracked
interface.
Note: You can also create an auto-configuration rule that assigns a matching interface to
the router's aggregate, untracked interface, even if another auto-configuration rule would
otherwise cause the interface to be discovered and tracked. For additional information, see
148
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
“Auto-configuration rule Action tab settings” on page 125 and the Merge with Router's
Aggregate Interface action.
For example, with a Broadband Network Gateway (BNG), you can select this setting and then
create auto-configuration rules that discover your business interfaces and other
mission-critical interfaces, but that do not discover your consumer interfaces. The
auto-configuration rule that matches all of your business interfaces needs to include a regular
expression that matches only the SNMP interface description of the business interfaces. You
can also select the Track by SNMP Description setting so that SP uses the SNMP
description to track the business interfaces instead of the SNMP name which can frequently
change.
Proprietary and Confidential Information of Arbor Networks Inc.
149
SP and TMS User Guide, Version 8.0
Configuring Interfaces
Introduction
SP learns about the interfaces on each router from SNMP or when it receives a flow record
that contains the interface’s index.
About the Interfaces page
The Interfaces page (Administration > Monitoring > Interfaces) displays detailed
interface statistics.
The table on the Interfaces page contains the following information:
Interfaces page details
Column
Description
Name
The name and description of an interface.
Router
The router to which an interface belongs.
Index
The SNMP index number of an interface.
Tags
The tags that have been applied to the interface configuration.
Tags can help you to categorize and to search easily for interfaces in
your deployment. For example, you might want to tag your interfaces
with the name of the customer associated with that interface.
Speed
The speed of an interface (in bps).
IP
The IP address associated with an interface.
ASNs
The ASNs associated with an interface.
Type
The classification type for an interface (external, internal, backbone,
mixed, ignore, or unassigned).
Classification Rule
The rule that the system uses to classify an interface.
About searching on the Interfaces page
You can use the Search box to search on the Interfaces page. The following are some
guidelines for using the Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string except when
searching for index or ASN values.
See “Acceptable search keywords and values for interfaces” on the facing page.
150
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Acceptable search keywords and values for interfaces
The following table lists the columns on the Interfaces page and, for each column, the
keywords and values that you can use to search on that column in the Search box. The Name
column has separate keywords for the name and the description.
Search keywords for columns
Column to
search on
Acceptable keywords and values
Name
n
Examples
name:LQWHUIDFH QDPH
description:LQWHUIDFH
GHVFULSWLRQ
n
n
n
name:interface123
description:link to xyz
Router
n
router:URXWHU QDPH
n
router:router231
Index
n
index:LQGH[ QXPEHU
n
index:1214
Tags
n
tags:LQWHUIDFH WDJ
n
tags:customer abc
IP
n
ip:LQWHUIDFH ,3
n
ip:192.168.1.1
ASNs
n
peer:$61 QXPEHU
peer_as:$61 QXPEHU
n
peer:251
n
peer_as:1921
n
Type
n
type:LQWHUIDFH W\SH
n
type:internal
Classification
Rule
n
rule:UXOH QDPH
n
rule:AutoClassRule
About collecting detailed statistics
SP collects detailed interface statistics if an interface’s classification type is “external.”
Detailed statistics include traffic breakdowns according to the following:
n application
n
AS
n
IP protocol for ingress and egress traffic
About traffic threshold alerting for interfaces
For interfaces, SP configures the traffic threshold value as a percentage of the interface link
speed, which the system learns through SNMP. Every minute, SP views the in and out traffic
for each interface and compares it with the thresholds for that interface. You can configure the
default threshold alerting for interfaces on the Configure Traffic Traps page (Administration
> Detection > Traffic Traps).
Note: SP does not create interface threshold alerts if an interface speed is less than 45 Mbps
(for example, a T3 provider or the equivalent). Alerts for smaller interfaces can be unreliable
because highly fluctuating traffic can saturate these interfaces in normal operations,
particularly for T1 providers.
Proprietary and Confidential Information of Arbor Networks Inc.
151
SP and TMS User Guide, Version 8.0
Editing an interface
To edit an interface:
1. Navigate to Interfaces page (Administration > Monitoring > Interfaces).
2. In the Name column, click an interface name link.
3. On the Edit Interface page, configure the interface settings.
See “Interface settings” below.
4. Click Save, and then commit your changes.
Interface settings
Use the following table to configure the interface settings:
Interface settings
152
Setting
Description
SNMP Index box
(Arbor does not recommend changing this SNMP-learned setting)
This number is the 6103 LQGH[ QXPEHU for this interface.
Name box
(Arbor does not recommend changing this SNMP-learned setting)
This setting is the interface QDPH.
Description box
(Arbor does not recommend changing this SNMP-learned setting)
This setting is the interface GHVFULSWLRQ.
Tags box
Type the WDJV that you want to apply to the interface. After you
type a tag, press COMMA, TAB, or ENTER to set the tag and to
continue.
Tags can help you to categorize and to search easily for interfaces
in your deployment. For example, you might want to tag your
interfaces with the name of the customer associated with that
interface.
Speed box
Type the VSHHG of the interface (in bps).
Automatic
Classification list
Select whether you want to enable automatic classification.
Type list
(Disabled automatic classification only) Select the classification
type.
Peer ASNs box
(Disabled automatic classification only) Type the SHHU $61V for
this interface.
Detailed Statistics
list
Select whether you want to enable detailed statistics. For an
external interface, the "default" setting is "on." For all other
interface types, the "default" setting is "off."
See “About collecting detailed statistics” on the previous page.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 7: Configuring Monitored Network Devices
Interface settings (Continued)
Setting
Description
High Threshold box
Type the WUDIILF UDWH that you want to trigger high usage
alerts.
Use a whole number that represents a percentage of the link
speed. The default percentage is 95.
See “About traffic threshold alerting for interfaces” on page 151.
Low Threshold box
Type the WUDIILF UDWH that you want to trigger low usage alerts.
Use a whole number that represents a percentage of the link
speed. To disable this threshold, type -1. SP disables this setting
by default because the low threshold can vary widely between
networks.
See “About traffic threshold alerting for interfaces” on page 151.
Proprietary and Confidential Information of Arbor Networks Inc.
153
SP and TMS User Guide, Version 8.0
154
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8:
Configuring Managed Objects
Introduction
This section describes how to configure managed objects. Managed objects are
administrator-configured resources that SP uses to help you to understand, protect, and
respond to problems in your network.
User access
Only administrators can perform all actions described in this section.
In this section
This section contains the following topics:
About Managed Objects
156
Defining a POP Using a Profile Managed Object
157
About the Configure Managed Objects Page
159
Configuring Managed Objects
162
Configuring Match Settings for Managed Objects
165
Configuring Boundaries for Managed Objects
174
Configuring Threshold Alerting for Managed Objects
181
Configuring Profiled Router Detection for Managed Objects
182
Configuring Host Detection for Managed Objects
186
Configuring Profiled Network Detection for Managed Objects
191
Configuring Mitigation Settings for Managed Objects
192
Configuring Mitigation Settings for Customer Managed Objects
193
Configuring Mitigation Settings for Peer Managed Objects
202
Configuring Mitigation Settings for Profile Managed Objects
203
Configuring Cloud Signaling Settings for Managed Objects
205
Configuring Learning Mitigation Settings for Managed Objects
208
Configuring Managed Object Children
210
Configuring Managed Services Settings for Managed Objects
211
Configuring VPN Site Managed Objects
213
About the VPN Sites Tab
216
SP and TMS User Guide, Version 8.0
155
SP and TMS User Guide, Version 8.0
About Managed Objects
Introduction
Managed objects are administrator-configured network resources that SP uses to sort, filter,
and store traffic and flow data. Managed objects define what SP protects.
Managed object types
SP categorizes managed objects into the following types:
Managed object types
Type
Description
Customer
A network entity that you can define to report traffic and detect anomalies. Use
this managed object to track customers (such as downstream BGP customers),
statically routed customers, or internal customers.
This managed object type is available to managed services users using the
scoped_customer.xml menu skin.
See “Configuring Menus” on page 283.
Profile
An arbitrary subset of your network or of another network.
Example: You might create a profile to monitor your DNS servers or a data
center within your network, or to monitor external services or providers, such as
YouTube or an upstream ASN.
Peer
An external network that connects to your network. Use the peer managed
object to track your peer traffic.
VPN
A VPN entity that you can define to report traffic and detect anomalies for VPNs.
VPN Site
A site within a VPN, defined by CIDR blocks or extended communities. This can
only be configured as part of a VPN managed object.
For VPN site configuration information, see “Configuring VPN Site Managed
Objects” on page 213.
This managed object type is available to managed services users using the
scoped_vpn.xml menu skin.
See “Configuring Menus” on page 283.
About naming managed objects
A managed object name can include up to 64 characters. Use the standard printable ASCII
characters, except for the following characters:
n backslash (\)
156
n
exclamation point (!)
n
quotation mark (“)
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Defining a POP Using a Profile Managed Object
Introduction
A point of presence (POP) is an access point to the Internet. Most POPs are defined by a
number of routers and interfaces. POPs can define a region, geography, or area of traffic within
the larger service provider network. When you define large groups of equipment by some
logical association such as a POP or a region, there are a number of ways to associate the
elements as a single object represented within SP.
About building a profile around a BGP community to represent a POP
Many network operations teams ensure that routes announced from a geographical location,
area, or POP are tagged with a specific community. This community designates that these
routes originate from the location. Therefore, the community ties geography or logical grouping
to traffic into and out of this portion of the network. You can create a profile managed object
that represents this portion of the network when you ensure that the match action used to
describe the POP contains the correct community.
The following figure shows a POP reference architecture with region routes marked with BGP
communities that indicate the origin location:
POP reference architecture
Example: adding a profile managed object for a POP using community matching
To create a profile managed object that represents traffic to or from a POP:
1. Navigate to the Configure Managed Objects page (Administration > Monitoring >
Managed Objects).
Proprietary and Confidential Information of Arbor Networks Inc.
157
SP and TMS User Guide, Version 8.0
2. Click Add Managed Object.
3. Select Profile from the Managed Object Family list, and then click Add.
4. Type Denver-POP in the Name box.
Tip: In the Name box, add a name that best describes the entire set of traffic that comes
into and goes out of the POP that matches the community.
5. Select the Match tab.
6. Select Communities from the Match 1 list.
7. Type 65000:300 in the Match Values box.
This is an example of the match value for the Denver POP community.
8. Click Save, and then commit your changes.
Viewing the POP profile
Use the Profile Summary report (Reports > Profiles > Summary) to view the traffic that
comes in and goes out of the profile. This traffic matches the set of routes in the iBGP table
that you tagged with the communities. Any traffic that has a source or destination address that
matches a route tagged with the community counts as traffic that matches this profile.
158
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
About the Configure Managed Objects Page
Introduction
The Configure Managed Objects page (Administration > Monitoring > Managed
Objects) lists the names of managed objects with their tags, match values, and host detection
settings.
You can do the following on the Configure Managed Objects page:
Configure new or existing managed objects
n
See “Configuring Managed Objects” on page 162.
n
Search for specific managed objects
See “About searching on the Configure Managed Objects page” below.
n
Sort the managed objects by name, description, tags, and match values
n
Sort the managed objects by name, description, tags, match values, type of host detection
settings (shared or custom), and name of shared sets
n
Access the host detection settings of a managed object
The Shared Settings column contains the name of the set of host detection settings. The
name is a link to the Edit Shared Host Detection Settings page for each managed object’s
set of host detection settings. The “Disabled” host detection setting does not have a link
because it cannot be edited. With VPN managed objects, no name appears in the Shared
Settings column because VPN managed objects cannot be configured for host detection.
See “About Managed Objects” on page 156.
About searching on the Configure Managed Objects page
To search for managed objects on the Configure Managed Objects page, you can use the
Search box, the search wizard, or you can click one of the filters below the Search box. When
you click a filter, the search values for the filter appear in the Search box and the search is
completed.
When you search with the Search box, use the following guidelines:
You can enter search values with or without keywords.
n
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
If a keyword is followed by more than one value, only the first value is associated with the
keyword. For any additional values, the search looks for those values in the name,
description, or tag fields of the managed objects. For example, if you type name:XYZ 123,
then the search returns all occurrences of managed objects that have XYZ in their name and
123 in their name, description, or tag fields.
n
A comma between search values creates an OR statement.
The comma cannot be followed by a space because a space creates an AND statement.
n
The percent character (%) must be placed before the following characters if you want to
Proprietary and Confidential Information of Arbor Networks Inc.
159
SP and TMS User Guide, Version 8.0
include them in the search: caret ^, dollar sign $, left parenthesis (, right parenthesis ),
percent %, period ., left bracket [, right bracket ], asterisk *, plus sign +, hyphen -, and
question mark ? . You cannot use the pipe character | at all.
n
For example, if you are searching for a managed object named "my-mo", use the following
search string: my%-mo
You can use quotation marks (“) to match a phrase. For example, to search for a managed
object with “This is the Chicago office,” you can type description:”Chicago office”.
See “Acceptable search keywords and values for managed objects” below.
Acceptable search keywords and values for managed objects
The following table lists the acceptable keywords and values that you can use to search in the
Search box for managed objects:
Search keywords for attributes
Attribute to
search by
Acceptable keywords and
values
name
n
name:PDQDJHG REMHFW QDPH
n
name:customer1
description
n
description:PDQDJHG
REMHFW GHVFULSWLRQ
n
description:”chicago
office”
tag
n
tag:PDQDJHG REMHFW WDJ
tags:PDQDJHG REMHFW WDJ,
PDQDJHG REMHFW WDJ
n
n
tag:”north america”
tags:boston, seattle
n
Examples
match
n
match:PDQDJHG REMHFW
PDWFK YDOXH
n
match:1.1.0.0/16
host detection
n
hostdetection:W\SH RI
KRVW GHWHFWLRQ VHW
hd:W\SH RI KRVW
GHWHFWLRQ VHW
n
hostdetection:shared
hd:custom
sharedsettings:QDPH RI
VKDUHG KRVW GHWHFWLRQ
VHW
ss:QDPH RI VKDUHG KRVW
GHWHFWLRQ VHW
n
n
shared settings
n
n
n
n
sharedsettings:default
ss:"my settings"
Deleting managed objects
To delete a managed object:
1. Navigate to the Configure Managed Objects page (Administration > Monitoring >
Managed Objects).
2. Select the check boxes for the managed objects or child managed objects that you want
to delete, and then click Delete.
Caution: SP does not prompt you for confirmation before it deletes managed objects.
However, you can revert to the last saved configuration to retrieve deleted managed
objects.
160
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Note: Check boxes do not appear before VPN sites that have been detected and
configured automatically because these VPN sites cannot be deleted.
Note: If you delete a managed object that uses a custom set of host detection settings,
the custom set is deleted as well. If it uses a shared set of host detection settings, the
shared set is not deleted even if the deleted managed object was the only one using that
shared set.
3. Commit your changes.
See “Committing configuration changes” on page 402.
Proprietary and Confidential Information of Arbor Networks Inc.
161
SP and TMS User Guide, Version 8.0
Configuring Managed Objects
Introduction
You can add, edit, and delete managed objects from the Configure Managed Objects page
(Administration > Monitoring > Managed Objects).
For more information about managed objects, see “About Managed Objects” on page 156.
For information about navigating through multiple pages of managed objects, see “Navigating
multiple pages” on page 30.
Adding and editing a managed object
To add or edit a managed object:
1. Navigate to the Configure Managed Objects page (Administration > Monitoring >
Managed Objects).
2. Choose one of the following steps:
l
To edit a managed object, click its name link.
l
To add a managed object, click Add Managed Object, and then click the type of
managed object that you want to add. See “Managed object types” on page 156.
3. Use the following table to configure the settings on the Description tab of a managed
object:
Setting
Description
Name box
Type the QDPH of the managed object. See “About naming
managed objects” on page 156.
Description box
Type a GHVFULSWLRQ of the managed object.
Tags box
Type the WDJV that you want to apply to the managed object.
After you type a tag, press COMMA, TAB, or ENTER to set the tag
and to continue.
Tags can help you to categorize and to search easily for the
managed objects that you monitor. For example, you might tag a
profile managed object with the name of the data center that it
represents or the types of attacks that have affected it.
Home on Data
Storage
Appliances selector
box
Select one or more SP appliances that have the data storage
role to serve as the home of the managed object. To select an
appliance, click in the Home on Data Storage Appliances
box and select an appliance from the list.
For redundancy, you can assign up to three appliances that
have the data storage role to a managed object. If one
appliance fails, SP automatically defaults that appliance’s
managed objects to their second home. For additional
information about homing and the data storage role, see “About
the SP Appliance Data Storage Role” on page 48.
4. Configure the settings on the other tabs of the managed object. See “Managed object
162
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
configuration settings” on the facing page.
5. Click Save, and then commit your changes.
Managed object configuration settings
When you configure a managed object, different tabs appear in addition to the Description
tab. The tabs that appear depend on the type of managed object and the match settings of the
managed object. The following table describes the different settings for the tabs that can
appear:
Managed object configuration settings
Tab
Description
Match
Allows you to configure the match settings for a managed object. See
“Configuring Match Settings for Managed Objects” on page 165.
Boundary
Allows you to define boundaries for an object. See “Configuring
Boundaries for Managed Objects” on page 174.
Threshold
Alerting
Allows you to configure threshold alerting for a managed object. See
“Configuring Threshold Alerting for Managed Objects” on page 181.
Profiled Router
Detection
Allows you to configure profiled router detection settings for a
managed object. See “Configuring Profiled Router Detection for
Managed Objects” on page 182.
Host Detection
Allows you to configure host detection settings for a managed object.
See “Configuring Host Detection for Managed Objects” on page 186.
Profiled Network
Detection
Allows you to configure profiled network detection settings for a
managed object. See “Configuring Profiled Network Detection for
Managed Objects” on page 191.
Mitigation
Allows you to configure mitigation settings for a managed object. See
“Configuring Mitigation Settings for Managed Objects” on page 192.
Cloud Signaling
Allows you to configure Cloud Signaling™ settings for a managed
object. See “Configuring Cloud Signaling Settings for Managed
Objects” on page 205.
This tab appears only when you create a customer or profile managed
object that has an IPv4 CIDR Blocks or CIDR Groups match type.
Learning
Mitigation
Allows you to configure learning mitigation settings for a managed
object. See “Configuring Learning Mitigation Settings for Managed
Objects” on page 208.
This tab appears only when you create a customer, peer, or profile
managed object that has a CIDR Blocks or CIDR Groups match type.
Children
Allows you to configure child managed objects. See “Configuring
Managed Object Children” on page 210.
Proprietary and Confidential Information of Arbor Networks Inc.
163
SP and TMS User Guide, Version 8.0
Managed object configuration settings (Continued)
Tab
Description
Managed
Services
Allows you to configure managed services settings for a managed
object. See “Configuring Managed Services Settings for Managed
Objects” on page 211.
This tab appears only when you create a customer managed object.
VPN Sites
Allows you to configure VPN sites for a managed object. See
“Configuring VPN Site Managed Objects” on page 213.
This tab appears only when you create a VPN managed object.
Misuse
Detection
In an SP 7.0 or later deployment, misuse detection is replaced by host
detection.
Important: Misuse detection generates alerts only in a multi-version
deployment with collectors running a version of SP prior to 7.0. When
the entire deployment is running SP 7.0 or later, misuse detection no
longer generates alerts.
For information about misuse detection, see the SP and Threat
Management System (TMS) User Guide for your previous version of
SP.
164
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring Match Settings for Managed Objects
Introduction
Match settings are used to define how SP should associate traffic with managed objects.
You can use the Match tab to add or edit the match settings when you configure a managed
object. See “Configuring Managed Objects” on page 155.
Important: A VPN managed object has unique match settings. See “Configuring match
settings for a VPN managed object” on page 173.
Configuring match settings for a customer, peer, or profile managed object
To configure match settings for a customer, peer, or profile managed object:
1. Navigate to the Match tab of the managed object.
See “Adding and editing a managed object” on page 162.
Note: For a VPN managed object, see “Configuring match settings for a VPN managed
object” on page 173.
2. From the Match 1 list, select a match type that defines the managed object.
SP displays the match settings that you can configure for the managed object. For more
information about each match type, see “About match types” on page 168.
3. Complete the next steps based on the match settings that you want to configure:
Match Type
Description
None
Go to Step 5.
Advanced
Boolean Matching
In the Match Values box, type a ERROHDQ H[SUHVVLRQ, and
then go to Step 4.
AppID
Click Edit AppIDs, use the selection wizard to add one or more
applications, and then go to Step 4. See “Using Selection
Wizards” on page 31.
AS Path Regular
Expression
In the Match Values box, type a UHJXODU H[SUHVVLRQ, and
then go to Step 4.
Note: A config diff of this match setting displays a different
command (asregexp_uri with a URL-encoded value) from what is
displayed in the CLI (asregexp with a non-URL-encoded value).
CIDR Blocks
In the Match Values box, type one or more &,'5 EORFN
SUHIL[HV, and then go to Step 4.
This option is available to managed services users.
Proprietary and Confidential Information of Arbor Networks Inc.
165
SP and TMS User Guide, Version 8.0
Match Type
Description
CIDR Groups
a. Click Edit CIDR Groups.
b. Do one of the following:
l
Type the &,'5 JURXSV in the CIDR Groups Wizard.
l
Browse to your file that contains a list of CIDR groups, and
then click Upload.
c. Click Select, and then go to Step 4.
Note: To open or save a file of the CIDR groups that are listed in
the CIDR Groups Wizard, click Download CIDR Groups.
CIDR IPv6 Blocks
In the Match Values box, type one or more &,'5 EORFNV, and
then go to Step 4.
Communities
In the Match Values box, type one or more FRPPXQLWLHV, and
then go to Step 4.
Extended
Communities
In the Match Values box, type one or more H[WHQGHG
FRPPXQLWLHV, and then go to Step 4.
Flow Filter
In the Flow Filter box, type one or more flow filters or click Open
FCAP Wizard to add a fingerprint expression to match flows, and
then go to Step 4. See “Using the FCAP Wizard” on page 32.
You can use the following as a match for a flow filter:
DYHUDJH SDFNHW OHQJWKV
n GHVWLQDWLRQ DGGUHVVHV
n GHVWLQDWLRQ SRUWV
n ,&03 FRGHV
n ,&03 W\SHV
n SURWRFROV
n VRXUFH DGGUHVVHV
n VRXUFH SRUWV
n 7&3 IODJV
n 726 ELWV
n
If you want the flow filter to only match dark IP traffic, then select
the Only match Dark IP traffic? check box. This setting works
only if dark IP address detection is configured. See “Configuring
dark IP address space detection” on page 129.
Important: Flow filter can strain the system. Monitor your CPU
utilization when you use this feature.
166
Interfaces
Go to Step 4.
Interface Groups
Go to Step 5.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Match Type
Description
Local
ASN/SubAS
a. In the Match Values box, type the $61 of a sub or local AS
on your network.
b. Select the Only match traffic with a local endpoint
check box to include only traffic with a local endpoint, and
then go to Step 4.
Peer ASNs
In the Match Values box, type the $61 V of a peer network, and
then go to Step 4.
TMS Ports
Go to Step 4.
TMS VLANs
Click Edit TMS VLANs, use the selection wizard to select one or
more TMS VLANs, and then go to Step 4. See “Using Selection
Wizards” on page 31.
4. Repeat Step 2 and Step 3 for the Match 2 and Match 3 lists (if necessary).
5. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
167
SP and TMS User Guide, Version 8.0
About match types
SP defines objects by name, match type, match values, and optional protocol and port filters.
SP supports the following match types:
Supported match types
168
Match Type
Description
None
You can set Match 1 to
“none” and then
specify the interface
and TMS boundaries.
This configuration
allows you to match all
traffic as limited by the
configured boundaries.
If you set Match 1 to
“none” and set the
boundaries to either
“none” or “global,” then
the managed object
does not match any
traffic.
Advanced Boolean Matching
A match expression
that combines multiple
traffic and routing
attributes, limited to AS
path regular
expressions, BGP
communities, and CIDR
blocks.
These matches cannot
include SubASNs.
Also, the clauses AND
and NOT cannot be
parents of CIDR block
entries.
AppID
One or more
application signatures
that the TMS
appliances support.
AS Path Regular Expression
A Cisco style, stringbased AS regular
expression.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Supported match types (Continued)
Match Type
Description
CIDR Blocks
One or more IPv4 CIDR
block prefixes with the
form A.B.C.D/N. To
separate multiple
prefixes, use spaces.
SP treats all CIDRs in
aggregate for traffic
reports and DoS alert
detection.
This match type is
available to managed
services users.
CIDR Groups
One or more CIDR
block prefixes with the
form A.B.C.D/N with
the name you assign to
the group and a
semicolon (;). To
separate multiple
prefixes, use spaces.
SP performs the DoS
profiled router
detection
independently for each
CIDR group but reports
the traffic data for all
CIDRs as a whole.
This match type is
available to managed
services users.
CIDR IPv6 Blocks
One or more IPv6 CIDR
blocks. To separate
multiple blocks, use a
comma (,) followed by a
space. SP treats all
CIDRs in aggregate for
traffic reports and DoS
alert deletion.
Example:
2001:DB8:FF00::/40,
2001:DB8:0000::/48
This match type is
available to managed
services users.
Proprietary and Confidential Information of Arbor Networks Inc.
169
SP and TMS User Guide, Version 8.0
Supported match types (Continued)
Match Type
Description
Communities
A regular expression
including one or more
BGP communities in
the form of X:Y, where
X represents the ASN
and Y represents the
number of local
significance to AS X.
To separate multiple
communities, use
commas. These
expressions must be in
a range of 0-65535.
Examples:
n
n
170
’2:20’ becomes (
|^|$) 2:20( |^|$)
and matches
community 2:20.
‘2.*:2.*’ becomes (
|^|$)2.*:2.*( |^|$)
and matches any
community
beginning with 2 for
X and Y (such as
2:20, 20:20, or
2:200).
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Supported match types (Continued)
Match Type
Description
Extended Communities
A regular expression
including one or more
BGP extended
communities in the
form of X:Y:Z, where X
represents the type
field and Y:Z
represents the route
target or site of origin.
The type field can be
either “route-target” or
“site-of-origin.” The
route target must use a
supported format. See
“Supported route target
formats” on page 173.
When you enter
multiple extended
communities, you can
use a space, comma, or
line break to separate
them.
Examples:
n
n
n
Flow Filter
Proprietary and Confidential Information of Arbor Networks Inc.
routetarget:10.2.1.5:100
routetarget:100:72698
site-oforigin:9642L:982
A fingerprint expression
defines which flows to
match.
As of SP 5.1, Flow
Filter does not support
the “rtr” and “iface”
match criteria. To
replace this
functionality, you can
edit boundary
interfaces.
171
SP and TMS User Guide, Version 8.0
Supported match types (Continued)
172
Match Type
Description
Interfaces
Bases the match on the
defined interface
boundary of the object.
For DoS profiled router
detection, SP
generates a baseline
based on all of the
defined interfaces.
Interface Groups
Bases the match on the
defined interface
boundary of the object.
SP performs the DoS
profiled router
detection
independently for each
interface in the group.
Local ASN/SubAS
The AS number of a
sub or local AS on your
network. These
numbers must be in the
range of 1-65535 and
unique across
customers.
Peer ASNs
One or more ASNs of a
peering network. These
ASNs must be in the
range of 1-65535 and
unique across
customers.
TMS Ports
The TMS port (in, out,
auto). SP maps the
selected port to the
managed object, so
traffic is into or out of
the managed object.
TMS ports represent a
network boundary
around a managed
object.
TMS VLANs
The VLANs that the
TMS appliance has
detected on the
network.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring match settings for a VPN managed object
To configure match settings for a VPN managed object:
1. Navigate to the Match tab of the VPN managed object.
See “Adding and editing a managed object” on page 162.
2. In the Match list, select one of the following options:
Option
Description
None
If you select None, then you cannot configure any match settings.
Route Target
If you select Route Target, then you can specify one or more
route targets for SP to use to identify this VPN. When Route
Target is selected, SP automatically detects and configures the
VPN sites that match the route target values that are configured
for this managed object.
Interfaces
If you select Interfaces, then you must enter the interfaces on the
Boundary tab. See “Configuring interface boundary settings for a
VPN managed object” on page 178.
3. If you selected Route Target in the Match list, then type one or more route targets that
identify this VPN In the Match Values box.
When you enter multiple route targets, you can use a space, comma, or line break to
separate them. See “Supported route target formats” below.
4. Click Save, and then commit your changes.
Supported route target formats
SP supports the following input string formats for route targets:
Supported formats for route targets
Format
Description
Example
<ASN>:<XX>
2 byte ASN:4 byte number
64496:100
<ASN>L:<XX>
4 byte ASNL:2 byte number
65536L:100
<w.x.y.z>:<XX>
4 byte IP :2 byte number
203.0.113.33:100
Important: These are the formats that are specified in RFC 5575. However, RFC 5575 is
vague enough that there are current incompatibilities with how various vendors have
implemented this standard. Consequently, although SP supports entering the route target in all
3 of these formats, only the 2 byte ASN:4 byte number has been verified to work at this time.
Proprietary and Confidential Information of Arbor Networks Inc.
173
SP and TMS User Guide, Version 8.0
Configuring Boundaries for Managed Objects
Introduction
You can use the Boundary tab to add or edit the incoming and outgoing traffic boundaries for
managed objects. By default, SP uses the network boundary (for example, the BGP edge or the
set of all interfaces that are classified as external) as the boundary for every managed object.
When you configure boundaries, SP measures all “in” and “out” traffic for a managed object at
its interface boundaries. This allows SP to avoid counting flows more than once when it
detects a managed object’s traffic at multiple routers in your network. Configuring boundaries
also allows you to have more fine-grained visibility into your network’s traffic, such as
customer-to-customer traffic.
Note: A VPN managed object uses only a subset of the boundary settings. See “Configuring
interface boundary settings for a VPN managed object” on page 178.
See “Configuring Managed Objects” on page 162.
Configuring router boundary settings for a customer, peer, or profile managed object
To configure router boundary settings for a customer, peer, or profile managed object:
1. Navigate to the Boundary tab.
See “Adding and editing a managed object” on page 162.
2. Select one of the following Choose Boundary options:
Option
Description
Network
Boundary
Select to use the network boundary for the managed object
boundary. When this option is selected you cannot configure any
interfaces for the router boundary or the TMS boundary. To
complete the configuration, click Save.
Interfaces
Select if you want to configure interfaces for the managed object
boundary. When this option is selected, options appear for
selecting interfaces for the router boundary.
Note: If the Choose Boundary options are disabled, then go to
Step 7. These options are disabled if you selected Interfaces or
Interface Groups on the Match tab.
3. If you selected the Interfaces option, then select one of the following router boundary
types in the Router Boundary section:
Router Boundary
Type
174
Description
None
SP uses the network boundary for the router boundary of the
managed object. To complete the configuration, click Save.
Global
customer, Ignore
Rules
SP uses the network boundary for the boundary of the managed
object and measures all traffic reported as "in" and "out." See
Step 4.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Router Boundary
Type
Description
Rules Only
SP uses dynamic auto-configuration rules to determine all
boundary interfaces. See Step 5.
Interfaces &
Rules
SP uses dynamic auto-configuration rules and your static
configurations to determine boundary interfaces. See Step 6.
Important: Arbor recommends that you configure interface boundaries with rules
whenever possible. Rules use regular expressions to match boundaries that are
dynamically based on interface descriptions (ifAlias value). This ensures that SP
automatically updates boundaries when the interface boundaries change.
4. If you selected Global customer, Ignore Rules for the router boundary type, then
configure the following setting, and click Save to complete the configuration:
Setting
Description
Locality
You can configure locality to determine whether to bin BGP
attributes for the source or the destination of the traffic flowing
into or out of a managed object. Select default unless you are
configuring locality for a managed object that is external to the
monitored network. If an object is external, then you must
configure it with external match settings and select external from
the Locality list.
5. If you selected Rules Only for the router boundary type, then configure the following
settings, and click Save to complete the configuration:
Setting
Description
Locality
You can configure locality to determine whether to bin BGP
attributes for the source or the destination of the traffic flowing
into or out of a managed object. Select default unless you are
configuring locality for a managed object that is external to the
monitored network. If an object is external, then you must
configure it with external match settings and select external
from the Locality list.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule, or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings” on
page 180.
Proprietary and Confidential Information of Arbor Networks Inc.
175
SP and TMS User Guide, Version 8.0
6. If you selected Interfaces & Rules for the router boundary type, then configure the
following Interface Boundary Type settings:
Option
Description
Advanced
If you select Advanced, then you can manually specify managed
object-facing interfaces and backbone-facing interfaces. See
Step 7.
A managed object-facing interface is always the output interface
for traffic coming into a managed object and the input interface
for traffic going out of a managed object. A backbone-facing
interface is always the output interface for traffic going out of a
managed object and the input interface for traffic going into a
managed object.
Note: If you selected Interfaces or Interface Groups on the
Match tab, then this option is selected, and the Interface
Boundary Type options are disabled.
Simple
If you select Simple, then SP automatically determines whether
traffic enters or leaves at the configured boundary interfaces of a
managed object, based on traffic characteristics and the match
type. See Step 8.
7. If you selected Interfaces or Interface Groups on the Match tab or Advanced for the
interface boundary type, then configure the following settings, and click Save to complete
the configuration:
Setting
Description
Backbone Facing
Interfaces
Click Edit Boundary Interface List, and then use the
selection wizard to select interfaces that face the backbone.
See “Using Selection Wizards” on page 31.
<managed object>
Facing Interfaces
Click Edit Boundary Interface List, and then use the
selection wizard to select interfaces that face the managed
object. See “Using Selection Wizards” on page 31.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule, or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings” on
page 180.
176
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
8. If you selected Simple for the interface boundary type, then configure the following
settings, and click Save to complete the configuration:
Setting
Description
Boundary
Interfaces
Click Edit Boundary Interface List, and then use the
selection wizard to select boundary interfaces. See “Using
Selection Wizards” on page 31.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule, or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings” on
page 180.
Configuring TMS boundary settings for a customer, peer, or profile managed object
To configure TMS boundary settings for a customer, peer, or profile managed object:
1. Navigate to the Boundary tab.
See “Adding and editing a managed object” on page 162.
2. Select one of the following Choose Boundary options:
Option
Description
Network
Boundary
Select to use the network boundary for the managed object
boundary. When this option is selected you cannot configure any
interfaces for the router boundary or the TMS boundary. To
complete the configuration, click Save.
Interfaces
Select if you want to configure interfaces for the managed object
boundary. When this option is selected, options for selecting
interfaces appear for the TMS boundary.
Note: Go to Step 4 if the Choose Boundary options are
disabled. These options are disabled if you selected TMS Ports
on the Match tab.
Proprietary and Confidential Information of Arbor Networks Inc.
177
SP and TMS User Guide, Version 8.0
3. If you selected Interfaces for the Choose Boundary option, then select one of the
following Type options In the TMS Boundary section:
Type Option
Description
None
Includes no TMS ports in the boundary of a managed object. To
complete the configuration, click Save.
Selected TMS
Ports
Allows you to manually configure which ports are a part of a
managed object’s boundary. For each port, you can designate
whether traffic over the port is “In” or “Out” of the managed object.
Alternatively, you can allow SP to determine the traffic directions
automatically. See Step 4.
All TMS Ports
Includes all TMS ports in the boundary of a managed object. When
you select this type, the direction of incoming or outgoing traffic is
determined by TMS Auto Ports rules. To complete the
configuration, click Save.
4. If you selected TMS Ports on the Match tab or selected Selected TMS Ports from the
Type options, the TMS Ports box appears. To enter ports in this box, select one of the
following options, use the selection wizard to select one or more TMS ports through which
to force incoming traffic, and click Save to save the configuration:
Option
Description
TMS In Ports
Counts only inbound traffic as “In” to the managed object.
TMS Out Ports
Counts only inbound traffic as “Out” to the managed object.
TMS Auto Ports
Counts inbound traffic on the selected ports as either “In” or “Out”
to the managed object, based on whether the managed object
matches the source or destination of the traffic
See “Using Selection Wizards” on page 31.
Important: When you select TMS ports for a managed object boundary, any given TMS
port must only be configured for one directionality: TMS In Ports, TMS Out Ports, or TMS
Auto Ports.
Configuring interface boundary settings for a VPN managed object
To configure interface boundary settings for a VPN managed object:
1. Navigate to the Boundary tab of a VPN managed object.
See “Adding and editing a managed object” on page 162.
2. Do one of the following:
178
l
If you selected None or Route Target on the Match tab, go to Step 3.
l
If you selected Interfaces on the Match tab, go to Step 5.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
3. Select one of the following VPN interface boundary types:
Type
Description
Rules Only
SP uses dynamic auto-configuration rules to determine all
boundary interfaces. See Step 4.
Interfaces &
Rules
SP uses dynamic auto-configuration rules and your static
configurations to determine boundary interfaces. See Step 5.
Important: Arbor recommends that you configure VPN interface boundaries with rules
whenever possible. Rules use regular expressions to match boundaries that are
dynamically based on interface descriptions (ifAlias value). This ensures that SP
automatically updates boundaries when the VPN interface boundaries change.
4. If you selected Rules Only for the VPN interface boundary type, then configure the
following settings, and click Save to complete the configuration:
Setting
Description
Locality
You can configure locality to determine whether to bin BGP
attributes for the source or the destination of the traffic flowing
into or out of a VPN managed object. Select default unless
you are configuring locality for a VPN managed object that is
external to the monitored network. If an object is external, then
you must configure it with external match settings and select
external from the Locality list.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule, or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings” on
the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
179
SP and TMS User Guide, Version 8.0
5. If you selected Interfaces on the Match tab or selected Interfaces & Rules for the
VPN interface boundary type, then configure the following settings, and click Save to
complete the configuration:
Setting
Description
Customer
Sub-Interfaces
Click Edit Boundary Interface List, and then use the
selection wizard to select boundary interfaces. See “Using
Selection Wizards” on page 31.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule, or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings”
below.
Automatically configured auto-configuration rule settings
When you add an auto-configuration rule to a managed object, the following settings are
automatically configured on the Action tab of the rule:
n The Set Managed Objects check box is selected.
n
If the managed object is a VPN, Managed object-facing is selected as the interface
boundary type. Otherwise, Simple is selected as the interface boundary type.
The interface boundary type that is selected allows SP to determine the directionality of the
interface boundary.
n
180
The managed object appears in the Managed Objects box.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring Threshold Alerting for Managed Objects
Introduction
You can use the Threshold Alerting tab to add or edit high and low traffic thresholds for a
managed object that you are configuring.
See “Configuring Managed Objects” on page 162.
How threshold alerting works
When incoming or outgoing traffic reaches or exceeds the high threshold rates for a managed
object, SP generates a high traffic threshold alert. Similarly, when traffic drops below the low
threshold rates, SP generates a low traffic threshold alert. SP sends up to one high and one
low threshold alert per managed object. If traffic for a managed object exceeds both bps and
pps thresholds for either low or high traffic, then SP sends one alert for the highest percentage
difference from the threshold for either bps or pps.
Example: A managed object has configured high threshold rates of 1 Mbps and 1 Kpps, and
SP detects traffic rates for that managed object at 4 Mbps and 10 Kpps. SP sends a high
threshold alert based on Kpps because the pps threshold was exceeded by 1000%, which is
greater than the bps threshold that was exceeded by 400%.
The time interval for threshold traffic data is one minute. When the average rate of traffic over a
one minute period exceeds a high threshold or is below a low threshold, then a threshold alert is
triggered.
Configuring threshold alerting settings
To configure threshold alerting settings:
1. Navigate to Threshold Alerting tab.
See “Adding and editing a managed object” on page 162.
2. Use the following table to configure the settings on the Threshold Alerting tab:
Setting
Description
High Threshold boxes
Type the KLJK WUDIILF WKUHVKROGV for bps and pps.
bps and pps lists
Select the corresponding high threshold traffic rates.
Low Threshold boxes
Type the ORZ WUDIILF WKUHVKROGV for bps and pps.
bps and pps lists
Select the corresponding low threshold traffic rates.
Proprietary and Confidential Information of Arbor Networks Inc.
181
SP and TMS User Guide, Version 8.0
Configuring Profiled Router Detection for Managed Objects
Introduction
On the Profiled Router Detection tab, you can enable profiled router detection. After you
enable profiled router detection, you can access the Profiled Router Detection Configuration
window to configure settings that determine when an alert is triggered and the severity level
that it is assigned. Separate incoming and outgoing traffic settings are provided because the
rate of traffic in one direction might be significantly different than the rate of traffic in the other
direction. For additional information about profiled router detection, see “About Profiled Router
Detection” on page 447.
You can also enable and configure automatic rate calculations. Arbor recommends that you
use the automatic rate calculations whenever possible. Automatic rate calculation is not
available if Interface Groups is selected on the Match tab. For more information about the
calculations and their settings, see “About automatic rate calculation for profiled router
detection” on page 449.
Configuring profiled router detection settings
To configure profiled router detection settings:
1. Navigate to the Profiled Router Detection tab.
See “Adding and editing a managed object” on page 162.
2. To enable profiled router detection, select the Enable Profiled Router Detection
check box.
3. Click Edit Profiled Router Configuration.
4. Configure the settings in the Profiled Router Detection Configuration window.
See “Profiled router detection configuration settings” on the facing page.
5. From the Outgoing Detection list, select one of the following settings:
l
Default (Use Global Setting)
This setting uses the global setting for profiled router outgoing detection that is
configured on the Configure Global Detection Settings page (Administration >
Detection > DDoS). The global profiled router outgoing detection setting is set to
Disabled by default.
l
Always Enabled or Always Disabled
These settings allow you to enable or disable profiled router outgoing detection on a per
managed object basis.
6. Click Save, and then commit your changes.
182
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Profiled router detection configuration settings
Use the following table to configure the settings in the Profiled Router Detection Configuration
window:
Profiled router detection configuration settings
Setting
Description
Severity Duration box
Type the QXPEHU RI VHFRQGV that traffic must exceed a given
threshold before SP escalates its severity.
For more information about how the severity duration is used to
classify an alert’s severity, see “How SP creates and classifies
profiled router detection alerts” on page 448.
Incoming Severity
Thresholds and
Outgoing Severity
Thresholds boxes
Type the VHYHULW\ WKUHVKROGV (in bps and pps).
The severity thresholds are applied on a per router basis for
profiled router protocol alerts and on a per interface basis for
profiled router bandwidth alerts.
For more information about how the severity thresholds are used
to classify an alert’s severity, see “How SP creates and classifies
profiled router detection alerts” on page 448.
Enable SNMP Link
Rate Severity
Calculation check box
Select if you want SP to use the SNMP link rate of an interface
as a severity threshold.
SP calculates the severity threshold based on the lower of the
auto-configured or manually configured high severity rate and
the SNMP link rate of the router interface on which the traffic
was detected.
Incoming Forced
Alert Thresholds and
Outgoing Forced
Alert Thresholds
boxes
Type the IRUFHG DOHUW WKUHVKROGV (in bps and pps).
For information on the use of forced alert thresholds, see “About
the use of forced alert thresholds” on page 449.
If traffic exceeds a forced alert threshold for the profiled router
latency period, SP generates an alert. The severity of the alert is
then determined by the severity duration, the severity thresholds,
and other factors.
For more information about the classification of an alert’s
severity, see “How SP creates and classifies profiled router
detection alerts” on page 448.
The forced alert thresholds are applied on a per router basis for
profiled router protocol alerts and on a per interface basis for
profiled router bandwidth alerts.
Incoming Alert Ignore
Rates and Outgoing
Alert Ignore Rates
boxes
Type the DOHUW LJQRUH UDWHV (in bps and pps) below which
you do not want SP to generate alerts.
Note: Ignore rates impose a floor to the baseline for the
configured type (bps or pps).
If the ignore rates are the same as the forced alert thresholds,
then the baselines are ignored when generating alerts.
Note: Forced alert thresholds supersede ignore rates.
Proprietary and Confidential Information of Arbor Networks Inc.
183
SP and TMS User Guide, Version 8.0
Profiled router detection configuration settings (Continued)
Setting
Description
Enable Automatic
Rate Calculation
check box
a. Select if you want to enable automatic rate calculation.
b. Configure the Automatic Rate Calculation settings.
See “Automatic rate calculation settings” below.
c. Finish configuring the profiled router detection settings
described in this table.
Note: This option is not available with the interface groups
match type.
Interface Bandwidth
Alerts, Interface
Packets Alerts, and
All Protocols Alerts
lists
In the Detection Sensitivity Thresholds section, select the
sensitivity thresholds for the different types of alerts.
A low number results in more alerts and a high number results in
fewer alerts. Arbor recommends that you select 3 as a starting
point in a production environment. You can then adjust this
setting to reduce or to increase the number of alerts that you
receive in your deployment.
Note: These options are not available with the interface groups
match type.
Suggest Rates button
Click if you want the system to generate the severity thresholds
using the most recent calculated automatic rates.
Note: This option is not available with the interface groups
match type.
Automatic rate calculation settings
Use the following table to configure the automatic rate calculation settings for profiled router
detection:
Automatic rate calculation settings
184
Setting
Description
Severity Percentile
box
Type the SHUFHQWDJH of normal traffic that you want SP to use as
a base value to calculate incoming and outgoing severity rates.
Typical percentile values range from 95 to 98.
Severity Multiplier
box
Type the QXPEHU that you want to multiply with the severity
percentile to calculate the high severity rate.
Example: If the 95th percentile value for incoming traffic is 100
Mbps and the multiplier is 1.1, then the high severity threshold for
that managed object becomes 110 Mbps.
Ignore Percentile
box
Type an ignore SHUFHQWLOH to calculate the ignore rate.
The default value is 40. This means that 60% of the data points
over the last 30 days are greater than the calculated trigger rate.
Arbor recommends that you enter a value between 40 and 50.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Automatic rate calculation settings (Continued)
Setting
Description
Severity Rate Floor
settings
Type the lowest YDOXHV for which you want SP to generate a
severity rate, and then select the corresponding traffic units from
the lists.
Ignore Rate Floor
settings
Type the lowest YDOXHV for which you want SP to generate an
ignore rate, and then select the corresponding traffic units from the
lists.
See “About automatic rate calculation for profiled router detection” on page 449.
To finish configuring profiled router detection, see “Configuring profiled router detection
settings” on page 182.
Proprietary and Confidential Information of Arbor Networks Inc.
185
SP and TMS User Guide, Version 8.0
Configuring Host Detection for Managed Objects
Introduction
Host detection monitors the IPv4 and IPv6 traffic to a host on all monitored routers. Host
detection can trigger a standard host alert or a fast flood host alert. A standard host alert is
triggered when the traffic on a monitored router towards a single host exceeds the configured
threshold of an enabled misuse type for a specified time period. A fast flood host alert is
triggered when large amounts of traffic towards a single host are detected for an enabled
misuse type. See “About Host Detection” on page 429.
If excessive traffic is detected for multiple misuse types that are enabled, then a single alert is
created instead of separate alerts for each misuse type. The alert identifies each misuse type
that had excessive traffic. See “Host detection misuse types” on page 189.
Note: If you experience an inordinate number of alerts because a host detection misuse type is
enabled, you can quickly disable that misuse type in every set of host detection settings. See
"Disabling and Enabling Host Detection Misuse Types" in the SP and TMS Advanced
Configuration Guide.
About reusing an ongoing TMS auto-mitigation
If a customer managed object is configured to use alert-triggered TMS auto-mitigation, then
the managed object can be configured to reuse an ongoing TMS auto-mitigation for multiple
host alerts. With this configuration, a host alert does not trigger a new auto-mitigation if
another auto-mitigation, which was triggered by another host alert of the managed object, is
ongoing. Instead, the prefix of the new host alert is added to the ongoing auto-mitigation. See
“About the TMS Auto-Mitigation Settings” on page 196.
About configuring shared and custom host detection settings
You can select a set of shared host detection settings or create a custom set. Managed service
administrators cannot edit shared sets of host detection settings, they can only view them. If
you want to permit a managed services administrator to control the host detection settings of a
profile managed object, then you must assign a custom set of host detection settings to the
managed object. See “About Shared Host Detection Settings” on page 436.
Configuring host detection using shared settings
You can select shared settings for host detection when you add or edit a managed object. The
settings you configure determine when an alert is generated and the severity of the alert. See
“How SP creates and classifies standard host alerts” on page 433.
To configure host detection using shared settings:
1. Navigate to the Host Detection tab of the managed object.
See “Adding and editing a managed object” on page 162.
2. For Host Detection Settings, click Shared.
3. From the Shared Settings list, select the set of host detection settings that you want to
use with this managed object.
4. In the Shared Settings section on the Host Detection tab of the managed object, you
can view the set of shared host detection settings that you selected.
This section displays only misuse types that are enabled. This section does not appear if
Disabled is selected in the Shared Settings list.
186
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
5. To change the settings, either select a different set of host detection settings from the
Shared Settings list or edit the current set of shared settings.
Important: If you click Edit Shared Settings and make changes to that set of host
detection settings, then those settings are changed for every managed object or service
that uses those settings. See “Configuring Shared Host Detection Settings” on page 442.
The Edit Shared Settings link does not appear if Disabledis selected in the Shared
Settings list.
If you have made changes to a managed object that you have not saved and click Edit
Shared Settings, then you are asked to either save the changes or continue editing.
Note: A managed services user cannot select a shared set of host detection settings.
They can only view the shared host detection settings that you have assigned to the
managed objects in their scope.
6. Click Save, and then commit your changes.
Configuring host detection using a custom set
You can configure a custom set of host detection settings when you add or edit a managed
object. The settings you configure determine when an alert is generated and the severity of the
alert. See “How SP creates and classifies standard host alerts” on page 433.
To configure a custom set of host detection settings for a managed object:
1. Navigate to the Host Detection tab of the managed object.
See “Adding and editing a managed object” on page 162.
2. For Host Detection Settings, click Custom.
The custom set is initially populated from the shared settings that were previously set,
otherwise it uses the Default set.
3. In the Shared Settings section, configure the custom host detection settings. See “Host
detection settings” on the next page.
Note: Managed services administrators can change the custom host detection settings
that you have assigned to the managed objects in their scope. If the parent managed
object has custom settings, a child managed object of it created by managed services
administrators will also have custom settings that they can change.
4. Click Save, and then commit your changes.
Note: After saving your custom set, if you click Shared, the Default set is selected in the
Shared Settings list instead of the shared set previously used by the managed object. The
Default set deletes the custom set, which is not saved.
Proprietary and Confidential Information of Arbor Networks Inc.
187
SP and TMS User Guide, Version 8.0
Host detection settings
The following are the host detection settings that appear on the Host Detection tab:
Host detection settings
Setting
Description
Host Detection
setting
Host detection is either enabled or disabled. Host detection monitors the
traffic to a host on all monitored routers. A host alert is triggered when
the traffic on a monitored router towards a single host exceeds the
configured threshold of an enabled misuse type for a specified time
period. See “About Host Detection” on page 429.
Severity
Duration setting
The number of seconds that SP waits before it escalates the severity
level of an alert. If the traffic exceeds 75% of the high severity rate for the
severity duration, then the alert is classified with a severity of Medium. If
the traffic exceeds the high severity rate for the severity duration, then
the alert is classified with a severity of High.
Note: If you enter a value for severity duration that is less than a whole
minute, SP rounds that value up to the next minute when determining the
severity duration. For example, if you set the severity duration to 10
seconds, SP uses a value of 1 minute for the severity duration.
Note: Fast flood host detection ignores this setting, and fast flood alerts
always have a high severity.
188
Fast Flood
Detection
setting
Fast flood detection is either enabled or disabled. When fast flood
detection is enabled, a host alert is triggered much faster when large
amounts of traffic toward a host are detected. See “About host detection
with fast flood detection enabled” on page 431.
Note: If you want a host alert that is triggered by fast flood detection to
start an auto-mitigation, then you must also configure auto-mitigation for
this managed object. See “Configuring Mitigation Settings for Managed
Objects” on page 192.
Misuse Type
column
The misuse types that host detection uses to detect excessive rates of
traffic. See “Host detection misuse types” on the facing page.
Trigger Rate
column
The trigger rate for each misuse type. See “Host detection terminology”
on page 429.
High Severity
Rate column
The high severity rate for each misuse type. See “Host detection
terminology” on page 429.
The high severity rate is applied on a per router basis for host detection.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Host detection misuse types
SP uses the following misuse types with host detection:
Host detection misuse types
Misuse Type
Type of Traffic
Can Help Detect
Total Traffic
The total traffic (in
bps or pps) for a
given host
Host attacks that do not follow a known attack
pattern
chargen
Amplification
chargen traffic (in
bps or pps) with the
UDP protocol and
source port 19
chargen (Character Generator Protocol)
reflection/amplification attacks
DNS
DNS traffic (in pps) Floods of DNS traffic
with the TCP and/or
UDP protocol and
destination port 53
traffic
DNS Amplification
DNS traffic (in bps
or pps) with the
UDP protocol and
source port 53
DNS reflection/amplification attacks
ICMP
IPv4 and IPv6
Internet Control
Message Protocol
traffic (in pps)
IPv4 ICMP and ICMPv6 packet-flooding
attacks
IP Fragment
Traffic (in pps) with
the IP fragment flag
TCP and UDP fragmentation attacks
Note: TCP and UDP fragmentation attacks
are often associated with chargen, DNS,
SNMP, SSDP, and MS SQL RS amplification
attacks.
IP Private
Traffic (in pps) for
private IP address
space
Spoofed IP addresses, which are not expected
to be routed over the Internet, that are used in
attacks
Note: SP uses the following IP spaces to
detect this misuse type:
n
n
Proprietary and Confidential Information of Arbor Networks Inc.
IPv4
l
10.0.0.0/8
l
172.16.0.0/12
l
192.168.0.0/16
IPv6
l
All spaces except 2000::/3
189
SP and TMS User Guide, Version 8.0
Host detection misuse types (Continued)
190
Misuse Type
Type of Traffic
Can Help Detect
IPv4 Protocol 0
Traffic (in pps) with Attacks in which the higher-layer transport
the protocol number protocol number is set to 0, which is an invalid
set to 0
protocol number (TCP is protocol 6, UDP is
protocol 17, and ICMP is protocol 1).
Note: The IPv4 Protocol 0 misuse type works
only with IPv4 traffic.
MS SQL RS
Amplification
UDP traffic (in bps
or pps)with source
port 1434
Microsoft SQL Resolution Service
reflection/amplification attacks
NTP Amplification
NTP traffic (in bps
or pps) with the
UDP protocol,
source port 123,
and invalid packet
sizes
NTP reflection/amplification attacks
SNMP Amplification
SNMP traffic (in
bps or pps) with the
UDP protocol and
source port 161
and/or 162.
SNMP reflection/amplification attacks
SSDP Amplification
UDP traffic (in bps
or pps) with source
port 1900
SSDP (Simple Service Discovery Protocol)
reflection/amplification attacks
TCP Null
TCP traffic (in pps)
that contains a
sequence number
but no flags
TCP Null-Flags attacks
TCP RST
TCP traffic (in pps)
with the reset flag
set
TCP reset attacks
TCP SYN
TCP traffic (in pps)
with the
synchronize flag set
Common TCP SYN flood attacks.
UDP
UDP traffic (in pps)
UDP attacks
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring Profiled Network Detection for Managed Objects
Introduction
Profiled network detection identifies excessive rates of traffic that cross a managed object
boundary. With profiled network detection enabled for a managed object, SP triggers an alert
when it identifies excessive rates of traffic at the managed object boundary based on baselines
that SP has calculated. The rate of traffic must exceed the baseline by the detection
percentage for a sustained period of time. When SP generates a profiled network detection
alert, it classifies the severity of the alert as low, medium, or high. See “About Profiled Network
Detection” on page 451.
Configuring profiled network detection for a managed object
To configure profiled network detection for a managed object:
1. Add or edit a managed object.
See “Adding and editing a managed object” on page 162.
2. Click the Profiled Network Detection tab.
3. Select the Enable Profiled Network Detection check box to enable profiled network
detection.
4. Use the following table to configure the profiled network detection settings:
Setting
Description
Enable Profiled
Country Detection
check box
Select if you want to enable profiled country detection.
Incoming Detection
Percent and Outgoing
Detection Percent box
Type the SHUFHQWDJH above the baseline that either
incoming or outgoing traffic must be before SP triggers the
alert.
Severity Duration box
Type the QXPEHU of minutes that an alert must exceed the
severity threshold before SP sets the alert to high severity.
If enabled, SP generates alerts when the traffic from a
country exceeds the baseline values for that country.
The severity rates are applied on a network wide basis.
Incoming Severity
Percent and Outgoing
Severity Percent boxes
Type the SHUFHQWDJH above the baseline that either
incoming or outgoing traffic must be before SP sets the
alert to high severity.
Incoming Ignore Rates
and Outgoing Ignore
Rates boxes
Type the traffic UDWHV (in bps and pps) below which you do
not want SP to generate alerts.
Note: Ignore rates impose a floor to the baseline for the
configured type (bps or pps).
5. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
191
SP and TMS User Guide, Version 8.0
Configuring Mitigation Settings for Managed Objects
Introduction
You can add or edit mitigation settings when you configure customer, peer, and profile
managed objects. Each type of managed object has a different procedure to configure the
mitigation settings.
For more information, see:
“Configuring Mitigation Settings for Customer Managed Objects” on the facing page
n
192
n
“Configuring Mitigation Settings for Peer Managed Objects” on page 202
n
“Configuring Mitigation Settings for Profile Managed Objects” on page 203
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring Mitigation Settings for Customer Managed Objects
Introduction
You can add or edit the following mitigation settings when you configure a customer managed
object:
n TMS Mitigation Settings
You can choose to collect data for enforcing baselines using the Protocol Baselines
countermeasure. You can also choose to have SP make rate policing suggestions based on
IP location information. In addition, you can configure GRE reinjection tunnels.
See “Configuring TMS mitigation settings” below.
n
Auto-Mitigation Settings
You can choose to automatically start a mitigation using an alert trigger or a traffic trigger. If
you choose an alert trigger, you can automatically start a TMS, blackhole, or a combined
TMS and blackhole mitigation when the managed object is attacked. With a TMS
mitigation, you can configure the managed object to reuse an ongoing auto-mitigation for
multiple host alerts, instead of creating a new auto-mitigation for each host alert. The prefix
of each new host alert is added to the ongoing auto-mitigation. You can also enable automitigation for alerts triggered by a host attack and then disable auto-mitigation for alerts
triggered by a profiled router attack or a profiled network attack. See “Configuring alerttriggered auto-mitigation settings” on the next page.
Note: Blackhole auto-mitigations can only be used with host alerts on IPv4-based
managed objects.
If you choose a traffic trigger, you can automatically start a mitigation when a TMS
appliance detects the traffic for the managed object exceeds a threshold value. See “About
traffic-triggered auto-mitigation” on page 199.
Auto-mitigation is disabled by default.
Configuring TMS mitigation settings
To configure TMS mitigation settings:
1. Navigate to the Mitigation tab.
See “Adding and editing a managed object” on page 162.
2. If you plan to enforce your baselines using the Protocol Baselines countermeasure, under
Enforced Baseline Protection, select Enabled. See “Configuring the Protocol
Baselines Countermeasure” on page 667.
Important: If you enable this setting, it likely will be at least 2 days before this
countermeasure is effective because of its data gathering requirements.
3. (IPv4-based managed objects only) If you want SP to make rate policing suggestions
based on IP location information, under Generate IP Location Policing Rate
Suggestions, select Enabled
Selecting this option loads IP location-specific rate suggestions into the IP Location
Policing countermeasure. These rate suggestions can then be transferred into rate limit
settings for a country. See “Configuring the IP Location Policing Countermeasure ” on
page 658.
Important: If you enable this setting, it likely will be at least 2 days before this
countermeasure is effective because of its data gathering requirements.
Proprietary and Confidential Information of Arbor Networks Inc.
193
SP and TMS User Guide, Version 8.0
4. Select the mitigation template that you want to use from the User-Initiated Mitigation
Template list.
If an auto-mitigation occurs in the managed services view, the managed services user can
view and edit that auto-mitigation with the auto-mitigation’s template applied, even if the
user’s assigned “User Initiated” mitigation template is different.
You use this template when you create a mitigation to protect a managed object. For
information about creating templates, see “About TMS Mitigations” on page 574.
5. (For managed objects that are configured to match CIDR blocks, CIDR groups, or
CIDR IPv6 blocks only) You can configure the settings for a static or redundant GRE
reinjection tunnel.
See “About configuring GRE reinjection tunnel settings” on page 200.
6. Click Save.
Configuring alert-triggered auto-mitigation settings
To configure alert-triggered auto-mitigation settings:
1. Navigate to the Mitigation tab.
See “Adding and editing a managed object” on page 162.
2. If the match type cannot automatically detect the IP version, select either the IPv4 or IPv6
option.
3. In the Constrain Protected Prefixes box, type the CIDR block SUHIL[HV for which you
want SP to create auto-mitigations. This setting is required if the managed object does not
match CIDR blocks.
If you do not set a constraint prefix, then the TMS appliance mitigates all of the contents
on the Protect tab of the configured mitigation. For information about how SP determines
the target prefix to auto-mitigate, see “Configuring Protect Settings for TMS Mitigations
and Templates” on page 626, “Determining the target prefix for auto-mitigation in host
attacks” on page 601, and “Determining the target prefix for auto-mitigation in profiled
router attacks” on page 601.
4. In the Auto-Mitigation Template list, select the mitigation template that you want to use.
You use this template when you create a mitigation to protect a managed object.
If an auto-mitigation occurs in the managed services view, the managed services user can
view and edit that auto-mitigation with the auto-mitigation’s template applied, even if the
user’s assigned “User Initiated” mitigation template is different.
For information about creating templates, see “About TMS Mitigations” on page 574.
5. Select the Alert-Triggered option.
194
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
6. Select a Mitigation Type option and then configure the settings for that option.
Mitigation Type options
Option
Description
TMS
Uses TMS systems to auto-mitigate the alert. See “About the
TMS Auto-Mitigation Settings” on the next page.
TMS + Blackhole
Uses TMS systems to auto-mitigate the alert until the incoming
TMS traffic exceeds the rate you specify, then redirects traffic by
announcing BGP routes. See “About the TMS Auto-Mitigation
Settings” on the next page and “About the Blackhole AutoMitigation Settings” on the next page.
Blackhole
Redirects traffic by announcing BGP routes. See “About the
Blackhole Auto-Mitigation Settings” on the next page.
Note: Blackhole auto-mitigations can only be used with host alerts on IPv4-based
managed objects.
7. (For managed objects that are configured to match CIDR blocks, CIDR groups, or
CIDR IPv6 blocks only) You can configure the settings for a static or redundant GRE
reinjection tunnel.
See “About configuring GRE reinjection tunnel settings” on page 200.
8. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
195
SP and TMS User Guide, Version 8.0
About the TMS Auto-Mitigation Settings
The following table describes the settings used with the TMS mitigation type and the TMS
settings used with the TMS + Blackhole mitigation type:
TMS auto-mitigation settings
Option
Description
Reuse TMS
Auto-Mitigations
for Multiple Host
Alerts options
(For TMS mitigation type only) Select whether to enable or disable the
reuse of a TMS auto-mitigation for multiple host alerts. With the
Enabled option selected, a host alert does not trigger a new automitigation if another auto-mitigation, which was triggered by another
host alert of the managed object, is ongoing. Instead, the prefix of the
new host alert is added to the ongoing auto-mitigation along with an
annotation that specifies the prefix that was added by the new host alert.
This option makes it possible for multiple host alerts of a managed object
to be associated with a single auto-mitigation.
If multiple host alerts are associated with an auto-mitigation only the
host alert that triggered the auto-mitigation appears in the Web UI.
However, if the host alert that triggered the auto-mitigation ends and
other host alerts that are associated with the auto-mitigation are still
ongoing, then one of the ongoing host alerts becomes the alert that
drives the auto-mitigation. When a different host alert becomes the alert
that drives the auto-mitigation, it then appears in the Web UI. The automitigation remains ongoing as long as one of the host alerts associated
with it is ongoing.
Profiled
Auto-Mitigations
options
Select whether to enable, disable or use the global default for automitigation of alerts that are triggered by a profiled router attack or a
profiled network attack while you enable auto-mitigation for DoS alerts
that are triggered by a host attack. See “About the Profiled AutoMitigations options” on the facing page.
End TMS
Auto-Mitigation
Select whether to automatically stop the auto-mitigation immediately
after the alert ends, a set period of time after the alert ends, or a set
period of time after the TMS auto-mitigation starts. You also have the
option of requiring that it be stopped manually. See “About the End TMS
Auto-Mitigation and End Blackhole Auto-Mitigation options” on
page 198.
About the Blackhole Auto-Mitigation Settings
The following table describes the settings used with Blackhole mitigation type and the
blackhole setting used with the TMS + Blackhole mitigation type:
Note: Blackhole auto-mitigations can only be used with host alerts on IPv4-based managed
objects.
196
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Blackhole auto-mitigation settings
Option
Description
Incoming TMS
Traffic Threshold
to Begin
Blackhole AutoMitigation options
(For the TMS + Blackhole mitigation type only) Enter the rate in
either bps, pps, or both. You can select the magnitude from each list:
giga (G), mega (M), kilo (K), or just bps/pps.
Community box
Choose one of the following steps:
n
n
Type the QXPEHU of the community group.
Click Lookup Community Groups to select one or more
groups from the Lookup Community Groups window to populate
the box.
See “Configuring BGP Community Groups” on page 750.
See “Identifiers for BGP Communities” on page 995.
Local AS check box
Select if the community is local and you are running confederations.
No advertise check
box
Select if the community is not advertised to its peers.
No export check
box
Select if the community is not advertised outside of a confederation
boundary.
No peer check box
Select if the community is not advertised past the neighboring AS.
IPv4 Nexthop
Select the Null Route, Diversion, or Custom option. The Null
Route and Diversion options use the value from the template. If
you select custom, type the value in the Custom Nexthop box. For
information about setting the null route and diversion template
values, see “Configuring Blackhole Nexthop Template Values” on
page 749.
IPv4 Router BGP
Sessions
Select the IPv4 BGP sessions that you want to use in the mitigation.
You must select at least one session.
End Blackhole AutoMitigation
Automatically stop the auto-mitigation immediately after the alert
ends, a set period of time after the alert ends, or a set period of time
after the blackhole auto-mitigation starts. You also have the option
of requiring that it be stopped manually. See “About the End TMS
Auto-Mitigation and End Blackhole Auto-Mitigation options” on the
next page.
About the Profiled Auto-Mitigations options
The Profiled Auto-Mitigations options are used with alert-triggered auto-mitigations. With
an IPv4-based managed object, they appear when you click the Alert-Triggered option. With
an IPv6 CIDR block-based managed object, they appear when you click Enable AutoMitigation on the managed object's Mitigation tab.
Proprietary and Confidential Information of Arbor Networks Inc.
197
SP and TMS User Guide, Version 8.0
The Profiled Auto-Mitigations options allow you to disable auto-mitigation for alerts that
are triggered by a profiled router attack or a profiled network attack while you enable automitigation for DoS alerts that are triggered by a host attack. For example, you can enable both
host detection and profiled network detection for a managed object, but only enable automitigation for DoS alerts that are triggered by a host attack.
The Profiled Auto-Mitigations options also allow you to use the global auto-mitigation
setting for alerts triggered by a profiled router attack or a profiled network attack. You configure
this global setting on the Configure Global TMS Mitigation Settings page (Administration >
Mitigation > Global Settings). See “Configuring Global TMS Mitigation Settings” on
page 597.
Note: Arbor Networks recommends that you disable auto-mitigation for DoS alerts that are
triggered by a profiled router attack or a profiled network attack.
The following table describes the Profiled Auto-Mitigations options:
Profiled Auto-Mitigations options
Option
Description
Global Default
Enables or disables auto-mitigation for DoS alerts that are triggered by
a profiled router attack or a profiled network attack based on the global
default setting.
Enabled
Enables auto-mitigation for DoS alerts that are triggered by a profiled
router attack or a profiled network attack. This option overrides the
global default setting.
Disabled
Disables auto-mitigation for DoS alerts that are triggered by a profiled
router attack or a profiled network attack. This option overrides the
global default setting.
About the End TMS Auto-Mitigation and End Blackhole Auto-Mitigation options
The End TMS Auto-Mitigation options appear when you choose Alert-Triggered and
either the TMS or TMS+Blackhole option for IPv4-based managed objects. The End
TMS Auto-Mitigation options appear when you just choose Alert-Triggered for
IPv6-based managed objects.
The End Blackhole Auto-Mitigation options appear when you click Alert-Triggered and
either the Blackhole or TMS+Blackhole option. Blackhole auto-mitigation options appear
only for IPv4-based managed objects.
The options configure SP to automatically stop an auto-mitigation that is triggered by an alert.
You can configure it to automatically stop the auto-mitigation immediately after the alert ends
(the default), a set period of time after the alert ends, or a set period of time after the automitigation starts. You also have the option of requiring that it be stopped manually.
198
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
The following table describes the options:
End TMS Auto-Mitigation and End Blackhole Auto-Mitigation options
Option
Description
When alert ends
Automatically stops the auto-mitigation when the DoS alert
ends.
7LPH SHULRG after
alert ends
Automatically stops the auto-mitigation the selected number of
minutes or hours after the DoS alert ends.
7LPH SHULRG after
TMS auto-mitigation
starts
or
7LPH SHULRG after
blackhole automitigation starts
Automatically stops the TMS or blackhole auto-mitigation the
selected number of minutes or hours after it starts.
Never
Does not automatically stop the auto-mitigation. It must be
stopped manually.
About traffic-triggered auto-mitigation
You can configure SP to start a mitigation automatically on an IPv4-based managed object
when a TMS appliance detects that the traffic for the managed object exceeds a threshold
value. When you configure the Traffic-Triggered option, SP automatically mitigates traffic
for managed objects when their observed traffic exceeds the threshold (100 pps by default) at
any TMS appliance. If, during a mitigation, a TMS appliance does not detect at least the
threshold (100 pps by default) for a period of five minutes, then SP ends the mitigation. The
traffic threshold is applied to traffic observed at each TMS appliance and is not related to the
amount of traffic reported for the managed object in the SP Reports menu.
You can change the default 100 pps threshold and five-minute timeout values using the CLI.
See “Changing the Default Traffic-Triggered Auto-Mitigation Settings” in the SP and TMS
Advanced Configuration Guide.
You can also enable the TMS appliance to announce BGP routes for the managed object’s
prefixes immediately. When you save this setting, the TMS appliance announces BGP routes
to its peering routers, regardless of whether active mitigations exist. This can be useful when all
of the following conditions describe your circumstances:
n you are a large managed services provider
n
you deploy TMS appliances
n
you would like to use BGP to draw mitigation traffic to your TMS appliances
n
you do not want BGP routes to change when mitigations start or stop
Note: The BGP community group that is used for these BGP route announcements is
configured on the Configure Global TMS Mitigation Settings page (Administration >
Mitigation > Global Settings). See “Configuring Global TMS Mitigation Settings” on
page 597.
Proprietary and Confidential Information of Arbor Networks Inc.
199
SP and TMS User Guide, Version 8.0
Note: A TMS appliance can only announce BGP routes; it cannot announce flow
specification routes.
Configuring traffic-triggered auto-mitigation
You can only configure traffic-triggered auto-mitigation for IPv4-based managed objects that
match CIDR prefixes.
To configure the traffic-triggered auto-mitigation settings:
1. Navigate to the Mitigation tab.
See “Adding and editing a managed object” on page 162.
2. In the Constrain Protected Prefixes box., type the CIDR block SUHIL[HV for which
you want SP to create auto-mitigations.
If you do not set a constraint prefix, then the TMS appliance mitigates all of the contents
on the Protect tab of the configured mitigation. For information about how SP determines
the target prefix to auto-mitigate, see “Configuring Protect Settings for TMS Mitigations
and Templates” on page 626, “Determining the target prefix for auto-mitigation in host
attacks” on page 601, and “Determining the target prefix for auto-mitigation in profiled
router attacks” on page 601.
3. In the Auto-Mitigation Template list, select the mitigation template that you want to use.
You use this template when you create a mitigation to protect a managed object.
If an auto-mitigation occurs in the managed services view, the managed services user can
view and edit that auto-mitigation with the auto-mitigation’s template applied, even if the
user’s assigned “User Initiated” mitigation template is different.
For information about creating templates, see “About TMS Mitigations” on page 574.
4. Select the Traffic-Triggered option.
5. If you want the TMS appliance to announce BGP routes immediately to the peering
routers configured on the TMS appliance’s Patch Panel tab, select the Enabled option
under Immediately announce BGP routes. Otherwise, select Disabled.
6. You can configure the settings for a static or redundant GRE reinjection tunnel.
See “About configuring GRE reinjection tunnel settings” below.
7. Click Save.
To change the default 100 pps threshold and five-minute timeout values, see “Changing the
Default Traffic-Triggered Auto-Mitigation Settings” in the SP and TMS Advanced
Configuration Guide.
About configuring GRE reinjection tunnel settings
When you enable custom GRE reinjection tunnels, SP creates a GRE tunnel on each TMS
that is included in the TMS group that you select. Each tunnel passes the traffic for the CIDR
blocks that you define on the Match tab to the specified tunnel destinations. SP uses the
tunnel source IP and keepalive settings that are defined for each TMS on the Configure
Appliances page (Administration > Appliances).
For information about configuring the tunnel source IP and keepalive settings on a TMS, see
“Configuring GRE Settings for a TMS Appliance or TMS-VSM ” on page 554. For information
about configuring TMS groups, see “Configuring TMS Groups” on page 567. For more
information about configuring match types for customer and profiled managed objects, see
“Configuring Match Settings for Managed Objects” on page 165.
200
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
When you make any managed object CIDR configuration changes, these changes are
automatically updated in your GRE tunnel configuration.
Note: If a destination prefix you set on an individual TMS appliance is identical to a managed
object prefix, the GRE reinjection tunnel settings that you define for the managed object
override the TMS settings.
Use the following table to configure the settings for a static or redundant GRE reinjection
tunnel:
Setting
Description
Enable Custom
GRE Reinjection
Tunnels check
box
Click to enable GRE reinjection settings.
TMS Group list
Select a TMS group or All to select the TMS appliances to which
these settings apply.
GRE MTU box
Type the largest ,3 SDFNHW VL]H (in bytes) that you want to allow
into the GRE tunnel (excluding the GRE header). The valid range for IP
packet size is 28-1544.
If a packet exceeds the MTU setting, the TMS appliance or TMS-VSM
fragments the packet and encapsulates each fragment in a separate
GRE packet.
Primary
Destination IP
box
Type the IP address of the primary tunnel endpoint. For an IPv4 GRE
tunnel, type an IPv4 IP address. For an IPv6 GRE tunnel, type an IPv6
address.
Note: If you do not type an IP address in the Primary Destination
IP box, the tunnel will not operate.
Secondary
Destination IP
box
(For a redundant GRE tunnel only) Type the IP address of the
secondary tunnel endpoint. For an IPv4 GRE tunnel, type an IPv4 IP
address. For an IPv6 GRE tunnel, type an IPv6 address.
Proprietary and Confidential Information of Arbor Networks Inc.
201
SP and TMS User Guide, Version 8.0
Configuring Mitigation Settings for Peer Managed Objects
Introduction
You can add or edit mitigation settings when you configure peer managed objects. You can
choose to collect data for enforcing baselines using the Protocol Baselines countermeasure.
You can also choose to have SP make rate policing suggestions based on IP location
information.
Configuring TMS mitigation settings
To configure TMS mitigation settings:
1. Navigate to the Mitigation tab.
See “Adding and editing a managed object” on page 162.
2. If you plan to enforce your baselines using the Protocol Baselines countermeasure, under
Enforced Baseline Protection, select Enabled. See “Configuring the Protocol
Baselines Countermeasure” on page 667.
Important: If you enable this setting, it likely will be at least 2 days before this
countermeasure is effective because of its data gathering requirements.
3. (IPv4-based managed objects only) If you want SP to make rate policing suggestions
based on IP location information, under Generate IP Location Policing Rate
Suggestions, select Enabled
Selecting this option loads IP location-specific rate suggestions into the IP Location
Policing countermeasure. These rate suggestions can then be transferred into rate limit
settings for a country. See “Configuring the IP Location Policing Countermeasure ” on
page 658.
Important: If you enable this setting, it likely will be at least 2 days before this
countermeasure is effective because of its data gathering requirements.
To enable this feature for auto-mitigation, you must select the Load Rates on
Mitigation Start check box in the mitigation template.
4. Select the mitigation template that you want to use from the User-Initiated template list.
If an auto-mitigation occurs in the managed services view, the managed services user can
view and edit that auto-mitigation with the auto-mitigation’s template applied, even if the
user’s assigned “User Initiated” mitigation template is different.
You use this template when you create a mitigation to protect a managed object. For
information about creating templates, see “About TMS Mitigations” on page 574.
5. Click Save.
202
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring Mitigation Settings for Profile Managed Objects
Introduction
You can add or edit mitigation settings when you configure profile managed objects. You can
choose to collect data for enforcing baselines using the Protocol Baselines countermeasure.
You can also choose to have SP make rate policing suggestions based on IP location
information. In addition, you can configure GRE reinjection tunnels.
Configuring TMS mitigation settings
To configure TMS mitigation settings:
1. Navigate to the Mitigation tab.
See “Adding and editing a managed object” on page 162.
2. If you plan to enforce your baselines using the Protocol Baselines countermeasure, under
Enforced Baseline Protection, select Enabled. See “Configuring the Protocol
Baselines Countermeasure” on page 667.
Important: If you enable this setting, it likely will be at least 2 days before this
countermeasure is effective because of its data gathering requirements.
3. (IPv4-based managed objects only) If you want SP to make rate policing suggestions
based on IP location information, under Generate IP Location Policing Rate
Suggestions, select Enabled
Selecting this option loads IP location-specific rate suggestions into the IP Location
Policing countermeasure. These rate suggestions can then be transferred into rate limit
settings for a country. See “Configuring the IP Location Policing Countermeasure ” on
page 658.
Important: If you enable this setting, it likely will be at least 2 days before this
countermeasure is effective because of its data gathering requirements.
To enable this feature for auto-mitigation, you must select the Load Rates on
Mitigation Start check box in the mitigation template.
4. Select the mitigation template that you want to use from the User-Initiated template list.
If an auto-mitigation occurs in the managed services view, the managed services user can
view and edit that auto-mitigation with the auto-mitigation’s template applied, even if the
user’s assigned “User Initiated” mitigation template is different.
You use this template when you create a mitigation to protect a managed object. For
information about creating templates, see “About TMS Mitigations” on page 574.
5. (For managed objects that are configured to match CIDR blocks, CIDR groups, or
CIDR IPv6 blocks only) You can configure the settings for a static or redundant GRE
reinjection tunnel. See “About configuring GRE reinjection tunnel settings” on the next
page.
Note: For more information about configuring match types for profiled managed objects,
see “Configuring Match Settings for Managed Objects” on page 165.
Proprietary and Confidential Information of Arbor Networks Inc.
203
SP and TMS User Guide, Version 8.0
Setting
Description
Enable Custom
GRE Reinjection
Tunnels check
box
Click to enable GRE reinjection settings.
TMS Group list
Select a TMS group or All to select the TMS appliances to which
these settings apply.
GRE MTU box
Type the largest ,3 SDFNHW VL]H (in bytes) that you want to
allow into the GRE tunnel (excluding the GRE header). The valid
range for IP packet size is 28-1544.
If a packet exceeds the MTU setting, the TMS appliance or
TMS-VSM fragments the packet and encapsulates each fragment
in a separate GRE packet.
Primary
Destination IP
box
Type the IP address of the primary tunnel endpoint. For an IPv4
GRE tunnel, type an IPv4 IP address. For an IPv6 GRE tunnel,
type an IPv6 address.
Note: If you do not type an IP address in the Primary Destination
box, the tunnel will not operate.
Secondary
Destination IP
box
(For a redundant GRE tunnel only) Type the IP address of the
secondary tunnel endpoint. For an IPv4 GRE tunnel, type an IPv4
IP address. For an IPv6 GRE tunnel, type an IPv6 address.
6. Click Save.
About configuring GRE reinjection tunnel settings
For profile managed objects, you can enable custom GRE reinjection tunnels on the
Mitigation tab. SP creates a GRE tunnel on each TMS that is included in the TMS group that
you select. Each tunnel passes the traffic for the CIDR blocks that you define on the Match
tab to the specified tunnel destinations. SP uses the tunnel source IP and keepalive settings
that are defined for each TMS on the Configure Appliances page (Administration >
Appliances).
When you make any managed object CIDR configuration changes, these changes are
automatically updated in your GRE tunnel configuration.
Note: If a destination prefix you set on an individual TMS appliance is identical to a managed
object prefix, the GRE reinjection tunnel settings that you define for the managed object
override the TMS settings.
For information about configuring the tunnel source IP and keepalive settings on a TMS, see
“Configuring GRE Settings for a TMS Appliance or TMS-VSM ” on page 554.
For information about configuring TMS groups, see “Configuring TMS Groups” on page 567
204
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring Cloud Signaling Settings for Managed Objects
Introduction
When you configure a managed object, you can use the Cloud Signaling™ tab to add or edit
Cloud Signaling settings for the managed object.
Arbor Networks® APS users can use Cloud Signaling to request cloud-based mitigation from
your SP deployment when APS cannot mitigate a large attack at the customer premises. For
more information about Cloud Signaling, see “Mitigating Customer Attacks in the Cloud” on
page 604.
About Configuring Cloud Signaling
In order to use Cloud Signaling, you must configure SP to accept and respond to alerts from an
APS. This is done by adding APS appliances to managed objects, assigning one or more SP
appliances as managers of the APS appliances, and then configuring communication and
mitigation settings. If you assign more than one SP appliance as a manager, then the APS
appliances can continue to communicate with SP when a manager goes down.
Note: If the leader appliance is down, cloud signaling will not work until the leader is back up
or until the failover to the backup leader is complete.
After you configure the settings, you can give the APS customer the following information so
that they can configure these communication settings on the APS appliances:
n IP addresses of the SP appliances that manage an APS appliance
n
APS ID
n
password information
Important: An APS appliance can be associated with only one managed object. However, a
managed object can be associated with multiple APS appliances.
Configuring Cloud Signaling settings
To configure Cloud Signaling settings:
1. Navigate to the Cloud Signaling tab.
This tab appears only when you create a customer or profile managed object that has an
IPv4 CIDR Blocks or CIDR Groups match type.
See “Adding and editing a managed object” on page 162.
2. Configure the Cloud Signaling settings.
See “Cloud Signaling settings” on the next page.
3. Click Save.
Note: SP does not save your changes until you click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
205
SP and TMS User Guide, Version 8.0
Cloud Signaling settings
Use the following table to configure the Cloud Signaling settings:
Cloud Signaling settings
Setting
Details
Enable Cloud
Signaling check
box
Select this check box to enable Cloud Signaling for the APS
appliances associated with this managed object.
Auto-Mitigate on
Cloud Signaling
Alert check box
Select this check box if you want SP to mitigate automatically when
an APS appliance sends a Cloud Signaling alert. If you do not select
this check box, an alert is created, and you can manually mitigate as
needed.
Managers box
Select one or more SP appliances to manage the APS appliances
that are assigned to this managed object. A manager can be a leader
appliance or a non-leader appliance that has the user interface role.
To select a manager, click in the Managers box and select an
appliance from the list. You can select up to 5 managers.
Important: If you select multiple managers and configure an APS
appliance to communicate with those managers, then the APS
appliance can continue to communicate with SP even if one of the
managers goes down.
If you select multiple managers, then an APS appliance that is
configured to communicate with those managers, sends its mitigation
requests to each of those managers. However, SP combines those
identical requests and triggers only a single mitigation alert.
206
IP Access Rules
Prefix List box
Type the access rules (IP prefixes) to allow the APS appliances to
communicate with the SP manager appliances. Only the APS
appliances whose IP addresses fall within this list of prefixes can send
mitigation requests to the SP manager appliances.
This list of access rules must be comma-separated.
Add APS button
Click this button to add an APS appliance to associate with this
managed object.
Important: An APS appliance can be associated with only one
managed object. However, a managed object can be associated with
multiple APS appliances.
APS ID box
Type the ID of the APS appliance that you want to add. This ID must
match the APS ID that is set when Cloud Signaling is configured on
the APS appliance.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Cloud Signaling settings (Continued)
Setting
Details
Delete button
Select the check box next to each APS appliance that you want to
delete, and then click this button.
Generate
Password for
Selected button
SP automatically generates a random password for each APS
appliance that you add. If you want to generate a new random
password, select the check box next to an APS appliance and click
this button.
Proprietary and Confidential Information of Arbor Networks Inc.
207
SP and TMS User Guide, Version 8.0
Configuring Learning Mitigation Settings for Managed Objects
Introduction
You can add or edit learning mitigation settings when you configure a managed object.
Learning mitigations allow you to view how TMS mitigation countermeasures would affect a
managed object’s traffic without actually taking action on the traffic. You can use this as a
reference point to help you determine how to configure an ongoing mitigation or mitigation
template.
See “Configuring Managed Objects” on page 162.
About learning mitigations
You can enable learning mitigations on managed objects that either match IPv4 or IPv6 CIDR
blocks or are configured with mitigation scoping CIDR groups or CIDR blocks. When you
create a learning mitigation for a managed object, the learning mitigation permanently inherits
the managed object’s IP version. If you later change the managed object’s match type, the
learning mitigation’s IP version will not change and you can no longer view the learning
mitigation on the Managed Object Edit page. However, the learning mitigation is still available
for use in mitigations and templates that have the same IP address family.
SP counts all running learning mitigations toward your licensed mitigation limit. If you are
approaching your limit, while running one or more learning mitigations, and then try to start a
regular mitigation, SP stops the learning mitigation to allow the regular mitigation to start.
Viewing the status of learned mitigations
After you configure learning mitigations for a managed object, SP displays the learned data on
the Learning Mitigations tab. You can click the magnifying glass button ( ) to open the
“Graphs for my <name> learning mitigation” window and view the dataset. These graphs
display the number of hosts (y-axis) that would be affected at a given configuration value for a
countermeasure (x-axis). You can click and then move the graph’s slider ( ) horizontally to
change the configuration value and view the affected hosts. To access the learning
mitigation’s unique report page, click the “direct link.”
You can view the status of learned mitigations when they are configured for managed objects
that have one of the following match types:
n CIDR Blocks
n
CIDR Groups
n
CIDR IPv6 Blocks
Configuring learning mitigation settings
To configure learning mitigation settings:
1. Navigate to the Learning Mitigations tab.
See “Adding and editing a managed object” on page 162.
2. Click Add Learning Mitigation.
208
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
3. Use the following table to configure learning mitigation settings, and then click Save:
Setting
Description
Name box
Type the QDPH of the learning mitigation.
Description box
Type a GHVFULSWLRQ to help you identify the learning
mitigation.
Prefixes box
Type the SUHIL[HV of the traffic that you want to monitor.
Start Time lists and
box
Set the start time of the learning mitigation.
Duration list
Select the learning mitigation’s duration.
TMS Group list
Select the TMS group to which belong the TMS appliances or
TMS-ISA clusters whose traffic you want to monitor.
4. On the Learning Mitigations tab, click Save.
Copying learning mitigation datasets
You can copy a different managed object’s learned mitigation dataset to the managed object
that you are configuring. The IP version (IPv4 or IPv6) of the learned mitigation dataset and the
managed object must be the same.
To copy a learning mitigation’s dataset:
1. Navigate to the Learning Mitigations tab.
See “Adding and editing a managed object” on page 162.
2. Click Copy Existing Dataset.
3. Select the managed object’s dataset that you want to copy, and then click OK.
Proprietary and Confidential Information of Arbor Networks Inc.
209
SP and TMS User Guide, Version 8.0
Configuring Managed Object Children
Introduction
You can add or edit managed object children when you configure a managed object. Managed
object children allow you to group managed objects hierarchically and create managed
services managed objects. You can use child managed objects to increase revenue and offer
traffic visibility, detection, and mitigation services to your customers.
See “Configuring Managed Objects” on page 162.
Managed object children settings
To configure managed object children settings:
1. Navigate to the Children tab.
See “Adding and editing a managed object” on page 162.
2. Type the maximum QXPEHU of child managed objects that you want to associate with this
managed object in the Maximum Child Managed Objects box.
3. Click Edit Child Managed Object List, and then use the selection wizard to select one
or more child managed objects.
See “Using Selection Wizards” on page 31.
4. Click Save.
210
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring Managed Services Settings for Managed Objects
Introduction
You can add or edit managed services settings when you configure a managed object. When
you configure managed services, you provide greater access to network data while still
controlling the types of data that different users can view.
See “Configuring Managed Objects” on page 162.
For more information about configuring managed services, see “Implementing a Managed
Services Deployment” on page 918.
Configuring managed services settings
To configure managed services settings for managed objects:
1. Navigate to the Managed Services tab.
This tab only appears when you create a customer managed object.
See “Adding and editing a managed object” on page 162.
2. Configure the TMS Mitigations settings for managed services.
See “TMS Mitigations settings for managed services” below.
3. Configure the Blackhole Mitigations settings for managed services.
See “Blackhole Mitigations settings for managed services” on the next page.
4. Click Save.
TMS Mitigations settings for managed services
Use the following table to configure the TMS Mitigations settings for managed services:
TMS Mitigations settings for managed services
Setting
Description
IPv4 Constraint
Prefixes (BGP and
Flowspec) box
(Optional) Type the &,'5 EORFNV for the IPv4 prefixes that you
want managed services users to be able to divert for TMS
mitigations. These prefixes can be used for BGP diversion or
flowspec diversion.
IPv6 Constraint
Prefixes (BGP) box
(Optional) Type the &,'5 EORFNV for the IPv6 prefixes that you
want managed services users to be able to divert using BGP for
TMS mitigations.
Proprietary and Confidential Information of Arbor Networks Inc.
211
SP and TMS User Guide, Version 8.0
Blackhole Mitigations settings for managed services
Use the following table to configure the Blackhole Mitigations settings for managed services:
Blackhole Mitigations settings for managed services
Setting
Description
IPv4 Constraint
Prefixes (BGP) box
(Optional) Type the &,'5 EORFNV for the IPv4 prefixes that you
want managed services users to be able to divert using BGP for
blackhole mitigations.
IPv6 Constraint
Prefixes (BGP) box
(Optional) Type the &,'5 EORFNV for the IPv6 prefixes that you
want managed services users to be able to divert using BGP for
blackhole mitigations.
IPv4 Nexthop (BGP)
box
(Optional) Type the %*3 QH[WKRS that you want IPv4 blackhole
mitigations to use.
IPv6 Nexthop (BGP)
box
(Optional) Type the %*3 QH[WKRS that you want IPv6 blackhole
mitigations to use.
BGP Communities
box
(Optional) To configure BGP communities for blackhole
mitigations, choose one of the following steps:
n
n
212
Type the QXPEHU of the community group. To separate
community numbers, use spaces.
Click Select Community Group, and then select a group
from the Community Groups window.
See “Configuring BGP Community Groups” on page 750.
Local AS check box
Select if the community is local and you are running
confederations.
No advertise check
box
Select if the community is not advertised to its peers.
No export check box
Select if the community is not advertised outside of a
confederation boundary.
No peer check box
Select if the community is not advertised past the neighboring
AS.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Configuring VPN Site Managed Objects
Introduction
You can track VPN site traffic for VPN sites that you configure and for VPN sites that are
auto-detected. You can configure VPN sites for a VPN managed object on the Configure
Managed Objects page (Administration > Monitoring > Managed Objects).
Note: The VPN sites of a VPN managed object do not count against the managed object
license limit.
The auto-detection of VPN sites occurs when the match type of a VPN managed object is a
route target and the VPN sites match the configured route targets. All of the VPN sites of a VPN
managed object are listed on the VPN Sites tab of the VPN managed object and as children
of the VPN managed object on the Configure Managed Objects page.
For additional information about configuring VPN sites and about the VPN Sites tab, see the
following topics:
n “Configuring Managed Objects” on page 162
n
“About the VPN Sites Tab” on page 216
Adding a VPN site
You only need to add VPN sites that are not detected and configured automatically. If the
match type of a VPN managed object is route target, then any VPN sites that match the
configured route targets are automatically detected and configured.
Note: After you create a VPN managed object, you must save it before you can add VPN sites.
To add a VPN site:
1. Navigate to the Configure Managed Objects page (Administration > Monitoring >
Managed Objects).
For information about adding a VPN managed object, see “Adding and editing a managed
object” on page 162
2. Click the name link of the VPN managed object.
3. On the Edit VPN page, click the VPN Sites tab, and then click Add VPN Site.
Proprietary and Confidential Information of Arbor Networks Inc.
213
SP and TMS User Guide, Version 8.0
4. In the Add VPN Site window, configure the following settings, and then click Save:
Setting
Description
Name box
Type the QDPH of the VPN site.
Description box
Type a GHVFULSWLRQ to help you identify the VPN site.
Tags box
Type any WDJV that you want to apply to the VPN site. After you
type a tag, press COMMA, TAB, or ENTER to set the tag and to
continue.
Match list
Select either CIDR Blocks or Extended Communities.
Match Values box
If you selected CIDR Blocks in the Match list, then type the
&,'5 EORFNV that you want to match. If you selected
Extended Communities in the Match list, then type the
H[WHQGHG FRPPXQLWLHV that you want to match.
5. On the Edit VPN page, click Save.
Editing a VPN site
To edit a VPN site:
1. Navigate to the Configure Managed Objects page (Administration > Monitoring >
Managed Objects).
For information about editing a VPN managed object, see “Adding and editing a managed
object” on page 162
2. Do one of the following:
l
l
Click the plus sign next to a VPN managed object, click the VPN site name link.
Click the name link of a VPN managed object, click the VPN Sites tab, and click the
VPN site name link on this tab.
3. On the Edit VPN Site page or window, configure the following settings, and then click
Save:
214
Setting
Description
Name box
Type the QDPH of the VPN site.
Description box
Type a GHVFULSWLRQ to help you identify the VPN site.
Tags box
Type any WDJV that you want to apply to the VPN site. After you
type a tag, press COMMA, TAB, or ENTER to set the tag and to
continue.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
Setting
Description
Match list
Select CIDR Blocks or Extended Communities.
Note: If the VPN site was auto-detected, then this list is
disabled.
Match Values box
If you selected CIDR Blocks in the Match list, then type the
&,'5 EORFNV that you want to match. If you selected
Extended Communities in the Match list, then type the
H[WHQGHG FRPPXQLWLHV that you want to match.
Note: A match occurs only when the traffic matches a match
value of the VPN site and a match value of the parent
VPN managed object.
Note: If the VPN site was auto-detected, then the ability to edit
these values is disabled.
Deleting VPN sites
You can delete a manually configured VPN site on the Configure Managed Objects page or on
the VPN Sites tab. However, you cannot delete a VPN site that is detected and configured
automatically.
Caution: SP does not prompt you for confirmation before it deletes a VPN site. However, you
can revert to the last saved configuration to retrieve deleted VPN sites.
To delete a VPN site on the Configure Managed Objects page:
1. On the Configure Managed Objects page, click the plus sign next to a VPN managed
object.
2. Select the check boxes for the VPN sites that you want to delete, and then click Delete.
If a VPN site was detected and configured automatically, then it is not preceded by a
check box.
To delete a VPN site on the VPN Sites tab:
1. On the Configure Managed Objects page, click the name link of a VPN managed object.
2. Click the VPN Sites tab.
3. Click
(Remove) to the right of the VPN site that you want to delete.
If a VPN site was detected and configured automatically, then
right of the VPN site.
Proprietary and Confidential Information of Arbor Networks Inc.
does not appear to the
215
SP and TMS User Guide, Version 8.0
About the VPN Sites Tab
Introduction
The VPN Sites tab lists the VPN sites that have been configured for a VPN managed object.
VPN sites can be configured manually or they can be detected and configured automatically.
The auto-detection of VPN sites occurs when the match type of a VPN managed object is a
route target and the VPN sites match the configured route targets. If you do not want VPN sites
to be detected automatically, you can disable auto-detection. See "Disabling and Enabling
Auto-detection of VPN Sites" in the SP and TMS Advanced Configuration Guide.
Note: The VPN sites of a VPN managed object do not count against the managed object
license limit.
What you can do on the VPN Sites tab
You can perform the following tasks on the VPN Sites tab:
Add VPN sites to a VPN managed object. See “Adding a VPN site” on page 213.
n
n
Edit existing VPN sites of a VPN managed object.
You can edit the name, description, and tags of all VPN sites, but you cannot edit the match
settings of VPN sites that were configured through auto-detection. See “Editing a VPN site”
on page 214.
n
Search for specific VPN sites that have been configured for a VPN managed object. See
“About searching on the VPN Sites tab” on the facing page.
n
Sort the VPN sites of a VPN managed object by name and type.
n
Navigate between multiple pages of VPN sites. See “Navigating multiple pages” on
page 30.
n
Delete VPN sites that were configured manually.
Caution: SP does not prompt you for confirmation before it deletes a VPN site. However,
you can revert to the last saved configuration to retrieve deleted VPN sites.
Note: You cannot delete VPN sites that are auto-detected.
216
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 8: Configuring Managed Objects
About the information displayed on the VPN Sites tab
The VPN Sites tab displays the following information:
VPN Sites tab information
Column
Description
Name
The name of a VPN site. If a VPN site name is longer than 30 characters, then the
name is abbreviated. The full name appears when you hover your mouse pointer
over the abbreviated name.
The name of an auto-detected VPN site is by default the BGP site-of-origin
string, but it can be edited. The BGP site-of-origin is a BGP extended community
attribute.
Match
The CIDR blocks or extended communities for manually configured VPN sites and
the BGP site-of-origin string for auto-detected VPN sites. If the VPN site match
values are longer than 40 characters, then the match values are abbreviated. The
full match values appear when you hover your mouse pointer over the
abbreviated values.
Type
The type is either Auto-Detected or Manual. It is Auto-Detected for VPN sites
that are detected and configured automatically, and it is Manual for VPN sites
that are manually configured.
About searching on the VPN Sites tab
To search for VPN sites on the VPN Sites tab, you can use the Search box or you can click
one of the filters below the Search box. When you click a filter, the search values for the filter
appear in the Search box and the search is completed.
When you search with the Search box, use the following guidelines:
You can enter search values with or without keywords.
n
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
The comma cannot be followed by a space because a space creates an AND statement.
See “Acceptable search keywords and values for VPN sites” on the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
217
SP and TMS User Guide, Version 8.0
Acceptable search keywords and values for VPN sites
The following table lists the acceptable keywords and values that you can use to search in the
Search box for VPN sites:
Search keywords for attributes
Attribute to
search by
Acceptable keywords
and values
name
n
name:931 VLWH QDPH
Examples
n
n
description
n
n
description:931
VLWH GHVFULSWLRQ
desc:931 VLWH
GHVFULSWLRQ
n
n
description:"VPN site of customer
ABC "
desc: "VPN site of customer XYZ"
tag
n
tags:931 VLWH WDJ
n
tags:"vpnsite"
match
n
match:931 PDWFK
YDOXH
n
match:203.0.113.33:100
match:203.9.113.0/24
type:931
FRQILJXUDWLRQ W\SH
n
type
218
name:"VPN site XYZ "
name:203.0.113.33:100
n
n
n
type:manual
type:auto
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9:
Configuring Other Network Resources
Introduction
This section describes how to configure other network resources in SP. Like managed objects,
SP uses these other network resources to help you understand, protect, and respond to
problems in your network.
User access
Only administrators can perform all actions described in this section.
In this section
This section contains the following topics:
Configuring Custom Applications
220
About Services
223
About the Configure Services Page
225
Adding, Editing, and Deleting Services
227
Configuring Match Settings for Services
229
Configuring Boundaries for Services or Subscribers
230
Configuring Threshold Alerting Settings for Services
235
Configuring Profiled Router Detection for Services
237
Configuring Host Detection for Services
241
Configuring Profiled Network Detection for Services
246
Configuring Mitigation Settings for Services
247
Configuring Fingerprints
248
Configuring Subscriber Groups and Subscriber Group Settings
251
Configuring BGP Thresholds, Hijacking, and Traps
255
SP and TMS User Guide, Version 8.0
219
SP and TMS User Guide, Version 8.0
Configuring Custom Applications
Introduction
SP includes system-defined applications that it reports on. However, you can also configure
custom applications on the Configure Applications page (Administration > Monitoring >
Applications). When you configure custom applications, SP collects data about them for
reports, and you can add them to custom service configurations.
You can configure an application to match different types of data to better learn how the traffic
on your network is being used. For example, using a custom application, you might find that
what appears to be normal Web traffic on port 80 is actually a peer-to-peer messaging
application.
Searching for applications
To search for an application:
1. Navigate to the Configure Applications page (Administration > Monitoring >
Applications).
2. Type the QDPH, WDJ, or GHVFULSWLRQ of an application in the Search box.
You can also use keywords in your search. See “Guidelines for searching on the Configure
Applications page” below and “Acceptable search keywords and values for applications”
on the facing page.
3. Click Search.
Guidelines for searching on the Configure Applications page
Below are guidelines for using the Search box:
You can enter search values with or without keywords.
n
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
The comma cannot be followed by a space because a space creates an AND statement.
220
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Acceptable search keywords and values for applications
The following table lists the columns on the Configure Applications page and, for each column,
the keywords and values that you can use to search on that column in the Search box.
Search keywords for columns
Column to
search on
Acceptable keywords and values
Name
n
name:DSSOLFDWLRQ QDPH
n
name:app123
Tags
n
tag:DSSOLFDWLRQ WDJ
tags:DSSOLFDWLRQ WDJ
n
tag:internet
tags:protocol
descr:DSSOLFDWLRQ GHVFULSWLRQ
description:DSSOLFDWLRQ
GHVFULSWLRQ
n
n
Description
n
n
Examples
n
n
descr:filesharing
description:database
server
Adding and editing custom applications
To add or edit a custom application:
1. Navigate to the Configure Applications page (Administration > Monitoring >
Applications).
2. Choose one of the following steps:
l
To add an application, click Add Application.
l
To edit an existing application, click its name link.
3. On the Add Application page or the Edit Application page, on the Description tab,
configure the following settings:
Setting
Description
Name box
Type the QDPH of the application.
Description box
Type a GHVFULSWLRQ to help you identify the application.
Tags box
Type any WDJV that you want to apply to the application. After
you type a tag, press COMMA, TAB, or ENTER to set the tag and to
continue.
Tags can help you to categorize and to search easily for
applications that you monitor.
4. On the Match Rules tab, for each flow source section, select the check boxes that
correspond to how you want SP to match the traffic of this application.
Important: You must select the appropriate check boxes in order for the configurations
that you perform in Step 5 to take effect.
Proprietary and Confidential Information of Arbor Networks Inc.
221
SP and TMS User Guide, Version 8.0
5. Choose your next steps based on how you configured application matching in Step 4:
Setting
Description
Use AppID Matching
a. Click the AppID Match tab.
b. Click Select AppIDs.
c. In the selection window, select the known application IDs
that you want SP to match for the application, and then
click OK.
SP notes under each application whether it is supported by
a TMS appliance or eSeries platform.
Use Port Definitions
a. Click the Port Match tab.
b. In the TCP Ports box, type the 7&3 SRUWV on which you
want SP to detect this application.
c. In the UDP Ports box, type the 8'3 SRUWV on which you
want SP to detect this application.
Important: These configurations do not take effect unless you enabled matching for them
in Step 4.
6. Click Save.
Deleting a custom application
To delete a custom application:
Select the check boxes for the applications that you want to delete, and then click Delete.
n
Note: You cannot delete system-defined applications.
Resetting an application to the default configuration
To reset an application to the default configuration:
1. Navigate to the Configure Applications page (Administration > Monitoring >
Applications).
2. Click an application’s name link, and then click Reset to system defaults on any tab.
222
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
About Services
Introduction
Services are combinations of applications and CIDR blocks on which SP detects and reports.
When you configure a service in SP, you specify the applications (for example, SIP and RTP for
a VoIP service) and the set of servers that provide the service.
Using services in conjunction with TMS appliances
When you use services in conjunction with TMS appliances, you can use the service
predefined perspective reports to view detailed metrics for VoIP (and other real-time services),
DNS, HTTP, and TCP-based services. How you deploy a TMS appliance affects its visibility
into traffic and, therefore, its ability to collect data about services. Deploying a TMS appliance
so that it only receives traffic from the client side or server side of transactions limits the service
metrics that it can collect for various applications.
The following table describes the service data that a TMS appliance can collect when it has
visibility into different sides of traffic:
Services and TMS appliance visibility
Traffic
Type
Traffic
Visibility
DNS
only from the
client
Top FQDN and Top RDN.
only from the
server
Top Failed FQDN and Top Failed RDN.
from both
client and
server
Top FQDN, Top RDN, Top Failed FQDN, and Top Failed RDN.
only from the
client
Top FQDN, RDN, User Agent, and Request Types.
only from the
server
Top FQDN, RDN, Request Types, MIME Types, and HTTP Status
Codes.
from both
client and
server
Top FQDN, RDN, User Agent, MIME Types, Request Types, and
HTTP Status Codes.
from either
the client or
the server
RTT, Packet Loss, TCP Flags, and Out of Order.
from both
client and
server
RTT, Packet Loss, TCP Flags, Throughput, Out of Order, and TCP
Window Size.
HTTP
TCP
Collectable Service Data
Proprietary and Confidential Information of Arbor Networks Inc.
223
SP and TMS User Guide, Version 8.0
Services and TMS appliance visibility (Continued)
224
Traffic
Type
Traffic
Visibility
VoIP
from either
the caller or
callee
SIP invites and Top Callers/Callees.
from both the
caller and
callee
All data, including Packet Loss, Jitter, and Out of Order. The TMS
appliance must be able to see both sides of SIP traffic in identify
the UDP ports that RTP uses to track packet loss, jitter, etc.
Collectable Service Data
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
About the Configure Services Page
Introduction
The Configure Services page (Administration > Monitoring > Services) lists the names
of services with their tags, match values, and host detection settings.
You can do the following on the Configure Services page:
Configure new or existing services
n
See “Adding, Editing, and Deleting Services” on page 227.
n
Search for specific services
See “About searching on the Configure Services page” below.
n
Sort the services by name, tags, match values, and host detection settings
n
Access the host detection settings of a service
The Host Detection Settings column contains the name of the set of host detection settings.
The name is a link to the Edit Shared Host Detection Settings page for each set of host
detection settings. The “Disabled” host detection setting does not have a link because it
cannot be edited.
See “About Services” on page 223.
About searching on the Configure Services page
To search for services on the Configure Services page, you can use the Search box, the
search wizard, or you can click one of the filters below the Search box. When you click a filter,
the search values for the filter appear in the Search box and the search is completed.
When you search with the Search box, use the following guidelines:
You can enter search values with or without keywords.
n
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
If a keyword is followed by more than one value, only the first value is associated with the
keyword. For any additional values, the search looks for those values in the name,
description, or tag fields of the services. For example, if you type name:XYZ 123, then the
search returns all occurrences of services that have XYZ in their name and 123 in their
name, description, or tag fields.
n
A comma between search values creates an OR statement.
n
The comma cannot be followed by a space because a space creates an AND statement.
You can use quotation marks (“) to match a phrase. For example, to search for a service with
“This is the Chicago office,” you can type description:”Chicago office”.
See “Acceptable search keywords and values for services” on the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
225
SP and TMS User Guide, Version 8.0
Acceptable search keywords and values for services
The following table lists the acceptable keywords and values that you can use to search in the
Search box for services:
Search keywords for attributes
Attribute to search
by
Acceptable keywords and
values
name
n
name:VHUYLFH QDPH
n
name:serviceXYZ
description
n
description:VHUYLFH
GHVFULSWLRQ
n
description:”chicago
office”
tag
n
tag:VHUYLFH WDJ
tags:VHUYLFH WDJ,
VHUYLFH WDJ
n
n
tag:”north america”
tags:boston, seattle
n
226
Examples
match
n
match:VHUYLFH PDWFK
YDOXH
n
match:1.1.0.0/16
host detection settings
n
host:VHW RI KRVW
GHWHFWLRQ VHWWLQJV
n
host:default
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Adding, Editing, and Deleting Services
Introduction
You can configure SP to monitor the services that you provide (such as VoIP, video, or data) on
the Configure Services page (Administration > Monitoring > Services).
Adding and editing services
To add or edit a service:
1. Navigate to the Configure Services page (Administration > Monitoring > Services).
2. Choose one of the following steps:
l
To add a new service, click Add Service.
l
To edit an existing service, click its name link.
3. On the Add Service page or the Edit Service page, on the Description tab, configure the
following basic identification settings for the service:
Setting
Description
Name box
Type the QDPH of the service.
Description box
Type a GHVFULSWLRQ to help you identify the service.
Tags box
Type any WDJV that you want to apply to the service. After you
type a tag, press COMMA, TAB, or ENTER to set the tag and to
continue.
Tags can help you to categorize and to search easily for
services that you monitor. The DNS, HTTP, VoIP, and TCP tags
have distinct meanings and affect which reports are available
for a service.
4. On the Add Service page or the Edit Service page, click the following tabs and add or edit
their settings:
Tab
Description
Match
Allows you to configure the match settings for a service. See
“Configuring Match Settings for Services” on page 229.
Boundary
Allows you to define boundaries for a service. See “Configuring
Boundaries for Services or Subscribers” on page 230.
Threshold
Alerting
Allows you to configure threshold alerting for a service. See
“Configuring Threshold Alerting Settings for Services” on
page 235.
Profiled Router
Detection
Allows you to configure profiled router detection settings for a
service. See “Configuring Profiled Router Detection for Services”
on page 237.
Proprietary and Confidential Information of Arbor Networks Inc.
227
SP and TMS User Guide, Version 8.0
Tab
Description
Host Detection
Allows you to configure host detection settings for a service. See
“Configuring Host Detection for Services” on page 241.
Note: Host detection only functions for services that have server
CIDRs configured on the Match tab, regardless of the host
detection setting.
Profiled
Network
Detection
Allows you to configure profiled network detection settings for a
service. See “Configuring Profiled Network Detection for Services”
on page 246.
Mitigation
Allows you to configure mitigation settings for a service. See
“Configuring Mitigation Settings for Services” on page 247.
Misuse
Detection
In an SP 7.0 or later deployment, misuse detection is replaced by
host detection.
Important: Misuse detection generates alerts only in a
multi-version deployment with collectors running a version of SP
prior to 7.0. When the entire deployment is running SP 7.0 or later,
misuse detection no longer generates alerts.
For information about misuse detection, see the SP and Threat
Management System (TMS) User Guide for your previous version
of SP.
5. Click Save, and then commit your changes.
Deleting services
To delete services:
1. Navigate to the Configure Services page (Administration > Monitoring > Services).
2. Select the check boxes for the services that you want to delete, and then click Delete.
3. Click Save, and then commit your changes.
228
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Configuring Match Settings for Services
Introduction
You can use the Match tab to add or edit match settings when you configure a service on the
Add Service page or Edit Service page. Match settings are used to define how SP should
associate traffic with services.
See “Adding, Editing, and Deleting Services” on page 227.
Configuring match settings for services
To configure match settings for services:
1. Navigate to the Add Service page or the Edit Service page.
See “Adding and editing services” on page 227.
2. Click the Match tab.
3. Click Edit Applications, and then use the selection wizard to add one or more
applications to the service.
See “Using Selection Wizards” on page 31.
4. To configure matching on server CIDR blocks, type between one and 100 &,'5 EORFN
SUHIL[HV in the Server CIDRs box.
5. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
229
SP and TMS User Guide, Version 8.0
Configuring Boundaries for Services or Subscribers
Introduction
You can use the Boundary tab to add or edit the incoming and outgoing traffic boundaries for
services or subscribers that you configure. By default, SP uses the network boundary (for
example, the BGP edge or the set of all interfaces that are classified as external) as the
boundary for every service or subscriber.
When you configure boundaries, SP measures all “in” and “out” traffic for a service or
subscriber at its interface boundaries. This allows SP to avoid counting flows more than once
when it detects the service's or subscriber's traffic at multiple routers in your network.
Configuring boundaries also allows you to have more fine-grained visibility into your network’s
traffic, such as customer-to-customer traffic.
See “Configuring Subscriber Groups and Subscriber Group Settings” on page 251, and
“Adding, Editing, and Deleting Services” on page 227.
Configuring router boundary settings for a service or subscriber
To configure router boundary settings for a service or subscriber:
1. Navigate to the Boundary tab.
See “Adding, Editing, and Deleting Services” on page 227 and “Configuring Subscriber
Groups and Subscriber Group Settings” on page 251.
2. Select one of the following Choose Boundary options:
Option
Description
Network
Boundary
Select to use the network boundary for the boundary of the service
or subscriber. When this option is selected, you cannot configure
any interfaces for the router boundary or the TMS boundary. To
complete the configuration, click Save.
Interfaces
Select if you want to configure interfaces for the boundary of the
service or subscriber. When this option is selected, options appear
for selecting interfaces for the router boundary and the TMS
boundary.
3. If you selected the Interfaces option, then select one of the following router boundary
types In the Router Boundary section:
Router Boundary
Type
230
Description
None
SP uses the network boundary for the router boundary of the
service or subscriber. To complete the configuration, click Save.
Global
customer, Ignore
Rules
SP uses the network boundary for the boundary of the service or
subscriber and measures all traffic reported as "in" and "out." See
Step 4.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Router Boundary
Type
Description
Rules Only
SP uses dynamic auto-configuration rules to determine all
boundary interfaces. See Step 5.
Interfaces &
Rules
SP uses dynamic auto-configuration rules and your static
configurations to determine boundary interfaces. See Step 6.
Important: Arbor recommends that you configure interface boundaries with rules
whenever possible. Rules use regular expressions to match boundaries that are
dynamically based on interface descriptions (ifAlias value). This ensures that SP
automatically updates boundaries when the interface boundaries change.
4. If you selected Global customer, Ignore Rules for the router boundary type, then
configure the following setting, and click Save to complete the configuration:
Setting
Description
Locality
You can configure locality to determine whether to bin BGP
attributes for the source or the destination of the traffic flowing
into or out of a service or subscriber. Select default unless you
are configuring locality for a service or subscriber that is external
to the monitored network. If an object is external, then you must
configure it with external match settings and select external from
the Locality list.
5. If you selected Rules Only for the router boundary type, then configure the following
settings, and click Save to complete the configuration:
Setting
Description
Locality
You can configure locality to determine whether to bin BGP
attributes for the source or the destination of the traffic flowing
into or out of a service or subscriber. Select default unless you
are configuring locality for a service or subscriber that is
external to the monitored network. If an object is external, then
you must configure it with external match settings and select
external from the Locality list.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule, or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings” on
page 234.
Proprietary and Confidential Information of Arbor Networks Inc.
231
SP and TMS User Guide, Version 8.0
6. If you selected Interfaces & Rules for the router boundary type, then select one of the
following Interface Boundary Type options:
Option
Description
Advanced
If you select Advanced, then you can manually specify
backbone-facing interfaces and service or subscriber facing
interfaces. See Step 7.
A backbone-facing interface is always the output interface for
traffic going out of a service or subscriber and the input interface
for traffic going into a service or subscriber. A service or
subscriber facing interface is always the output interface for
traffic coming into a service or subscriber and the input interface
for traffic going out of a service or subscriber.
Simple
If you select Simple, then SP automatically determines whether
traffic enters or leaves at the configured boundary interfaces of a
service or subscriber, based on traffic characteristics and the
match type. See Step 8.
7. If you selected Advanced for the interface boundary type, then configure the following
settings, and click Save to complete the configuration:
Setting
Description
Backbone Facing
Interfaces
Click Edit Boundary Interface List, and then use the
selection wizard to select interfaces that face the backbone.
See “Using Selection Wizards” on page 31.
Service Facing
Interfaces or
Subscriber Facing
Interfaces
Click Edit Boundary Interface List, and then use the
selection wizard to select interfaces that face the service or
subscriber. See “Using Selection Wizards” on page 31.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule, or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings” on
page 234.
232
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
8. If you selected Simple for the interface boundary type, then configure the following
settings, and click Save to complete the configuration:
Setting
Description
Boundary
Interfaces
Click Edit Boundary Interface List, and then use the
selection wizard to select boundary interfaces. See “Using
Selection Wizards” on page 31.
Auto-Configuration
Rules
Click Add to add an auto-configuration rule or click the name
link of an existing rule to edit it. For information about
configuring interface classification rules, see “Configuring
Interface Classification Rules” on page 123. To delete an
auto-configuration rule, click Delete to the right of the rule.
Note: When you add an auto-configuration rule, settings are
automatically configured on the Action tab of the rule. See
“Automatically configured auto-configuration rule settings” on
the next page.
Configuring TMS boundary settings for a service or subscriber
To configure TMS boundary settings for a service or subscriber:
1. Navigate to the Boundary tab.
See “Adding, Editing, and Deleting Services” on page 227 and “Configuring Subscriber
Groups and Subscriber Group Settings” on page 251.
2. Select one of the following Choose Boundary options:
Option
Description
Network
Boundary
Select to use the network boundary for the boundary of the service
or subscriber. When this option is selected you cannot configure
any interfaces for the router boundary or the TMS boundary. To
complete the configuration, click Save.
Interfaces
Select if you want to configure interfaces for the boundary of the
service or subscriber. When this option is selected, options for
selecting interfaces appear for the router boundary and the TMS
boundary.
Proprietary and Confidential Information of Arbor Networks Inc.
233
SP and TMS User Guide, Version 8.0
3. If you selected the Interfaces option, then select one of the following Type options In the
TMS Boundary section:
Type Option
Description
None
Includes no TMS ports in the boundary of a service or subscriber.
To complete the configuration, click Save.
Selected TMS
Ports
Allows you to manually configure which ports are a part of a
boundary of a service or subscriber. For each port, you can
designate whether traffic over the port is “In” or “Out” of the
service or subscriber. Alternatively, you can allow SP to determine
the traffic directions automatically. See Step 4.
All TMS Ports
Includes all TMS ports in the boundary of a service or subscriber.
When you select this type, the direction of incoming or outgoing
traffic is determined by TMS Auto Ports rules. To complete the
configuration, click Save.
4. If you selected Selected TMS Ports from the Type options, the TMS Ports box
appears. To enter ports in this box, select one of the following options, use the selection
wizard to select one or more TMS ports through which to force incoming traffic, and click
Save to complete the configuration:
Option
Description
TMS In Ports
Counts only inbound traffic as “In” to the service or subscriber.
TMS Out Ports
Counts only inbound traffic as “Out” to the service or subscriber.
TMS Auto Ports
Counts inbound traffic on the selected ports as either “In” or “Out”
to the service or subscriber, based on whether the service or
subscriber matches the source or destination of the traffic
See “Using Selection Wizards” on page 31.
Important: When you select TMS ports for a boundary of a service or subscriber, any
given TMS port must only be configured for one directionality: TMS In Ports, TMS Out
Ports, or TMS Auto Ports.
Automatically configured auto-configuration rule settings
When you add an auto-configuration rule to a service or subscriber, the following settings are
automatically configured on the Action tab of the rule:
n The Set Managed Objects check box is selected.
n
Simple is selected as the interface boundary type.
This boundary type allows SP to determine the directionality of the interface boundary.
n
234
The managed object appears in the Managed Objects box.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Configuring Threshold Alerting Settings for Services
Introduction
You can use the Threshold Alerting tab to add or edit threshold settings for the service, for
the specific applications used by the service, or for both the service and any of its applications.
The % Loss and ms Jitter thresholds are high thresholds and would only be used for applicable
services.
See “Adding, Editing, and Deleting Services” on page 227.
How threshold alerting works
When incoming or outgoing traffic reaches or exceeds the high threshold rates for a service,
SP generates a high traffic threshold alert. Similarly, when traffic drops below the low
threshold rates, SP generates a low traffic threshold alert. SP sends up to one high and one
low threshold alert per service. If traffic for a service exceeds more than one high or low
threshold, then SP sends one alert for the threshold that is exceeded by the highest
percentage.
Example: A VoIP service has configured high threshold rates of 1 Mbps and 1 Kpps, and an
ms Jitter threshold of 100 ms. SP detects traffic rates for that service at 4 Mbps, 10 Kpps, and
200 ms Jitter. SP sends a high threshold alert based on Kpps because the pps threshold was
exceeded by 1000%, which is greater than the bps threshold that was exceeded by 400% and
the ms Jitter threshold that was exceeded by 100%.
Configuring threshold alerting settings for services
To configure threshold alerting settings for services:
1. Navigate to the Add Service page or the Edit Service page.
See “Adding and editing services” on page 227.
2. Click the Threshold Alerting tab.
See “How threshold alerting works” above.
3. Configure the following threshold alerting settings:
Setting
Description
High Threshold
boxes
Type the KLJK WUDIILF WKUHVKROGV and select the
corresponding bps and pps units.
% Loss box
Type the SHUFHQWDJH of dropped traffic to be used as the high
threshold for a TCP based service.
% Loss represents the average percentage of TCP packet loss
observed by SP from ArborFlow that is exported from a TMS
appliance. A TMS appliance passes this information to SP only
if an interface on the TMS has the flow check box set. This
threshold only applies to TCP based services.
Proprietary and Confidential Information of Arbor Networks Inc.
235
SP and TMS User Guide, Version 8.0
Setting
Description
ms Jitter box
Type the QXPEHU of milliseconds of jitter to be used as the high
threshold for applicable services.
Jitter represents the average variation in packet arrival time. For
VoIP, high jitter may mean delayed transmission of packets that
leads to quality of service issues.
Low Threshold
boxes
Type ORZ WUDIILF WKUHVKROGV and select the
corresponding units.
4. Click Save.
5. Configure the following application threshold alerting settings:
Setting
Description
High boxes
Type the KLJK DSSOLFDWLRQ WKUHVKROGV and select the
corresponding units.
Low boxes
Type ORZ DSSOLFDWLRQ WKUHVKROGV and select the
corresponding units.
6. Click Save.
236
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Configuring Profiled Router Detection for Services
Introduction
On the Profiled Router Detection tab, you can enable profiled router detection. After you
enable profiled router detection, you can access the Profiled Router Detection Configuration
window to configure settings that determine when an alert is generated and the severity level
that it is assigned. Separate incoming and outgoing traffic settings are provided because the
rate of traffic in one direction might be significantly different than the rate of traffic in the other
direction.
See “About Profiled Router Detection” on page 447.
You can also enable and configure automatic rate calculations. Arbor recommends that you
use the automatic rate calculations whenever possible.
For more information about the calculations and their settings, see “About automatic rate
calculation for profiled router detection” on page 449.
Configuring profiled router detection settings
To configure profiled router detection settings:
1. Navigate to the Profiled Router Detection tab.
See “Adding and editing services” on page 227.
2. To enable profiled router detection, select the Enable Profiled Router Detection
check box.
3. Click Edit Profiled Router Configuration.
4. Configure the settings in the Profiled Router Detection Configuration window.
See “Profiled Router Detection Configuration settings” on the next page.
5. From the Outgoing Detection list, select one of the following settings:
l
Default (Use Global Setting)
This setting uses the global setting for profiled router outgoing detection that is
configured on the Configure Global Detection Settings page (Administration >
Detection > DDoS). The global profiled router outgoing detection setting is set to
Disabled by default.
l
Always Enabled or Always Disabled
These settings allow you to enable or disable profiled router outgoing detection on a per
managed object basis.
6. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
237
SP and TMS User Guide, Version 8.0
Profiled Router Detection Configuration settings
Use the following table to configure the settings in the Profiled Router Detection Configuration
window:
Profiled Router Detection Configuration settings
238
Setting
Description
Severity Duration box
Type the QXPEHU RI VHFRQGV that traffic must exceed a given
threshold before SP escalates its severity.
For more information about how the severity duration is used to
classify an alert’s severity, see “How SP creates and classifies
profiled router detection alerts” on page 448.
Incoming Severity
Thresholds and
Outgoing Severity
Thresholds boxes
Type the VHYHULW\ WKUHVKROGV (in bps and pps).
The severity thresholds are applied on a per router basis for
profiled router protocol alerts and on a per interface basis for
profiled router bandwidth alerts.
For more information about how the severity thresholds are used
to classify an alert’s severity, see “How SP creates and classifies
profiled router detection alerts” on page 448.
Enable SNMP Link
Rate Severity
Calculation check box
Select if you want SP to use the SNMP link rate of an interface
as a severity threshold.
SP calculates the severity threshold based on the lower of the
auto-configured or manually configured high severity rate and
the SNMP link rate of the router interface on which the traffic
was detected.
Incoming Forced
Alert Thresholds and
Outgoing Forced
Alert Thresholds
boxes
Type the IRUFHG DOHUW WKUHVKROGV (in bps and pps).
For information on the use of forced alert thresholds, see “About
the use of forced alert thresholds” on page 449.
If traffic exceeds a forced alert threshold for the profiled router
latency period, SP generates an alert. The severity of the alert is
then determined by the severity duration, the severity thresholds,
and other factors.
For more information about the classification of an alert’s
severity, see “How SP creates and classifies profiled router
detection alerts” on page 448.
The forced alert thresholds are applied on a per router basis for
profiled router protocol alerts and on a per interface basis for
profiled router bandwidth alerts.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Profiled Router Detection Configuration settings (Continued)
Setting
Description
Incoming Alert Ignore
Rates and Outgoing
Alert Ignore Rates
boxes
Type the DOHUW LJQRUH UDWHV (in bps and pps) below which
you do not want SP to generate alerts.
Note: Ignore rates impose a floor to the baseline for the
configured type (bps or pps).
Traffic must exceed an ignore rate for an alert to be generated. If
the ignore rates are the same as the forced alert thresholds, then
the baselines are ignored when generating alerts.
Note: Forced alert thresholds supersede ignore rates.
Enable Automatic
Rate Calculation
check box
a. Select if you want to enable automatic rate calculation.
b. Configure the Automatic Rate Calculation settings.
See “Automatic rate calculation settings” below.
c. Finish configuring the profiled router detection settings
described in this table.
Interface Bandwidth
Alerts, Interface
Packets Alerts, and
All Protocols Alerts
lists
In the Detection Sensitivity Thresholds section, select the
sensitivity thresholds for the different types of alerts.
A low number results in more alerts and a high number results in
fewer alerts. Arbor recommends that you select 3 as a starting
point in a production environment. You can then adjust this
setting to reduce or to increase the number of alerts that you
receive in your deployment.
Suggest Rates button
Click if you want the system to generate the severity thresholds
using the most recent calculated automatic rates.
Automatic rate calculation settings
Use the following table to configure the automatic rate calculation settings for profiled router
detection:
Automatic rate calculation settings
Setting
Description
Severity Percentile
box
Type the SHUFHQWDJH of normal traffic that you want SP to use as
a base value to calculate incoming and outgoing severity rates.
Typical percentile values range from 95 to 98.
Severity Multiplier
box
Type the QXPEHU that you want to multiply with the severity
percentile to calculate the high severity rate.
Example: If the 95th percentile value for incoming traffic is 100
Mbps and the multiplier is 1.1, then the high severity threshold for
that managed object becomes 110 Mbps.
Proprietary and Confidential Information of Arbor Networks Inc.
239
SP and TMS User Guide, Version 8.0
Automatic rate calculation settings (Continued)
Setting
Description
Ignore Percentile
box
Type an ignore SHUFHQWLOH to calculate the ignore rate.
The default value is 40. This means that 60% of the data points
over the last 30 days are greater than the calculated trigger rate.
Arbor recommends that you enter a value between 40 and 50.
Severity Rate Floor
settings
Type the lowest YDOXHV for which you want SP to generate a
severity rate, and then select the corresponding traffic units from
the lists.
Ignore Rate Floor
settings
Type the lowest YDOXHV for which you want SP to generate an
ignore rate, and then select the corresponding traffic units from the
lists.
See “About automatic rate calculation for profiled router detection” on page 449.
To finish configuring profiled router detection, see “Configuring profiled router detection
settings” on page 237.
240
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Configuring Host Detection for Services
Introduction
Host detection monitors the IPv4 and IPv6 traffic to a host on all monitored routers. Host
detection can trigger a standard host alert or a fast flood host alert. A standard host alert is
triggered when the traffic on a monitored router towards a single host exceeds the configured
threshold of an enabled misuse type for a specified time period. A fast flood host alert is
triggered when large amounts of traffic towards a single host are detected for an enabled
misuse type. See “About Host Detection” on page 429.
If excessive traffic is detected for multiple misuse types that are enabled, then a single alert is
created instead of separate alerts for each misuse type. The alert identifies each misuse type
that had excessive traffic. See “Host detection misuse types” on page 243.
You can select a set of shared host detection settings or create a custom set.
Note: If you experience an inordinate number of alerts because a host detection misuse type is
enabled, you can quickly disable that misuse type in every set of host detection settings. See
"Disabling and Enabling Host Detection Misuse Types" in the SP and TMS Advanced
Configuration Guide.
Configuring host detection for a service using shared settings
You can select shared settings for host detection when you add or edit a service. The settings
you configure determine when an alert is generated and the severity of the alert. See “How SP
creates and classifies standard host alerts” on page 433.
To configure host detection using shared settings:
1. Navigate to the Host Detection tab of the service.
See “Adding and editing services” on page 227.
2. For Host Detection Settings, click Shared.
3. From the Shared Settings list, select the set of host detection settings that you want to
use with this service.
4. In the Shared Settings section on the Host Detection tab of the service, you can view
the set of shared host detection settings that you selected.
This section displays only misuse types that are enabled. This section does not appear if
Disabled is selected in the Shared Settings list.
5. To change the settings, either select a different set of host detection settings from the
Shared Settings list or edit the current set of shared settings.
Important: If you click Edit Shared Settings and make changes to that set of host
detection settings, then those settings are changed for every managed object or service
that uses those settings. See “Configuring Shared Host Detection Settings” on page 442.
The Edit Shared Settings link does not appear if Disabledis selected in the Shared
Settings list.
If you have made changes to a managed object that you have not saved and click Edit
Shared Settings, then you are asked to either save the changes or continue editing.
6. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
241
SP and TMS User Guide, Version 8.0
Configuring host detection for a service using a custom set
You can configure a custom set of host detection settings when you add or edit a service. The
settings you configure determine when an alert is generated and the severity of the alert. See
“How SP creates and classifies standard host alerts” on page 433.
To configure a custom set of host detection settings for a service:
1. Navigate to the Host Detection tab of the service.
See “Adding and editing services” on page 227.
2. For Host Detection Settings, click Custom.
If the service previously used a shared set, the custom set is initially populated with those
settings.
3. In the Shared Settings section, configure the custom host detection settings. See “Host
detection settings” below.
4. Click Save, and then commit your changes.
Note: After saving your custom set, if you click Shared, the Default set is selected in the
Shared Settings list instead of the shared set previously used by the managed object. The
Default set deletes the custom set, which is not saved.
Host detection settings
The following are the host detection settings that appear on the Host Detection tab:
Host detection settings
Setting
Description
Host Detection
setting
Host detection is either enabled or disabled. Host detection monitors the
traffic to a host on all monitored routers. A host alert is triggered when
the traffic on a monitored router towards a single host exceeds the
configured threshold of an enabled misuse type for a specified time
period. See “About Host Detection” on page 429.
Severity
Duration setting
The number of seconds that SP waits before it escalates the severity
level of an alert. If the traffic exceeds 75% of the high severity rate for the
severity duration, then the alert is classified with a severity of Medium. If
the traffic exceeds the high severity rate for the severity duration, then
the alert is classified with a severity of High.
Note: If you enter a value for severity duration that is less than a whole
minute, SP rounds that value up to the next minute when determining the
severity duration. For example, if you set the severity duration to 10
seconds, SP uses a value of 1 minute for the severity duration.
Note: Fast flood host detection ignores this setting, and fast flood alerts
always have a high severity.
242
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Host detection settings (Continued)
Setting
Description
Fast Flood
Detection
setting
Fast flood detection is either enabled or disabled. When fast flood
detection is enabled a host alert is triggered much faster when large
amounts of traffic toward a host are detected. See “About host detection
with fast flood detection enabled” on page 431.
Note: If you want a host alert that is triggered by fast flood detection to
start an auto-mitigation, then you must also configure auto-mitigation for
this managed object. See “Configuring Mitigation Settings for Managed
Objects” on page 192.
Misuse Type
column
The misuse types that host detection uses to detect excessive rates of
traffic. See “Host detection misuse types” below.
Trigger Rate
column
The trigger rate for each misuse type. See “Host detection terminology”
on page 429.
High Severity
Rate column
The high severity rate for each misuse type. See “Host detection
terminology” on page 429.
The high severity rate is applied on a per router basis for host detection.
Host detection misuse types
SP uses the following misuse types with host detection:
Host detection misuse types
Misuse Type
Type of Traffic
Can Help Detect
Total Traffic
The total traffic (in
bps or pps) for a
given host
Host attacks that do not follow a known attack
pattern
chargen
Amplification
chargen traffic (in
bps or pps) with the
UDP protocol and
source port 19
chargen (Character Generator Protocol)
reflection/amplification attacks
DNS
DNS traffic (in pps) Floods of DNS traffic
with the TCP and/or
UDP protocol and
destination port 53
traffic
DNS Amplification
DNS traffic (in bps
or pps) with the
UDP protocol and
source port 53
Proprietary and Confidential Information of Arbor Networks Inc.
DNS reflection/amplification attacks
243
SP and TMS User Guide, Version 8.0
Host detection misuse types (Continued)
Misuse Type
Type of Traffic
Can Help Detect
ICMP
IPv4 and IPv6
Internet Control
Message Protocol
traffic (in pps)
IPv4 ICMP and ICMPv6 packet-flooding
attacks
IP Fragment
Traffic (in pps) with
the IP fragment flag
TCP and UDP fragmentation attacks
Note: TCP and UDP fragmentation attacks
are often associated with chargen, DNS,
SNMP, SSDP, and MS SQL RS amplification
attacks.
IP Private
Traffic (in pps) for
private IP address
space
Spoofed IP addresses, which are not expected
to be routed over the Internet, that are used in
attacks
Note: SP uses the following IP spaces to
detect this misuse type:
n
n
244
IPv4
l
10.0.0.0/8
l
172.16.0.0/12
l
192.168.0.0/16
IPv6
l
All spaces except 2000::/3
IPv4 Protocol 0
Traffic (in pps) with Attacks in which the higher-layer transport
the protocol number protocol number is set to 0, which is an invalid
set to 0
protocol number (TCP is protocol 6, UDP is
protocol 17, and ICMP is protocol 1).
Note: The IPv4 Protocol 0 misuse type works
only with IPv4 traffic.
MS SQL RS
Amplification
UDP traffic (in bps
or pps)with source
port 1434
Microsoft SQL Resolution Service
reflection/amplification attacks
NTP Amplification
NTP traffic (in bps
or pps) with the
UDP protocol,
source port 123,
and invalid packet
sizes
NTP reflection/amplification attacks
SNMP Amplification
SNMP traffic (in
bps or pps) with the
UDP protocol and
source port 161
and/or 162.
SNMP reflection/amplification attacks
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Host detection misuse types (Continued)
Misuse Type
Type of Traffic
Can Help Detect
SSDP Amplification
UDP traffic (in bps
or pps) with source
port 1900
SSDP (Simple Service Discovery Protocol)
reflection/amplification attacks
TCP Null
TCP traffic (in pps)
that contains a
sequence number
but no flags
TCP Null-Flags attacks
TCP RST
TCP traffic (in pps)
with the reset flag
set
TCP reset attacks
TCP SYN
TCP traffic (in pps)
with the
synchronize flag set
Common TCP SYN flood attacks.
UDP
UDP traffic (in pps)
UDP attacks
Proprietary and Confidential Information of Arbor Networks Inc.
245
SP and TMS User Guide, Version 8.0
Configuring Profiled Network Detection for Services
Introduction
Profiled network detection identifies excessive rates of traffic that cross a service boundary.
With profiled network detection enabled for a service, SP triggers an alert when it identifies
excessive rates of traffic at the service boundary based on baselines that SP has calculated.
The rate of traffic must exceed the baseline by the detection percentage for a sustained period
of time. When SP generates a profiled network detection alert, it classifies the severity of the
alert as low, medium, or high. See “About Profiled Network Detection” on page 451.
Configuring profiled network detection for a service
To configure profiled network detection for a service:
1. Add or edit a service.
2. Click the Profiled Network Detection tab.
3. Select the Enable Profiled Network Detection check box to enable profiled network
detection.
4. Use the following table to configure the profiled network detection settings:
Setting
Description
Enable Profiled
Country Detection
check box
Select if you want to enable profiled country detection.
Incoming Detection
Percent and Outgoing
Detection Percent box
Type the SHUFHQWDJH above the baseline that either
incoming or outgoing traffic must be before SP triggers the
alert.
Severity Duration box
Type the QXPEHU of minutes that an alert must exceed the
severity threshold before SP sets the alert to high severity.
If enabled, SP generates alerts when the traffic from a
country exceeds the baseline values for that country.
The severity rates are applied on a network wide basis.
Incoming Severity
Percent and Outgoing
Severity Percent boxes
Type the SHUFHQWDJH above the baseline that either
incoming or outgoing traffic must be before SP sets the
alert to high severity.
Incoming Ignore Rates
and Outgoing Ignore
Rates boxes
Type the traffic UDWHV (in bps and pps) below which you do
not want SP to generate alerts.
Note: Ignore rates impose a floor to the baseline for the
configured type (bps or pps).
5. Click Save.
246
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Configuring Mitigation Settings for Services
Introduction
You can add or edit mitigation settings when you configure services. Mitigation settings allow
SP to collect data for enforcing baselines for services.
See “Adding, Editing, and Deleting Services” on page 227.
Configuring mitigation settings for services
To configure mitigation settings for services:
1. Navigate to the Add Service page or the Edit Service page.
See “Adding and editing services” on page 227.
2. Click the Mitigation tab.
3. Configure the following settings:
Setting
Description
Enable Enforced
Baseline
Protection check
box
Select to collect historical traffic data.
Generate IP
Location Policing
Rate Suggestions
check box
Select to enable SP to make rate policing suggestions based on
IP Location information.
User Initiated list
Select the mitigation template that you want to use.
Enforced Baseline Protection helps protect your network from
uncharacteristic surges in traffic volume. When this value is set,
SP collects historical traffic data from the configured service. If
you then enable the Protocol Baselines countermeasure for the
managed object in a TMS mitigation, the TMS appliance uses
this historical data to blacklist the traffic dynamically.
See “Configuring the IP Location Policing Countermeasure ” on
page 658.
If an auto-mitigation occurs in the managed services view, the
managed services user can view and edit that auto-mitigation
with the auto-mitigation’s template applied, even if the user’s
assigned “User Initiated” mitigation template is different.
You use this template when you create a mitigation to protect a
service.
For information about creating templates, see “About TMS
Mitigation Templates” on page 587.
Proprietary and Confidential Information of Arbor Networks Inc.
247
SP and TMS User Guide, Version 8.0
Configuring Fingerprints
Introduction
You can configure reporting and alerting for system-defined and custom fingerprints on the
Configure Fingerprints page (Administration > Monitoring > Fingerprints). The
Configure Fingerprints page displays all configured fingerprints, their descriptions, and whether
they are enabled for reporting and alerting.
When you enable fingerprint reporting, you can view data about the different fingerprints that
SP detects in your network traffic. When you enable fingerprint alerting, SP compares the
incoming and outgoing fingerprint traffic that it detects on your network to the expected traffic
thresholds that you set.
About fingerprints
You can use fingerprints to do the following:
detect network activity that defies acceptable use
n
n
detect threats, such as bots, botnets, DNS hi-jacks, and phishing, in real-time
n
report on top talkers (high bandwidth consumers) using FCAP expressions
n
mitigate threats
n
monitor traffic traveling to and from service delivery infrastructure devices
See “About the Fingerprint Threshold Alert Pages” on page 475.
Adding and editing fingerprints
To add or edit a fingerprint:
1. Navigate to the Configure Fingerprints page (Administration > Monitoring >
Fingerprints).
2. Choose one of the following steps:
l
To add a fingerprint, click Add Fingerprint.
l
To edit a custom fingerprint, click its name link.
3. On the Add Fingerprint page or the Edit Fingerprint page, on the Description tab,
configure the following basic identification settings:
Setting
Description
Name box
Type a unique QDPH for the fingerprint. This setting is disabled
for a system-defined fingerprint.
Description box
Type a GHVFULSWLRQ that can help you to easily identify the
fingerprint in a list. This setting is disabled for a system-defined
fingerprint.
Enabled check box
Select the Enabled box to enable detection and reporting of
the fingerprint. If you clear this check box, the detection and
reporting of the fingerprint is disabled but not deleted.
This is selected by default.
248
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
4. Do one of the following:
l
If you are adding or editing a custom fingerprint, go to Step 5.
l
If you are editing a system-defined fingerprint, go to Step 6.
5. On the Match tab, select one of the following match types and complete the
configuration for that match type:
Match Type
Procedure
Flow Filter
Click Open FCAP Wizard, and then add a fingerprint.
See “Using the FCAP Wizard” on page 32.
AIF Threat
a. Click Select AIF Elements.
b. In the selection wizard, select the AIF elements that you
want the fingerprint to match, and then click OK.
Tip: You can reduce the list of AIF elements by selecting the
AIF threat to which an element belongs from the AIF Threat
list or by searching for an element in the Search box.
6. On the Alerting tab, configure the following settings:
Setting
Description
Enable alerting
check box
Select the Enable alerting check box, if you want to enable
alerting.
High Threshold
boxes
Type the high WKUHVKROGV that you want to trigger alerts for
this fingerprint as both bps and pps values.
Low Threshold
boxes
Type the low WKUHVKROGV that you want to trigger alerts for
this fingerprint as both bps and pps values.
7. Click Save, and then commit your changes.
Disabling detection and reporting of a fingerprint
You can disable detection and reporting of a fingerprint without deleting it.
To disable detection and reporting of a fingerprint:
1. Navigate to the Configure Fingerprints page (Administration > Monitoring >
Fingerprints).
2. Click the name link for an existing fingerprint.
3. On the Edit Fingerprint page, on the Description tab, clear the Enabled check box.
4. Click Save, and then commit your changes.
Deleting fingerprints
To delete fingerprints:
1. Navigate to the Configure Fingerprints page (Administration > Monitoring >
Fingerprints).
2. Select the check boxes for the fingerprints that you want to delete, and then click Delete.
Proprietary and Confidential Information of Arbor Networks Inc.
249
SP and TMS User Guide, Version 8.0
You cannot delete a system-defined fingerprint.
3. Click Save, and then commit your changes.
250
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Configuring Subscriber Groups and Subscriber Group Settings
Introduction
The Subscriber Settings Administration page (Administration > Monitoring >
Subscribers) allows you to configure and monitor subscriber groups on your network. You can
configure subscriber groups to detect malicious hosts that violate (match) fingerprint
signatures at the subscriber edge of your network. Fingerprint signatures provide enough detail
to allow you to trace the traffic matching the fingerprint signatures back to individual
subscribers in your network. This is particularly valuable for mobile service providers. See
“Configuring Fingerprints” on page 248.
You can also use subscriber groups to report on and analyze traffic from all subscribers. You
can monitor subscriber groups’ traffic on the Subscriber Dashboard. See “About the
Subscriber Dashboard” on page 804.
The subscriber feature is disabled by default. See “Enabling the Subscriber Feature” in the
SP and TMS Advanced Configuration Guide.
Configuring subscriber groups
To configure a subscriber group:
1. Navigate to the Subscriber Settings Administration page (Administration >
Monitoring > Subscribers).
2. On the List tab, do one of the following:
l
To add a subscriber group, click Add Subscriber.
l
To edit a subscriber group, click its name link.
3. On the Add Subscriber page or the Edit Subscriber page, on the Description tab,
configure the following basic identification settings:
Setting
Description
Name box
Type a unique QDPH for the subscriber group.
Description box
Type a GHVFULSWLRQ that can help you to easily identify the
subscriber group in a list.
Tags box
Type one or more WDJV that describe the subscriber group.
After you type a tag, press COMMA, TAB, or ENTER to set the tag
and to continue.
Proprietary and Confidential Information of Arbor Networks Inc.
251
SP and TMS User Guide, Version 8.0
4. On the Add Subscriber page or the Edit Subscriber page, click the following tabs and add
or edit their settings:
Tab
Description
Match
Allows you to configure the match settings for a subscriber group.
See “Configuring match settings for a subscriber group” below.
Boundary
Allows you to define boundaries for a subscriber group. See
“Configuring Boundaries for Services or Subscribers” on
page 230.
Malicious
Fingerprints
Allows you to select the malicious fingerprints that you want SP to
detect for the subscriber group. To select the malicious
fingerprints, click Edit Malicious Fingerprints. See “Using
Selection Wizards” on page 31and “Configuring Fingerprints” on
page 248.
5. On the Add Subscriber page or the Edit Subscriber page, click Save.
6. On the Subscriber Settings Administration page, click the Settings tab, and configure
the syslog settings so that SP can alert you about the malicious hosts that it detects.
See “Configuring syslog messaging settings for a subscriber group” on the facing page.
7. Click Save.
Configuring match settings for a subscriber group
To configure match settings for a subscriber group:
1. Navigate to the Add Subscriber page or the Edit Subscriber page.
See “Configuring subscriber groups” on the previous page.
2. On the Match tab, select a match pattern that defines the managed object from the
Match 1 list. You can select one of the following match types:
Match Type
Description
None
Allows you to match all traffic as limited by the interface and TMS
boundaries you specify. If you set Match 1 to “none” and set the
boundaries to either “none” or “global,” then the subscriber group
does not match any traffic.
CIDR Blocks
One or more IPv4 CIDR block prefixes with the form A.B.C.D/N. To
separate multiple prefixes, use spaces. SP treats all CIDRs in
aggregate for traffic reports and DoS alert detection.
Communities
A regular expression including one or more BGP communities in
the form of X:Y, where X represents the ASN and Y represents the
number of local significance to AS X. To separate multiple
communities, use commas. These expressions must be in a range
of 0-65535.
Example: '(^| )2:20( |$)' matches community 2:20.
252
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Match Type
Description
Extended
Communities
A regular expression including one or more BGP extended
communities in the form of X:Y:Z, where X represents the type
field and Y:Z represents the route target or site of origin. The type
field can be either “route-target” or “site-of-origin.” The route
target must use a supported format. See “Supported route target
formats” on page 173.
When you enter multiple extended communities, you can use a
space, comma, or line break to separate them.
Examples:
n
n
n
Local ASN/SubAS
route-target:10.2.1.5:100
route-target:100:72698
site-of-origin:9642L:982
The AS number of a sub or local AS on your network. These
numbers must be in the range of 1-65535 and unique across
customers.
3. Complete the next steps based on the match settings that you want to configure:
Match Type
Procedure
None
Go to Step 4.
CIDR Blocks
Type one or more &,'5 EORFN SUHIL[HV in the Match Values
box.
Communities
Type one or more FRPPXQLWLHV in the Match Values box.
Extended
Communities
Type one or more H[WHQGHG FRPPXQLWLHV in the Match
Values box.
Local ASN/SubAS
a. Type the $61 of a sub or local AS on your network in the
Match Values box.
b. Select the Only match traffic with a local endpoint
check box to include only traffic with a local endpoint.
4. Click Save.
Configuring syslog messaging settings for a subscriber group
You can configure syslog (system log) messaging so that SP alerts you about the malicious
subscriber groups that it detects. When you configure syslog messaging, SP sends syslog
messages from each appliance that is monitoring subscriber traffic, not just the leader
appliance. Each appliance that has the traffic and routing analysis role sends up to 500
messages per second, not to exceed a maximum of 20,000 messages in a five-minute period.
To configure syslog messaging settings for a subscriber group:
1. Navigate to Subscriber Settings Administration page (Administration > Monitoring >
Subscribers).
2. Click the Settings tab.
Proprietary and Confidential Information of Arbor Networks Inc.
253
SP and TMS User Guide, Version 8.0
3. To save malicious host data in the syslog, configure the following settings:
Setting
Description
Log File Age Max
box
Type the maximum QXPEHU of days that you want to save
malicious hosts in the syslog.
Remote Syslog
Hosts box
Type the ,3 DGGUHVVHV of the remote hosts to which you
want syslog notifications sent.
Remote Syslog
Port box
Type the SRUW to access the remote hosts where you want
syslog notifications sent.
Facility list
Select the syslog facility.
Priority list
Select the syslog priority.
You can also download malicious host data as a CSV file. See “Downloading malicious
subscriber group data as a CSV file” below.
Downloading malicious subscriber group data as a CSV file
SP aggregates subscriber group data from all of the appliances in your deployment that have
the traffic and routing analysis role into a single CSV file. This file contains up to 20,000 of the
top malicious subscriber groups for all configured subscriber groups in a five-minute bin period.
This file lists one entry per host and fingerprint pair.
To download malicious subscriber group data as a CSV file:
1. Navigate to the Subscriber Settings Administration page (Administration >
Monitoring > Subscribers).
2. Click the Logs tab.
3. Configure the following settings, and then click Download Aggregated CSV:
Setting
Description
Date list
Select the date for which you want to view malicious
subscriber group data.
Hour and Minute
bin lists
Select the hour and minute bin for which you want to view
malicious subscriber group data.
SP collects data in five-minute bins.
254
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
Configuring BGP Thresholds, Hijacking, and Traps
Introduction
You can configure BGP thresholds to trigger alerts on BGP updates.
Configuring BGP Instability Threshold and BGP Hijacking
To configure BGP thresholds and BGP hijacking:
1. Navigate to the Configure BGP Instability page (Administration > Detection > BGP
Instability).
2. Type a WKUHVKROG QXPEHU in the Threshold box.
Note: The threshold is the number of BGP updates that will be tolerated in a five-minute
period without triggering an alert. The default is 5000.
3. Select the Detect BGP Hijacking check box to detect a BGP announcement of local
address space by an external AS.
Note: Detection of BGP hijacking depends on correct configuration of local address
space and ASNs on the Configure Network Definition page.
For more information about how to configure your local address space, see “Defining Your
Network and Configuring Network Boundaries” on page 118.
4. Click Save.
Adding and editing a BGP trap
You can use a BGP trap to notify you of an event that affects a CIDR block that your system
monitors. SP can alert you to any changes to your routes, such as changes to CIDR prefixes.
For example, you might configure a BGP trap to alert you if the route is withdrawn from a VoIP
CIDR block.
The Configure BGP Traps page (Administration > Detection > BGP Traps) allows you to
trap BGP route changes. The page displays the list of configured BGP events per name,
associated prefixes, events, and notification groups.
To add or edit a BGP trap:
1. Navigate to the Configure BGP Traps page (Administration > Detection > BGP
Traps).
2. Do one of the following:
l
To add a BGP trap, click Add BGP Trap.
l
To edit an existing BGP trap, click a name link.
Proprietary and Confidential Information of Arbor Networks Inc.
255
SP and TMS User Guide, Version 8.0
3. On the Add BGP Trap page or Edit BGP Trap page, configure the following settings:
Setting
Description
Name box
Type the QDPH RI WKH %*3 WUDS.
Prefixes box
Type the &,'5 EORFNV that you want the system to monitor,
separated by spaces (for example, 192.168.10.0/24
192.168.0.3/8).
Events check boxes
Select the check boxes for the events for which you want to be
notified of changes.
Notification Group
list
Select a notification group.
To filter the list, type any part of the name of a notification group
that does not include a space.
Note: If you do not select a notification group, SP sends alerts
to the default notification group.
4. Click Save.
Deleting BGP traps
To delete a BGP trap:
1. Navigate to the Configure BGP Traps page (Administration > Detection > BGP
Traps).
2. Select the check boxes for the BGP traps that you want to delete, and then click Delete.
About the interface usage thresholds
The Interface Usage Thresholds are absolute boundaries. If at any given time an interface is
utilized more than the High Threshold or less than the Low Threshold, SP generates an
Interface Usage alert. The default is to generate an alert if an interface exceeds 95 percent
utilization (95Mbps for a 100Mb interface, 950Mbps for a 1 Gigabit interface, etc.) The High
and Low Interface thresholds can also be set on a per-interface basis.
Example: If you have an interface that should never drop below 30 percent utilization, you
can set a Low Interface Threshold alert for that interface with a value of 30 percent.
Configuring traffic traps
The Configure Traffic Traps page allows you to configure managed object threshold alerting.
To configure traffic traps:
1. Navigate to the Configure Traffic Traps page (Administration > Detection > Traffic
Traps).
256
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 9: Configuring Other Network Resources
2. Configure the high and low threshold as follows:
Action
Steps
Turn off the high or
low threshold
Type -1 in the High Threshold or Low Threshold box.
Turn on the high or
low threshold
Type a SHUFHQWDJH YDOXH (1-100) of the interface speed in
the High Threshold or Low Threshold box.
Note: When traffic on an interface exceeds this number, SP
triggers a traffic trap.
Use the default
values
Leave the High Threshold or Low Threshold box blank.
See “About the interface usage thresholds” on the previous page.
3. Select the Enable Managed Object Threshold-based Alerting check box to send
alerts about the usage thresholds on a managed object's interface.
4. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
257
SP and TMS User Guide, Version 8.0
258
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10:
Configuring Alert Notifications
Introduction
This section describes how to configure SP to send alert notifications for attack traffic and for
operational issues with non-TMS appliances.
User access
Only administrators can configure the settings described in this section.
In this section
This section contains the following topics:
Configuring Global Notification Settings for Alerts
260
About Notification Groups
261
Configuring Notification Groups
263
Configuring SP System Monitoring Alerts
266
About Alert Notification Rules
268
Configuring Alert Notification Rules
270
Understanding XML for Alert Notifications
271
SP and TMS User Guide, Version 8.0
259
SP and TMS User Guide, Version 8.0
Configuring Global Notification Settings for Alerts
Introduction
You can configure the global notification settings that SP uses to send alert notifications on
the Global Notification Settings page.
Configuring global notification settings for alerts
To configure global notification settings for alerts:
1. Navigate to the Global Notification Settings page (Administration > Notification >
Global Settings).
2. In the Flow Down Timeout box, type the number of VHFRQGV that you want the system
to wait before it notifies the group that it is not receiving the expected traffic flows.
3. From the Default Notification Group list, select the notification group that you want to
be the default group.
The default group receives notifications for all high alerts for all parent managed objects. It
also is the only group that receives notifications for non DoS alerts.
To filter the list, type any part of the name of a notification group that does not include a
space. For information about configuring notification groups, see “Configuring Notification
Groups” on page 263.
4. Enable system monitoring notifications in the CLI.
For these instructions, see “Enabling and Disabling System Alert Notifications” in the
SP and TMS Advanced Configuration Guide.
5. Click Save, and then commit your changes.
260
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
About Notification Groups
Introduction
You can use the Notification Groups page (Administration > Notification > Groups) to
create groups to which SP sends system notifications. SP can send notifications by email and
SNMP traps or by syslog events to remote servers. These notifications include DoS alert, BGP
trap, mitigation event, system event (such as a disk failure), and report information. See
“Configuring Notification Groups” on page 263.
You can create a default notification group to receive all system notifications, and you can
define unique groups to receive specific DoS alerts and reports, but not mitigation information.
(Mitigation notifications are only sent to the default notification group).
After you create a group, you can designate it as the default group, create rules for DoS alerts,
or assign that group to receive emailed reports from SP.
Mitigation prefixes in notifications
In mitigation start and stop notifications, the number of mitigation prefixes that are included
varies depending on how the notification is sent, as follows:
n Emailed notifications include the first 10 prefixes in a mitigation.
n
SNMP notifications include the first 10 prefixes in a mitigation.
n
Syslog notifications do not include the prefix in a mitigation.
About searching on the Notification Groups page
You can use the Search box to search on the Notification Groups page. The following are
some guidelines for using the Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
See “Acceptable search keywords and values for notification groups” on the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
261
SP and TMS User Guide, Version 8.0
Acceptable search keywords and values for notification groups
The following table lists the columns on the Notification Groups page and the keywords and
values that you can use to search on that column in the Search box:
Search keywords for columns
Column to
search on
Acceptable keywords and
values
Name
n
name:QRWLILFDWLRQ
JURXS QDPH
n
name:notification_group1
Description
n
desc:QRWLILFDWLRQ
JURXS GHVFULSWLRQ
description:
QRWLILFDWLRQ JURXS
GHVFULSWLRQ
n
desc:default group
description:DoS alert group
email:HPDLO DGGUHVV
smtp_addresses:HPDLO
DGGUHVV
n
n
Email Addresses
n
n
262
Examples
n
n
email:dos-alertsgroup@example.com
smtp_addresses:alertsgroup@example.com
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
Configuring Notification Groups
Introduction
You can configure Notification Groups settings on the Notification Groups page
(Administration > Notification > Groups).
See “About Notification Groups” on page 261.
Adding and editing alert notification groups
To add or edit a notification group:
1. Navigate to the Notification Groups page (Administration > Notification > Groups).
2. Choose one of the following steps:
l
To add a notification group, click Add Notification Group.
l
To edit a notification group, click a name link.
3. On the Add Notification Group or Edit Notification Group page, configure the following
settings:
Setting
Description
Name box
Type the QDPH of the group.
Description box
Type a GHVFULSWLRQ of the group.
4. In the Email section, type the destination HPDLO DGGUHVVHV in one of the following boxes
depending on the format in which you want to send a DoS alert notification:
l
Text Email Addresses box
l
DoS XML Email Addresses box
You can separate multiple email addresses with commas or spaces or by pressing ENTER.
5. Configure one of the following notification methods:
l
SNMP
See “Creating an SNMP group” on the next page.
l
Remote Syslog
See “Creating a syslog group” on page 265.
Typically, you configure either SNMP trap settings or syslog settings for each notification
group but not both.
6. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
263
SP and TMS User Guide, Version 8.0
Creating an SNMP group
Use the following table to configure the SNMP group settings:
SNMP settings
Setting
Description
Trap Destinations box
Type the ,3 DGGUHVV for each SNMP trap receiver.
Type multiple IP addresses as a comma-separated list.
Source IP Override
box
(Optional) Type the host ,3 DGGUHVV.
Community box
Type the FRPPXQLW\ VWULQJ (password) to use for
authenticating the SNMP information.
Version list
Select the SNMP version that you use.
If you selected version 3 from the Version list, then configure the following version 3 settings:
SNMP version 3 settings
Version 3 Setting
Procedure
SNMPv3 Security
Level list
Select one of the following options:
n
n
n
264
noAuthNoPriv — No passphrase authentication is
performed.
authNoPriv — Passphrase authentication is performed but
there is no encryption of the data in the trap messages.
authPriv — Passphrase authentication is performed and the
data in the trap messages is encrypted.
SNMPv3
Authorization
Protocol list
Select an authentication protocol (MD5 or SHA).
If the Security Level setting is set to authNoPriv or authPriv,
this value must match the value that is expected by your trap
receiver.
SNMPv3
Authentication
Username box
Type an SNMP XVHU QDPH.
This setting is required and must match one of the names that is
configured on your trap receiver.
SNMPv3
Authentication
Password box
Type the SDVVZRUG for the SNMP user name that you specified
above.
If the Security Level setting is set to noAuthNoPriv, then do
not configure this setting.
SNMPv3 Privacy Key
box
If the Security Level setting is set to authPriv, then type the
SULYDF\ NH\ that is expected by your trap receiver.
Note: SP uses the DES privacy protocol.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
Creating a syslog group
Use the following table to configure the syslog group settings in the Remote Syslog section:
Remote Syslog settings
Setting
Description
Destinations box
Type the GHVWLQDWLRQ DGGUHVV.
Port box
(Optional) The default setting is port 514. Type the SRUW QXPEHU
if you do not want to use the default port.
Facility list
Select a syslog IDFLOLW\ YDOXH to indicate the source of the
message as defined in the syslog protocol RFC 3164.
Severity list
Select one of the following syslog VHYHULW\ YDOXHV:
n
n
n
n
n
n
n
n
emerg — emergency, system is unusable
alert — action must be taken immediately
crit — critical condition
err — error condition
warning — warning condition
notice — normal but significant condition
info — informational message
debug — debug-level message
Deleting notification groups
Important: You might need to remove any standard rules that are associated with a
notification group before you delete it. SP does not automatically delete rules for deleted
groups.
To delete a notification group:
1. Navigate to the Notification Groups page (Administration > Notification > Groups).
2. Select the check boxes for the groups that you want to delete, and then click Delete.
Tip: You can select the check box next to the Name column heading to select all the
notification groups on the page for deletion.
Proprietary and Confidential Information of Arbor Networks Inc.
265
SP and TMS User Guide, Version 8.0
Configuring SP System Monitoring Alerts
Introduction
You can configure SP to alert you with an SP System Monitoring alert when one or more nonTMS appliances experience operational issues. You configure these system alerts on the
Configure SP System Monitoring Alerts page (Administration > Detection > SP System
Monitoring Alerts). These alerts help you to identify issues and their causes as they occur so
you can address them more quickly and efficiently. You can configure SP to send alert
notifications through email, syslog, or SNMP traps.
The leader monitors data that all non-TMS appliances report when generating these alerts.
Important: To prevent spam, after SP ends an alert, it does not trigger another alert of that
same type until 30 minutes after the last alert of that type ended.
Enabling SP System Monitoring alerts
To prevent spam, SP disables system notifications for alerts by default.
To enable system alert notifications, see “Enabling and Disabling System Alert Notifications” in
the SP and TMS Advanced Configuration Guide.
Where to view SP System Monitoring alerts
You can view SP System Monitoring alerts on the following pages:
All Alerts (Alerts > All Alerts)
n
n
Alerts Ongoing (Alerts > Ongoing)
n
System Error Alerts (Alerts > System Error)
To view just SP System Monitoring alerts on these alert pages, use at:"SP System
Monitoring" for the search keyword and value.
For additional information about these alert pages, see “About the Alert Listing Pages” on
page 465.
If an SP System Monitoring alert is in the top 5 ongoing alerts, you can also view it on the
Security Status page (Alerts > Summary). See “About the Security Status Page” on
page 471.
Configuring SP System Monitoring alerts
To configure SP System Monitoring alerts:
1. Navigate to the Configure SP System Monitoring Alerts page (Administration >
Detection > SP System Monitoring Alerts).
2. Select the Enable process error alerts check box to allow SP to display system alerts
when SP experiences an unexpected process error.
3. To set alerts for 15-minute CPU loads, in the Set 15-minute CPU load alert
threshold box, type a WKUHVKROG QXPEHU.
The threshold value represents the CPU load, which is the number of processes using the
CPU or waiting for the CPU. A high CPU load can indicate compromised system
performance.
266
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
4. To set alerts when disk space reaches or nears capacity, in the Set disk space alert
threshold (percentage) box, type the SHUFHQWDJH of disk capacity used on the SP
appliance.
This alert monitors the appliance's database storage partition and reports on the disk
percentage capacity used. If this percentage becomes too high, then SP is in danger of
critical failure or data loss.
5. To set alerts for when SP drops flows, in the Set dropped flows alert threshold box,
type the QXPEHU of dropped flows after which you want SP to send an alert.
Tip: To disable this alert, leave the box blank. Typing 0 does not disable the alert. If you
type 0, then SP will send an alert when one or more flows drop.
6. To set alerts for memory usage, in the Set memory usage alert threshold
(percentage) box, type the SHUFHQWDJH of real memory that SP uses.
When memory usage is high, the SP appliance will not be able to cache as much data as
with the faster RAM memory. Instead, it must use a hard disk swap (a much slower
mechanism), which reduces system performance.
7. To set alerts for short-term database runtime, in the Set short-term database runtime
alert threshold (seconds) box, type the QXPEHU of seconds that the database
operation will run.
8. To set alerts when an NTP clock skew exists between a leader and another appliance, in
the Set system clock skew alert threshold box, type the QXPEHU of seconds of skew.
When an NTP clock skew exists between a leader and another appliance, problems can
occur with traffic binning and DoS alert handling.
9. Click Save, and then commit your changes.
Disabling SP System Monitoring alerts
To disable specific SP System Monitoring Alerts:
1. Navigate to the Configure SP System Monitoring Alerts page (Administration >
Detection > System Monitoring Alerts).
2. Clear the check boxes or text boxes for the settings that you want to disable.
3. Click Save, and then commit your changes.
To enable the notifications for all of these alerts, see “Enabling and Disabling System Alert
Notifications” in the SP and TMS Advanced Configuration Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
267
SP and TMS User Guide, Version 8.0
About Alert Notification Rules
Introduction
You can configure notification rules for specific resources and managed objects on the
Rule-Based Notification page (Administration > Notification > Rules). SP sends alerts
to notification groups that contain sets of email addresses (for XML and email alerts) or IP
addresses (for SNMP and syslog alerts). See “Configuring Alert Notification Rules” on
page 270.
Example: You can create a notification rule for a Managed Services DDoS customer. DDoS
alerts for that customer can then be directed to an SNMP trap receiver or syslog server to be
processed in a timely manner, giving the Managed Services customer prioritized service.
Matching rules against sources
When SP matches an alert against a defined notification rule, it sends the alert using the
mechanisms and destinations specified within the notification group. Alerts that affect a larger
address space (that contains the resource CIDR block) do not trigger the rule.
Example: If SP detects a DoS alert and applies the alert to 10.0.0.0/32, and you create a rule
with the resource CIDR block 10.0.0.0/16, then SP sends a notification message using the
mechanism and destination addresses specified within the rule. It sends a notification message
if the alert’s importance is greater than or equal to the importance level specified in the rule.
About searching on the Rule-Based Notification page
You can use the Search box to search on the Rule-Based Notification page. The following are
some guidelines for using the Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
See “Acceptable search keywords and values for alert notification rules” on the facing page.
268
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
Acceptable search keywords and values for alert notification rules
The following table lists the columns on the Rule-Based Notification page and the keywords
and values that you can use to search on that column in the Search box:
Search keywords for attributes
Column to
search on
Acceptable keywords and
values
Name
n
name:QRWLILFDWLRQ UXOH
QDPH
n
name:notification rule1
Resource
n
res:{&,'5 EORFN | PDQDJHG
REMHFW QDPH}
resource:{&,'5 EORFN |
PDQDJHG REMHFW QDPH}
n
n
res:customer xyz
resource:10.0.0.0/16
n
Examples
Importance
n
importance:{high | medium |
low}
n
importance:high
Notification
Group
n
group:JURXS QDPH
notification_group:JURXS
QDPH
notification_group_
name:JURXS QDPH
n
group:notification group1
notification_group:notification
group2
notification_group_
name:notification group3
n
n
Proprietary and Confidential Information of Arbor Networks Inc.
n
n
269
SP and TMS User Guide, Version 8.0
Configuring Alert Notification Rules
Introduction
You can configure alert notification rules on the Rule-Based Notification page
(Administration > Notification > Rules). See “About Alert Notification Rules” on
page 268.
Adding and editing alert notification rules
To add or edit an alert notification rule:
1. Navigate to the Rule-Based Notification page (Administration > Notification >
Rules).
2. Do one of the following:
l
Click Add Rule to add a rule.
l
Click an existing name link to edit a rule.
3. On the Add Notification Rule page or Edit Notification Rule page, configure the following
settings:
Setting
Description
Name box
Type the QDPH RI WKH UXOH.
Resource Type
options
Click the resource type that you want to use in the alert
notification rule. If you click CIDR, the CIDR box appears. If
you click Managed Object, the Managed Object list
appears.
CIDR box
Type the &,'5 EORFN that you want to use in the alert
notification rule.
Managed Object
list
Select the name of the managed object that you want to use in
the alert notification rule.
To filter the list, type any part of the name of a managed object
that does not include a space.
Importance list
Select the importance level of the rule.
A rule is triggered if the alert’s importance level is greater than
or equal to the importance specified in the rule.
Notification Group
list
Select the group to which you want to send the notification.
To filter the list, type any part of the name of a notification group
that does not include a space.
4. Click Save, and then commit your changes.
Deleting alert notification rules
To delete an alert notification rule:
Select the check boxes for the rules that you want to delete, and then click Delete.
n
270
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
Understanding XML for Alert Notifications
Introduction
You can parse the components and elements that appear in the XML alert notifications for your
own purposes. Review the example and then refer to the other sections for explanations.
Alert notification example
The following example is for a Total Traffic DoS host alert:
"[PO YHUVLRQ HQFRGLQJ XWI"!
DOHUWOLVW!
DOHUWBFRXQW!DOHUWBFRXQW!
DOHUW LG LVBIDVWBGHWHFWHG I W\SH 'R6 +RVW $OHUW!
GHYLFH JLG QDPH VSBOHDGHU!
DQQRWDWLRQOLVW!
DQQRWDWLRQ!
DGGHG!DGGHG!
DXWKRU!DXWRDQQRWDWLRQDXWKRU!
FRQWHQW!7KH 7RWDO 7UDIILF KRVW DOHUW VLJQDWXUH KDV EHHQ
WULJJHUHG DW URXWHU URXWHU H[SHFWHG UDWH 0ESV .SSV REVHUYHG UDWH *ESV
.SSV FRQWHQW!
DQQRWDWLRQ!
DQQRWDWLRQOLVW!
LPSRUWDQFH OHYHO KLJK!
UHVRXUFH!
LS!LS!
PDQDJHGBREMHFW JLG QDPH $6 VHYBSFW VHYB
UDWH VHYBLVBESV W PLVXVHBVLJ 7RWDO
7UDIILF!PDQDJHGBREMHFW!
UHVRXUFH!
FODVVLILFDWLRQ!3RVVLEOH $WWDFNFODVVLILFDWLRQ!
GXUDWLRQ RQJRLQJ I VWDUW VWRS VWDUWBDVFLL 7 VWRSBDVFLL 7 OHQJWK !
KRVWBGHWHFWLRQ KRVWBDGGUHVV LSBYHUVLRQ !
PLVXVH!7RWDO 7UDIILFPLVXVH!
PDQDJHGBREMHFWV!
PDQDJHGBREMHFW JLG QDPH $6 VXPPDU\B
XUO SDJH"LG FXVWRPHUBVXPPDU\ DPSJLG HGLWBXUO VHYBSFW VHYBUDWH VHYBLVBESV W PLVXVHB
VLJ 7RWDO 7UDIILF LPSRUWDQFH KLJK!
PDQDJHGBREMHFWV!
KRVWBGHWHFWLRQ!
VHYHULW\ WKUHVKROG SFW XQLW SSV!
Proprietary and Confidential Information of Arbor Networks Inc.
271
SP and TMS User Guide, Version 8.0
GLUHFWLRQ!,QFRPLQJGLUHFWLRQ!
LPSDFW ESV SSV ERXQGDU\ URXWHU!
URXWHU JLG QDPH URXWHU LS VHYHULW\ VHYBSFW !URXWHU!
URXWHU JLG QDPH URXWHU LS VHYHULW\ VHYBSFW !URXWHU!
URXWHU JLG QDPH URXWHU LS VHYHULW\ VHYBSFW !URXWHU!
WKUHVKROGV!
WKUHVKROG PLVXVHBW\SH WKUHVKROGBXQLW SSV WULJJHUB
UDWH !WKUHVKROG!
WKUHVKROG PLVXVHBW\SH WKUHVKROGBXQLW SSV WULJJHUB
UDWH !WKUHVKROG!
WKUHVKROG PLVXVHBW\SH WKUHVKROGBXQLW SSV WULJJHUB
UDWH !WKUHVKROG!
WKUHVKROGV!
DOHUW!
DOHUWOLVW!
About the <alert-list> XML elements
The following table describes the various elements that appear in the DOHUWOLVW!
component of XML notifications:
XML <alert-list> elements
Element
Attributes
Description
DOHUWOLVW!
None
The container for the alert.
DOHUWFRXQW!
None
The number of alerts in the list. This will
always be 1 for alert notifications, since
this data has the same source as the alert
listing page.
DOHUW!
LG
The alert ID number and type.
The LVBIDVWBGHWHFWHG attribute
specifies whether or not it is a fast flood
alert.
The DOHUW!component contains several
other components. See “About the
<alert> XML elements” on the facing
page.
LVBIDVWBGHWHFWHG
W\SH
272
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
About the <alert> XML elements
The following table describes the various elements that appear in the DOHUW! component in
XML notifications:
XML <alert> elements
Element
Attributes
Description
GHYLFH!
JLG
The name and gid of the SP leader
device.
QDPH
DQQRWDWLRQOLVW!
None
The container for the annotations
attached to the alert.
The DQQRWDWLRQOLVW! component
contains several elements. See “About
the XML elements for the <annotationlist> component” on the next page.
LPSRUWDQFH!
OHYHO
The alert's importance.
See “Alert levels of importance” on
page 456.
UHVRXUFH!
None
The resource affected by the reported
alerts, such as an IP address, a CIDR
address, or a managed object.
The UHVRXUFH!component contains
several elements. See “About the XML
elements for the <resource>
component” on page 275.
FODVVLILFDWLRQ!
None
The alert classification type.
See “Alert classification types” on
page 488.
GXUDWLRQ!
RQJRLQJ
The alert duration.
The RQJRLQJ attribute is either W or I.
The VWDUW and VWRS attributes are in
UNIX epoch time.
The VWDUWBDVFLL and VWRSBDVFLL
attributes are human-readable dates.
The OHQJWK attribute is the number of
seconds the alert lasted.
VWDUW
VWRS
VWDUWBDVFLL
VWRSBDVFLL
OHQJWK
KRVW GHWHFWLRQ!
KRVWBDGGUHVV
LSBYHUVLRQ
VHYHULW\!
WKUHVKROG
SFW
XQLW
Proprietary and Confidential Information of Arbor Networks Inc.
The KRVW GHWHFWLRQ! component
contains several elements. See “About
the XML elements for the <host
detection> component” on page 275.
The alert severity.
273
SP and TMS User Guide, Version 8.0
XML <alert> elements (Continued)
Element
Attributes
Description
GLUHFWLRQ!
None
The direction of the alert traffic.
See “About key alert information on the
Summary tab” on page 498.
LPSDFW!
ESV
SSV
ERXQGDU\
The impact value from the summary
portion of the page.
See “About key alert information on the
Summary tab” on page 498.
URXWHU!
JLG
QDPH
LS
VHYHULW\
VHYBSFW
Each router, its severity (in other words,
its importance level where 0 = low, 1 =
medium, and 2 = high), and severity
percentage.
See “About key alert information on the
Summary tab” on page 498.
WKUHVKROGV!
Not applicable
Contains the XML data for producing
graphs in the SP UI. You can ignore this
when parsing the XML.
About the XML elements for the <annotation-list> component
The following table describes the various elements that appear in the DQQRWDWLRQOLVW!
component in XML notifications:
XML elements for the <annotation-list> component
274
Element
Attributes
Description
DQQRWDWLRQ!
None
The container for each annotation
attached to the alert
DGGHG!
None
The UNIX epoch time when the
annotation was added.
DXWKRU!
None
The author of the annotation.
FRQWHQW!
None
The text of the annotation text.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 10: Configuring Alert Notifications
About the XML elements for the <resource> component
The following table describes the various elements that appear in the UHVRXUFH! component
in XML notifications:
XML elements for the <resource> component
Element
Attributes
Description
LS!
None
The IP address of the resource affected
by the alert.
PDQDJHGBREMHFW!
JLG
QDPH
VHYBSFW
VHYBUDWH
VHYBLVBESV
PLVXVHBVLJ
The managed object on which the alert is
triggered and its data.
See “About key alert information on the
Summary tab” on page 498.
About the XML elements for the <host detection> component
The following table describes the various elements that appear in the KRVW GHWHFWLRQ!
component in XML notifications:
XML elements for the <host detection> component
Element
Attributes
Description
PLVXVH!
None
The misuse type detected.
See “Host detection misuse types” on
page 189.
PDQDJHGBREMHFWV!
None
The container for a single managed
object.
PDQDJHGBREMHFW!
JLG
QDPH
VXPPDU\BXUO
HGLWBXUO
VHYBSFW
VHYBUDWH
VHYBLVBESV
PLVXVHBVLJ
LPSRUWDQFH
The managed object on which the alert is
triggered and its data.
See “About key alert information on the
Summary tab” on page 498.
Proprietary and Confidential Information of Arbor Networks Inc.
275
SP and TMS User Guide, Version 8.0
276
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 11:
Configuring User Interface Settings
Introduction
This section describes the different user interface settings that you can configure so that your
SP Web UI meets the needs and requirements of your organization.
User access
Only administrators can perform the tasks described in this section.
In this section
This section contains the following topics:
Configuring Global UI Settings
278
Configuring Ticketing
280
Configuring Audio Alerting
281
Customizing the Login Page
282
Configuring Menus
283
Configuring Name Mappings
285
SP and TMS User Guide, Version 8.0
277
SP and TMS User Guide, Version 8.0
Configuring Global UI Settings
Introduction
You can configure the following on the Configure UI Preferences page (Administration >
User Interface > Global Settings):
n a custom logo for the SP Web UI
n
the support email address
n
the login timeout period
n
status page update preferences
n
ticketing
n
audio alerting
These settings are described below, except for the procedures for ticketing and audio alerting
that are described in more detail in separate topics. For information about configuring these
settings, see “Configuring Ticketing” on page 280 and “Configuring Audio Alerting” on
page 281.
Uploading a custom logo
You can upload a custom logo as a PNG image to appear on all SP Web UI pages. Custom
logo configuration is specific to the Web UI appliance (leader appliance or appliance that has
the user interface role) on which it is configured.
To upload a custom logo to the Web UI:
1. Navigate to the Configure UI Preferences page (Administration > User Interface >
Global Settings).
2. In the Custom Logo section, click Browse.
3. Select the image file that you would like to upload, and then click Open.
Note: The image must be a PNG file that is between 20 and 31 pixels high and between
100 and 300 pixels wide.
4. Click Upload Image, and then click Save.
You can also reset the image to the default image, which is the SP logo. To reset the image to
Arbor’s default logo, click Reset Image.
Configuring the support email address
SP allows you to change the support email address that appears at the bottom of all Web UI
pages.
To set the support email address:
1. Navigate to the Configure UI Preferences page (Administration > User Interface >
Global Settings).
2. In the System section, in the Support Email box, type the HPDLO DGGUHVV to which you
want assistance requests sent, and then click Save.
278
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 11: Configuring User Interface Settings
Setting the inactive session timeout period
You can edit the default inactive session timeout period. The default value is 10 minutes. If a
user is inactive for this timeout period, then the user must log in again in order to access the
Web UI.
To set the login timeout period:
1. Navigate to the Configure UI Preferences page (Administration > User Interface >
Global Settings).
2. In the System section, from the Inactive Session Timeout Period list, select the
timeout period, and then click Save.
Setting the status page update period
You can specify the frequency at which you want the status pages to update information.
To set the status page update period:
1. Navigate to the Configure UI Preferences page (Administration > User Interface >
Global Settings).
2. In the System section, from the Status Page Update Period list, select the frequency,
and then click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
279
SP and TMS User Guide, Version 8.0
Configuring Ticketing
Introduction
You can configure SP to integrate with your current Web-based ticketing system on the
Configure UI Preferences page (Administration > User Interface > Global Settings).
This helps you to better track and reference system alerts.
Configuring the ticketing feature
To configure the ticketing feature:
1. Navigate to the Configure UI Preferences page (Administration > User Interface >
Global Settings).
2. In the System section, in the Ticketing System URL box, type your WLFNHW V\VWHP
85/.
Tip: To obtain a URL setting that is correct for your particular ticketing system, cut the
URL from an actual ticket, paste it into the Ticketing System URL box, and replace the
ticket number with the characters V.
Associating alerts with a ticket number
After you configure the ticketing feature, a
(ticket) icon appears in the Ticket column for
each alert on an alert listing page. When ticketing is configured, a
icon also appears in the
upper-right corner of the page of each DoS alert, Fingerprint alert, Service Threshold alert,
BGP Instability alert, and Cloud Signaling Mitigation Request alert.
You can click to enter the ticket number to associate with an alert. When you do this, the
characters “%s” in the configured ticketing URL are substituted with that ticket number. This
allows you to use the ticket link on the alert row to navigate directly to the corresponding ticket
in your system.
To associate a ticket number with an alert:
1. Click the
icon that appears with the alert.
A Ticket ID window appears.
2. Type the WLFNHW ,' QXPEHU that you are associating with an alert, and then click Save.
Deleting ticket numbers
To delete a ticket number:
1. Click the
icon that appears with the alert.
The Ticket ID window appears, with the ticket number that you assigned to the alert.
2. Delete the ticket number, and then click Save.
280
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 11: Configuring User Interface Settings
Configuring Audio Alerting
Introduction
You can use the Configure UI Preferences page (Administration > User Interface >
Global Settings) to upload customized audio files that correspond with each alert level.
When audio alerting is configured, SP plays a sound when an alert appears on the Security
Status page (Alerts > Summary). You can set a different audio file to play for low, medium,
and high-importance alerts.
Note: Audio alerting is specific to the Web UI appliance (leader appliance or appliance that
has the user interface role) on which it is configured. The configuration does not appear on
other appliances.
Enabling audio alerting
To enable audio alerting:
1. Navigate to the Configure UI Preferences page (Administration > User Interface >
Global Settings).
2. In the Audio Alerts section, from the Enable Audio Alerting list, select Enabled.
3. Next to the Select an Audio File For High DoS Alerts box, click Browse.
4. Select the sound file that you want to play for high alert notifications, and then click
Open.
5. Click Upload.
Note: You can also click Play to hear the audio file.
6. Repeat Step 3 through Step 5 to select audio files for medium and low DoS alerts.
7. Click Save.
Disabling audio alerting
To disable audio alerting:
1. Navigate to the Configure UI Preferences page (Administration > User Interface >
Global Settings).
2. In the Audio Alerts section, from the Enable Audio Alerting list, select Disabled, and
then click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
281
SP and TMS User Guide, Version 8.0
Customizing the Login Page
Introduction
You can create a customized login page for an appliance that has the user interface role by
using the Customize Login page (Administration > User Interface > Custom Login
Page). Customized login pages are specific to the appliance on which they are configured.
You can restore the default login page using the CLI. See “Restoring the Default Login Page”
in the SP and TMS Advanced Configuration Guide.
Customizing the login page
To customize the login page:
1. Navigate to the Customize Login page (Administration > User Interface > Custom
Login Page).
2. Choose your next steps based on how you want to add the HTML:
Action
Steps
Manually type the
HTML
Type your +70/ FRGH in the text box.
Upload an HTML file
a. Click Browse to upload an HTML file.
b. Select the file that you want to upload, and click Upload
File.
Important: Your HTML must include the text %login. SP replaces this text with the proper
login form, which allows users to authenticate to the Web UI. If the code does not include
%login, you will not be able to log in to the Web UI.
3. Click Save.
4. While you are still logged in to the Web UI, test the new login page using a separate
browser. This allows you to make changes if the new login page does not work.
282
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 11: Configuring User Interface Settings
Configuring Menus
Introduction
You can view and customize sets of menus on the Configure Menus page (Administration >
User Interface > Menus).
Note: When you configure custom menu skins on the leader appliance, the leader appliance
synchronizes the changes on all the appliances that have the user interface role. However,
when you create a custom menu skin on a non-leader appliance that has the user interface
role, that menu skin is only available on that appliance.
You can apply menu skins when you configure account groups and user accounts.
See “Configuring User Accounts” on page 291 and “Configuring Account Groups” on
page 302.
About pre-configured menu skins
You can use the following pre-configured menu skins:
Pre-configured menu skins
Menu
Description
default.xml
The default menu skin for non-managed services users. It
provides the user access to all SP functionality.
peering_coordinator.xml
A menu skin designed to meet the needs of peering
coordinators.
scoped_customer.xml
A menu skin designed for managed services customers who are
scoped within a customer managed object. It provides a limited
subset of general-purpose functionality and few administrative
options.
Note: This menu skin should not be applied to normal users.
scoped_vpn.xml
A menu skin designed for managed services customers who are
scoped within a VPN managed object. It provides a limited
subset of general-purpose functionality and few administrative
options.
Note: This menu skin should not be applied to normal users.
tms_management.xml
A menu skin designed to provide a workflow for mitigating DoS
attacks with TMS appliances.
traffic.xml
A menu skin designed to facilitate the tasks of a network
engineer, including the full range of traffic reports.
Proprietary and Confidential Information of Arbor Networks Inc.
283
SP and TMS User Guide, Version 8.0
Adding custom menu skins
In addition to the pre-configured menu skin sets, you can create custom menu skins.
To add a custom menu skin:
1. Navigate to the Configure Menus page (Administration > User Interface > Menus).
2. Click Add Menu.
3. On the Add Menu page, in the Name box, type the QDPH that you want to call the new
menu skin.
4. Type the PHQX GHILQLWLRQ (in XML format) in the box, and then click Save.
Note: You can edit a customized menu skin by clicking the menu skin name link on the
Configure Menus page.
For information about the custom menu XML schema, see "The XML Menu Schema" in the
SP and TMS Advanced Configuration Guide.
Copying a menu skin
You can copy an existing menu skin and edit it to create a new menu skin.
To copy a menu skin:
1. Navigate to the Configure Menus page (Administration > User Interface > Menus).
2. Select the check box that corresponds to the menu skin that you want to copy, and then
click Duplicate.
3. On the Duplicate Menu page, in the Name box, type the QDPH for the new menu skin, and
then click Save.
Deleting a menu skin
To delete a menu skin:
1. Navigate to the Configure Menus page (Administration > User Interface > Menus).
2. Select the check boxes for the menu skins that you want to delete, and then click Delete.
284
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 11: Configuring User Interface Settings
Configuring Name Mappings
Introduction
An SP set of pre-configured name mappings is used to determine how ports, ASN names, and
ToS names are displayed in the Web UI. You can also configure name mappings for TCP and
UDP ports, ASNs, and Type of Service on the Configure Name Mappings page
(Administration > User Interface > Name/Number Mappings).
Name mapping formats
You must use the following specific formats for name mappings:
Name mapping formats
Name mapping type
Required format
TCP/UDP
SRUWQDPH WFS RSWLRQDO FRPPHQW
ASN
$61$0(
ToS
7261$0(
Configuring name mappings
To configure name mappings:
1. Navigate to the Configure Name Mappings page (Administration > User Interface >
Name/Number Mappings).
2. From the Name Mappings list, select the mappings type that you want to add.
The user-configured name mappings for the type that you selected and the correct format
for adding the name mappings are displayed.
3. Do one of the following:
l
Type your OLVW of mappings in the large text box.
l
Click Browse to upload a file containing a list of mappings in the Upload List box,
select the mappings file that you want to upload, and then click Send File.
4. Click Save.
Note: Name mappings that you configure on an appliance that has the user interface role are
not synchronized with other appliances that have the user interface role.
Proprietary and Confidential Information of Arbor Networks Inc.
285
SP and TMS User Guide, Version 8.0
286
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12:
Configuring User Accounts, Account
Groups, and Login Options
Introduction
This section describes user accounts, account groups, and capability groups and how to use
them to allow users to access specific managed objects’ traffic data and to use specific
features. It also describes the login options that you can configure and how to edit your
account.
User access
Administrators can perform all of the actions described in this section, except they cannot
delete their own user accounts. Non-administrative users can update their own user accounts,
but they cannot view or edit other user accounts or account groups.
In this section
This section contains the following topics:
About the User Accounts Page
288
Configuring User Accounts
291
Editing Your User Account
295
About the User Account Login Records Page
297
About Account Groups
299
Configuring Account Groups
302
About Capability Groups
306
Configuring Capability Groups
307
Configuring Login Options
310
Configuring Accounting
312
Configuring Authentication
314
SP and TMS User Guide, Version 8.0
287
SP and TMS User Guide, Version 8.0
About the User Accounts Page
Introduction
You can use the User Accounts page to create, edit, delete, and view detailed user account
information. You can view all of the users on your network and configure user accounts on the
User Accounts page. This page displays non-local users only if their user account has local
data like real name, email, or timezone.
You can access the User Accounts page at Administration > Accounts/Accounting >
User Accounts.
For information about configuring user accounts, see “Configuring User Accounts” on
page 291.
For information about the last login attempt of users, see “About the User Account Login
Records Page” on page 297.
User access
By default, the User Accounts page can only be accessed by administrators.
User Accounts page
The User Accounts page displays the following information:
User Accounts page details
Column
Description
Select this check box for the user accounts that you want to delete,
disable, or enable. You can also select this check box for a user
account, and then click View As to view the SP Web UI with that
user's account settings.
288
Username
A user name as a link to the Edit Existing Account page.
Real Name
A user’s full name.
Account Group
The account group to which a user belongs.
Capability Level
A user’s capability level, which is either an administrator or a user.
Email
A user’s email address.
Device
The SP appliance with which a user is associated. The SP appliance is
either a specific appliance name or global, which associates a user
with all appliances.
For more information about associating a user with appliances, see
“About user-appliance association” on page 291.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
User Accounts page details (Continued)
Column
Description
UI Menu
The UI menu that is assigned to a user. The UI menu determines what
menu choices are available to a user. You configure menus on the
Configure Menus page (Administration > User Interface >
Menus).
For information on configuring menus, see “Configuring Menus” on
page 283.
Status
Disabled appears in this column for a user account that is disabled;
otherwise, this column is blank.
About searching on the User Accounts page
You can use the Search box to search for user accounts. The following are some guidelines for
using the Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
See “Acceptable search keywords and values for user accounts” below.
Acceptable search keywords and values for user accounts
The following table lists the columns on the User Accounts page and the keywords and values
that you can use to search on that column in the Search box:
Search keywords for columns
Column to
search on
Acceptable keywords and
values
Name
n
name:XVHU QDPH
n
name:account_group1
Real Name
n
realname:XVHU UHDO QDPH
n
realname:John Doe
Account Group
n
group_name:DFFRXQW JURXS
QDPH
account_group:DFFRXQW
JURXS QDPH
account_group_
name:DFFRXQW JURXS QDPH
n
group_name:system_admin
account_group:system_user
account_group_
name:system_operator
n
n
Proprietary and Confidential Information of Arbor Networks Inc.
Examples
n
n
289
SP and TMS User Guide, Version 8.0
Search keywords for columns (Continued)
Column to
search on
Acceptable keywords and
values
Capability Level
n
capability_level:
{administrator | user}
n
capability_level:user
Email
n
email:HPDLO DGGUHVV
n
email:user@example.com
Device
n
device_name:DSSOLDQFH
QDPH
n
device_name:global
UI Menu
n
ui_menu:8, PHQX
n
ui_menu:default
Status
n
disabled:disabled
status:disabled
n
disabled:disabled
status:disabled
n
290
Examples
n
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
Configuring User Accounts
Introduction
You can configure user accounts on the User Accounts page.
You can access the User Accounts page at Administration > Accounts/Accounting >
User Accounts.
See “About the User Accounts Page” on page 288.
User access for editing accounts
Only administrators can access the User Accounts page. Non-administrative users can access
their own user account settings on the Edit My Account page (Administration >
Accounts/Accounting > My Account).
For more information about the different levels of system access, see “About Account Groups”
on page 299.
Choosing a secure and acceptable password
Passwords must meet the following criteria:
Must contain at least 7 characters
n
Note: An administrator can set a higher minimum password length.
n
Must not exceed the maximum length if an administrator has configured a maximum length
n
Can include special characters, spaces, and quotation marks
n
Cannot be all digits
n
Cannot be all uppercase letters
n
Cannot be all lowercase letters
n
Cannot be only letters followed by only digits (for example, abcd123)
n
Cannot be only digits followed by only letters (for example, 123abcd)
Administrators can configure the minimum and maximum password length and enforce more
stringent password requirements for user accounts.
See “Configuring Advanced Password Requirements” in the SP and TMS Advanced
Configuration Guide.
About user-appliance association
When you configure user accounts, you can choose to associate a user with a specific SP
appliance (local) or with all of the SP appliances (global) in your deployment. This assignment
allows the user to access specific SP appliances.
If you assign a user name to a specific SP appliance and assign another user with the same
user name to all SP appliances, then the appliance-specific, local user has access to that SP
appliance and the global user does not. Global users only have access to an SP appliance
when there is no matching local user name for that SP appliance.
You cannot associate users with TMS appliances.
Proprietary and Confidential Information of Arbor Networks Inc.
291
SP and TMS User Guide, Version 8.0
Adding and editing user accounts
To add or edit a user account:
1. Navigate to the User Accounts page (Administration > Accounts/Accounting >
User Accounts).
2. Choose one of the following steps:
l
To add a user, click Add Account.
l
To edit a user, click the user name link on the User Accounts page.
3. On the Account Configuration tab, configure the user account settings.
See “User account configuration settings” below.
4. Click Save, and then commit your changes.
Important: After you add new users, advise them to change their passwords to maintain
security. For information on how users change their passwords, see “Editing Your User
Account” on page 295.
User account configuration settings
Use the following table to configure the settings on the Account Configuration tab:
Account Configuration tab settings
Setting
Description
Username box
Type a XQLTXH QDPH.
The user name must meet the following criteria:
n
n
n
n
Must contain from 1 to 31 characters, digits, or any combination
of both
Can begin with and include uppercase and lowercase letters,
digits, a period (.), an underscore (_), and an @
Cannot begin with a hyphen but can include a hyphen
Cannot contain spaces
You cannot change the user name in an existing account.
292
Real Name box
Type the user’s IXOO QDPH.
Email Address box
Type the user’s HPDLO DGGUHVV as a fully qualified domain name.
For example, user@example.com.
Old Password for
<user> box
(Existing account only) Type the FXUUHQW SDVVZRUG for this user.
New Password box
Confirm New
Password box
Type a QHZ SDVVZRUG, and then re-type it to confirm it. For
information about password criteria, see “Choosing a secure and
acceptable password” on the previous page.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
Account Configuration tab settings (Continued)
Setting
Description
Appliance list
Select one of the following appliance assignment options:
n
n
To assign the user to all SP appliances in your deployment, select
Global.
To assign the user to a single SP appliance, select an appliance
name.
You cannot change the appliance in an existing account, and you
cannot associate a user with a TMS appliance. See “About userappliance association” on page 291.
Account Group list
Select the account group to assign to this user. To filter the list, type
any part of the account group name that does not include a space.
The account group determines the user’s level of system access.
See “About Account Groups” on page 299.
Capability Level list
Select the capability level to assign to this user. The capability level
is either user or administrator.
Timezone list
Select the time zone in which the appliance is located.
UI Menu list
Select the Web UI menu skin to be displayed for this user. The menu
skin you select determines what a user can see in the Web UI.
This list of menu skins includes the pre-configured menu skins and
any custom menu skins that you have configured. You can configure
custom menu skins on the Configure Menus page (Administration
> User Interface > Menus). For a description of the
pre-configured menu skins, see “About pre-configured menu skins”
on page 283.
Disabling user accounts
To disable a user account:
1. Navigate to the User Accounts page (Administration > Accounts/Accounting >
User Accounts).
2. Select the check boxes for the accounts that you want to disable, and then click Disable.
Deleting user accounts
To delete a user account:
1. Navigate to the User Accounts page (Administration > Accounts/Accounting >
User Accounts).
2. Select the check boxes for the users that you want to delete, and then click Delete.
You cannot delete your own user account.
Viewing the UI as a specific user
To view the UI as a specific user:
1. Navigate to the User Accounts page (Administration > Accounts/Accounting >
User Accounts).
Proprietary and Confidential Information of Arbor Networks Inc.
293
SP and TMS User Guide, Version 8.0
2. Select the check box of the user account for which you want to view the UI, and then click
View As.
3. To return to the UI of your own account, in the menu bar, click Exit Scoped View.
Exit Scoped View only appears if the user is a scoped user. If the user is not a scoped
user, you must log out and log in using your account.
294
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
Editing Your User Account
Introduction
The Edit My Account page allows you to edit your user account settings.
A local user and TACACS+ user can edit the following settings:
Password
n
n
Real name
n
Email address
n
Timezone
n
UI menu (administrators only)
Note: A local administrator can edit all of the settings on this page except the Appliance list.
Editing your user account
To edit your user account:
1. Navigate to the Edit My Account page (Administration > Accounts/Accounting >
My Account).
2. On the Account Configuration tab, configure the user account settings.
See “Your user account configuration settings” below.
3. Click Save, and then commit your changes.
Your user account configuration settings
Use the following table to configure your user account configuration settings:
User account configuration settings
Setting
Description
Username box
Displays your user name. A local user cannot edit this setting.
Real Name box
Type your IXOO QDPH.
Email Address box
Type your HPDLO DGGUHVV as a fully qualified domain name. For
example, user@example.com.
Old Password for
<user> box
To change your password, type your ROG SDVVZRUG.
New Password box
Confirm New
Password box
Type a QHZ SDVVZRUG, and then re-type it to confirm it.
For information about password criteria, see “Choosing a secure
and acceptable password” on page 291.
Appliance list
Displays the appliances to which you are assigned.
You can be assigned to a single appliance or to all appliances.
Account Group list
Displays the account group that is assigned to you.
The account group determines your level of system access.
See “About Account Groups” on page 299.
Proprietary and Confidential Information of Arbor Networks Inc.
295
SP and TMS User Guide, Version 8.0
User account configuration settings (Continued)
296
Setting
Description
Capability Level list
Displays the capability group that is assigned to you.
The capability group determines the features in SP that you can
access.
For more information about capability groups, see “Configuring
Capability Groups” on page 307.
Timezone list
Select your time zone.
UI Menu list
Displays the Web UI menu skin that is assigned to you. The menu
skin determines which UI menu items are displayed. Only
administrators can select UI menu skins.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
About the User Account Login Records Page
Introduction
The User Account Login Records page displays information about the last login attempt by
users. This list includes users that have been deleted. You can access the User Account Login
Records page at Administration > Accounts/Accounting > Login Records.
Hiding non-local user data
If you do not want non-local users’ data to appear on the User Account Login Records page of
an appliance’s Web UI, then you can hide it. For instructions, see “Hiding Non-Local User Data
on the User Account Login Records Page” in the SP and TMS Advanced Configuration
Guide.
User Account Login Records page
The User Account Login Records page displays the following information:
User Account Login Records page details
Column
Description
Username
The user name of an account.
Last Login
Location
The IP address from which a user last attempted to connect to SP.
Last Login Time
The time at which a user last attempted to connect to SP.
Login Failures
The number of times that a user last tried to log in but was unsuccessful.
The number reverts to zero when a user successfully logs in.
About searching on the User Account Login Records page
You can use the Search box to search on the User Account Login Records page. The
following are some guidelines for using the Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
See “Acceptable search keywords and values for user account login records” on the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
297
SP and TMS User Guide, Version 8.0
Acceptable search keywords and values for user account login records
The following table lists the columns on the User Account Login Records page and the
keywords and values that you can use to search on that column in the Search box:
Search keywords for columns
Column to search
on
Acceptable keywords and values
Name
n
n
Last Login Location
n
n
Login Failures
n
n
n
298
Examples
name:XVHU QDPH
username:XVHU QDPH
n
location:,3 DGGUHVV
login_location:,3 DGGUHVV
n
count_last:QXPEHU RI
IDLOXUHV
login_failures:QXPEHU RI
IDLOXUHV
num_fails:QXPEHU RI
IDLOXUHV
n
n
n
n
n
name:admin
username:user1
location:10.0.0.1
login_location:10.0.0.2
count_last:1
login_failures:2
num_fails:3
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
About Account Groups
Introduction
Account groups are user groups that allow users to access specific managed objects’ traffic
data and to use specific SP features. Each account group is associated with a set of
capabilities that are inherited by the users assigned to that group. You can use pre-configured
account groups or create new account groups.
You can view all of the configured account groups and create new account groups on the
Configure Account Groups page (Administration > Accounts/Accounting > Account
Groups).
See “Configuring Account Groups” on page 302.
Note: Non-administrative users cannot edit a user’s account group.
About the Configure Account Groups page
The Configure Account Groups page (Administration > Accounts/Accounting >
Account Groups) contains the following information:
Configure Account Groups page details
Column
Description
Selection check
box
Select this to delete an account group.
Name
The name of an account group.
Appliance
The appliance with which an account group is associated. The
appliance can be a specific appliance name or global, which
associates users with all appliances.
Description
A user-defined description of an account group.
Administrator
Capability Group
A capability group assigned to administrators in an account group.
User Capability
Group
A capability group assigned to users in an account group.
Managed Services?
Indicates whether an account group is a managed services account
group.
Managed Objects
The managed objects that are assigned to an account group.
Copy?
Click Copy to copy the settings of the current group and create a
new account group that has the same settings.
For more information about capability groups, see “Configuring Capability Groups” on
page 307.
Proprietary and Confidential Information of Arbor Networks Inc.
299
SP and TMS User Guide, Version 8.0
About searching on the Configure Account Groups page
You can use the Search box to search for account groups on the Configure Account Groups
page. The following are some guidelines for using the Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
See “Acceptable search keywords and values for account groups” below.
Acceptable search keywords and values for account groups
The following table lists the columns on the Configure Account Groups page and the keywords
and values that you can use to search on that column in the Search box:
Search keywords for columns
Column to search
on
Acceptable keywords and values
Name
n
name:DFFRXQW JURXS QDPH
n
name:system_user
Appliance
n
device_name:DSSOLDQFH
n
device_name:global
Description
n
desc:DFFRXQW JURXS
GHVFULSWLRQ
description:DFFRXQW JURXS
GHVFULSWLRQ
n
desc:default user
group
description:default
admin
n
n
Administrator
Capability Group
n
admin_capability_group_
name:DGPLQLVWUDWRU
FDSDELOLW\ JURXS QDPH
n
admin_capability_
group_name:admin1
User Capability
Group
n
user_capability_group:XVHU
FDSDELOLW\ JURXS QDPH
n
user_capability_
group:user1
Managed Services?
n
managed_services:{yes | no}
n
managed_services:yes
Managed Objects
n
managed_objects:PDQDJHG
REMHFW QDPH
managed_objects_
names:PDQDJHG REMHFW QDPH
n
managed_
objects:customer1
managed_objects_
names:customer2
n
300
Examples
n
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
Pre-configured account groups
SP contains the following pre-configured account groups:
Pre-configured account groups
Name
Description
system_admin
This group is for administrators of the system who have full read and
write privileges to all pages.
system_none
This group has no privileges. A user in this group is effectively disabled.
system_operator
Users in this group can configure most settings in the Web UI.
However, they cannot edit account information in the CLI or Web UI or
configure basic system-level configuration in the CLI (such as ArbOS
network interfaces, IP access rules, ARP configuration, routing
configuration, and system time).
system_ms_admin
This group is reserved for managed services administrators. Nonadministrative users should not be assigned to this group. The
administrators in this group can edit their own accounts and the
accounts of others who share the same account group.
system_ms_user
This group is reserved for managed services users. Non-administrative
users should not be assigned to this group. The users in this group can
edit their own accounts.
system_user
This group has basic privileges and read privileges for all reports. The
users in this group cannot make configuration changes, except to their
own account information.
Note: To provide backward compatibility for upgraded accounts with TACACS+ and RADIUS
user configurations, SP 8.0 includes “arbor_<role>” account groups from previous SP
versions. You can delete these “arbor_<role>” groups from SP after you transition any users in
these groups to the new “system_<role>” groups. The “arbor_<role>” groups are copies of
the “system_<role>” groups.
Deleting custom account groups
To delete a custom account group, follow these steps:
Navigate to the Configure Account Groups page (Administration >
Accounts/Accounting >Account Groups).
n
n
Select the check boxes for the groups that you want to delete, and then click Delete.
Proprietary and Confidential Information of Arbor Networks Inc.
301
SP and TMS User Guide, Version 8.0
Configuring Account Groups
Introduction
You manage account groups on the Configure Account Groups page (Administration >
Accounts/Accounting > Account Groups). You can either create a new account group or
copy an existing account group. You cannot edit a pre-configured account group, but you can
copy it, and then edit the copy. Before you create a new account group, you must first create a
capability group to associate with the account group.
Note: Non-administrative users cannot edit a user’s account group.
See “Configuring Capability Groups” on page 307 and “About Account Groups” on page 299.
Adding and editing account groups
To add or edit an account group, follow these steps:
1. Navigate to the Configure Account Groups page (Administration >
Accounts/Accounting >Account Groups).
2. Choose one of the following steps:
l
To add a new group, click Add Account Group.
l
To edit an existing group, click a group name link.
You can edit only the custom account groups.
3. On the Add Account Group page or Edit Account Group page, on the Description tab,
configure the following settings:
Setting
Description
Name box
Type a QDPH for the account group.
The account group name must meet the following criteria:
n
n
n
n
Description box
302
Must contain from 1 to 31 characters, digits, or any
combination of both
Can begin with and include uppercase and lowercase
letters, digits, a period (.), an underscore (_), and an @
Cannot begin with a hyphen but can include a hyphen
Cannot contain spaces
Type a GHVFULSWLRQ of the group.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
4. On the Settings tab, configure the following settings:
Setting
Description
Appliance list
Select one of the following options:
n
To assign the group to all of the SP appliances in your
deployment, select Global.
n
To assign the group to a single SP appliance, select an
appliance name.
You cannot associate a group with a TMS appliance.
Administrator list
Select the capability group to assign to this account
group’s administrators.
User list
Select the capability group to assign to this account
group’s users.
Default Level list
Select the default capability level to assign to this group.
Timezone list
Select the time zone in which the appliance or appliances
are located.
UI Menu list
Select the Web UI menu skin to use for the group’s users.
This list of menu skins includes the pre-configured menu
skins and any custom menu skins that you have configured.
You can configure custom menu skins on the Configure
Menus page (Administration > User Interface >
Menus). For a description of the pre-configured menu
skins, see “About pre-configured menu skins” on page 283.
5. (Optional) On the Managed Objects tab, configure the following settings:
Setting
Description
Select Managed
Objects button
Click this button to select the managed objects to be
associated with this account group. The users in this account
group will be restricted to the managed objects that you select.
When you click this button, the Select one or more Managed
Objects window appears. In this window, select the check
boxes for the managed objects to assign to the account group,
and then click OK.
Managed Services
Group check box
Select this check box if you want this account group to be a
managed services group. This check box is disabled until you
select managed objects.
If you indicate that an account group is for managed services
users, then SP also limits those users’ access to routing data
and other information about the network’s routers and
interfaces.
See “About managed services account groups” on page 925.
Proprietary and Confidential Information of Arbor Networks Inc.
303
SP and TMS User Guide, Version 8.0
6. On the Mitigations tab, configure the following settings:
Setting
Description
Default Mitigation
Action list
Select the default mitigation type to use to mitigate attack
traffic for this account group.
Allow TMS
Mitigations check
box
Select this check box to allow managed services users to
initiate TMS mitigations.
Allow Blackhole
Mitigations check
box
Select this check box to allow managed services users to
initiate blackhole mitigations.
(Optional) In the Maximum concurrent box, type the
maximum QXPEHU of ongoing mitigations that managed
services users can run concurrently.
(Optional) In the Maximum concurrent box, type the
maximum QXPEHU of blackhole mitigations that managed
services users can run concurrently.
7. On the Alerting tab, set the maximum age of alert data to save for this account group for
each of the following alert importance levels:
l
High
l
Medium
l
Low
These settings apply only to alerts specifically associated with configured managed
objects for this account group.
Note: Any values set here take effect only if their duration is shorter than system-wide
settings. See “Deleting Alerts” on page 411.
8. Click Save.
Copying account groups
You can copy an account group and then edit it to make a new group. You cannot edit a preconfigured account group, but you can copy it, and then edit the copy.
To copy an account group, follow these steps:
1. Navigate to the Configure Account Groups page (Administration >
Accounts/Accounting > Account Groups).
2. Click the Copy link for the group that you want to copy.
3. On the Copy Account Groups page, configure the following settings:
Setting
Description
Copy to box
Type the QDPH of the new group.
Appliance list
Select the appliance to which this account group belongs.
4. Click Save.
5. Follow the procedure for adding and editing account groups.
See “Adding and editing account groups” on page 302.
304
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
Viewing users assigned to an account group
To view the users who are assigned to an account group, follow these steps:
1. Navigate to the Configure Account Groups page (Administration >
Accounts/Accounting >Account Groups).
2. Click the name link for the custom account group whose users you want to view.
3. Click the Users tab.
Proprietary and Confidential Information of Arbor Networks Inc.
305
SP and TMS User Guide, Version 8.0
About Capability Groups
Introduction
Capability groups allow you to control users’ access to SP features. You must assign a
capability group to any account group that you create. All users in the account group then
inherit the capabilities assigned to the account group. You can configure capability groups on
the Configure Capability Groups page (Administration > Accounts/Accounting >
Capability Groups).
About searching on the Configure Capability Groups page
You can use the Search box to search on the Configure Capability Groups page. The
following are some guidelines for using the Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
See “Acceptable search keywords and values for capability groups” below.
Acceptable search keywords and values for capability groups
The following table lists the columns on the Configure Capability Groups page and the
keywords and values that you can use to search on that column in the Search box:
Search keywords for columns
Column to search
on
Acceptable keywords and values
Name
n
name:FDSDELOLW\ JURXS QDPH
n
name:administrator
Description
n
description:FDSDELOLW\ JURXS
GHVFULSWLRQ
n
description:network
operator
Examples
Deleting custom capability groups
To delete a custom capability group:
1. Navigate to the Configure Capability Groups page (Administration >
Accounts/Accounting > Capability Groups).
2. Select the check boxes for the capability groups that you want to delete, and then click
Delete.
306
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
Configuring Capability Groups
Introduction
You can configure capability groups on the Configure Capability Groups page
(Administration > Accounts/Accounting > Capability Groups).
Configuring capability groups
To configure a capability group:
1. Navigate to the Configure Capability Groups page (Administration >
Accounts/Accounting > Capability Groups).
2. Choose one of the following steps:
l
To add a group, click Add Capability Group.
l
To edit a group, click the capability group’s name link.
3. On the Add Capability Group page or Edit Capability Group page, on the Description
tab, configure the following settings:
Setting
Description
Name box
Type the QDPH of the capability group.
Description box
Type a GHVFULSWLRQ of the capability group.
4. On the Capabilities tab, select the check boxes for the capabilities that you want users
in this group to have.
See “Capabilities granted by login_cli and sp_admin” on the next page and “Custom
reports capabilities” on page 309
5. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
307
SP and TMS User Guide, Version 8.0
Capabilities granted by login_cli and sp_admin
Unlike other administrative capabilities, the login_cli and sp_admin capabilities encapsulate
other capabilities. The login_cli and sp_admin capabilities grant users the following child
capabilities:
Capabilities granted by login_cli and sp_admin
Administrative
capability
Child capabilities
login_cli
n
n
n
n
n
n
n
n
n
n
n
n
n
n
n
n
n
n
sp_admin
n
n
n
n
308
clock
ip_access
ip_arp
ip_int
ip_route
ip_snoop
ip_tee
reload
shutdown
srv_log
srv_ssh
srv_ssh_key
srv_telnet
sys
sys_att
sys_cdrom
sys_disk
sys_file
conf_show
conf_write
srv_dns
srv_ntp
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
Custom reports capabilities
The following table lists the required capability groups that a user needs to view the different
types of custom reports:
Capabilities for viewing custom reports
Custom Report
Type
Required Capability Group
Wizard reports
sp_reports_view
Classic XML
n
n
Classic DoS
sp_traffic
sp_managed_object_view (includes all managed object-based
reports except Internal and External Customer Top Talker reports
and Internal and External Profile Top Talker reports)
sp_alerts
Note: Any user with the appropriate capability can view any custom report that is associated
with the capability, regardless of the report’s content.
Proprietary and Confidential Information of Arbor Networks Inc.
309
SP and TMS User Guide, Version 8.0
Configuring Login Options
Introduction
You can configure SP to disable a local user account automatically after a certain number of
repeated login failures. You can also set the maximum number of concurrent logins that are
allowed for a given user on the same appliance. You configure login options on the Configure
Accounts Options page (Administration > Accounts/Accounting > Options).
Note: You cannot disable TACACS+ or RADIUS accounts.
Configuring login failures
To configure the number of login failures for local accounts:
1. Navigate to the Configure Accounts Options page (Administration >
Accounts/Accounting > Options).
2. Choose one of the following steps:
l
Type the PD[LPXP QXPEHU of incorrect logins that SP will permit local users to attempt
before SP disables the account in the Max Login Failures (Local Accounts) box.
For example, if you want SP to disable user accounts on the fourth attempt, type 3 in
the Max Login Failures (Local Accounts) box.
l
Type XQOLPLWHG in the Max Login Failures (Local Accounts) box to allow any
number of login attempts.
Note: By default, SP allows an unlimited number of login attempts.
3. Click Save.
4. On each of the appliances that have the user interface role, log in to its CLI and issue the
FRQILJ ZULWH command.
See "Using CLI Commands" in the SP and TMS Advanced Configuration Guide.
Note: Administrators can re-enable user accounts on the User Accounts page
(Administration > Accounts/Accounting > User Accounts).
About maximum concurrent logins
The maximum concurrent logins setting determines how many times a user can log in to an
appliance concurrently with a given user account. This setting applies to the leader or nonleader appliance on which it is set. It does not apply system-wide. This setting applies to all
users.
If a user tries to log in to an appliance that has the user interface role when they have exceeded
the maximum number of concurrent logins, SP displays an error message instructing them to
terminate an existing session to continue.
Configuring concurrent logins
To configure the maximum number of concurrent logins for a user:
1. Navigate to the Configure Accounts Options page (Administration >
Accounts/Accounting > Options).
2. In the Max Concurrent Logins (Per User) box, choose one of the following steps:
l
Type the PD[LPXP QXPEHU of times that a user can log in to the same appliance
concurrently.
310
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
l
Type unlimited to allow a user to log in to the same appliance an unlimited number of
times concurrently. This value is the default.
3. Click Save.
4. On each of the appliances that have the user interface role, log in to its CLI and issue the
FRQILJ ZULWH command.
See "Using CLI Commands" in the SP and TMS Advanced Configuration Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
311
SP and TMS User Guide, Version 8.0
Configuring Accounting
Introduction
You can configure SP to log the following levels of user-accounting records on the Configure
Accounting page (Administration > Accounts/Accounting > TACACS+ / RADIUS
Accounting):
n logins and logouts
n
configuration changes
n
all commands
For information about authenticating users, see “Configuring Authentication” on page 314.
About methods of logging accounting
You can configure SP to log accounting records using the following methods:
the local syslog
n
n
TACACS+ servers
n
RADIUS servers
Each of these methods is configured separately, and multiple methods can run concurrently.
Configuring local syslog accounting settings
To configure SP to log accounting records to the local syslog:
1. Navigate to the Configure Accounting page (Administration >
Accounts/Accounting > TACACS+ / RADIUS Accounting).
2. On the Local tab, from the Accounting Level list, select the accounting setting and then
click Save.
Configuring RADIUS or TACACS+ accounting settings
To configure SP to log accounting records to a RADIUS and/or TACACS+ server:
1. Navigate to the Configure Accounting page (Administration >
Accounts/Accounting > TACACS+ / RADIUS Accounting).
2. Click the RADIUS or TACACS+ tab, depending on the server that you choose.
3. In the Primary Server IP box, type the ,3 DGGUHVV of the primary server.
4. In the Primary Server Port box, type the SRUW QXPEHU.
Note: For a RADIUS server, this must be a UDP port. For a TACACS+ server, this must be
a TCP port.
5. In the Primary Server Shared Secret box, type a VKDUHG VHFUHW to allow
communication with the primary server.
6. In the Confirm Primary Server Secret box, retype the VKDUHG VHFUHW.
7. In the Backup Server IP box, type the ,3 DGGUHVV of the backup server, if applicable.
8. In the Backup Server Port box, type the SRUW QXPEHU to connect to the backup
server, if applicable.
Note: For a RADIUS server, this must be a UDP port. For a TACACS+ server, this must be
a TCP port.
9. In the Backup Server Shared Secret box, type a VKDUHG VHFUHW to allow
communication with the backup server.
312
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
10. In the Confirm Backup Server Secret box, retype the VKDUHG VHFUHW.
11. From the Accounting Level list, select the accounting setting, and then click Save.
Note: The options that are available depend on the server that you choose.
Proprietary and Confidential Information of Arbor Networks Inc.
313
SP and TMS User Guide, Version 8.0
Configuring Authentication
Introduction
You can configure SP to integrate with your existing TACACS+ and RADIUS servers to
authenticate users on the Configure Authentication page (Administration >
Accounts/Accounting > TACACS+ / RADIUS Authentication).
For information about logging accounting records, see “Configuring Accounting” on page 312.
About authentication methods
You can set more than one method to authenticate users. If you do not set a method, then the
system defaults to local authentication. If you specify more than one method, then SP attempts
to use each method in the order in which you configured them.
About exclusive login
If you enable exclusive login, SP tries only the first working method for authentication. If the
user cannot authenticate to it, then the user login is denied and SP does not try any other
method on the list. If this feature is not enabled, then a user login attempt that fails one
authentication method will be submitted to the next method on the list. The login attempt will be
denied only if the user is unable to authenticate using any listed method.
Setting the authentication methods and exclusive login
To set the authentication methods and exclusive login:
1. Navigate to the Configure Authentication page (Administration >
Accounts/Accounting > TACACS+ / RADIUS Authentication).
2. On the Method tab, in the Method box, type the PHWKRGV RI DXWKHQWLFDWLRQ that
you want SP to use.
If you set more than one authentication method, type the methods in the order in which you
want SP to use them and separate them by commas.
3. Select the Enabled check box if you want to enable exclusive login, and then click Save.
If you enable exclusive login and the first authentication method does not have a user
configured with administrator privileges, then you will no longer be able to log in as an
administrator. You also might not be able to properly manage the SP configuration.
About TACACS+ password expiration
SP notifies TACACS+ users before their passwords expire. SP displays a reminder message in
the Web UI that is similar to the following:
Your password will expire in 2 more logins.
After a user’s password expires, that user cannot log in to SP. When a user sees the reminder
message, the user must change his or her password. SP does not differentiate between an
expired password and an incorrect password.
Configuring authentication using RADIUS and TACACS+
To configure authentication using RADIUS and/or TACACS+:
1. Navigate to the Configure Authentication page (Administration >
Accounts/Accounting > TACACS+ / RADIUS Authentication).
314
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 12: Configuring User Accounts, Account Groups, and Login Options
2. Click the RADIUS or TACACS+ tab, depending on the server that you choose.
3. In the Primary Server IP box, type the ,3 DGGUHVV of the primary server.
4. In the Primary Server Port box, type the SRUW QXPEHU to connect to the primary server.
5. In the Primary Server Shared Secret box, type a VKDUHG VHFUHW to allow
communication with the primary server.
6. In the Confirm Primary Server Secret box, retype the VKDUHG VHFUHW.
7. In the Backup Server IP box, type the ,3 DGGUHVV of the backup server.
8. In the Backup Server Port box, type the SRUW QXPEHU to connect to the backup server.
9. In the Backup Server Shared Secret box, type a VKDUHG VHFUHW to allow
communication with the backup server.
10. In the Confirm Backup Server Secret box, retype the VKDUHG VHFUHW.
11. In the Timeout box, type the QXPEHU RI VHFRQGV (between 1 and 60) after which you
want an authentication attempt to the server to fail.
12. Choose your next steps based on the server that you choose:
Authentication
server
Steps
RADIUS
a. In the Retries box, type the QXPEHU RI WLPHV that you
want an authentication attempt to the RADIUS server to be
repeated before trying the next authentication method.
b. If desired, in the NAS Identifier box, type an $6&,, VWULQJ
of up to 253 characters for a Network Access Server (NAS)
identifier, and then click Save.
TACACS+
Select the Password Expiry Notification check box to allow
SP to send warnings to users when their passwords are about to
expire, and then click Save.
Note: For authentication to work, you must set RADIUS attributes and TACACS+ services on
the RADIUS and TACACS+ servers.
See “About the required RADIUS server attribute” below and “About the required TACACS+
server service” on the next page.
About the required RADIUS server attribute
To specify the account group to which a RADIUS user is assigned upon authentication by SP,
you need to set the $UERU3ULYLOHJH/HYHO attribute on the RADIUS server. You also need
to add two lines to the RADIUS dictionary file so that the RADIUS server can interpret the
$UERU3ULYLOHJH/HYHO attribute.
You set the attribute with the value of the account group on the SP appliance that the user
connects to. You can also add a /(9(/ suffix to the account group name to specify the
capability level of the account group. If you do not specify an account group, the user is
assigned to the default account group for externally authenticated users.
Examples
$UERU3ULYLOHJH/HYHO
V\VWHPBDGPLQ
$UERU3ULYLOHJH/HYHO
$FFRXQW*URXSDGPLQ
Proprietary and Confidential Information of Arbor Networks Inc.
315
SP and TMS User Guide, Version 8.0
$UERU3ULYLOHJH/HYHO
$FFRXQW*URXSXVHU
The following are the two lines that you need to add to the RADIUS dictionary file so that the
RADIUS server can interpret the $UERU3ULYLOHJH/HYHO attribute:
9(1'25
$UERU
$775,%87(
$UERU3ULYLOHJH/HYHO
VWULQJ $UERU
Note: The Arbor-Privilege-Level is the only attribute that SP uses from the RADIUS server
response.
See “Configuring Account Groups” on page 302 and “Changing the Default
RADIUS/TACACS+ User Group” in the SP and TMS Advanced Configuration Guide.
About the required TACACS+ server service
To specify which account group a TACACS+ user is assigned to when they authenticate
through SP, you need to set an arbor service on the TACACS+ server. You set the service with
an DUERUBJURXS attribute that has the value of the account group on the SP box that the user
connects to. You can also add a /(9(/ suffix to the account group name to specify the
capability level of the account group. If you do not specify an account group, the user is
assigned to the default account group for externally authenticated users.
Examples
VHUYLFH
DUERU ^
DUERUBJURXS
V\VWHPBDGPLQ
`
VHUYLFH
DUERU ^
DUERUBJURXS
$FFRXQW*URXSDGPLQ
`
VHUYLFH
DUERU ^
DUERUBJURXS $FFRXQW*URXSXVHU
`
See “Configuring Account Groups” on page 302 and “Changing the Default
RADIUS/TACACS+ User Group” in the SP and TMS Advanced Configuration Guide.
Changing TACACS+ passwords
TACACS+ users can change their passwords on the My Account page.
See “Editing Your User Account” on page 295.
316
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 13:
Configuring ATLAS Services
Introduction
This section describes the ATLAS® services that you can use to monitor Internet threats and
trends, to detect and block attack traffic, to see how your network is viewed from a global
perspective, and to exchange anomaly information.
User access
Administrators can perform all actions described in this section. Non-administrative users can
view the configurations but cannot make changes.
In this section
This section contains the following topics:
Active Threat Level Analysis System (ATLAS)
318
Configuring ATLAS Intelligence Feed (AIF)
319
About ATLAS Intelligence Feed (AIF) DDoS Regular Expressions (Used by TMS)
324
Enabling and Disabling BGP Routeview Reporting
325
ATLAS Visibility
326
SP and TMS User Guide, Version 8.0
317
SP and TMS User Guide, Version 8.0
Active Threat Level Analysis System (ATLAS)
Introduction
Arbor’s Active Threat Level Analysis System (ATLAS®) is a threat analysis network that
analyzes data from darknets and the Internet’s core backbone. Darknets are IP address blocks
allocated by Regional Internet Registries (RIRs) and globally routed by service providers but not
yet assigned to internal or customer systems. ATLAS correlates this intelligence with additional
datasets to determine a given host’s current threat and malicious activity level on the Internet.
ATLAS provides this information to help Arbor users identify new attacks.
ATLAS components
The following are the different components of ATLAS that you can access with SP:
ATLAS components
Component
Description
ATLAS
Intelligence Feed
(AIF)
AIF has the following two feeds that SP can automatically download:
n
n
AIF standard feed for SP
The AIF standard feed provides timely, accurate information on
new, changed, and expired threats. This download contains FCAP
signatures that are displayed on the AIF tab of the ATLAS page
(Reports > ATLAS 2.0 > Summary). See “About the AIF Tab
on the ATLAS Page” on page 816.
You can use these FCAP signatures when you configure the match
settings for fingerprints. See “Configuring Fingerprints” on
page 248.
AIF DDoS regular expressions feed used by TMS
The AIF DDoS regular expressions feed provides real-time threat
information from ATLAS. These regular expressions can be used to
detect and block emerging botnet attacks and application-layer
attacks. See “About ATLAS Intelligence Feed (AIF) DDoS Regular
Expressions (Used by TMS)” on page 324 and “Configuring the
AIF and HTTP/URL Regular Expression Countermeasure” on
page 682.
See “Configuring ATLAS Intelligence Feed (AIF)” on the facing page.
318
Routeviews
Routeviews provides a global view of BGP routing information from
the perspective of other ISPs around the Internet. Routeviews allows
you to view the routing tables of other large providers to see how your
network is viewed from a global perspective. See “Enabling and
Disabling BGP Routeview Reporting” on page 325.
ATLAS Visibility
ATLAS Visibility allows you to share anonymized data with Arbor for
use by Arbor in its security initiatives. See “ATLAS Visibility” on
page 326.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 13: Configuring ATLAS Services
Configuring ATLAS Intelligence Feed (AIF)
Introduction
The ATLAS Intelligence Feed tab on the Configure ATLAS Services page
(Administration > ATLAS) allows you to configure settings for the following SP features:
n AIF standard feed
n
AIF DDoS regular expressions feed
n
HTTP proxy
During an update of the AIF standard feed or the AIF DDoS regular expressions feed, SP uses
HTTPS to download the latest data. The Arbor Security Engineering and Response Team
(ASERT) verifies every threat feed to ensure the quality of the updates.
For more information about ATLAS and AIF, see “Active Threat Level Analysis System
(ATLAS)” on the previous page and “About ATLAS Intelligence Feed (AIF) DDoS Regular
Expressions (Used by TMS)” on page 324.
Configuring the AIF Standard Feed for SP settings
The Arbor Security Engineering and Response Team (ASERT) gathers information about
current and emerging threats from a wide range of sources and incorporates it into a database
of threat profiles that it maintains on AIF servers. When the AIF standard feed is enabled, SP
automatically polls the AIF server for updates.
The AIF standard feed downloads FCAP signatures that appear on the AIF tab of the ATLAS
page (Reports > ATLAS 2.0 > Summary). For more information about FCAP signatures,
see “About the AIF Tab on the ATLAS Page” on page 816.
To configure the AIF Standard Feed for SP settings:
1. Navigate to the Configure ATLAS Services page (Administration > ATLAS).
2. On the ATLAS Intelligence Feed tab, in the AIF Standard Feed for SP section,
configure the following settings:
Setting
Description
Enable FCAP
Signatures
check box
Clear this check box to disable automatic updates of FCAP
signatures, or select this check box to enable automatic updates of
FCAP signatures.
This check box is selected by default.
Update Interval
(in hours) box.
Type the KRXUO\ LQWHUYDO at which you want SP to poll the AIF
server. The default setting is one hour.
Important: If you must modify the default setting, first contact
ATAC (Arbor Technical Assistance Center). See “Contacting the
Arbor Technical Assistance Center” on page 17.
3. Click Save, and then commit your changes.
Note: If you deploy your leader appliance behind a firewall that requires using an HTTP proxy,
then you must configure HTTP proxy settings in SP in order to receive the standard AIF feed.
See “Configuring HTTP proxy settings” on page 322.
Proprietary and Confidential Information of Arbor Networks Inc.
319
SP and TMS User Guide, Version 8.0
Configuring the AIF DDoS Regular Expressions Feed (used by TMS) settings
The AIF DDoS Regular Expressions Feed (used by TMS) settings allow you to enable or
disable the automatic feed of DDoS regular expressions from the AIF servers. You can also
update this feed manually.
Note: If you do not have DNS configured on the leader appliance, then you have to use the
CLI to set the AIF server address before you can configure the AIF DDoS Regular Expressions
(used by TMS) settings. See “Setting the AIF Server Address” in the SP and TMS Advanced
Configuration Guide.
To configure the AIF DDoS Regular Expressions Feed (used by TMS) settings:
1. Navigate to the Configure ATLAS Services page (Administration > ATLAS).
2. On the ATLAS Intelligence Feed tab, in the AIF DDoS Regular Expressions Feed
(used by TMS) section, configure the following settings:
Setting
Description
Update Now
button
Click this button to force SP to check the AIF servers for updates
to the DDoS regular expressions data.
If you have not uploaded a flexible license, then this button is
enabled only if a valid AIF license key has been typed in the
License Key boxes. If you have uploaded a flexible license, then
this button is enabled only if an AIF license with sufficient capacity
has been added for each TMS appliance in your deployment. See
“Uploading a Flexible License” on page 92 and “Flexible-licensed
capacity for AIF” on page 94.
Note: The status of the last update of the AIF DDoS regular
expressions is displayed above the settings. See “About the update
status of the AIF DDoS regular expressions” on the facing page.
Enable
Automated
Connection to
AIF check box
Select this check box to download AIF DDoS regular expressions
automatically, or clear this check box to disable the automatic
updates.
Update Interval
box
Type the KRXUO\ LQWHUYDO at which SP should check the AIF
server for updates to the DDoS regular expressions data. The
default interval is 1 hour.
Note: The status of the last update of the AIF DDoS regular
expressions is displayed above the settings. See “About the update
status of the AIF DDoS regular expressions” on the facing page.
Important: If you must modify the default setting, first contact
ATAC (Arbor Technical Assistance Center). See “Contacting the
Arbor Technical Assistance Center” on page 17.
320
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 13: Configuring ATLAS Services
Setting
Description
License Key
boxes
These boxes appear only if you have not uploaded a flexible
license. In the first box, type the product name. If you did not
receive a product name, type SP-TMS-AIF, which is this product’s
default name. In the second box, type the license key for AIF.
SP cannot communicate with or obtain updates from the AIF
servers until a valid AIF license key is applied. See “About
AIF licenses” on the next page.
AIF License
Status
If you have uploaded a flexible license, this setting appears and
displays one of the following AIF license status messages:
n
AIF is enabled.
The flexible license has AIF license capacity for all of your
TMS appliances.
n
AIF is disabled.
The flexible license does not have AIF license capacity for all of
your TMS appliances.
n
AIF is not enabled.
The flexible license does not include any AIF licenses. See
“Flexible-licensed capacity for AIF” on page 94.
When a flexible license has been uploaded, the AIF license status
also appears below the Deployment Status table on the
Deployment tab of the Deployment Status page (System >
Status > Deployment Status). See “About the Deployment
Status table on the Deployment tab” on page 337 and “About
AIF licenses” on the next page.
3. Click Save, and then commit your changes.
Note: If you deploy your leader appliance behind a firewall that requires using an HTTP proxy,
then you must configure HTTP proxy settings in SP in order to receive the AIF DDoS regular
expressions feed. See “Configuring HTTP proxy settings” on the next page.
About the update status of the AIF DDoS regular expressions
Information about the status of the last AIF update appears at the top of the AIF DDoS Regular
Expressions Feed (used by TMS) section. The status information also includes when the last
successful update occurred with the date and time. The status can be one of the following:
n Succeeded
The update was successful.
n
Failed
The update failed for some reason.
n
None
The AIF feed has not been updated or no new data was available when the AIF servers were
last queried.
With appliance-based licensing, a valid AIF license must be applied before SP can display any
status information. With Flexible Licensing, SP displays the status information when an AIF
license has been added that has license capacity for all of your TMS appliances. If AIF
Proprietary and Confidential Information of Arbor Networks Inc.
321
SP and TMS User Guide, Version 8.0
becomes disabled because of insufficient AIF license capacity, then the status information is
no longer updated and the last status information is displayed.
About AIF licenses
Before SP can download DDoS regular expressions from the AIF servers, your Arbor Networks
deployment must have the appropriate AIF licenses. If you have not uploaded a flexible license,
then you add the AIF license key on the ATLAS Intelligence Feed tab. If you have uploaded
a flexible license, then any AIF licenses that you have purchased are included with the flexible
license. See “Uploading a Flexible License” on page 92.
AIF licenses can have a 5G, 20G, 40G, or 100G capacity. To enable AIF, you must add an AIF
license for each TMS appliance, and the capacity of each AIF license must be equal to or
greater than the bandwidth of the TMS appliance. For example, if you have two 20G AIF
licenses, AIF would be enabled if you have two TMS appliances and each TMS appliance has
a bandwidth of 20G or less. However, AIF would not be enabled if any of the TMS appliances
has a bandwidth greater than 20G or if you have three or more TMS appliances.
If you have a flexible license, then the Time-Based Flexible Licenses table on the Deployment
Status page displays information about your AIF licenses. See “About the Time-Based Flexible
Licenses table on the Deployment tab” on page 340.
Configuring HTTP proxy settings
The HTTP proxy settings allow you to connect to the AIF servers through a proxy server.
To configure HTTP proxy settings:
1. Navigate to the Configure ATLAS Services page (Administration > ATLAS).
2. On the ATLAS Intelligence Feed tab, in the HTTP Proxy Settings section, configure
the following settings, click Save and and then commit your changes:
Setting
Description
Use
configured IP
address of
egress
interface as
source check
box
Select to use the IP address of the interface from which packets
leave as the source IP address. By default, the source IP address is
the configured IP address of the appliance.
Enable HTTP
Proxy check box
A good use case would be when the following are true:
n
n
An appliance’s configured IP address is from a non-routed private
space.
Access to external Arbor services is through a second interface
that has a publicly routed IP address.
(Optional) Select this check box to allow SP to connect to the AIF
server through a proxy server.
AIF uses the same proxy server settings that are configured on the
HTTP Proxy tab on the Configure Network Services page. The
settings are linked so that if a proxy server is defined on the HTTP
Proxy tab, the same proxy server information appears here. If you
change the proxy settings in one place, it affects the settings in the
other place. See “About HTTP proxy settings” on page 415.
322
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 13: Configuring ATLAS Services
Setting
Description
Proxy Server
box
Type the ,3 DGGUHVV of the proxy server.
Proxy Port box
(Optional) Type the SRUW QXPEHU of the Proxy Server box. If you
leave this box blank, then SP uses the default setting (port 1080).
Authentication
Method option
Select the authentication method that you want to use. If you select
Basic Authentication or Digest Authentication, then you must
also specify the Proxy Username and Proxy Password that are
required to access the proxy server.
Proprietary and Confidential Information of Arbor Networks Inc.
323
SP and TMS User Guide, Version 8.0
About ATLAS Intelligence Feed (AIF) DDoS Regular Expressions
(Used by TMS)
Introduction
ATLAS Intelligence Feed (AIF) allows an Arbor Networks deployment to provide automatic
protection against specific, known threats. AIF downloads real-time threat information from
Arbor's Active Threat Level Analysis System (ATLAS). TMS uses this information to detect and
block emerging botnet attacks and application-layer attacks.
Botnets change and update constantly to thwart detection. Arbor’s security team keeps up
with these changes, identifies new DDoS threats, and continually updates the feed with the
new threat data.
AIF updates occur in real time without requiring any software upgrades, system downtime, or
restarts.
How the AIF regular expressions detect threats
The AIF updates contain regular expressions that define malware families. You enable the use
of the AIF regular expressions to block traffic when you select the Enable AIF Malware Family
Blocking check box in the AIF and HTTP/URL Regular Expression countermeasure. You can
then set the enforcement level for the countermeasure at low, medium, or high.
For information about the AIF and HTTP/URL Regular Expression countermeasure, see
“Configuring the AIF and HTTP/URL Regular Expression Countermeasure” on page 682.
To detect the threats that the AIF regular expressions define, TMS performs packet-based,
regular expression matching. TMS inspects all of the HTTP traffic and applies each AIF regular
expression separately to each line of the HTTP headers. When a packet’s HTTP header
matches a regular expression, TMS records the traffic statistics for that packet.
If the regular expression’s enforcement level matches or is lower than the enforcement level set
in the countermeasure, TMS blocks the packet and temporarily blocks the source host. For
example, if the enforcement level of the countermeasure is medium, TMS blocks any packet
that matches the medium or low regular expressions.
Threats that the AIF regular expressions detect
The AIF regular expressions can detect the following types of threats:
Threats that AIF detects
324
Threat
Description
DDoS botnet attacks
A large number of compromised computers flood the victim server
with messages.
Examples: BlackEnergy, Darkness
Voluntary botnet
attacks
An attack by botnet computers whose users become part of the
botnet voluntarily.
Examples: LOIC, HOIC, and GOIC
Emerging DDoS
attacks detected by
ATLAS
Arbor’s security team constantly identifies new DDoS botnets and
includes their signatures in the AIF threat feed.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 13: Configuring ATLAS Services
Enabling and Disabling BGP Routeview Reporting
Introduction
You can disable and enable BGP routeviews reporting on the Configure ATLAS Services page
(Administration > ATLAS > Routeviews tab). Routeview reporting is enabled by default,
but you might want to disable it if SP does not have direct Internet access to the routeviews
server or if corporate policy restricts such outbound connections.
See “Active Threat Level Analysis System (ATLAS)” on page 318.
About BGP routeviews
When you enable BGP routeviews reporting, you can directly query BGP routing tables from
various large, global ISPs. Having a view into the routing tables of other large providers allows
you to see how your network is viewed from a global perspective. This allows you to investigate
routing issues that affect network traffic.
Note: You do not need to share your network’s routing information in order to see this
information. However, if you are interested in sharing your anonymized data with Arbor for use
in this feature, contact your Arbor Networks Support Engineer (SE).
Disabling BGP routeview reporting
To disable BGP routeview reporting:
1. Navigate to the Configure ATLAS Services page (Administration > ATLAS).
2. On the Routeviews tab, clear the Enable Arbor Remote BGP Routeviews check
box.
3. Click Save, and then commit your changes.
Important: You must log out and then log in again in order to deactivate routeviewsrelated menu items.
Enabling BGP routeview reporting
To enable BGP routeview reporting:
1. Navigate to the Configure ATLAS Services page (Administration > ATLAS).
2. On the Routeviews tab, select the Enable Arbor Remote BGP Routeviews check
box.
3. Type the ,3 DGGUHVVHV of the Arbor routeviews server in the Server Addresses box.
The following are the default server addresses:
l
204.181.64.13 (hostname: routetracker.arbor.net)
l
204.118.128.91 (hostname: routeview1.arbor.net)
Note: SP stores the default server addresses. If you enable BGP routeviews, there is no
need to retype the addresses. To restore the default server addresses, clear the text box,
and then click Save.
4. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
325
SP and TMS User Guide, Version 8.0
ATLAS Visibility
Introduction
SP gathers and stores a rich set of attack and traffic statistics in each network on which it is
deployed. SP allows you to share these statistics by participating in ATLAS Visibility. This
Arbor service protects your and others’ privacy, using algorithms that anonymize data. You can
then use the statistics that have been gathered from different worldwide deployments to help
you analyze global threats and traffic patterns.
You can enable or disable participation in ATLAS Visibility on the ATLAS Visibility tab of the
Configure ATLAS Services page (Administration > ATLAS > ATLAS Visibility tab).
Note: By default, this feature is disabled.
For more information about ATLAS, see “Active Threat Level Analysis System (ATLAS)” on
page 318.
Types of statistics that are shared
When you enable ATLAS Visibility, the following types of data are shared with Arbor and other
participating SP customers:
n A breakdown of the SP deployment size
n
A list of all medium and high severity DoS alerts during the last 24 hours
Note: SP replaces the first two octets of specific customer IP addresses, anonymizes the
destination of incoming attacks, and anonymizes the source of outgoing attacks.
n
Top TCP, UDP, protocol, and packet lengths
n
Overall network incoming and outgoing traffic
n
TMS mitigation statistics
To download and view the data most recently shared with Arbor, click Download.
Enabling participation in ATLAS Visibility
To enable participation in ATLAS Visibility:
1. Navigate to the Configure ATLAS Services page (Administration > ATLAS).
2. On the ATLAS Visibility tab, read the legal text below the Participate in ATLAS
Visibility check box, and then select the check box.
3. Select the option that best describes you from the Self Categorization Provider Type
list.
4. Select your geographic location from the Self Classification of Monitored Routers
Location list.
5. Type the DGGUHVV of the Arbor ATLAS Visibility server in the Server box.
The current address is atlas-visibility.arbor.net.
6. Click Save, and then commit your changes.
Important: You must log out of SP and then log in again to activate ATLAS
Visibility-related menu items.
7. Enable appropriate HTTPS (port 443) firewall rules between the leader and
atlas-visibility.arbor.net.
The leader must HTTPS POST to and HTTPS GET from atlas-visibility.arbor.net.
326
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 13: Configuring ATLAS Services
Disabling participation in ATLAS Visibility
To disable participation in ATLAS Visibility:
1. Navigate to the Configure ATLAS Services page (Administration > ATLAS).
2. On the ATLAS Visibility tab, clear the Participate in ATLAS Visibility check box.
3. Click Save, and then commit your changes.
Important: You must log out of SP and then log in again to deactivate ATLAS Visibilityrelated menu items.
Proprietary and Confidential Information of Arbor Networks Inc.
327
SP and TMS User Guide, Version 8.0
328
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14:
Monitoring the System
Introduction
This section describes how to view the state of your SP deployment.
User access
Only administrators can perform the actions described in this section.
In this section
This section contains the following topics:
About the My SP Dashboard
330
About Monitoring Cloud Signaling Status
332
Monitoring Your Deployment
335
About the Appliance Status Page
342
Viewing General Appliance Statistics
344
Viewing Web UI Statistics
354
Viewing Managed Services UI Statistics
356
Viewing TMS Appliance Statistics
357
Monitoring Your Arbor Networks Appliances
360
About the Summary Tab on the Appliance Monitoring Page
361
About the Per Appliance Metrics Tab on the Appliance Monitoring Page
366
About the Metric Comparison Tab on the Appliance Monitoring Page
374
Viewing ArborFlow Statistics
383
Monitoring Account Status
385
Monitoring Routers
386
Monitoring Interfaces
391
Monitoring Interface Configuration
393
Monitoring Interface Configuration History
394
Monitoring the Syslog
396
Viewing Flow Tuning Data
397
Monitoring SOAP Activity
398
Monitoring the UI Status
399
SP and TMS User Guide, Version 8.0
329
SP and TMS User Guide, Version 8.0
About the My SP Dashboard
Introduction
For users with the sp_traffic capability, the My SP dashboard (System > My SP) is the
default SP home page. You can customize your My SP dashboard to display network data that
is most relevant to you in your role. The My SP dashboard is customized on a per-user basis;
therefore, changes that you make to your dashboard are only displayed in your view of the SP
Web UI.
For information about capabilities, see “Configuring Capability Groups” on page 307.
Default content of your My SP dashboard
By default, your My SP dashboard contains the following gadgets:
My SP dashboard default gadgets
Gadget
Description
Introduction
A welcome gadget that describes how to use and customize the My
SP dashboard.
Top DoS Alerts
A summary of the top five ongoing DoS alerts on the network. Only
high or medium alerts are displayed.
Network Summary
A summary of your network’s traffic over the last 24 hours.
Top Customers
A summary of the top five customers consuming bandwidth on your
network.
Top Applications
A summary of the top five applications detected in your network’s
traffic.
Top Countries
A summary of the top five countries consuming bandwidth on your
network.
Note: IP Location data is only available when you deploy appliances
that have the traffic and routing analysis role or Flow Sensor
appliances with appliance-based licensing.
Adding content to your My SP dashboard
To add content to your My SP dashboard:
1. Navigate to the My SP page (System > My SP).
2. Click Add Content.
3. Hover your mouse pointer over the gadget that you want to add, and then click Add to
Report.
4. Repeat Step 3 for each gadget that you want to add, and then click Hide.
Customizing the appearance of your My SP gadgets
To customize the appearance of your My SP gadgets:
1. Navigate to the My SP page (System > My SP).
2. Click
330
(configure) next to the gadget.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
3. Choose your next steps based on what you want to customize, and then click Save:
Action
Steps
Edit the gadget’s
title
Type the new QDPH for the gadget in the Title box.
Edit the gadget’s
color
Select the color that you want from the Change color options.
Changing the layout of your My SP dashboard gadgets
To change the layout of your My SP dashboard gadgets:
1. Navigate to the My SPpage (System > My SP).
2. Do one or more of the following:
Action
Steps
Collapse or expand
a gadget
Click
Delete a gadget
Click
Rearrange a gadget
Click a gadget’s title bar and drag it to a different location on the
dashboard.
(collapse) or
(expand) next to the gadget.
These layout changes are not retained when you refresh the My
SP dashboard.
(delete), and then click Remove.
Viewing additional information about the data on your My SP dashboard
On your My SP dashboard, you can view additional information about some of the data using
the following methods:
n If the mouse pointer becomes a hand pointer when you hover it over the gadget, click the
gadget to open a predefined report that is related to the gadget.
n
Click a link to view more information (for example, an alert ID link).
Proprietary and Confidential Information of Arbor Networks Inc.
331
SP and TMS User Guide, Version 8.0
About Monitoring Cloud Signaling Status
Introduction
You can use the Cloud Signaling Status page (System > Status > Cloud Signaling
Status) to view managed object, ID, and status information for your Cloud Signaling clients.
For more information about Cloud Signaling, see “Mitigating Customer Attacks in the Cloud”
on page 604.
About the Cloud Signaling Status page
The Cloud Signaling Status page contains the following information:
Cloud Signaling Status page information
Component /
Column
332
Description
Manager list
Select an SP manager from this list to display information for its
Cloud Signaling clients. Select All to display information for all
configured Cloud Signaling clients.
By default, SP displays the manager on which you are currently
logged in.
Search box
You can use partial or complete text strings to search for specific
entries in the APS ID, Managed Object, and Managers columns.
See “Sorting and searching on the Cloud Signaling Status page”
on the facing page.
Results display (next to
the Search box)
Displays the total number of results and the time it took to run the
query.
You can view this number to determine if your SP deployment or
the leader appliance is close to the supported cloud signaling limit.
APS ID column
If you select an SP manager from the Manager list, this column
lists the APS IDs for that manager. If you select All from the
Manager list, this column lists all APS IDs.
Managed Object
column
Displays the associated managed object for each APS ID.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Cloud Signaling Status page information (Continued)
Component /
Column
Status column
(appears when you
select an individual SP
leader from the
Manager list)
Description
Contains the following alert information:
n
A
n
Alert number (Click the link to view alert details on the Cloud
Signaling Request Alert page.)
Alert start time and stop time (if applicable)
Duration of the alert (in parentheses)
Mitigation link (Click to view mitigation details on the TMS
Mitigation Status page.)
Mitigation start time and end time (if applicable)
Duration of the mitigation (in parentheses)
Example: Alert 38000 started Jun 17 00:21, ended 21:11,
Jun 20 (3d, 20:50) Mitigation started Jun 23 00:48, ended
03:34 (2:47)
If no heartbeat is received in four hours, SP displays the last
time it saw a heartbeat and from what IP address.
n
n
n
n
n
n
Managers column
(appears when you
select All from the
Manager list)
(red alert) icon if the alert is ongoing
Displays the SP managers associated with the APS appliance.
Sorting and searching on the Cloud Signaling Status page
You can sort the data by APS ID or managed object name. You can use the Search box to
search on the Cloud Signaling Status page. The following are some guidelines for using the
Search box:
n You can enter search values with or without keywords.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
Proprietary and Confidential Information of Arbor Networks Inc.
333
SP and TMS User Guide, Version 8.0
Acceptable search keywords and values for searching on the Cloud Signaling Status
page
The following table lists the columns on the Cloud Signaling Status page when All is selected
in the Manager list and the keyword and value that you can use to search on that column in
the Search box:
Search keywords for columns
334
Column to search
on
Acceptable keywords and
values
APS ID
n
id:$36 ,'
n
id:APS_3
Managed Object
n
mo:PDQDJHG REMHFW QDPH
n
mo:customer_5
Managers
n
manager:PDQDJLQJ
DSSOLDQFH
n
manager:appliance_231
Examples
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Monitoring Your Deployment
Introduction
The Deployment Status page (System > Status > Deployment Status) allows you to do
the following:
n Monitor the performance and use of your SP and TMS appliances.
n
Monitor usage and, for appliances in flexible license mode, compare the usage with licensed
capacities.
n
Add flexible licenses to your deployment.
For information about the different components on the Deployment Status page, see the
following:
n “About the Upload Flexible License button” below
n
“About the Deployment Status graphs on the Deployment tab” below
n
“About the Deployment Status table on the Deployment tab” on page 337
n
“About the Ongoing System Alerts table on the Deployment tab” on page 340
n
“About the Time-Based Flexible Licenses table on the Deployment tab” on page 340
n
“About the Flow Monitoring tab” on page 341
n
“About the Users tab” on page 341
n
“About the TMS tab” on page 341
About the Upload Flexible License button
On the leader appliance, an Upload Flexible License button appears in the upper-right
corner of the Deployment Status page. You can click this button to upload a flexible license.
See “About Flexible Licensing” on page 89 and “Uploading a Flexible License” on page 92.
Note: On a leader with cloud-based licensing, this button does not appear.
About the Deployment Status graphs on the Deployment tab
The Deployment Status graphs allow you to view flows per second, TMS bandwidth, and
active users for your deployment for a selected timeframe. To change the timeframe, see
“Changing the display timeframe of the Status graphs on the Deployment tab” on the next
page.
The graphs include the following:
A green trend line showing average usage when the selected timeframe is a week or longer.
n
n
A horizontal black line for the maximum licensed capacity when usage is approaching this
maximum capacity. This line does not appear for the Flows per Second - total graph.
n
A vertical red line indicating the most recent midnight if the selected timeframe is a week or
shorter.
Note: If you have uploaded a flexible license, SP displays separate graphs for core and edge
router flows per second.
Proprietary and Confidential Information of Arbor Networks Inc.
335
SP and TMS User Guide, Version 8.0
The following graphs appear on the Deployment tab:
Deployment tab graphs
Graph Name
Description
Flows per
Second - total
Displays a graph for the selected timeframe of your deployment's total
flow rate (in flows per second) across all appliances that are in your
deployment.
Flows per
Second - core
Displays a graph for the selected timeframe of your deployment's total
flow rate (in flows per second) on core routers that are monitored by
appliances in flexible license mode.
This graph appears only if a flexible license has been uploaded. See
“Uploading a Flexible License” on page 92.
Flows per
Second - edge
Displays a graph for the selected timeframe of your deployment's total
flow rate (in flows per second) on edge routers that are monitored by
appliances in flexible license mode.
This graph appears only if a flexible license has been uploaded. See
“Uploading a Flexible License” on page 92.
TMS Total
Bandwidth
Displays a graph of the amount of total bandwidth (in bps) being
consumed on your TMS appliances for the selected timeframe.
TMS IPv6
Bandwidth
Displays a graph of the amount of IPv6 bandwidth (in bps) being
consumed on your TMS appliances for the selected timeframe.
Active Users
Displays a graph for the selected timeframe of the total number of
active users in your deployment.
Changing the display timeframe of the Status graphs on the Deployment tab
You can use the Time bar above the Status graphs to change the timeframe of the graphs. You
can select a predefined timeframe or specify a time range. You can also click and drag on a
graph to select a timeframe. The area on the graph that you select becomes the new
timeframe.
To change the display timeframe:
1. In the Time bar, click one of the following buttons:
l
Y - the previous year ending today
l
M - the previous four weeks ending today
l
W - the previous week ending today
l
D - the previous 24 hours
l
Other - a time range
2. If you select Other, you can then click
(calendar) and select the starting date and time
or you can type entries like the following in the Start and End boxes to specify the date
and time:
l
2 weeks ago
336
l
100 hours ago
l
last Monday
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
l
last sat of Jan 2016
l
yesterday noon
l
7 PM
l
t1415 (which means the time 14:15)
l
5 May (of the current year)
l
10/15/15 (mm/dd/yy)
l
2015-8-15 (yyyy-mm-dd)
l
20151010 (yyyymmdd)
3. Click Update.
About the Deployment Status table on the Deployment tab
The Deployment Status table displays the status of items in your deployment. If you have
uploaded a flexible license, items whose capacities are governed by a flexible license appear
with an asterisk (*) appended to their capacity. The status of the AIF license appears below the
table near the bottom of the page.
The Current column includes a graph. This graph displays the current usage over the maximum
capacity. The usage appears as a dark gray bar when usage is well below the maximum
capacity. When usage starts to approach the maximum capacity, the bar changes to orange.
When usage reaches or exceeds the maximum capacity, the bar changes to red.
When the usage bar is orange or red, you can hover your mouse cursor over the item to view a
message describing the item status. When the bar is orange, the message indicates that the
usage is nearing capacity. When the bar is red, the message describes the impact that
reaching or exceeding the maximum capacity has on your deployment. The % Total for the item
is also highlighted with a red background when you reach or exceed the maximum capacity.
Note: If you have uploaded a flexible license, SP displays entries for flows per second for core
and edge routers and separate entries for core and edge routers.
Proprietary and Confidential Information of Arbor Networks Inc.
337
SP and TMS User Guide, Version 8.0
The following monitored items appear in the Deployment Status table on the Deployment
tab:
Deployment Status table items
338
Entry
Description
Flows per Second core
or
Flows per Second edge
The number of flows per second on the core and edge routers in
your deployment, out of the total number of flows per second that
your deployment supports on the core and edge routers. These
numbers are only for routers that are managed by appliances in
flexible license mode.
The vertical black bar represents the highest 30 minute average
of flows per second over the past 30 days.
For information about the enforcement of the flows per second
capacity, see “Flexible-licensed capacity for flows per second ”
on page 94.
Routers - appliancebased
The number of configured routers in your deployment, out of the
total number of routers that your deployment supports. This
number is only the routers that are managed by appliances in
appliance-based license mode.
You can click the Routers - appliance-based link to access
the Configure Routers page. When you configure a router, you
can select the managing appliance for the router on the Router
tab.
Routers - core
or
Routers - edge
The number of configured core and edge routers in your
deployment, out of the total number of core and edge routers that
your deployment supports with Flexible Licensing. These
numbers are only for core or edge routers that are managed by
appliances in flexible license mode.
You can click the Routers - core or Routers - edge link to
access the Configure Routers page. When you configure a
router, you can select the managing appliance for the router on
the Router tab.
For information about the enforcement of the routers capacity,
see “Flexible-licensed capacity for routers” on page 94.
Total Routes
The number of BGP routes received from monitored routers, out
of the total number of routes that your deployment supports.
You can click the Total Routes link to access the Peer
Compare report, which displays the number of routers per peer.
Interfaces
The number of router interfaces that SP detects in your
deployment using flow and SNMP data, out of the total number
of interfaces that your deployment supports.
You can click the Interfaces link to access the Configure
Interfaces page.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Deployment Status table items (Continued)
Entry
Description
Active Users flexible
The number of users currently logged in to your deployment on
appliances in flexible license mode, out of the total number of
concurrent users that your deployment supports. The vertical
black bar represents the highest 30 minute average of active
users over the past 30 days.
You can click the Active Users - flexible link to access the
User Accounts page.
For information about the enforcement of the number of active
users, see “Flexible-licensed capacity for active users” on
page 93.
Active Users appliance-based
The number of users currently logged in to your deployment on
appliances in appliance-based license mode, out of the total
number of concurrent users that your deployment supports. The
vertical black bar represents the highest 30 minute average of
active users over the past 30 days.
You can click the Active Users - appliance-based link to
access the User Accounts page.
Managed Objects
The number of managed objects configured in your deployment,
out of the total licensed capacity for managed objects in your
deployment. The licensed capacity for managed objects is the
sum of the base licensed capacity (1,000 managed objects), the
flexible-licensed capacity, and the licensed capacity of each
appliance in appliance-based license mode that has the data
storage role.
You can click the Managed Objects link to access the
Configure Managed Objects page.
For information about the enforcement of the managed objects
capacity with Flexible Licensing, see “Licensed capacity for
managed objects” on page 94.
Mitigations
The number of ongoing mitigations, out of the total number of
mitigations that your deployment supports. You can click the
Mitigations link to access the All Mitigations page.
TMS Bandwidth
The current amount of consumed TMS bandwidth, out of the
total TMS bandwidth capacity. The vertical black bar represents
the highest 30 minute average of TMS bandwidth over the past
30 days. You can click the TMS Bandwidth link to access the
Appliance Status page.
Proprietary and Confidential Information of Arbor Networks Inc.
339
SP and TMS User Guide, Version 8.0
About the Ongoing System Alerts table on the Deployment tab
The Ongoing Alerts Affecting Deployment table displays up to 30 ongoing system alerts
related to your SP appliances. You can click on the heading in each column to sort the table
rows according to the order of the items in that column.
The table includes the following:
Ongoing System Alerts table information
Information
Description
ID
The unique number that is assigned to each alert.
Importance
The alert’s severity level (high or medium).
Alert
The type of alert that is reported and information about the alert.
Start Time
The time when the alert activity was first detected, followed by the
duration of the alert in days, hours, and minutes (DD d, HH:MM).
About the Time-Based Flexible Licenses table on the Deployment tab
If you have uploaded a flexible license and have any time-based flexible licenses in your SP
deployment, then the Time-Based Flexible Licenses table appears below the Deployment
Status table. Time-based flexible licenses include trial licenses for any of the licensed
capacities and AIF licenses. The table lists the licenses with the time remaining on the license
and the expiration date of the license. For AIF licenses, it lists only the license that has the
closest expiration date. See “About AIF licenses” on page 322.
About the Cloud-based License section on the Deployment tab
If you use cloud-based licensing, a Cloud-based License section appears at the bottom of the
Deployment tab on the Deployment Status page. This section provides information on the
status of your cloud-based license. For additional information about cloud-based licensing, see
“About Cloud-based Licensing” on page 96.
If the last attempted refresh of the local copy of the cloud license was successful, this section
displays the date and time of the refresh with no additional information. If the last refresh was
unsuccessful, this section displays one of the following types of messages:
n A warning that SP was unable to refresh the local copy and the number of days until the
local copy will expire
n
A warning that the local copy has expired
These warnings also include the following information:
An error message that can help debug cloud-based license issues, particularly if you need to
contact ATAC
n
n
The date and time of the last successful refresh
n
The date and time of the last attempted refresh
n
The date and time when the license expired or will expire
Note: If the local copy of the cloud-based license will expire in 9 or fewer days, a Cloud Based
License window also appears whenever an SP administrator logs in to SP. The warning in this
window includes the same information that appears in the Cloud-based License section of the
340
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Deployment Status page. The warning in the Cloud Based License window also includes a link
to the Deployment Status page.
The Cloud-based License section also includes a Refresh Local Copy of License button.
You can click this button to do the following:
n Verify that you still have a connection with the license server after you make changes to
your firewall or other changes to your deployment.
n
Manually attempt to refresh the local copy of the cloud license after resolving the issues that
you believe caused the license refresh to fail.
Note: After the local copy of the license is refreshed, you must reload the Deployment
Status page to see updated license information.
About the Flow Monitoring tab
You can use the Flow Monitoring tab to view the rate at which an appliance receives flow,
the number of items that an appliance is tracking, and how the appliance is performing.
Note: “Items Tracked” are the unique traffic entities for which SP stores data. For example
TCP port 80 for a single customer managed object is one item tracked.
About the Users tab
You can use the Users tab to view how many active users are logged in through the Web UI to
an SP appliance, the level of their activity, and the basic performance of the appliance. You
can click the name link for an appliance to navigate to the UI Statistics tab on the Appliance
Status page.
About the TMS tab
The TMS tab displays statistics for each TMS appliance in your deployment. You can click the
name link for an appliance to navigate to the TMS Statistics tab on the Appliance Status
page.
Proprietary and Confidential Information of Arbor Networks Inc.
341
SP and TMS User Guide, Version 8.0
About the Appliance Status Page
Introduction
The Appliance Status page (System > Status > Appliance Status) displays real-time
status information for each individual Arbor Networks appliance. You can use this information
for capacity planning and to monitor general system health, load, upgrade status, and
performance over time.
Note: On the Appliance Monitoring page, you can select a metric for your Arbor Networks
appliances and view status information for all of the appliances at the same time. See
“Monitoring Your Arbor Networks Appliances” on page 360.
About the Appliance Status page tabs
The Appliance Status page displays information on the following tabs:
Appliance Status tabs
Tab
Description
Reference
General
System diagnostics over a
designated period of time for all
appliances.
“Viewing General Appliance
Statistics” on page 344
UI Statistics
Diagnostics for the Web UI
appliances over a designated period
of time.
“Viewing Web UI Statistics”
on page 354
Managed Services
UI Statistics
How your managed services
appliances are being used.
“Viewing Managed Services
UI Statistics” on page 356
TMS Statistics
Your TMS appliances for capacity
planning and to monitor appliance
utilization.
“Viewing TMS Appliance
Statistics” on page 357
Changing the data displayed on Appliance Status page tabs
You can change the data displayed on the Appliance Status page tabs. The tables display data
from the last five minutes.
To change the data displayed on a Appliance Status page tab:
1. Navigate to the Appliance Status page (System > Status > Appliance Status).
2. On any tab, from the Metric list, select the metric option that you want to view.
For a description of the different metric options, see the following:
l
“Arbor Networks appliance metrics” on page 344
l
“UI Statistics metrics” on page 354
l
“Viewing Managed Services UI Statistics” on page 356
l
“TMS Statistics metrics” on page 357
3. On any tab, from the Period list, select the time period for which you want to view data.
342
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
4. On the Managed Services UI Statistics tab, from the Account Groups list, select the
account group.
To filter the list, type any part of the account group name that does not include a space.
Proprietary and Confidential Information of Arbor Networks Inc.
343
SP and TMS User Guide, Version 8.0
Viewing General Appliance Statistics
Introduction
You can monitor the system diagnostics for all appliances on the General tab of the Appliance
Status page (System > Status > Appliance Status). This tab displays a graph of the
metric and time period that you select and a table that shows the operational status of all
configured appliances. The table displays data for the last five minutes.
Note: The graph of a metric can take up to 10 minutes to update after changes are made to an
appliance.
Arbor Networks appliance metrics
The following table describes all of the metrics that you can select on the Appliance Status
page. The appliance type or role determines if data can be displayed for a selected metric. A
Flow Sensor appliance can display data for the same metrics as a Traffic and Routing Analysis
appliance.
Appliance metrics
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
BGP messages
received per
second
ݲ
ݲ
The average number of BGP messages
that the appliance received per second.
The average is based on 5-minute periods.
BGP peering
sessions
(Established)
ݲ
ݲ
The number of primary and secondary
BGP peering sessions that the appliance
has established with routers in your
deployment.
BGP peering
sessions
configured
ݲ
ݲ
The number of primary and secondary
BGP peering sessions that have been
configured on this appliance with routers
in your deployment.
BGP routes
ݲ
ݲ
The total number of active BGP routes on
the appliance.
CPU load
ݲ
ݲ
ݲ
ݲ
The average number of processes in the
system run queue during a 5 minute
period.
Note: This is the standard UNIX CPU load
measurement.
Disk (data
partition) used %
ݲ
ݲ
ݲ
ݲ
The percentage of the data partition of the
disk that is being used.
344
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
DoS alert refine
jobs
ݲ
The number of DoS alert refine jobs that
are running on the appliance. A refine job
looks at the flow in order to update the
data for ongoing DoS alerts.
Flow (ArborFlow)
bps sent
ݲ
ݲ
ݲ
The average amount of ArborFlow sent
from the appliance in bps during a
5-minute period.
Flow (ArborFlow)
pps sent
ݲ
ݲ
ݲ
The average amount of ArborFlow sent
from the appliance in pps during a
5-minute period.
Flow (Total) bps
received
ݲ
ݲ
The average amount of flow received by
the appliance in bps during a 5-minute
period.
Flow (Total) pps
received
ݲ
ݲ
The average amount of flow received by
the appliance in pps during a 5-minute
period.
Flows
(ArborFlow)
dropped per 5
minutes
ݲ
ݲ
The number of ArborFlow packets that
were dropped during a 5-minute period.
With a Flow Sensor appliance, it is the
number of packets that the appliance sent
that did not arrive. With any other
appliance, it is the number of packets that
the appliance did not receive based on
missing sequence numbers seen in
received flow.
Flows
(ArborFlow)
received per
second
ݲ
ݲ
The average number of ArborFlow records
that the appliance has received per
second during a 5-minute period.
Flows
(ArborFlow) sent
per second
ݲ
ݲ
The average number of ArborFlow records
that the appliance has sent per second
during a 5-minute period.
Proprietary and Confidential Information of Arbor Networks Inc.
345
ݲ
SP and TMS User Guide, Version 8.0
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Flows (Core)
processed per
second
ݲ
ݲ
The average number of flows per second
that passed through core routers and were
processed by the appliance during a
5-minute period. When flow is sampled,
an appliance only processes the sampled
flow.
Flows (Core)
received per
second
ݲ
ݲ
The average number of flows per second
that passed through core routers and were
received by the appliance during a
5-minute period.
Flows (Edge)
processed per
second
ݲ
ݲ
The average number of flows per second
that passed through edge routers and
were processed by the appliance during a
5-minute period. When flow is sampled,
an appliance only processes the sampled
flow.
Flows (Edge)
received per
second
ݲ
ݲ
The average number of flows per second
that passed through edge routers and
were received by the appliance during a
5-minute period.
Flows (Total)
dropped per 5
minutes
ݲ
ݲ
The total number of flows dropped during
a 5-minute period, based on missing
sequence numbers seen in received flows.
This counts both ArborFlow and router
flow that is dropped.
Flows (Total)
processed per
second
ݲ
ݲ
The total number of flows per second that
the appliance processed based on a 5minute period. This includes ArborFlow
that was received from TMS appliances
and Flow Sensor appliances (with
appliance-based licensing). When flow is
sampled, an appliance only processes the
sampled flow.
346
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Flows (Total)
received per
second
ݲ
Interfaces in flow
per 5 minutes
ݲ
The number of interfaces that the
appliance monitored during a 5-minute
period. An interface is monitored only if
flow has been detected and classified.
Note: This number will never exceed the
licensed capacity for interfaces because
SP does not monitor interfaces that
exceed the licensed capacity.
Interfaces total
ݲ
The total number of interfaces that the
appliance has seen regardless of whether
flow has been detected at the interface.
Interfaces with
detailed
statistics tracked
ݲ
The number of interfaces that the
appliance monitored that have been
configured to collect detailed statistics or
that collect detailed statistics by default.
By default, external interfaces collect
detailed statistics. For more information
about configuring interfaces to collect
detailed statistics, see “Configuring
Interfaces” on page 150.
Items tracked per
5 minutes
ݲ
ݲ
The number of unique traffic items in the
database during a 5-minute period.
Items tracked per
day
ݲ
ݲ
The number of unique traffic items in the
database during the course of a day.
Managed
objects matched
in/out per
second
ݲ
ݲ
The average number of managed object
matches per second on the appliance
during a 5-minute period, but only for flow
that is In or Out.
Managed
objects matched
per flow
ݲ
ݲ
The average number of managed object
matches per flow on the appliance during
a 5-minute period.
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
The total number of flows received by the
appliance per second based on a 5minute period. This includes ArborFlow
that was received from TMS appliances
and Flow Sensor appliances (with
appliance-based licensing).
347
SP and TMS User Guide, Version 8.0
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Managed
objects matched
per second
ݲ
ݲ
The average number of managed object
matches per second on the appliance
during a 5-minute period.
Managed
objects with data
stored
ݲ
ݲ
The total number of managed objects with
traffic data that has been added to the
database. This number includes VPN sites.
Memory used %
ݲ
ݲ
The percentage of the physical memory
that is being used.
Packets dropped
per second
ݲ
ݲ
The average number of flow packets
dropped per second during a 5-minute
period.
Packets received
per second
ݲ
ݲ
The average number of flow packets
received per second during a 5-minute
period.
Routers
configured
ݲ
The number of routers that the appliance
is configured to monitor.
Routers
configured for
SNMP polling
ݲ
The number of routers that the appliance
monitors that have been configured to
collect SNMP data.
Routers
responding to
SNMP polling
ݲ
The number of routers that are sending
SNMP data to the appliance.
Routers sending
flow
ݲ
The number of routers that are sending
flow to the appliance during a 5-minute
period.
TMS devices
configured to
send ArborFlow
ݲ
The number of TMS appliances that are
configured to send ArborFlow to the
appliance.
TMS devices
managed
ݲ
The number of TMS appliances that the
appliance manages.
TMS devices
sending
ArborFlow
ݲ
The number of TMS appliances that are
sending ArborFlow to the appliance during
a 5-minute period.
ݲ
ݲ
TMS ongoing
mitigations
ݲ
The number of ongoing mitigations running
on the TMS appliance.
348
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Traffic database
bytes read
(short-term)
ݲ
ݲ
The total number of bytes read from the
database during a 5-minute period. The
short-term database is used for merging
sample data into a day timeframe.
Traffic database
bytes written
(short-term)
ݲ
ݲ
The total number of bytes written to the
database during a 5-minute period. The
short-term database is used for merging
sample data into a day timeframe.
Traffic database
files (short-term)
ݲ
ݲ
The total number of files in the database
during a 5-minute period. The short-term
database is used for merging sample data
into a day timeframe.
Traffic database
run time
(long-term)
ݲ
ݲ
The number of seconds taken to merge
day samples into week, 4-week, and year
timeframes in the database. The long-term
database run merges sample data into
week, month, and year timeframes.
Traffic database
run time
(short-term)
ݲ
ݲ
The number of seconds taken to merge
each new 5-minute sample period into the
database. The short-term database run
merges sample data into a day timeframe.
Traffic database
write duration(s)
ݲ
ݲ
ݲ
The number of seconds it took to write
new samples to disk during a 5-minute
period. This data includes monitoring data
and traffic data.
Virtual memory
used %
ݲ
ݲ
ݲ
The percentage of virtual memory that is
being used.
ݲ
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
349
SP and TMS User Guide, Version 8.0
About the table on the General tab
The table on the General tab of the Appliance Status page displays the following information
for each appliance:
General tab table information
Column
350
Description
(expand)
Click
to view an additional pane with system details, package
information, and ongoing system alerts.
See “Appliance status details” on page 353.
(option)
Select to include an appliance's traffic in the graph.
(context menu)
A
(context menu) icon is to the left of an appliance name. The
icon becomes more visible when you hover your mouse pointer over it.
When you click , the following options appear:
n View in Appliance Monitoring
Allows you to see all of the metrics for that appliance on the Per
Appliance Metrics tab of the Appliance Monitoring page.
n Edit Appliance
Allows you to edit the appliance's configuration on the Edit
Appliance page.
Name
The configured hostname of each appliance.
Note: The leader’s name appears in bold text.
Type
The type of the appliance. See “Types of appliances with hybrid
licensing” on page 38.
License Mode
The license mode of the appliance. If an appliance is in
appliance-based license mode, its license mode is Appliance. If an
appliance is in flexible license mode, its license mode is Flexible.
This column appears only if a flexible license has been uploaded. See
“Uploading a Flexible License” on page 92.
Appliance
A brief description of an appliance’s status. See “Appliance status
descriptions” on page 352.
Flow
Indicates the total number of routers that are configured to send Flow
to this appliance.
X / Y is displayed. X represents the number of configured routers that
are currently sending flow. Y represents the total number of routers that
are configured to send flow.
ArborFlow
Indicates the total number of Arbor Networks appliances that are
configured to send ArborFlow to this appliance.
X / Y is displayed. X represents the number of configured appliances
that are currently sending ArborFlow. Y represents the total number of
appliances that are configured to send ArborFlow.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
General tab table information (Continued)
Column
Description
SNMP
Indicates the total number of routers that are configured to send SNMP
data to this appliance.
X / Y is displayed. X represents the number of configured routers that
are currently sending SNMP data. Y represents the total number of
routers that are configured to send SNMP data. .
BGP
Indicates the total number of configured and established BGP peering
sessions.
X / Y is displayed. X represents the number of primary and secondary
peering sessions that the appliance has established with routers in your
deployment. Y represents the number of primary and secondary BGP
peering sessions that have been configured on this appliance with
routers in your deployment.
The status of the BGP peering sessions of an appliance is indicated by
the following:
n
n
n
No shading - all BGP sessions are up
Orange shading- a TMS has non-fatal BGP errors
Red shading - a BGP session is down
Memory
The percentage of physical memory on the appliance currently being
used by SP.
Load
The average number of processes in the system run queue of the
appliance.
This number includes processes that are using or waiting for CPU as
well as processes waiting to access the disk or network. These
different processes can lead to markedly different results if many
processes remain blocked in I/O due to a busy or stalled I/O system.
The number of processes is for all cores, and some cores can have
processes that are pinned to them.
Disk
The percentage of available disk space on the appliance being used to
store traffic and routing data.
SP Uptime
The amount of time that has elapsed since SP was last restarted on the
appliance.
Proprietary and Confidential Information of Arbor Networks Inc.
351
SP and TMS User Guide, Version 8.0
Appliance status descriptions
The Appliance Status column on the General tab displays one of the following statuses:
General tab appliance status descriptions
352
Status
Description
Clock skew
detected (off by
about WLPH)
The clock on the appliance does not match the leader. This indicates
a failure or misconfiguration of NTP.
Configuration out of
date
The appliance is not running with an up-to-date configuration. If you
recently committed changes on the leader appliance or an appliance
that has the user interface role, this status is displayed until the new
configuration is distributed. If this status continues to be displayed for
more than 30 minutes, then the appliance may be experiencing a
more significant issue.
Interface
Classification In
Progress (WLPH left)
The appliance is currently running interface auto-classification.
Never seen
The leader has not received a heartbeat from this appliance since the
appliance was configured.
No heartbeat (WLPH)
The leader has not received a heartbeat from this appliance for the
specified amount of time. This status is displayed only when a
heartbeat has not been received for two minutes.
Running
The appliance is operating normally and collecting data.
Running / Appliance
Model Mismatch
The appliance-based license of the appliance does not match the
appliance type.
Running / License
Exceeded
For appliances in flexible licensing mode, a flexible licensed capacity
has been exceeded.
System Starting
(WLPH left)
The appliance is waiting for the start-up state to be completed.
Maximum number
of router interfaces
reached (QXPEHU)
The appliance has reached the maximum number of router interfaces.
Maximum number
of monitored router
interfaces reached
(QXPEHU)
The appliance has reached the maximum number of monitored router
interfaces.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance status details
When you click the plus sign icon (+) next to an appliance name on the Appliance Status
page, one or more of the following tables appear that display detailed information about the
appliance:
n System Details
This table displays the version of SP that is installed on the appliance.
n
Installed Packages
This table displays the packages that are installed on the appliance, including the version
numbers.
n
Ongoing System Alerts
This table displays any ongoing system alerts for the appliance. This section appears only
when there are ongoing alerts for an appliance.
Proprietary and Confidential Information of Arbor Networks Inc.
353
SP and TMS User Guide, Version 8.0
Viewing Web UI Statistics
Introduction
You can monitor the diagnostics for the Web UI appliances on the UI Statistics tab on the
Appliance Status page (System > Status > Appliance Status). This tab displays a graph
and a table that contains information about the Web UI appliances. The table displays data
from the last five minutes.
UI Statistics metrics
The following table describes the metrics that you can select on the UI Statistics tab:
UI Statistics metrics
Graph Option
Description
Active Users
The number of active users during a selected time period.
SOAP Queries
The number of times that users made SOAP queries during a
selected time period.
Query Duration
The duration of queries during a selected period of time. The page
reports the duration in milliseconds.
Viewed Reports
The number of times that users viewed reports during a selected time
period.
Loaded Pages
The number of times that users loaded a page during a selected time
period.
Bandwidth (bps)
The amount of bandwidth (in bps) used during a time period.
Bandwidth (pps)
The amount of bandwidth (in pps) used during a time period.
User Login
The number of users who logged in to an appliance during a time
period.
User Logout
The number of users who logged out from an appliance during a time
period.
The UI Statistics table
The UI Statistics table contains the following information for each Web UI appliance:
UI Statistics table information
Column
Option button (
354
Description
)
Click to include an appliance's traffic in a graph.
Name
The configured hostname of a Web UI appliance.
Active Users
The number of users currently logged in.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
UI Statistics table information (Continued)
Column
Description
SOAP Queries
The number of SOAP queries made.
Query Duration (ms)
The duration of queries in milliseconds.
Reports
The number of reports that users have viewed.
Page Loads
The number of times that users have loaded the page.
Bandwidth (pps)
The bandwidth per UI appliance (in pps).
Bandwidth (bps)
The bandwidth per UI appliance (in bps).
User Login
The number of users who logged in during a time period.
User Logout
The number of users who logged out during a time period.
Proprietary and Confidential Information of Arbor Networks Inc.
355
SP and TMS User Guide, Version 8.0
Viewing Managed Services UI Statistics
Introduction
You can monitor how your managed services UI appliances are being used on the Managed
Services UI Statistics tab on the Appliance Status page (System > Status > Appliance
Status). This tab displays a graph and a table that contains information about managed
services user activity on the leader appliance and all appliances that have the user interface
role.
Managed Services UI Statistics metrics
The following table describes the metrics that you can select on the Managed Services UI
Statistics tab:
Managed Services UI Statistics metrics
Graph Option
Description
Query Duration
The duration of queries over time.
Number of Viewed Reports
The number of times that users viewed reports.
Number of Loaded Pages
The number of page views across all users.
Managed Services UI Statistics table
The Managed Services UI Statistics table displays the current data from the last five minutes
and the following information for each appliance:
Managed Services UI Statistics table information
Column
Option button (
356
Description
)
Select to include an appliance's user statistics in a graph.
Appliance
The configured hostname of the leader appliance and each appliance
that has the user interface role.
Query Duration
(ms)
The duration of the queries.
Reports
The number of reports that users have viewed.
Page Loads
The number of page loads.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Viewing TMS Appliance Statistics
Introduction
You can monitor your TMS appliances for capacity planning and appliance utilization on the
TMS Statistics tab on the Appliance Status page (System > Status > Appliance
Status). This tab displays a graph and a table that contains information about the TMS
appliances. The table displays data from the last five minutes.
When you initiate a TMS mitigation, you must select a TMS appliance. In order for you to select
a TMS with capacity for another mitigation, this tab (which includes the number of mitigations
and bps in traffic per TMS) is critical. Without the ability to see the status in terms of bps in and
out traffic, the user cannot know if a mitigation through a TMS appliance will work or if traffic
will overload the ingress interfaces, causing normal traffic to be dropped.
TMS Statistics metrics
The following table describes the metrics that you can select on the TMS Statistics tab:
TMS Statistics metrics
Graph Option
Description
CPU Load
The average number of processes on the system run queue.
Note: This is the standard UNIX CPU load measurement.
Memory Usage
The percentage of the physical memory used.
Pass/Drop
Bandwidth (Total)
The total amount of passed and dropped IPv4 and IPv6 bandwidth.
Pass/Drop
Bandwidth (IPv4)
The amount of passed and dropped IPv4 bandwidth.
Pass/Drop
Bandwidth (IPv6)
The amount of passed and dropped IPv6 bandwidth.
Number of
Mitigations by
Managed Object
The number of mitigations that a TMS appliance processed for a
selected time period.
Note: This is the total number of mitigations associated with
managed objects. If you start a mitigation but do not associate it with
a managed object, then the mitigation is not included in the graph.
Bandwidth by
Managed Object
The amount of bandwidth used per managed object.
Bandwidth by Port
The amount of bandwidth used per port.
About TMS faults
The SP console displays TMS fault messages. If a TMS appliance experiences a fault, it reports
the fault in the heartbeat status message to the console and the message appears on the
Appliance Status page.
Proprietary and Confidential Information of Arbor Networks Inc.
357
SP and TMS User Guide, Version 8.0
TMS Statistics table
The TMS Statistics table contains the following information:
TMS Statistics table information
Column
(option)
358
Description
Select to include an appliance's traffic in a graph.
Name
The configured hostname of an appliance, as a link to the appliance
configuration page.
Type
The type of TMS appliance.
Appliance Status
A brief description of each appliance status.
See “Appliance status descriptions” on page 352.
BGP
The status of configured BGP peers. In each column, X/Y is displayed,
where X represents the number of configured peers that are currently
established and Y represents the total number of peers that are
configured on the TMS appliance.
GRE
The status for the configured GRE destination IP addresses for all
tunnels. In each column, X/Y is displayed, where X represents the
number of running, unique destination IP addresses and Y represents
the total number of unique destination IP addresses.
Mitigations
The number of ongoing mitigations during the last heartbeat. The
column also shows the maximum number of mitigations that you are
allowed per appliance. The column background is red when the
mitigations exceed the appliance’s mitigation limit, the background is
orange when the appliance’s mitigations reach between 80 and 100
percent of the limit, and the background is green when the appliance’s
mitigations are below 80 percent of the limit.
In
The amount of incoming traffic to the appliance. The column also
shows the maximum amount of in traffic that you are allowed per
appliance. A red background indicates that the incoming traffic
exceeds 80 percent of the appliance capacity. A green background
indicates that the incoming traffic is at or below 80 percent of the
appliance’s capacity.
Out
The amount of outgoing traffic from the appliance.
% Passed
The percentage of traffic that the appliance did not block.
Memory
The percentage of physical memory that is currently being used by the
appliance.
Load
The average number of processes in the system run queue.
Note: This is the standard UNIX CPU load measurement.
Disk
The percentage of available disk space that is used to store traffic and
routing data.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
TMS Statistics table information (Continued)
Column
Description
Uptime
The amount of time that has elapsed since the appliance was last
restarted.
Alerts
The number of alerts seen by the appliance.
(expand)
When clicked, displays the five most recent alerts seen by the
appliance including the ID number, start and stop times, the appliance
that reported the alert, alert type, and what triggered the alert.
Proprietary and Confidential Information of Arbor Networks Inc.
359
SP and TMS User Guide, Version 8.0
Monitoring Your Arbor Networks Appliances
Introduction
The Appliance Monitoring page (System > Status > Appliance Monitoring) allows you to
view information about the health and usage of your Arbor Networks appliances. The ability to
view how your appliances are being used allows you to monitor the health of your deployment
and to do capacity planning.
About the tabs on the Appliance Monitoring page
The following tabs appear on the Appliance Monitoring page:
Appliance Monitoring tabs
360
Tab
Description
Reference
Summary
Displays a summary of the health and
usage information for your Arbor Network
appliances.
“About the Summary Tab on the
Appliance Monitoring Page” on
the facing page
Per
Appliance
Metrics
Displays all of the metrics for a selected
Arbor Networks appliance.
“About the Per Appliance
Metrics Tab on the Appliance
Monitoring Page” on page 366
Metric
Comparison
Displays a selected metric for all of your
Arbor Networks appliances.
“About the Metric Comparison
Tab on the Appliance
Monitoring Page” on page 374
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
About the Summary Tab on the Appliance Monitoring Page
Introduction
The Summary tab on the Appliance Monitoring page (System > Status > Appliance
Monitoring) allows you to view a summary of the health and usage information for your Arbor
Networks appliances. For more information about the Appliance Monitoring page, see
“Monitoring Your Arbor Networks Appliances” on the previous page.
Viewing summary information about your Arbor Networks appliances
To view summary information about your Arbor Networks appliances:
1. Navigate to the Appliance Monitoring page (System > Status > Appliance
Monitoring).
2. Click the Summary tab.
About the table on the Summary tab of the Appliance Monitoring page
The table on the Summary tab of the Appliance Monitoring page displays a summary of the
health and usage information for the appliances in your deployment. When an appliance is in
an unhealthy state, one or more of its metrics are highlighted in red or pink to call attention to
the problem. See “How to assess appliance health” on page 363.
By default, the appliances in this table are sorted with the appliances with the most ongoing
alerts appearing first and those with the least ongoing alerts last. You can sort the appliances
by the data in the Memory Used %, Disk (data) Used %, and Ongoing Alerts columns.
Summary tab information
Column
Description
Name
The configured hostname of each appliance with a brief description of
the appliance role or type. The name of the leader appliance is bold
with "(Leader)" appended.
A
(context menu) icon precedes each name that allows you to
quickly access additional information about the appliance. See “About
the context menu icon that precedes an appliance name” on page 363.
Status
A brief description of an appliance’s status. See “Appliance status
descriptions” on page 364.
Flow
Indicates the total number of routers that are configured to send flow to
this appliance.
; / < is displayed. ; represents the number of configured routers that
are currently sending flow. < represents the total number of routers that
are configured to send flow.
ArborFlow
Indicates the total number of Arbor Networks appliances that are
configured to send ArborFlow to this appliance.
; / < is displayed. ; represents the number of configured appliances
that are currently sending ArborFlow. < represents the total number of
appliances that are configured to send ArborFlow.
Proprietary and Confidential Information of Arbor Networks Inc.
361
SP and TMS User Guide, Version 8.0
Summary tab information (Continued)
362
Column
Description
SNMP
Indicates the total number of routers that are configured to send SNMP
data to this appliance.
; / < is displayed. ; represents the number of configured routers that
are currently sending SNMP data. < represents the total number of
routers that are configured to send SNMP data. .
BGP
Indicates the total number of configured and established BGP peering
sessions.
; / < is displayed. ; represents the number of primary and secondary
peering sessions that the appliance has established with routers in
your deployment. < represents the number of primary and secondary
BGP peering sessions that have been configured on this appliance
with routers in your deployment.
GRE
Indicates the total number of configured GRE destination IP addresses
for all tunnels that are configured on TMS appliances.
; / < is displayed. ; represents the number of running, unique
destination IP addresses. < represents the total number of unique
destination IP addresses.
CPU Load
Average
The average number of processes in the system run queue of the
appliance waiting to run during a 5 minute period.
This number includes processes that are using or waiting for CPU as
well as processes waiting to access the disk or network. These
different processes can lead to markedly different results if many
processes remain blocked in I/O due to a busy or stalled I/O system.
The number of processes is for all cores, and some cores can have
processes that are pinned to them.
Memory Used %
The percentage of physical memory on the appliance that is currently
being used. With a TMS appliance this applies only to the MCM
memory.
Disk (data)
Used %
The percentage of the traffic and routing data storage used on the
appliance.
SP Uptime
The amount of time that has elapsed since the Arbor Networks
software was last started on the appliance.
Ongoing Alerts
The number of ongoing System Error alerts or TMS Fault alerts for the
appliance.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
About the context menu icon that precedes an appliance name
A
(context menu) icon precedes each appliance name on the Summary tab of the
Appliance Monitoring page. The
icon becomes more visible when you hover you mouse
pointer over it. When you click , the following options appear:
n View Per Appliance Metrics
Allows you to see all of the metrics for that appliance on the Per Appliance Metrics tab
of the Appliance Monitoring page.
n
Edit Appliance
Allows you to edit the appliance's configuration on the the Edit Appliance page.
How to assess appliance health
When an appliance is in an unhealthy state, one or more of its metrics on the Summary tab
are highlighted in red or pink to call attention to the problem. Red indicates a status with high
severity, and pink indicates a status with a medium severity.
If SP detects that an appliance is running, then any metric for that appliance that has an
unhealthy status is highlighted in red or pink. However, if SP cannot detect that an appliance is
running, then only the Summary column is highlighted in red or pink for that appliance, even if
the appliance has other table cells with an unhealthy status that would otherwise be
highlighted in red or pink. When SP cannot detect if an appliance is running, the appliance has
one of the following statuses in the Summary column:
n Never seen
n
No heartbeat (WLPH)
n
System Starting (WLPH left)
For a description of the different appliance statuses, see “Appliance status descriptions” on the
next page.
The following table describes when a metric on the Summary tab can have a severity of
medium or high:
Appliance
Metric
Status
Medium Severity
High Severity
The appliance has one of the
following statuses:
The appliance has one of the
following statuses:
n
n
n
n
n
Flow, ArborFlow,
SNMP, BGP, or
GRE
Interface Classification in
Progress (WLPH left)
Never seen
Running / Appliance Model
Mismatch
Running / License Exceeded
System Starting (WLPH left)
(BGP only) The appliance is
unable to negotiate a peering
session with a router.
Proprietary and Confidential Information of Arbor Networks Inc.
n
n
n
n
n
Clock skew detected (off by
about WLPH)
Configuration out of date
No heartbeat (WLPH)
Maximum number of router
interfaces reached (QXPEHU)
Maximum number of monitored
router interfaces reached
(QXPEHU)
The numerator does not match the
denominator.
363
SP and TMS User Guide, Version 8.0
Appliance
Metric
Medium Severity
High Severity
Memory Used %
or Disk (data
partition) Used %
The usage reaches or exceeds
100%.
Ongoing Alerts
The appliance has one or more
alerts.
Appliance status descriptions
The Status column on the Summary tab displays one of the following statuses:
Appliance status descriptions
364
Status
Description
Clock skew
detected (off by
about WLPH)
The clock on the appliance does not match the leader. This indicates
a failure or misconfiguration of NTP.
Configuration out of
date
The appliance is not running with an up-to-date configuration. If you
recently committed changes on the leader appliance or an appliance
that has the user interface role, this status is displayed until the new
configuration is distributed. If this status continues to be displayed for
more than 30 minutes, then the appliance may be experiencing a
more significant issue.
Interface
Classification in
Progress (WLPH left)
The appliance is currently running interface auto-classification.
Never seen
The leader has not received a heartbeat from this appliance since the
appliance was configured.
No heartbeat (WLPH)
The leader has not received a heartbeat from this appliance for the
specified amount of time. This status is displayed only when a
heartbeat has not been received for two minutes.
Running
The appliance is operating normally and collecting data.
Running / Appliance
Model Mismatch
The appliance-based license of the appliance does not match the
appliance type.
Running / License
Exceeded
For appliances in flexible licensing mode, a flexible licensed capacity
has been exceeded.
System Starting
(WLPH left)
The appliance is waiting for the start-up state to be completed.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance status descriptions (Continued)
Status
Description
Maximum number
of router interfaces
reached (QXPEHU)
The appliance has reached the maximum number of router interfaces.
Maximum number
of monitored router
interfaces reached
(QXPEHU)
The appliance has reached the maximum number of monitored router
interfaces.
Proprietary and Confidential Information of Arbor Networks Inc.
365
SP and TMS User Guide, Version 8.0
About the Per Appliance Metrics Tab on the Appliance Monitoring
Page
Introduction
The Per Appliance Metrics tab on the Appliance Monitoring page (System > Status >
Appliance Monitoring) allows you to view the health metrics for a selected Arbor Networks
appliance. Each metric displays a different category of usage data for the appliance. For more
information about the Appliance Monitoring page, see "Monitoring Your Arbor Networks
Appliances" on page 360.
Note: You can click the name of a metric on this page to view that metric for all of your Arbor
Networks appliances on the Metric Comparison tab. See “About the Metric Comparison Tab
on the Appliance Monitoring Page” on page 374.
Viewing the metrics of an Arbor Networks appliance
To view the metrics of an Arbor Networks appliance:
1. Navigate to the Appliance Monitoring page (System > Status > Appliance
Monitoring).
2. Click the Per Appliance Metrics tab.
3. From the Displayed Appliance list, select the appliance.
All of the metrics are displayed for that appliance. For a description of each metric, see
“Appliance Metrics” on page 368. For information about the graphs that appear, see
“About the graphs on the Per Appliance Metrics tab of the Appliance Monitoring page” on
the facing page.
Note: By default, the metrics for the leader appliance are displayed.
4. From the Time Period options, select the time period for the data that you want to view.
See “Time periods for the Per Appliance Metrics tab of the Appliance Monitoring page”
below.
Note: When you select a time period on the Per Appliance Metrics tab, the same time
period is selected on the Metric Comparison tab on the Appliance Monitoring page
when you navigate to it.
Time periods for the Per Appliance Metrics tab of the Appliance Monitoring page
The time periods that you can select on the Per Appliance Metrics tab of the Appliance
Monitoring page have the following start and end times:
Predefined time period start and end times
366
Time Period
Start Time
End Time
Y (year)
52 weeks ago
Now
M (month)
28 days ago
Now
W (week)
7 days ago
Now
D (today)
24 hours ago
Now
Other
user-specified
user-specified
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
If you select Other, you can then type entries like the following in the Start and End boxes to
specify the date and time:
n 2 weeks ago
n
100 hours ago
n
last Monday
n
last sat of Jan 2016
n
yesterday noon
n
7 PM
n
t1415 (which means the time 14:15)
n
5 May (of the current year)
n
10/15/15 (mm/dd/yy)
n
2015-8-15 (yyyy-mm-dd)
n
20151010 (yyyymmdd)
About the graphs on the Per Appliance Metrics tab of the Appliance Monitoring page
The graphs are arranged so that the graphs for the metrics that most likely need attention
appear first. The graphs for the metrics with a configured limit appear first, followed by the
graphs without a configured limit. If a graph has a configured limit, then a dashed line appears
on the graph that represents the configured limit. A configured limit represents what is
considered to be the maximum amount of usage that should be seen for an appliance for that
metric.
Five of the metrics have limits that are configured by default. Because these default limits are
the same for all appliances, you will probably need to modify these limits for some of your
appliances. You can use the CLI to set and change any limits, including the default limits. See
“Default limits for appliance metrics” on the next page and "Configuring Limits for Appliance
Metrics" in the SP and TMS Advanced Configuration Guide.
SP determines the order of the graphs that have a configured limit by taking the highest point
on each graph and using this value to calculate its percentage of the graph's configured limit.
The higher the percentage, the higher the graph appears in the list. The graphs of the metrics
that do not have a configured limit appear in the Metrics Without Limits (Unknown Severity)
section. These graphs are sorted by the maximum data point on each graph. The larger the
maximum data point, the higher the graph of the metric appears in the list.
By default, the graphs on the Per Appliance Metrics tab of the Appliance Monitoring page
are colored gray. However, if a metric of an appliance has a configured limit, then the graph
becomes red if any part of the graph exceeds the limit.
Note: When SP aggregates the data for longer time periods, it uses an averaging process that
can eliminate peaks in the data. Consequently, a peak in the data that displays a metric
exceeding a configured limit when a short time period is selected may not display a metric
exceeding the limit when a longer time period is selected.
If more than one metric has a graph that exceeds its configured limit, then the graph for the
metric exceeding its limit by the largest percentage has the darkest shade of red. The shading
on the other graphs that are colored red is proportionately lighter based on the percentage by
which they exceed their configured limit.
When you hover your mouse pointer over a graph, a vertical line along with a pop-up window
appears on the graph at the location of the pointer. The pop-up window displays the time and
Proprietary and Confidential Information of Arbor Networks Inc.
367
SP and TMS User Guide, Version 8.0
the value of the metric at the point where the vertical line intersects the graph. If a limit has
been configured for the metric, the pop-up also displays the value of the limit.
Default limits for appliance metrics
The following metrics have default limits:
Metric
Default Limit
CPU load
15 (processes in the system run queue per 5 minutes)
Disk (data partition) used %
75%
Flows (Total) dropped per 5
minutes
50,000
Managed objects matched
per flow
8
Memory used %
85%
These default limits are set for all of the appliances in your deployment. You can use the CLI to
change a default limit for an individual appliance. For information about changing a limit for an
appliance metric, see "Configuring Limits for Appliance Metrics" in the SP and TMS
Advanced Configuration Guide.
Appliance Metrics
The following table describes all of the metrics that can appear on the Per Appliance
Metrics of the Appliance Monitoring page. The appliance type or role determines if data can
be displayed for a metric. A Flow Sensor appliance can display data for the same metrics as a
Traffic and Routing Analysis appliance.
Appliance metrics
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
BGP messages
received per
second
ݲ
ݲ
The average number of BGP messages
that the appliance received per second.
The average is based on 5-minute periods.
BGP peering
sessions
(Established)
ݲ
ݲ
The number of primary and secondary
BGP peering sessions that the appliance
has established with routers in your
deployment.
BGP peering
sessions
configured
ݲ
ݲ
The number of primary and secondary
BGP peering sessions that have been
configured on this appliance with routers
in your deployment.
368
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
BGP routes
ݲ
ݲ
The total number of active BGP routes on
the appliance.
CPU load
ݲ
ݲ
ݲ
ݲ
The average number of processes in the
system run queue during a 5 minute
period. By default, the configured limit is
15.
Note: This is the standard UNIX CPU load
measurement.
Disk (data
partition) used %
ݲ
ݲ
ݲ
ݲ
The percentage of the data partition of the
disk that is being used. By default, the
configured limit is 75%.
DoS alert refine
jobs
ݲ
Flow (ArborFlow)
bps sent
ݲ
ݲ
ݲ
The average amount of ArborFlow sent
from the appliance in bps during a
5-minute period.
Flow (ArborFlow)
pps sent
ݲ
ݲ
ݲ
The average amount of ArborFlow sent
from the appliance in pps during a
5-minute period.
Flow (Total) bps
received
ݲ
ݲ
The average amount of flow received by
the appliance in bps during a 5-minute
period.
Flow (Total) pps
received
ݲ
ݲ
The average amount of flow received by
the appliance in pps during a 5-minute
period.
Flows
(ArborFlow)
dropped per 5
minutes
ݲ
ݲ
The number of ArborFlow packets that
were dropped during a 5-minute period.
With a Flow Sensor appliance, it is the
number of packets that the appliance sent
that did not arrive. With any other
appliance, it is the number of packets that
the appliance did not receive based on
missing sequence numbers seen in
received flow.
Proprietary and Confidential Information of Arbor Networks Inc.
369
The number of DoS alert refine jobs that
are running on the appliance. A refine job
looks at the flow in order to update the
data for ongoing DoS alerts.
SP and TMS User Guide, Version 8.0
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
Flows
(ArborFlow)
received per
second
ݲ
Flows
(ArborFlow) sent
per second
ݲ
Flows (Core)
processed per
second
User
Interface
TMS
Data
Storage
Description
ݲ
The average number of ArborFlow records
that the appliance has received per
second during a 5-minute period.
ݲ
The average number of ArborFlow records
that the appliance has sent per second
during a 5-minute period.
ݲ
ݲ
The average number of flows per second
that passed through core routers and were
processed by the appliance during a
5-minute period. When flow is sampled,
an appliance only processes the sampled
flow.
Flows (Core)
received per
second
ݲ
ݲ
The average number of flows per second
that passed through core routers and were
received by the appliance during a
5-minute period.
Flows (Edge)
processed per
second
ݲ
ݲ
The average number of flows per second
that passed through edge routers and
were processed by the appliance during a
5-minute period. When flow is sampled,
an appliance only processes the sampled
flow.
Flows (Edge)
received per
second
ݲ
ݲ
The average number of flows per second
that passed through edge routers and
were received by the appliance during a
5-minute period.
Flows (Total)
dropped per 5
minutes
ݲ
ݲ
The total number of flows dropped during
a 5-minute period, based on missing
sequence numbers seen in received flows.
This counts both ArborFlow and router
flow that is dropped. By default, the
configured limit is 50,000.
370
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Flows (Total)
processed per
second
ݲ
ݲ
The total number of flows per second that
the appliance processed based on a 5minute period. This includes ArborFlow
that was received from TMS appliances
and Flow Sensor appliances (with
appliance-based licensing). When flow is
sampled, an appliance only processes the
sampled flow.
Flows (Total)
received per
second
ݲ
ݲ
The total number of flows received by the
appliance per second based on a 5minute period. This includes ArborFlow
that was received from TMS appliances
and Flow Sensor appliances (with
appliance-based licensing).
Interfaces in flow
per 5 minutes
ݲ
The number of interfaces that the
appliance monitored during a 5-minute
period. An interface is monitored only if
flow has been detected and classified.
Note: This number will never exceed the
licensed capacity for interfaces because
SP does not monitor interfaces that
exceed the licensed capacity.
Interfaces total
ݲ
The total number of interfaces that the
appliance has seen regardless of whether
flow has been detected at the interface.
Interfaces with
detailed
statistics tracked
ݲ
The number of interfaces that the
appliance monitored that have been
configured to collect detailed statistics or
that collect detailed statistics by default.
By default, external interfaces collect
detailed statistics. For more information
about configuring interfaces to collect
detailed statistics, see “Configuring
Interfaces” on page 150.
Items tracked per
5 minutes
ݲ
ݲ
The number of unique traffic items in the
database during a 5-minute period.
Items tracked per
day
ݲ
ݲ
The number of unique traffic items in the
database during the course of a day.
Proprietary and Confidential Information of Arbor Networks Inc.
371
SP and TMS User Guide, Version 8.0
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Managed
objects matched
in/out per
second
ݲ
ݲ
The average number of managed object
matches per second on the appliance
during a 5-minute period, but only for flow
that is In or Out.
Managed
objects matched
per flow
ݲ
ݲ
The average number of managed object
matches per flow on the appliance during
a 5-minute period. By default, the
configured limit is 8.
Managed
objects matched
per second
ݲ
ݲ
The average number of managed object
matches per second on the appliance
during a 5-minute period.
Managed
objects with data
stored
ݲ
ݲ
The total number of managed objects with
traffic data that has been added to the
database. This number includes VPN sites.
Memory used %
ݲ
ݲ
The percentage of the physical memory
that is being used. By default, the
configured limit is 85%.
Packets dropped
per second
ݲ
ݲ
The average number of flow packets
dropped per second during a 5-minute
period.
Packets received
per second
ݲ
ݲ
The average number of flow packets
received per second during a 5-minute
period.
Routers
configured
ݲ
The number of routers that the appliance
is configured to monitor.
Routers
configured for
SNMP polling
ݲ
The number of routers that the appliance
monitors that have been configured to
collect SNMP data.
Routers
responding to
SNMP polling
ݲ
The number of routers that are sending
SNMP data to the appliance.
Routers sending
flow
ݲ
The number of routers that are sending
flow to the appliance during a 5-minute
period.
372
ݲ
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
TMS devices
configured to
send ArborFlow
ݲ
The number of TMS appliances that are
configured to send ArborFlow to the
appliance.
TMS devices
managed
ݲ
The number of TMS appliances that the
appliance manages.
TMS devices
sending
ArborFlow
ݲ
The number of TMS appliances that are
sending ArborFlow to the appliance during
a 5-minute period.
TMS ongoing
mitigations
The number of ongoing mitigations running
on the TMS appliance.
ݲ
Traffic database
bytes read
(short-term)
ݲ
ݲ
The total number of bytes read from the
database during a 5-minute period. The
short-term database is used for merging
sample data into a day timeframe.
Traffic database
bytes written
(short-term)
ݲ
ݲ
The total number of bytes written to the
database during a 5-minute period. The
short-term database is used for merging
sample data into a day timeframe.
Traffic database
files (short-term)
ݲ
ݲ
The total number of files in the database
during a 5-minute period. The short-term
database is used for merging sample data
into a day timeframe.
Traffic database
run time
(long-term)
ݲ
ݲ
The number of seconds taken to merge
day samples into week, 4-week, and year
timeframes in the database. The long-term
database run merges sample data into
week, month, and year timeframes.
Traffic database
run time
(short-term)
ݲ
ݲ
The number of seconds taken to merge
each new 5-minute sample period into the
database. The short-term database run
merges sample data into a day timeframe.
Traffic database
write duration(s)
ݲ
ݲ
ݲ
The number of seconds it took to write
new samples to disk during a 5-minute
period. This data includes monitoring data
and traffic data.
Virtual memory
used %
ݲ
ݲ
ݲ
The percentage of virtual memory that is
being used.
ݲ
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
373
SP and TMS User Guide, Version 8.0
About the Metric Comparison Tab on the Appliance Monitoring
Page
Introduction
The Metric Comparison tab on the Appliance Monitoring page (System > Status >
Appliance Monitoring) allows you to view a health metric for all of your Arbor Networks
appliances. Each metric displays different usage data for the appliances. For more information
about the Appliance Monitoring page, see "Monitoring Your Arbor Networks Appliances" on
page 360.
The appliance type or role determines if data is displayed for a given metric. For a description of
the different metrics and the appliance type or role for which data is displayed, see “Appliance
Metrics” on page 377.
Viewing the usage of your Arbor Networks appliances
To view the usage of your Arbor Networks appliances:
1. Navigate to the Appliance Monitoring page (System > Status > Appliance
Monitoring).
2. Click the Metric Comparison tab.
3. From the Time Period options, select the time period for the data that you want to view.
See “Time periods for the metrics on Metric Comparison tab of the Appliance Monitoring
page” on the facing page.
Note: When you select a time period on the Metric Comparison tab, the same time
period is selected on the Per Appliance Metrics tab on the Appliance Monitoring page
when you navigate to it.
4. Select a metric from the Metric 1 list.
For a description of each metric, see “Appliance Metrics” on page 377. For information
about the graphs that appear, see “About the graphs on the Metric Comparison tab of the
Appliance Monitoring page” on the facing page.
Note: You can use the
(context menu) icon that precedes the name of an appliance to
display all of the metrics for that appliance on the Per Appliance Metrics tab or to
access the Edit Appliance page for that appliance. See “About the context menu icon that
precedes an appliance name” on page 376.
Note: The graph of a metric can take up to 10 minutes to update after changes are made
to an appliance.
374
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Time periods for the metrics on Metric Comparison tab of the Appliance Monitoring
page
The time periods that you can select on the Metric Comparison tab of the Appliance
Monitoring page have the following start and end times:
Predefined time period start and end times
Time Period
Start Time
End Time
Y (year)
52 weeks ago
Now
M (month)
28 days ago
Now
W (week)
7 days ago
Now
D (today)
24 hours ago
Now
Other
user-specified
user-specified
If you select Other, you can then type entries like the following in the Start and End boxes to
specify the date and time:
n 2 weeks ago
n
100 hours ago
n
last Monday
n
last sat of Jan 2016
n
yesterday noon
n
7 PM
n
t1415 (which means the time 14:15)
n
5 May (of the current year)
n
10/15/15 (mm/dd/yy)
n
2015-8-15 (yyyy-mm-dd)
n
20151010 (yyyymmdd)
About the graphs on the Metric Comparison tab of the Appliance Monitoring page
The graphs are arranged so that the graphs for the appliances that most likely need attention
appear first. The appliances that have a configured limit for a metric appear first, followed by
the graphs without a configured limit. If a graph has a configured limit, then a dashed line
appears on the graph. A configured limit represents what is considered to be the maximum
amount of usage that should be seen for an appliance for that metric.
Five of the metrics have limits that are configured by default. Because these default limits are
the same for all appliances, you will probably need to modify these limits for some of your
appliances. You can use the CLI to set and change any limits, including the default limits. See
“Default limits for appliance metrics” on the next page and "Configuring Limits for Appliance
Metrics" in the SP and TMS Advanced Configuration Guide.
SP determines the order of the appliances that have a configured limit for a metric by taking the
highest point on each graph and using this value to calculate its percentage of the configured
limit on that graph. The higher the percentage, the higher the appliance appears in the list. The
Proprietary and Confidential Information of Arbor Networks Inc.
375
SP and TMS User Guide, Version 8.0
appliances that do not have a configured metric limit are sorted by the maximum data point on
each graph. The larger the maximum data point, the higher the appliance appears in the list.
By default, the graphs on the Metric Comparison tab of the Appliance Monitoring page are
colored gray. However, if a selected metric has an appliance with a configured limit, then its
graph becomes red if any part of the graph exceeds the limit.
Note: When SP aggregates the data for longer time periods, it uses an averaging process that
can eliminate peaks in the data. Consequently, a peak in the data that displays a metric
exceeding a configured limit when a short time period is selected may not display a metric
exceeding the limit when a longer time period is selected.
If more than one appliance has a graph that exceeds its configured limit, then the graph for the
metric exceeding its limit by the largest percentage has the darkest shade of red. The shading
on the other graphs that are colored red becomes proportionately lighter as the percentage by
which they exceed their configured limit becomes smaller.
When you hover your mouse pointer over a graph, a vertical line along with a pop-up window
appears on the graph at the location of the pointer. The pop-up window displays the time and
the value of the metric at the point where the vertical line intersects the graph. If a limit has
been configured for the metric, the pop-up also displays the value of the limit.
About the context menu icon that precedes an appliance name
A
(context menu) icon precedes each appliance name on the Metric Comparison tab of
the Appliance Monitoring page. The
icon becomes more visible when you hover you mouse
pointer over it. When you click , the following options appear:
n View Per Appliance Metrics
Allows you to see all of the metrics for that appliance on the Per Appliance Metrics tab
of the Appliance Monitoring page.
n
Edit Appliance
Allows you to edit the appliance's configuration on the the Edit Appliance page.
Default limits for appliance metrics
The following metrics have default limits:
Metric
Default Limit
CPU load
15 (processes in the system run queue per 5 minutes)
Disk (data partition) used %
75%
Flows (Total) dropped per 5
minutes
50,000
Managed objects matched
per flow
8
Memory used %
85%
These default limits are set for all of the appliances in your deployment. You can use the CLI to
change a default limit for an individual appliance. For information about changing a limit for an
appliance metric, see "Configuring Limits for Appliance Metrics" in the SP and TMS
Advanced Configuration Guide.
376
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance Metrics
The following table describes all of the metrics that you can select on the Metric
Comparison tab of the Appliance Monitoring page. The appliance type or role determines if
data can be displayed for a selected metric. A Flow Sensor appliance can display data for the
same metrics as a Traffic and Routing Analysis appliance.
Appliance metrics
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
BGP messages
received per
second
ݲ
ݲ
The average number of BGP messages
that the appliance received per second.
The average is based on 5-minute periods.
BGP peering
sessions
(Established)
ݲ
ݲ
The number of primary and secondary
BGP peering sessions that the appliance
has established with routers in your
deployment.
BGP peering
sessions
configured
ݲ
ݲ
The number of primary and secondary
BGP peering sessions that have been
configured on this appliance with routers
in your deployment.
BGP routes
ݲ
ݲ
The total number of active BGP routes on
the appliance.
CPU load
ݲ
ݲ
ݲ
ݲ
The average number of processes in the
system run queue during a 5 minute
period. By default, the configured limit is
15.
Note: This is the standard UNIX CPU load
measurement.
Disk (data
partition) used %
ݲ
ݲ
ݲ
ݲ
The percentage of the data partition of the
disk that is being used. By default, the
configured limit is 75%.
DoS alert refine
jobs
ݲ
Flow (ArborFlow)
bps sent
ݲ
The number of DoS alert refine jobs that
are running on the appliance. A refine job
looks at the flow in order to update the
data for ongoing DoS alerts.
ݲ
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
The average amount of ArborFlow sent
from the appliance in bps during a
5-minute period.
377
SP and TMS User Guide, Version 8.0
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
ݲ
ݲ
The average amount of ArborFlow sent
from the appliance in pps during a
5-minute period.
Description
Flow (ArborFlow)
pps sent
ݲ
Flow (Total) bps
received
ݲ
ݲ
The average amount of flow received by
the appliance in bps during a 5-minute
period.
Flow (Total) pps
received
ݲ
ݲ
The average amount of flow received by
the appliance in pps during a 5-minute
period.
Flows
(ArborFlow)
dropped per 5
minutes
ݲ
ݲ
The number of ArborFlow packets that
were dropped during a 5-minute period.
With a Flow Sensor appliance, it is the
number of packets that the appliance sent
that did not arrive. With any other
appliance, it is the number of packets that
the appliance did not receive based on
missing sequence numbers seen in
received flow.
Flows
(ArborFlow)
received per
second
ݲ
ݲ
The average number of ArborFlow records
that the appliance has received per
second during a 5-minute period.
Flows
(ArborFlow) sent
per second
ݲ
ݲ
The average number of ArborFlow records
that the appliance has sent per second
during a 5-minute period.
Flows (Core)
processed per
second
ݲ
ݲ
The average number of flows per second
that passed through core routers and were
processed by the appliance during a
5-minute period. When flow is sampled,
an appliance only processes the sampled
flow.
Flows (Core)
received per
second
ݲ
ݲ
The average number of flows per second
that passed through core routers and were
received by the appliance during a
5-minute period.
378
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Flows (Edge)
processed per
second
ݲ
ݲ
The average number of flows per second
that passed through edge routers and
were processed by the appliance during a
5-minute period. When flow is sampled,
an appliance only processes the sampled
flow.
Flows (Edge)
received per
second
ݲ
ݲ
The average number of flows per second
that passed through edge routers and
were received by the appliance during a
5-minute period.
Flows (Total)
dropped per 5
minutes
ݲ
ݲ
The total number of flows dropped during
a 5-minute period, based on missing
sequence numbers seen in received flows.
This counts both ArborFlow and router
flow that is dropped. By default, the
configured limit is 50,000.
Flows (Total)
processed per
second
ݲ
ݲ
The total number of flows per second that
the appliance processed based on a 5minute period. This includes ArborFlow
that was received from TMS appliances
and Flow Sensor appliances (with
appliance-based licensing). When flow is
sampled, an appliance only processes the
sampled flow.
Flows (Total)
received per
second
ݲ
ݲ
The total number of flows received by the
appliance per second based on a 5minute period. This includes ArborFlow
that was received from TMS appliances
and Flow Sensor appliances (with
appliance-based licensing).
Interfaces in flow
per 5 minutes
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
The number of interfaces that the
appliance monitored during a 5-minute
period. An interface is monitored only if
flow has been detected and classified.
Note: This number will never exceed the
licensed capacity for interfaces because
SP does not monitor interfaces that
exceed the licensed capacity.
379
SP and TMS User Guide, Version 8.0
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Interfaces total
ݲ
The total number of interfaces that the
appliance has seen regardless of whether
flow has been detected at the interface.
Interfaces with
detailed
statistics tracked
ݲ
The number of interfaces that the
appliance monitored that have been
configured to collect detailed statistics or
that collect detailed statistics by default.
By default, external interfaces collect
detailed statistics. For more information
about configuring interfaces to collect
detailed statistics, see “Configuring
Interfaces” on page 150.
Items tracked per
5 minutes
ݲ
ݲ
The number of unique traffic items in the
database during a 5-minute period.
Items tracked per
day
ݲ
ݲ
The number of unique traffic items in the
database during the course of a day.
Managed
objects matched
in/out per
second
ݲ
ݲ
The average number of managed object
matches per second on the appliance
during a 5-minute period, but only for flow
that is In or Out.
Managed
objects matched
per flow
ݲ
ݲ
The average number of managed object
matches per flow on the appliance during
a 5-minute period. By default, the
configured limit is 8.
Managed
objects matched
per second
ݲ
ݲ
The average number of managed object
matches per second on the appliance
during a 5-minute period.
Managed
objects with data
stored
ݲ
ݲ
The total number of managed objects with
traffic data that has been added to the
database. This number includes VPN sites.
Memory used %
ݲ
ݲ
The percentage of the physical memory
that is being used. By default, the
configured limit is 85%.
Packets dropped
per second
ݲ
ݲ
The average number of flow packets
dropped per second during a 5-minute
period.
380
ݲ
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
TMS
Data
Storage
Description
Packets received
per second
ݲ
Routers
configured
ݲ
The number of routers that the appliance
is configured to monitor.
Routers
configured for
SNMP polling
ݲ
The number of routers that the appliance
monitors that have been configured to
collect SNMP data.
Routers
responding to
SNMP polling
ݲ
The number of routers that are sending
SNMP data to the appliance.
Routers sending
flow
ݲ
The number of routers that are sending
flow to the appliance during a 5-minute
period.
TMS devices
configured to
send ArborFlow
ݲ
The number of TMS appliances that are
configured to send ArborFlow to the
appliance.
TMS devices
managed
ݲ
The number of TMS appliances that the
appliance manages.
TMS devices
sending
ArborFlow
ݲ
The number of TMS appliances that are
sending ArborFlow to the appliance during
a 5-minute period.
TMS ongoing
mitigations
ݲ
The average number of flow packets
received per second during a 5-minute
period.
The number of ongoing mitigations running
on the TMS appliance.
ݲ
Traffic database
bytes read
(short-term)
ݲ
ݲ
The total number of bytes read from the
database during a 5-minute period. The
short-term database is used for merging
sample data into a day timeframe.
Traffic database
bytes written
(short-term)
ݲ
ݲ
The total number of bytes written to the
database during a 5-minute period. The
short-term database is used for merging
sample data into a day timeframe.
Proprietary and Confidential Information of Arbor Networks Inc.
381
SP and TMS User Guide, Version 8.0
Appliance metrics (Continued)
Appliance Type or Role for Which Data
is Displayed
Metric
Traffic &
Routing
Analysis
User
Interface
Traffic database
files (short-term)
ݲ
Traffic database
run time
(long-term)
ݲ
Traffic database
run time
(short-term)
ݲ
Traffic database
write duration(s)
ݲ
ݲ
Virtual memory
used %
ݲ
ݲ
382
TMS
ݲ
ݲ
Data
Storage
Description
ݲ
The total number of files in the database
during a 5-minute period. The short-term
database is used for merging sample data
into a day timeframe.
ݲ
The number of seconds taken to merge
day samples into week, 4-week, and year
timeframes in the database. The long-term
database run merges sample data into
week, month, and year timeframes.
ݲ
The number of seconds taken to merge
each new 5-minute sample period into the
database. The short-term database run
merges sample data into a day timeframe.
ݲ
The number of seconds it took to write
new samples to disk during a 5-minute
period. This data includes monitoring data
and traffic data.
ݲ
The percentage of virtual memory that is
being used.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Viewing ArborFlow Statistics
Introduction
You can verify that your SP appliances are communicating ArborFlow properly by viewing the
ArborFlow Sent From and Received By page (System > Status > ArborFlow Statistics).
SP bins and archives ArborFlow statistics, and this page displays the sent and received
ArborFlow statistics for appliances.
Viewing ArborFlow statistics for an appliance
To view ArborFlow statistics for an appliance, follow the steps below:
1. Navigate to the ArborFlow Sent From and Received By page (System > Status >
ArborFlow Statistics).
2. Click Select Appliance to select an appliance.
3. Select a time period from the Period list, and then click Update.
The granularity of the data depends on the time period selected. For more information, see
“Data granularity for reports” on page 756.
About the ArborFlow Sent section
The ArborFlow Sent section displays a graph of the amount of ArborFlow that an appliance
sent over the selected period of time. The data table displays the following information:
ArborFlow Sent section data table information
Column
Description
Appliance
The name of an SP appliance.
FPS
The flows per second that an appliance sent.
bps
The bits per second that an appliance sent.
pps
The packets per second that an appliance sent.
Dropped
The amount of dropped flow.
About the ArborFlow Received section
The ArborFlow Received section displays a graph of the amount of ArborFlow that an
appliance received over the selected period of time. The data table displays the following
information:
ArborFlow Received section data table information
Column
Description
Appliance
The name of the SP appliance.
FPS
The flows per second that the appliance received.
bps
The bits per second that the appliance received.
Proprietary and Confidential Information of Arbor Networks Inc.
383
SP and TMS User Guide, Version 8.0
ArborFlow Received section data table information (Continued)
384
Column
Description
pps
The packets per second that the appliance received.
Dropped
The amount of dropped flow.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Monitoring Account Status
Introduction
You can monitor who accesses your SP appliances and the amount of time that they spend
logged in to the system on the Account Login History page (System > Status > Account
History).
About the Account Login History page
The table on the Account Login History page displays the following information:
Account Login History page information
Column
Description
Account
Name
The user name of an account.
Appliance
The Web UI appliance to which a user connects.
From
The IP address from which a user logged in.
Type
The UI type to which a user logged in.
Login Time
The time at which a user logged in to an appliance.
Duration
(H:M:S)
The amount of time that the user was or has been logged in to an appliance.
SP displays currently on when users are currently logged in to the Web UI.
Note: SP updates the duration every 5 minutes when the page reloads.
Searching login history
To search the login history on the Account Login History page:
1. Navigate to Account Login History page (System > Status > Account History).
2. Select an appliance from the Choose Appliance list.
3. Select the time period for which you are searching from the Period list.
Note: If you select Other, then you must select or type a start and end date or time.
4. Type the XVHU QDPH of the user for which you are searching in the User box, and then
click Update.
Note: You can search using % as a variable-length string. For example, a% matches
alpha, admin, and aardvark. Ad% matches admin and adrenaline.
Tip: You can also press ENTER to update the page with the user name criteria.
Proprietary and Confidential Information of Arbor Networks Inc.
385
SP and TMS User Guide, Version 8.0
Monitoring Routers
Introduction
You can view real-time snapshots of router traffic rates and connectivity information on the
Router Status page (System > Status > Routers).
Viewing router status information
To view router status information:
1. Navigate to the Router Status page (System > Status > Routers).
2. Select the type of data that you want to view from the Graph list.
3. Select the timeframe of data that you want to view from the Period list.
Note: The graph automatically updates after each selection.
About the router status table
By default, the routers that appear at the top of the list are more likely to need your attention. If
a router is down or if it has a configured BGP session that is down, it appears at the top of the
list with a (red alert) icon in the Score column. If a router is working properly, it is given a
score that is used to determine where it appears in the list. The higher a router's score, the
higher it appears in the list. For information on what determines a router's score, see “About a
router's score” on page 388.
The router status table contains the following information:
Router status table information
Column
(expand)
386
Description
When you click , an additional pane with detailed router information
appears.
Name
The name of the router. You can click this name link to view the router
configuration page.
With Flexible Licensing, the router's license type appears after the
router name. A router's license type can be core, edge, or unset.
License Type
The type of license that applies to the router. If the router is managed by
an appliance in appliance-based license mode, then the license type is
Appliance-based and the router counts against the licensed capacity
of that appliance. If the router is managed by an appliance in flexible
license mode, then the license type is either Core, Edge, or Unset.
When the license type is Core or Edge, then the router is counted
against the flexible-licensed capacity of your core routers or edge
routers.
This column appears only if a flexible license has been uploaded. See
“Uploading a Flexible License” on page 92.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Router status table information (Continued)
Column
Description
Appliance
The name of the appliance that is managing the router.
The
(in-progress) icon appears after an appliance name when the
router is in the process of being reassigned to that appliance. When the
reassignment is complete, the
(done) icon appears after an
appliance name for one minute. The
(pending commit) icon appears
after an appliance name when the router has been reassigned to that
appliance, and the configuration change has been saved but not
committed. If you hover the mouse pointer over either of these icons,
SP displays information about the reassignment process.
Note: A status message also appears at the top of the page when
routers are being reassigned to appliances and when the reassignment
is complete.
Bit Rates, Total
Moving average of traffic.
Bit Rates, ACL’ed
Moving average of the traffic that enters the router but does not leave
the router because of the Access Control List. This traffic is
represented in a flow record with a valid input interface, but with 0 as
the output interface.
Flows/s
The average number of flows per second.
Flow Last Seen
The amount of time elapsed since the last flow record was received. If
this time exceeds 30 seconds, then the text is orange. If the time
exceeds one minute, then the text is red.
For a description of the notifications that can appear instead of a value,
see “Router status table notifications” on page 390.
SNMP
The status of the current CPU and memory use from a router’s primary
route processor.
For a description of the notifications that can appear instead of a value,
see “Router status table notifications” on page 390.
Active Routes
(BGP)
The number of active BGP routes announced by this router (if BGP
peering with this router is enabled), followed by the number of VPNs in
parentheses.
For a description of the notifications that can appear instead of a value,
see “Router status table notifications” on page 390.
Score
If a router is down or if it has a configured BGP session that is down, a
(red alert) icon appears in this column. If a router is working properly,
a bar graph appears that provides a visual display of the router's score
in comparison with the other routers. The router with the highest score
will have a bar graph that fills the Score column. The length of the bar
graph for the other routers is proportional to that of the router with the
highest score. For information on how a router's score is determined,
see “About a router's score” on the next page.
If a router is not configured for SNMP, BGP, and flow, then it does not
have a bar graph. If none of the routers are being utilized, then none of
them will have a bar graph.
Proprietary and Confidential Information of Arbor Networks Inc.
387
SP and TMS User Guide, Version 8.0
About a router's score
Each of the following criteria plays an equal role in determining the score that a router is
assigned:
n Flows per second
n
SNMP-reported CPU usage
n
SNMP-reported memory usage
n
Number of active routes
n
Number of alerts
n
Number of interfaces
The score that is assigned to a router increases as the values associated with these criteria
increase.
About searching on the Router Status page
To search on the Router Status page, you can use any the following:
the Search box
n
See “Guidelines for searching on the Router Status page” below.
n
the Appliance list
The Appliance list allows you to filter by the managing appliance. You can select All or a
specific appliance. When you select an appliance, the keywords and search values for the
appliance appear in the Search box and the search is performed.
n
the "Filter by license type" links
The Appliance-based, Core, Edge, and Unset links allow you to filter by license type.
When you click a “Filter by license type” link, the keywords and search values for the license
type appear in the Search box and the search is performed. These links appear only if a
flexible license has been uploaded on the Deployment Status page. See “Uploading a
Flexible License” on page 92.
These links work as follows:
l
l
The Appliance-based link filters the list of routers to display only routers that are
managed by an appliance in the appliance-based license mode.
The Core, Edge, and Unset links filter the list of routers to display core, edge, or unset
routers that are managed by an appliance in flexible license mode.
Guidelines for searching on the Router Status page
Below are guidelines for using the Search box:
You can enter search values with or without keywords.
n
388
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on specific columns, search for a router's primary or
secondary BGP session name, or search for a router's license type.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
n
You can enter multiple keyword and value sets with a space between each set. This type of
search returns the routers that match all of the keyword and value sets. For example,
name:router123 type:core returns all the core routers that have the text string
"router123" in the name of the router.
See “Acceptable search keywords and values for routers” below.
Acceptable search keywords and values for routers
The following table lists the keywords and values that you can use to search in the Search box
on the Router Status page:
Search keywords for items
Items to search
on
Acceptable keywords
and values
name
n
name:URXWHU QDPH
n
name:router123
license type
n
type:OLFHQVH W\SH
license_
type:OLFHQVH W\SH
n
type:core
license_type:unset
appliance:PDQDJLQJ
DSSOLDQFH
collector:PDQDJLQJ
DSSOLDQFH
manager:PDQDJLQJ
DSSOLDQFH
n
tag:URXWHU WDJ
tags:URXWHU WDJ
n
descr:URXWHU
GHVFULSWLRQ
sysdescr:URXWHU
GHVFULSWLRQ
description:URXWHU
GHVFULSWLRQ
n
n
appliance
n
n
n
tags
n
n
description
n
n
n
Examples
n
n
n
n
n
n
appliance:appliance_231
collector:appliance_345
manager:appliance_412
tag:east_region
tags:midwest_region
descr:router123
sysdescr:"router in xyz"
description:"router in abc"
Note: This keyword searches on the
SNMP System Description.
primary BGP
session
n
primary_bgp_
session:VHVVLRQ
QDPH
n
primary_bgp_session:primary123
secondary BGP
session
n
secondary_bgp_
session:VHVVLRQ
QDPH
n
secondary_bgp_
session:secondary123
Proprietary and Confidential Information of Arbor Networks Inc.
389
SP and TMS User Guide, Version 8.0
Router status table notifications
The following table lists the notifications that can appear in the last four columns of the router
status table instead of a value. The only notification that can appear in the Flow Last Seen
column is Never or No Heartbeat. The only notifications that can appear in the Active Routes
(BGP) column are Down, Not Configured, and No Heartbeat.
Router status table notifications
390
Notification
Description
Down
SNMP connectivity is configured but down. With Active Routes
(BGP), this includes a description of the session that is down.
Never
No flow has ever been seen from this router.
No Heartbeat
The leader has not received a heartbeat from this router's
managing appliance for at least two minutes.
Not Configured
SNMP is not configured for this router.
Uninitialized
SNMP connectivity has not yet been polled.
Unknown
SNMP connectivity is up, but SP could not successfully query the
information from the router.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Monitoring Interfaces
Introduction
You can view real-time snapshots of interface traffic rates on the Interface Status page
(System > Status > Interfaces). You can edit, download, and email the status information
on this page.
For information about the
(download) and
(email) icons on the Arbor Smart Bar, see
“About the Arbor Smart Bar ” on page 28.
Viewing router interface information
To view a router’s interface information:
1. Navigate to the Interface Status page (System > Status > Interfaces).
2. From the routers list at the top of the page, select the router whose interface information
you want to view.
To filter the list, type any part of the name of a router that does not include a space.
3. Click Update.
About the Interface Status table
The Interface Status table contains the following information:
Interface Status table information
Column
Description
SNMP
Index
The SNMP index of a selected interface.
Name
The name of an interface. The name is one of the following:
n
n
n
user-configured
SNMP-learned
the string index:y, where y is the SNMP interface index
Description
A user-configured or SNMP-learned interface description.
Type
An auto-classified or user-configured interface type. An interface type can be
one of the following:
n
n
n
n
n
internal
external
backbone
mixed
ignore
Speed
The user-configured or SNMP-learned link speed of an interface, if available.
In
The current incoming traffic rate of an interface, as determined by monitored
flow records.
Out
The current outgoing traffic rate of an interface, as determined by monitored
flow records.
Proprietary and Confidential Information of Arbor Networks Inc.
391
SP and TMS User Guide, Version 8.0
Interface Status table information (Continued)
392
Column
Description
Dropped
The amount of dropped traffic on an interface, as determined by monitored
flow records.
Multicast
The amount of multicast traffic entering your network through an interface.
Multicast allows traffic to be sent from one host to many hosts simultaneously.
This potentially uses less bandwidth. Multicast traffic is traffic sent from one
source address to one destination address that many people share, called a
multicast address.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Monitoring Interface Configuration
Introduction
SP allows you to view the configurations of interface classification to understand why the
system collects the traffic data it does based on the configuration. The Auto-Configuration
menu is useful for doing the following:
n understanding why peer traffic changes
n
understanding why the system reports on certain traffic for a given peer or external customer
n
finding the interfaces that peer with a particular AS currently or in the past
For information on how SP classifies interfaces automatically, see “About Interface
Classification” on page 119
About the Current Interface Configuration page
The Current Interface Configuration page (Administration > Monitoring > Current
Interface Configuration) displays the current classification information for the configured
interfaces.
Note: The Differences Between Revisions page displays the same information as the Current
Interface Configuration page.
See “Viewing revision differences” on the next page.
The following table describes the table on the Current Interface Configuration page:
Current Interface Configuration page information
Column
Description
Router
The name of the associated router.
Index
The SNMP index number of an interface.
Name/Description
The name and description of an interface connected to the router.
Speed
The speed of an interface.
Traffic
The amount of traffic that flows into and out of an interface.
IP
The IP address assigned to an interface.
Classification
An interface’s associated ASNs, type, and regex rule.
Boundaries
The boundary information associated with the interface, including its
managed object, boundary perspective, and rule.
About the Interface Configuration Version <number> page
The Interface Configuration Version <number> page displays the same information as the
Current Integration Configuration page, but it displays the information for the configuration
version that you select. You can select a configuration version on the Interface Configuration
History page. See “Monitoring Interface Configuration History” on the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
393
SP and TMS User Guide, Version 8.0
Monitoring Interface Configuration History
Introduction
You can view current and previous versions of interface classifications on the Interface
Configuration History page (Administration > Monitoring > Interface Configuration
History).
Limiting the number of revisions to display
By default, SP does not limit the number of revisions displayed on the Interface Configuration
History page. If you want to expedite page load, then you can set a maximum number of
revisions to display using the CLI.
See “Overriding the Number of Configuration Changes Shown on the Interface Configuration
History Page” in the SP and TMS Advanced Configuration Guide.
About the Interface Configuration History page
The Interface Configuration History page displays the following information:
Interface Configuration History page information
Column
Description
Revision
The revision number, as a link to the Interface Configuration Version
<number> page. The page displays information for that revision.
Date
The date the user committed the revision.
Log Message
The log message for the revision.
Diff to previous
A link to the Differences between revisions page.
Viewing revision differences
To view revision differences:
1. Navigate to the Interface Configuration History page (Administration > Monitoring >
Interface Configuration History).
2. Use one of the following methods:
Method
Procedure
Method 1
Locate a revision that you want to view, and then click Diff to
previous. The Differences between revisions page appears.
Method 2
a. Click View Other Differences.
b. Type the two revision QXPEHUV that you want to compare in
the text boxes, and then click Update.
The Differences Between Revisions page appears.
See “About the Differences Between Revisions page” on the facing page.
394
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
About the Differences Between Revisions page
The table on the Differences Between Revisions page contains the same information as the
Current Interface Configuration page table, but it also displays a + or - to indicate what was
added to or deleted from the configuration.
See “About the Current Interface Configuration page” on page 393 and “Viewing revision
differences” on the previous page.
Proprietary and Confidential Information of Arbor Networks Inc.
395
SP and TMS User Guide, Version 8.0
Monitoring the Syslog
Introduction
You can use the System Logging (Syslog) page (System > Logging) to help you
troubleshoot the system. System logging is always enabled to facilitate troubleshooting and
issue resolution. Syslog messages occur regularly and in response to specific events. You can
edit, download, and email the information on this page.
For information about the
(download) and
(email) icons on the Arbor Smart Bar, see
“About the Arbor Smart Bar ” on page 28.
Viewing Syslog information
1. Navigate to the System Logging page (System > Logging).
2. Click Select Resource, select an appliance, and click OK.
3. Click Update.
Note: You can access the entire Syslog using the CLI.
About the System Logging page
The System Logging page displays the latest event entries for an appliance in the system log.
Syslog events are displayed in order, from oldest to most recent.
Editing the logging report
The data that appears on the System Logging page is generated by the classic XML logging
report. To edit this report, click Edit in the upper-right corner of the page.
See “Configuring Classic XML Reports” on page 878.
396
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Viewing Flow Tuning Data
Introduction
SP uses the Flow Tuning page (System > Tuning) to provide proof of data reporting
accuracy.
The Flow Tuning page displays a graph of the flow and SNMP traffic for a router and a table of
traffic for each interface on the router. This allows you to compare the flow with SNMP. This
flow is used to determine traffic rates throughout all of the system’s reports.
Viewing data on the Flow Tuning page
To view data on the Flow Tuning page, follow the steps below:
1. Navigate to the Flow Tuning page (System > Tuning).
2. Click Select Router to select a router.
3. Select a timeframe for the data from the Period list, and then click Update.
The granularity of the data depends on the time period selected. For more information, see
“Data granularity for reports” on page 756
4. To select a type of data calculation, click Current, Average, Max, or PCT95.
For more information about data calculation, see “Report data calculation options” on
page 760.
About the flow tuning table
The flow tuning table contains the following information:
Flow tuning table information
Column
Description
Indicates whether an interface’s traffic is displayed in the graph.
Interface
The name of an interface on the selected router.
SNMP Index
The SNMP index number for an interface.
In (Flow / SNMP)
The flow and SNMP traffic rates flowing into an interface.
In Ratio
The computed ratio of flow to SNMP traffic that is flowing into an
interface. This ratio is a measure of the difference between
inbound flow and SNMP traffic.
Out (Flow / SNMP)
The flow and SNMP traffic rates flowing out of an interface.
Out Ratio
The computed ratio of flow to SNMP traffic that is flowing out of
an interface. This ratio is a measure of the difference between
outbound flow and SNMP traffic.
Total (Flow / SNMP)
The total flow and SNMP traffic rate flowing into and out of an
interface.
Proprietary and Confidential Information of Arbor Networks Inc.
397
SP and TMS User Guide, Version 8.0
Monitoring SOAP Activity
Introduction
You can use the SOAP Activity page (System > SOAP Activity) to view a log of all SOAP
API calls that were made to the appliance that you are using. The appliance must have the user
interface role or the traffic and routing analysis role.
Monitoring SOAP activity
To view a log of SOAP API activity for an appliance that has the user interface role or the
traffic and routing analysis role, navigate to the SOAP Activity page (System > SOAP
Activity). SP displays activity data for each account that has accessed SP data on the
appliance using the SOAP API.
398
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 14: Monitoring the System
Monitoring the UI Status
Introduction
You can view information about the performance of the SP Web UI on the Recent Page Loads
page (System > UI). This page includes a log of Web UI usage and the amount of system
time that is spent generating each page. This is useful for determining when Web UI
slowdowns are the result of bottlenecks within SP or when they are the result of network
problems.
Recent Page Loads page
The Recent Page Loads page displays information about the last 100 page loads, in order,
from oldest to most recent. The page includes the following information:
Recent Page Loads page information
Column
Description
Date
The date and time when a page was loaded.
User
The user who loaded a page.
From
The IP address on which a page was loaded.
Report
The page loaded.
Avg. Load Time
(number of page
views)
The number of seconds SP took to build a page. The number of page
views is the number of times that someone has loaded that particular
page in their browser.
Proprietary and Confidential Information of Arbor Networks Inc.
399
SP and TMS User Guide, Version 8.0
400
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15:
System Maintenance
Introduction
This section describes how to maintain your SP deployment.
User access
Administrators can perform all actions described in this section. Non-administrative users can
view the configurations but cannot make changes.
In this section
This section contains the following topics:
Maintaining SP Configurations
402
Managing System Backups
406
Deleting Alerts
411
Deleting Traffic Reports
413
Enabling Software Updates
414
Configuring Network Services
415
SP and TMS User Guide, Version 8.0
401
SP and TMS User Guide, Version 8.0
Maintaining SP Configurations
Introduction
You can export, import, commit changes to, and view the history of your SP configuration from
the Config Version menu (Administration > System Maintenance > Config Version).
Viewing uncommitted configuration changes
To view your uncommitted configuration changes:
Navigate to the Configuration Commit page (Administration > System Maintenance
> Config Version > Commit).
n
The uncommitted configuration changes are listed in the Configuration Changes box.
Committing configuration changes
When you make a configuration change, you must “commit” it in order for the changes to go
into effect. You can commit configuration changes on the Configuration Commit page
(Administration > System Maintenance > Config Version > Commit) or from any
page in the Web UI.
To commit configuration changes:
1. Do one of the following:
l
Click the Config Commit button in the upper-right corner of the Web UI page.
l
Navigate to the Configuration Commit page (Administration > System
Maintenance > Config Version > Commit).
2. (Optional) Type a ORJ PHVVDJH to describe the changes.
3. From the Select Commit Scope list, select the scope for the changes that you want to
commit.
You can select All, Nonscoped, or any scoped account group that has been created and
that has at least one user. If you select Nonscoped, then any changes that nonscoped
users can make are committed. If you select a specific scoped account group, then any
changes that users in that account group can make are committed.
Note: This list does not appear for scoped users.
4. Click Commit.
About the Configuration History/Rollback page
You can view and “roll back” to previously saved configurations on the Configuration
History/Rollback page (Administration > System Maintenance > Config Version >
History).
Configuration history is displayed in a table that contains the following information:
Configuration history table information
402
Column
Description
Version
The configuration version.
Date
The time and date when a version was committed.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
Configuration history table information (Continued)
Column
Description
User
The user who committed a configuration version.
Log Message
The descriptive message for a configuration version.
Rollback?
The Rollback link allows you to revert the system to an earlier
configuration.
You can use any of the following methods to locate specific configurations on the
Configuration History/Rollback page:
n Search for the configurations
See “Guidelines for searching on the Configuration History/Rollback page” below and
“Acceptable search keywords and values for configurations” on the next page.
n
Sort the configuration data by column
See “Sorting data tables” on page 29.
n
Navigate between different pages of configurations
See “Navigating multiple pages” on page 30.
Guidelines for searching on the Configuration History/Rollback page
When you search with the Search box, use the following guidelines:
You can enter search values with or without keywords.
n
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A comma between search values creates an OR statement.
You can enter multiple keyword and value sets with a space between each set. This type of
search returns the configuration versions that match all of the keyword and value sets. For
example, version:1.3 user:admin returns all the configuration versions that have the
text string "1.3" in the Version column of the configuration and the text string "admin" in the
User column of the configuration.
n
See “Acceptable search keywords and values for configurations” on the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
403
SP and TMS User Guide, Version 8.0
Acceptable search keywords and values for configurations
The following table lists the columns on the Configuration History/Rollback page and the
keywords and values that you can use to search on that column in the Search box:
Search keywords for columns
Column to
search on
Acceptable keywords and values
Version
n
version:FRQILJXUDWLRQ YHUVLRQ
n
version:1.203
User
n
user:XVHU QDPH
n
user:admin
Log Message
n
log:ORJ PHVVDJH
log_message:ORJ PHVVDJH
n
log:”message A”
log message:”message B”
n
Examples
n
Reverting uncommitted configuration changes
Do one of the following to revert uncommitted configuration changes:
Navigate to the Configuration Revert page (Administration > System Maintenance >
Config Version > Revert), and then click Revert.
n
n
Click the Config Commit button in the upper-right corner of the Web UI page, and then
click Cancel and Revert Changes to revert any uncommitted configuration changes.
n
Navigate to the Configuration Commit page (Administration > System Maintenance
> Config Version > Commit), and then click Cancel And Revert Changes to cancel
any uncommitted configuration changes.
Rolling back to a previous configuration
Do the following to roll back to a previously saved configuration:
Navigate to the Configuration History/Rollback page (Administration > System
Maintenance > Config Version > History), and then click Rollback for the
configuration version to which you want to revert.
n
Exporting configuration files
To view and export the configuration file:
1. Navigate to the Configuration Export page (Administration > System Maintenance
> Config Version > Export).
2. Click Download.
Uploading configuration files
You can upload new configuration files and apply them to your SP leader appliance on the
Configuration Import page (Administration > System Maintenance > Config Version
> Import).
Important: Arbor does not support importing configurations that were exported from different
SP versions than the version that is currently installed on the appliance.
404
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
If the appliance from which you are uploading a configuration file has a different version of SP
than the appliance to which you are importing it, you can do one of the following:
n Upgrade the original appliance to the desired SP version and then export the configuration
that you want to save.
n
Load the desired appliance with the same version as the exported configuration and then
upgrade the SP software normally.
To upload new configuration files:
1. Navigate to the Configuration Import page (Administration > System Maintenance
> Config Version > Import).
2. Do one of the following:
l
Type a ILOH ORFDWLRQ in the Choose File to Upload box.
l
Click Browse to find the file to upload to your local or networked system.
3. Click Upload Configuration.
4. If you want to apply the new configuration, click Apply and reboot.
The system replaces the current configuration with the new file, and the leader appliance
reboots. When the system finishes rebooting, you must open your Web browser and log in
to the system again to navigate to the Web UI.
Proprietary and Confidential Information of Arbor Networks Inc.
405
SP and TMS User Guide, Version 8.0
Managing System Backups
Introduction
You can use the Manage Backups page (Administration > System Maintenance >
Backups) to perform the following tasks globally:
n back up all SP appliances manually
n
view the status of backups
n
schedule recurring backups
n
import backups
n
export backups
n
restore backups
This feature is available on appliances with Web UIs. You can also schedule per-appliance
backups by using the CLI. See “Configuring Scheduled Backups of Individual Appliances” in
the SP and TMS Advanced Configuration Guide.
Full backups vs. incremental backups
You can perform either a full backup or an incremental backup of appliances. When you
perform a full backup, SP backs up all of the database files, configuration files, and other files
necessary to restore an SP appliance to that point in time. When you perform an incremental
backup, SP backs up only the changes that have occurred since you ran the last full backup.
The advantage of an incremental backup is that it takes less time. Both types of backups are
stored in a single file, which is a gzip compressed tarball.
Important: You must create a full backup before you can create an incremental backup.
Appliances exempted from global backups
When you use the CLI to configure an appliance with its own full or incremental backup
schedule, that appliance is exempted from any corresponding global full or incremental backup
schedule, respectively.
See “Configuring Scheduled Backups of Individual Appliances” in the SP and TMS Advanced
Configuration Guide.
Backup storage
Each appliance can locally store one full backup and one incremental backup. Each time you
perform a backup, SP replaces the previous backup. If you want to save multiple backups, you
can export them to a remote server.
SP can only restore system backups created in the same SP version that is currently running.
406
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
About the Backup Status tab
The Backup Status tab on the Manage Backups page (Administration > System
Maintenance > Backups) displays all configured appliances and the status of their backedup disk images, and allows you to control the display of backup task failure messages. The
following table contains details about the Backup Status tab:
Backup Status tab information
Column
Description
Name
The name of each configured appliance.
State
The operational state of each appliance.
Last Error
The most recently reported error.
Full Image
Timestamp
The time at which the last full backup was run.
Incremental Image
Timestamp
The time at which the last incremental backup was run.
Hide Backup Task
Failed Message
button
Click to suppress a backup error message that is currently displayed
in the Web UI’s Status Message box.
If SP generates a new backup error, it disables the error message
suppression. This ensures that you are made aware of any new
backup errors that occur, even if you have suppressed a previous
error message.
Show Backup
Task Failed
Message button
Click to display a backup error message that you previously
suppressed. When you click this button, the suppressed error
message appears again on every page of the SP Web UI.
Backing up your system manually
You can manually create a one-time full or incremental backup of your SP deployment on the
Perform Tasks tab of the Manage Backups page.
To manually create a one-time full or incremental backup:
1. Navigate to the Manage Backups page (Administration > System Maintenance >
Backups).
2. On the Perform Tasks tab, from the Task list, select Create Full Backup Image or
Create Incremental Backup Image.
3. From the Appliance list, select the desired appliances, and then click Execute.
About exporting and importing backup images
When you export or import a backup image, the file transfer uses SCP on port 22. FTP and
other protocols are not supported for exporting or importing a backup image.
When you export an image, the name of the file depends on whether it is a full backup or an
incremental backup and whether you specified a custom timestamp format. You use the
appliance's CLI to specify a custom timestamp format. When you import a backup image file,
Proprietary and Confidential Information of Arbor Networks Inc.
407
SP and TMS User Guide, Version 8.0
the name of the file makes it clear whether it is a full or incremental backup and whether it has
a custom timestamp.
See “Setting a Timestamp Suffix” in the SP and TMS Advanced Configuration Guide.
Examples
A full backup without a custom timestamp:
DSSOLDQFHBQDPH!EDFNXSOHYHOWDU
n
DSSOLDQFHBQDPH!EDFNXSOHYHOWDUOLVW
n
An incremental backup without a custom timestamp:
DSSOLDQFHBQDPH!EDFNXSOHYHOWDU
DSSOLDQFHBQDPH!EDFNXSOHYHOWDUOLVW
n
A full backup with a custom timestamp:
DSSOLDQFHBQDPH!EDFNXSFXVWRPBVWULQJ!OHYHOWDU
DSSOLDQFHBQDPH!EDFNXSFXVWRPBVWULQJ!OHYHOWDUOLVW
n
An incremental backup with a custom timestamp:
DSSOLDQFHBQDPH!EDFNXSFXVWRPBVWULQJ!OHYHOWDU
DSSOLDQFHBQDPH!EDFNXSFXVWRPBVWULQJ!OHYHOWDUOLVW
Exporting full or incremental backup images
To export a full or incremental backup image:
1. Navigate to the Manage Backups page (Administration > System Maintenance >
Backups).
2. On the Perform Tasks tab, from the Task list, select Export Full Backup Image or
Export Incremental Backup Image.
3. From the Appliance list, select the desired appliances.
4. In the Remote Host box, type a UHPRWH KRVW ,3 DGGUHVV to which you want to
export the backup image.
5. In the Backup Path on Remote Host box, type the SDWK to the remote host.
6. In the Remote User box, type the UHPRWH XVHU QDPH.
7. In the Remote Password box, type the remote SDVVZRUG for the user.
8. In the Confirm Password box, retype the SDVVZRUG for the user.
9. Click Execute.
SP exports the backup using SCP over SSH on port 22.
Importing full or incremental backup images
To import a full or incremental backup image:
1. Navigate to the Manage Backups page (Administration > System Maintenance >
Backups).
2. On the Perform Tasks tab, from the Task list, select Import Full Backup Image or
Import Incremental Backup Image from the Task list.
3. From the Appliance list, select the desired appliances.
4. In the Remote Host box, type a UHPRWH KRVW ,3 DGGUHVV from which you want to
retrieve the backup image.
5. In the Backup Path on Remote Host box, type the SDWK on the remote host.
408
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
6. (Optional) In the Timestamp on remote file box, type the WLPHVWDPS on the remote
file.
7. In the Remote User box, type the UHPRWH XVHU QDPH.
8. In the Remote Password box, type the remote SDVVZRUG for the user.
9. In the Confirm Password box, retype the SDVVZRUG for the user.
10. Click Execute.
SP imports the backup using SCP over SSH on port 22.
Scheduling recurring full or incremental backups
To schedule a recurring full or incremental backup:
1. Navigate to the Manage Backups page (Administration > System Maintenance >
Backups).
2. On the Schedule Backups tab, navigate to the Schedule Recurring Full Backups
section or Schedule Recurring Incremental Backups section.
Note that any appliances that will be exempted from this schedule are displayed in the
Exempted Appliances box. See “Appliances exempted from global backups” on page 406.
3. In the Backup Schedule box, type a WLPH in hh:mm format.
4. From the Backup Schedule list, select one of the following:
l
Days of the week: 0-6, comma separated
l
Days of the month: 1-31, comma separated
5. Type the appropriate LQWHJHU V of the day(s) representing the days on which you want
backups to generate. Separate the integers by commas.
0 represents Sunday.
6. In the Remote host to export to box, type the IP address of the remote host to which
you want to send the backup image.
7. In the Backup path on remote host box, type a 85/ on the remote host to which your
backup image will be uploaded.
8. In the Remote user box, type the XVHU QDPH required to log in to the remote host.
9. In the Export Password box, type the remote user’s SDVVZRUG.
10. In the Confirm Password box, re-type the remote user’s SDVVZRUG, and then click
Save.
Note: When you schedule recurring backups, SP backs up all appliances.
Restoring from a backup
When you restore SP appliances from a backup, you replace the existing configuration with the
local backup that you most recently created.
To restore an SP appliance from a backup:
1. Navigate to the Manage Backups page (Administration > System Maintenance >
Backups).
2. On the Perform Tasks tab, from the Task list, select Restore.
3. From the Appliance list, select the appliances that you want to restore from the backup,
and then click Execute.
Note: As part of the restoration process, SP reboots.
Proprietary and Confidential Information of Arbor Networks Inc.
409
SP and TMS User Guide, Version 8.0
Stopping a backup task
You can stop a backup task while it is currently running.
To stop a running backup task:
1. Navigate to the Manage Backups page (Administration > System Maintenance >
Backups).
2. On the Perform Tasks tab, from the Task list, select Stop Task.
3. From the Appliance list, select the appliances that you want to stop the task on, and then
click Execute.
410
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
Deleting Alerts
Introduction
You can use the following methods to delete alerts:
manually delete alerts on an individual basis on the Delete Alerts page (Administration >
System Maintenance > Delete Alerts)
n
n
schedule SP to delete alerts automatically on the Schedule Auto-Deletion of Alerts page
(Administration > System Maintenance > Schedule Auto-Deletion)
Important: When you delete an alert, any record of it is removed and the alert cannot be
restored.
Deleting alerts manually
To delete alerts manually:
1. Navigate to the Delete Alerts page (Administration > System Maintenance >
Delete Alerts).
2. Choose one of the following steps:
l
To delete all alerts, select All Alerts, and then go to Step 4.
l
To delete specific alerts, select Alerts Matching.
3. Choose your next steps based on the matching criteria on which you want to base the
deletions:
Matching
criteria
Steps
alert ID
Select the ID check box, and then type the DOHUW ,'V.
alert class
Select the Class check box, and then in the Class list, select the
class of alerts to delete.
alert type
Select the type of alerts that you want to delete from the Type list.
The options that are available depend on the alert class that you
select.
alert age
Select the Age check box, and then configure the timeframe
options for the age of alerts to delete.
alert duration
Select the Duration check box, and then configure the timeframe
options for the duration of alerts to delete.
alert importance
Select the Importance check box, and then select the check
boxes for the importance levels of alerts to delete.
affected resource
Select the Resource check box, and then type the DIIHFWHG
UHVRXUFH in the box.
4. Click Delete, and then click Delete again on the Confirm Delete Alerts page.
Proprietary and Confidential Information of Arbor Networks Inc.
411
SP and TMS User Guide, Version 8.0
Deleting alerts automatically
To schedule the automatic deletion of alerts:
1. Navigate to the Schedule Auto-Deletion of Alerts page (Administration > System
Maintenance > Schedule Auto-Deletion).
2. Select the check boxes for the importance levels of alerts that you want to delete (low,
medium, or high).
3. For the older than settings, follow these steps:
l
In the boxes, type the QXPEHU of days, weeks, or months at which you want the alerts to
be deleted.
l
From the lists, select the corresponding timeframes.
4. Click Save.
The default settings for the automatic deletion of alerts are as follows:
Low alerts - 1 week
n
n
Medium alerts - 1 month
n
High alerts - 4 months
The Schedule Auto-Deletion of Alerts settings apply system wide when set by a member of the
system_admin account group. If they are set by a member of an account group that is restricted
to a set of managed objects, they apply only to alerts related to those managed objects.
Members of the system_admin account group can also set alert deletion schedules specific to
account groups on the Edit Account Group page. See “Configuring Account Groups” on
page 302.
Note: Settings specific to account groups take effect only if their duration is shorter than the
system-wide settings.
412
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
Deleting Traffic Reports
Introduction
You can schedule the automatic deletion of traffic reports on the Schedule Auto-Deletion of
Reports page (Administration > System Maintenance > Report Database).
Note: You can also manually delete traffic reports on the View Reports page.
Deleting traffic reports
To schedule automatic deletion of traffic reports:
1. Navigate to the Schedule Auto-Deletion of Reports page (Administration > System
Maintenance > Report Database).
2. Select the Enable Automatic Deletion check box.
3. Type the QXPEHU of days, weeks, or months at which you want reports to be deleted in the
Older than box.
4. Select the corresponding timeframe from the list, and then click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
413
SP and TMS User Guide, Version 8.0
Enabling Software Updates
Introduction
You can enable a leader appliance to obtain information about SP software updates from the
Arbor server and then share that information with the other appliances in your deployment. You
can view and enable software updates using the tabs on the Configure Software Updates
page (Administration > System Maintenance > Software Updates).
For information about downloading and distributing software updates on a leader appliance,
see “Adding Software Updates to the Appliances in Your Deployment” in the SP and TMS
Advanced Configuration Guide.
Viewing the software status of SP appliances
You can view the software status of your SP appliances on the Status tab of the Configure
Software Updates page. This page displays which software version is installed on each
configured appliance in your deployment. It also displays the available software updates for
each appliance, including the following information:
n The name of an available software update
n
A description of the update
n
A link to download any available release notes, which contain information about the update
Enabling software updates
To enable software updates:
1. Navigate to the Configure Software Updates page (Administration > System
Maintenance > Software Updates).
2. Select the Enable Software Updates check box on the Settings tab.
3. Use the CLI to obtain and copy software updates to the appliance.
Note: If you deploy your leader appliance behind a firewall that requires using an HTTP proxy,
then you must configure HTTP proxy settings in SP in order to receive software updates. See
“Configuring HTTP proxy settings” on page 418.
414
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
Configuring Network Services
Introduction
You can configure network services settings for DNS, NTP, SMTP, SNMP, and HTTP proxy
servers on your SP leader appliance and apply them globally to your other SP appliances
(except TMS appliances). This feature allows you to configure settings once. You can globally
configure server settings on the Configure Network Services page (Administration >
System Maintenance > Network Services). These settings are optional; however, Arbor
recommends that you configure them.
You can also download MIB files on the SNMP tab of the Configure Network Services page.
See “Downloading a MIB file” on page 417.
How SP operates with NTP and DNS servers
You can connect SP to your NTP servers so that SP operates on the same time as your NTP
servers. This is important for data consistency. SP requires DNS servers so that it can look up
hostnames for individual hosts that appear in DoS alerts or in flow queries. Also, there are
additional uses for DNS servers. For example, if a DNS server is configured, SP can replace any
IP address from a system file’s copy command with a hostname.
How SP uses the SMTP settings
You must configure the SMTP settings so that the system can send you alert notifications by
email. SP supports password authenticated SMTP servers. You can enter a user name and
password to authenticate with a password-protected SMTP server.
About setting the alert URL
When you set the alert URL to contact your support system, SP defines three variables for
reference with your support system. The system replaces %name with the leader appliance
name for host alerts and with the customer's name for all other alerts. It replaces %id with the
ID number of the originating alert. It replaces %page_id with profiled_router_alert for profiled
router alerts, with host_alert for host alerts, and with profiled_network_alert for profiled
network alerts.
If you are linking to an alert in SP, you will need to include id=%page_id&alert_id=%id in the
URL query string. The name parameter is not required for linking to an alert in SP.
Example: If you set the alert URL to https://customerportal.example.com/page?id=%page_
id&alert_id=%id&customer=%name and a customer named sinclair_meats receives an alert
notification for a DoS profiled router alert number 1234, the link goes to
https://customerportal.example.com/page?id=profiled_router_alert&alert_
id=1234&customer=sinclair_meats
About HTTP proxy settings
Your leader appliance must be able to connect to remote services provided by Arbor using
HTTP. If you deploy the leader behind a firewall that requires using an HTTP proxy to connect
to the Arbor servers that provide these services, then you must configure HTTP proxy settings.
You can configure HTTP proxy settings on the HTTP Proxy tab.
For information about the remote services ports, see “Ports Used by SP” in the SP and TMS
Advanced Configuration Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
415
SP and TMS User Guide, Version 8.0
The HTTP proxy settings affect the remote services provided by the following Arbor servers:
Arbor ATLAS Intelligence Feed (AIF) server (FCAP signatures)
n
See “Configuring ATLAS Intelligence Feed (AIF)” on page 319.
n
Arbor ATLAS Intelligence Feed (AIF) server (DDoS regular expressions)
See “Configuring ATLAS Intelligence Feed (AIF)” on page 319.
n
ATLAS Visibility server
For information about this server, see “ATLAS Visibility” on page 326.
n
Software Update server
See “Enabling Software Updates” on page 414.
Local and global configuration guidelines for DNS or NTP servers
Use the following guidelines to decide whether to add a DNS or NTP server to a local or global
configuration:
n If you want all appliances to use the server, use a global configuration.
n
If you want individual appliances to use different DNS or NTP servers, use a local
configuration.
The following are some additional guidelines for adding a DNS or NTP server to a local or
global configuration:
n If you add a DNS or NTP server to a local configuration, you can then add the DNS or NTP
server to a global configuration on that appliance without first deleting the local
configuration. If you then delete the DNS or NTP server from the global configuration, the
local configuration is restored.
n
If a DNS or NTP server has been added to a global configuration, then you cannot add the
DNS or NTP server to a local configuration.
For information on adding a DNS or NTP server to a local configuration, see “Configuring DNS
Servers” and “Configuring NTP Servers” in the SP and TMS Advanced Configuration Guide.
Configuring global DNS servers
To configure global DNS servers:
1. Navigate to the Configure Network Services page (Administration > System
Maintenance > Network Services).
2. Select the DNS tab.
3. In the Global DNS Name Servers box, type the ,3 DGGUHVVHV or KRVWQDPHV of the
DNS servers.
Use spaces, commas, or new lines to separate multiple IP addresses.
4. Click Save, and then commit your changes.
Configuring global NTP servers
To configure global NTP servers:
1. Navigate to the Configure Network Services page (Administration > System
Maintenance > Network Services).
2. Select the NTP tab.
3. In the Global NTP Servers box, type the ,3 DGGUHVVHV KRVWQDPHV of the NTP
servers.
416
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 15: System Maintenance
Use spaces, commas, or new lines to separate multiple IP addresses.
4. Click Save, and then commit your changes.
Configuring SMTP servers
To configure SMTP servers:
1. Navigate to the Configure Network Services page (Administration > System
Maintenance > Network Services).
2. Select the SMTP tab.
3. Use the following settings to configure the settings on the SMTP tab.
Setting
Description
SMTP Server box
Type the )4'1 QDPH or the ,3 DGGUHVV of the SMTP server
used to send email notifications
SMTP Server
Username box
Type the XVHU QDPH that SP uses to authenticate logins to the
SMTP server.
SMTP Server
Password box
Type the SDVVZRUG that SP uses to authenticate logins to the
SMTP server.
SMTP Server
Confirm Password
box
Re-type the 6073 VHUYHU SDVVZRUG.
SMTP From
Address box
Type the DGGUHVV that appears in the From field in the email
notifications.
Alert URL box
Type the 85/ of the support link to include with notifications.
Email Footer box
Type the WH[W that you want to include in the footer of each
email notification (for example, instructions, contact
information, and marketing messages).
4. Click Save, and then commit your changes.
Configuring SNMP servers
To configure SNMP servers:
1. Navigate to the Configure Network Services page (Administration > System
Maintenance > Network Services).
2. Select the SNMP tab.
3. In the SNMPv3 EngineID box, type the HQJLQH ,' if you use SNMP v3.
4. Click Save, and then commit your changes.
Downloading a MIB file
You can download the following Management Information Base (MIB) files:
Arbor Networks MIB
n
n
DoS MIB
Proprietary and Confidential Information of Arbor Networks Inc.
417
SP and TMS User Guide, Version 8.0
n
SP MIB
n
SP TMS MIB
To download a MIB file:
1. Navigate to the Configure Network Services page (Administration > System
Maintenance > Network Services).
2. Select the SNMP tab.
3. From the Download MIB list, select the MIB that you want to download, and then click
Download MIB.
4. Open or save the MIB file.
Configuring HTTP proxy settings
To configure HTTP proxy settings:
1. Navigate to the Configure Network Services page (Administration > System
Maintenance > Network Services).
2. Select the HTTP Proxy tab.
3. Use the following table to configure the settings on the HTTP Proxy tab.
Setting
Description
Use configured IP
address of egress
interface as source
check box
Select to use the IP address of the interface from which
packets leave as the source IP address. By default, the source
IP address is the configured IP address of the appliance.
For example, this option is useful in the following cases:
n
n
An appliance’s configured IP address is from a non-routed
private space.
Access to external Arbor services is through a second
interface that has a publicly routed IP address.
Enable HTTP Proxy
check box
Select to enable HTTP proxy.
Proxy Server box
Type the ,3 DGGUHVV of the internal proxy.
Proxy Port box
(Optional) Type the SRUW on which the proxy listens.
If you leave this box blank, then SP uses the default setting
(port 1080).
Authentication
Method option
Select the authentication method that you want to use. If you
select Basic Authentication or Digest Authentication,
then you must also specify the Proxy Username and Proxy
Password that are required to access the proxy server.
4. Click Save.
418
Proprietary and Confidential Information of Arbor Networks Inc.
Part III:
DDoS Detection and
Mitigation
SP and TMS User Guide, Version 8.0
420
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16:
About DoS Detection
Introduction
This section describes how SP detects DoS attack traffic.
User access
Only administrators can configure the settings described in this section.
In this section
This section contains the following topics:
Configuring Global Detection Settings
422
About Detection Settings for Managed Objects and Services
427
About Host Detection
429
About Shared Host Detection Settings
436
About the Shared Host Detection Settings Page
438
Configuring Shared Host Detection Settings
442
About Profiled Router Detection
447
About Profiled Network Detection
451
SP and TMS User Guide, Version 8.0
421
SP and TMS User Guide, Version 8.0
Configuring Global Detection Settings
Introduction
On the Configure Global Detection Settings page (Administration > Detection > DDoS),
you can configure global settings for host detection, profiled router detection, profiled network
detection, auto-rate calculation, and DNS baseline alerts.
For additional information see:
“About Profiled Router Detection” on page 447
n
n
“About Profiled Network Detection” on page 451
n
“About Host Detection” on page 429
n
“About automatic rate calculation for profiled router detection” on page 449
Configuring global settings for profiled router detection
To configure global settings for profiled router detection:
1. Navigate to the Configure Global Detection Settings page (Administration >
Detection > DDoS).
2. In the Profiled Router Settings section, configure the following settings:
Setting
Description
Profiled Router
Latency list
Select the number of minutes for which traffic must remain above
the sensitivity threshold before SP generates an alert. The default
setting is 5 minutes. For information about the sensitivity threshold,
see “Profiled router detection terminology” on page 447.
Profiled Router
Outgoing
Detection option
Select Enabled or Disabled. The system default is Disabled.
Profiled Router
“All” Group
Settings option
Select Enabled or Disabled. The system default is Disabled. If
you select Enabled, then you can edit the “all” group profiled
router settings. See ““All” group profiled router detection settings”
below.
Note: By default, the system provides alerts on incoming traffic for
profiled router detection alerts.
3. Click Save, and then commit your changes.
“All” group profiled router detection settings
Profiled router “all” group detection settings apply to all traffic. These settings produce profiled
router protocol or profiled router bandwidth alerts at any router where the baselines are
exceeded.
To edit the profiled router "all" group settings, click Edit All Group Settings, and then
configure the settings in the Global Profiled Router "All" Group Detection Settings window.
Note: The “all” group detection settings do not include settings for forced alert thresholds. For
information about forced alert thresholds, see “About the use of forced alert thresholds” on
page 449.
422
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
Use the following table to configure the "All" group profiled router detection settings:
"All" group profiled router detection settings configuration
Setting
Description
Severity Duration box
Type the QXPEHU RI VHFRQGV for which traffic must exceed a
given threshold before SP escalates its severity. The default
setting is 300 seconds.
For more information about how the severity duration is used to
classify an alert’s severity, see “How SP creates and classifies
profiled router detection alerts” on page 448.
Incoming Severity
Thresholds and
Outgoing Severity
Thresholds boxes
Type the VHYHULW\ WKUHVKROGV (in bps and pps).
The severity thresholds are applied on a per router basis for
profiled router protocol alerts and on a per interface basis for
profiled router bandwidth alerts.
For more information about how the severity thresholds are used
to classify an alert’s severity, see “How SP creates and classifies
profiled router detection alerts” on page 448.
Use SNMP Link
Rates option
Select Enabled if you want SP to use the SNMP link rate of an
interface as a severity threshold.
SP calculates the severity threshold based on the lower of the
auto-configured or manually configured high severity rate and
the SNMP link rate of the router interface on which the traffic
was detected.
Incoming Alert
Ignore Rates and
Outgoing Alert
Ignore Rates boxes
Type the DOHUW LJQRUH UDWHV (in bps and pps) below which
you do not want SP to generate alerts.
Note: Ignore rates impose a floor to the baseline for the
configured type (bps or pps).
If the ignore rates are the same as the forced alert thresholds,
then the profiled router baselines are ignored and alerts are
generated only when the forced alert thresholds are exceeded.
For information about forced alert thresholds, see “About the use
of forced alert thresholds” on page 449.
Interface Bandwidth
Alerts, Interface
Packets Alerts, and
All Protocols Alerts
lists
In the Detection Sensitivity Thresholds section, select the
sensitivity thresholds for the different types of alerts. The default
setting for each of these lists is 2.
A low number results in more alerts and a high number results in
fewer alerts. Arbor recommends that you select 3 as a starting
point in a production environment. You can then adjust this
setting to reduce or to increase the number of alerts that you
receive in your deployment.
Configuring the global settings for profiled network detection
To configure the global settings for profiled network detection:
1. Navigate to the Configure Global Detection Settings page (Administration >
Detection > DDoS).
Proprietary and Confidential Information of Arbor Networks Inc.
423
SP and TMS User Guide, Version 8.0
2. In the Profiled Network Settings section, configure the following settings:
Setting
Description
Profiled
Network Start
Latency list
Select the number of minutes for which traffic must exceed the
trigger rate before SP generates an alert. For a definition of trigger
rate, see “Profiled network detection terminology” on page 451.
The default is 5 minutes.
Profiled
Network End
Latency list
Select the number of minutes for which traffic must stay below the
trigger rate before SP ends an alert. For a definition of trigger rate,
see “Profiled network detection terminology” on page 451. The
default is 5 minutes.
3. Click Save, and then commit your changes.
Configuring the global settings for host detection
The global settings for host detection allow you to set the start latency and end latency for host
detection and to select the host detection settings to use for host global detection. See “About
Host Detection” on page 429.
To configure the global settings for host detection:
1. Navigate to the Configure Global Detection Settings page (Administration >
Detection > DDoS).
2. In the Host Detection Settings section, configure the following settings, then click Save,
and commit your changes:
Setting
Description
Host Detection
Start Latency list
Select the number of minutes for which traffic must exceed the
trigger rate before SP generates an alert. The default is 2
minutes. For information about the trigger rate, see “Host
detection terminology” on page 429.
Note: SP actually generates an alert during the final 60
seconds of the start latency period. For example, if the start
latency is set at 2 minutes, then SP would generate an alert
between the 1 and 2 minute mark.
Host Detection
End Latency list
Select the number of minutes that traffic must stay below the
trigger rate before SP ends an alert. The default is 4 minutes.
Host Global
Detection list
Select the host detection settings that you want to use for host
global detection. See “About host global detection” on the
facing page.
You can click Edit Shared Settings to view or edit the host
detection settings. If you select Disabled, then the Edit
Shared Settings link does not appear. See “Configuring
Shared Host Detection Settings” on page 442.
Host global detection is disabled if you select Disabled or if
the set of host detection settings that you select has host
detection disabled.
424
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
About host global detection
Host global detection detects excessive rates of traffic toward a single host that does not
match a customer, peer, or profile managed object or a service. It also detects excessive rates
of traffic for dark IP addresses that are configured on the Configure Address Space page
(Administration > Monitoring > Address Space). It detects the excessive rates of traffic
for the host misuse types that are enabled.
Note: Prior to SP 7.0, the equivalent type of detection was called misuse “other” detection.
Configuring the automatic rate calculation settings
If you have enabled global settings for profiled router detection, you can also enable automatic
rate calculation settings for profiled router detection. Arbor recommends that you use the
automatic rate calculation whenever possible, because the calculated rates automatically
adjust to changes in traffic patterns. For more information about automatic rates, see “About
automatic rate calculation for profiled router detection” on page 449.
To configure the global automatic rate calculations:
1. Navigate to the Configure Global Detection Settings page (Administration >
Detection > DDoS).
2. In the Automatic Rate Calculation Settings section, configure the following settings:
Setting
Description
Severity Rate
Percentile box
Type the VHYHULW\ UDWH SHUFHQWLOH. The default setting is
95.
Severity Rate
Multiplier box
Type the QXPEHU by which the severity rate is multiplied. The
default setting is 1.1.
Ignore Rate
Percentile box
Type the LJQRUH UDWH SHUFHQWLOH. The default setting is 40.
Severity Rate
Floor boxes (bps,
pps)
Type the VHYHULW\ UDWH QXPEHU.
Ignore Rate
Floor boxes (bps,
pps)
Type the LJQRUH UDWH QXPEHU. The Ignore Rate Floor places
a minimum on the ignore rate determined by auto-rate calculation.
SP never uses ignore rates below these values. If the calculated
rate is lower, then SP uses the Ignore Rate Floor value.
The Severity Rate Floor places a minimum on the severity rate
determined by auto-rate calculation. SP never uses severity rates
below these values. If the calculated rate is lower, then SP uses
the Severity Rate Floor value.
3. Click Save, and then commit your changes.
Configuring the DNS baseline alert settings
To configure the DNS baseline alert settings:
1. Navigate to the Configure Global Detection Settings page (Administration >
Detection > DDoS).
Proprietary and Confidential Information of Arbor Networks Inc.
425
SP and TMS User Guide, Version 8.0
2. In the DNS Baseline Settings section, configure the following settings:
Setting
Description
Baseline Alert
Ignore
Threshold box
Type the minimum QXPEHU RI TXHULHV SHU VHFRQG
difference between the baseline and the current query count
before a DoS alert is triggered. This feature is disabled by default. If
you do not set a a baseline alert ignore threshold, SP does not
generate DNS Baseline alerts.
Note: This feature is not supported for a TMS-CGSE or a
TMS-ISA.
Baseline Alert
Sensitivity box
Type the QXPEHU RI VWDQGDUG GHYLDWLRQV from the baseline
(measured in queries per second) that the current query count
must reach before a DoS alert is generated. The default setting is
5.
Note: This feature is not supported for a TMS-CGSE or a
TMS-ISA.
3. Click Save, and then commit your changes.
Configuring the global settings for misuse detection
In an SP 7.0 or later deployment, misuse detection is replaced by host detection.
Important: Misuse detection generates alerts only in a multi-version deployment with
collectors running a version of SP prior to 7.0. When the entire deployment is running SP 7.0
or later, misuse detection no longer generates alerts.
For information about the global misuse settings, see the SP and Threat Management System
(TMS) User Guide for your previous version of SP.
426
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
About Detection Settings for Managed Objects and Services
Introduction
When you configure a customer, peer, or profile managed object, or a service, you can use the
Detection tabs to configure detection settings. As SP monitors the traffic towards your
managed objects and services, it triggers DoS alerts based on the detection settings.
You can configure detection settings for individual managed objects and services. See
“Configuring Managed Objects” on page 162 and “Adding, Editing, and Deleting Services” on
page 227.
You can also configure global detection settings on the Configure Global Detection Settings
page (Administration > Detection > DDoS) for customer, peer, and profile managed
objects, or services. See “Configuring Global Detection Settings” on page 422.
About detection types
You can configure the following types of attack detection:
Profiled Router
n
Profiled router detection detects excessive rates of traffic on a router as compared to the
traffic rates that SP expects on each router. Profiled router detection can also detect
excessive rates of traffic based on a manually configured threshold. When SP generates a
profiled router alert, it gathers details about the anomalous traffic on the affected routers.
See “Configuring Profiled Router Detection for Managed Objects” on page 182 and
“Configuring Profiled Router Detection for Services” on page 237.
The severity thresholds for profiled router detection are applied on a per router basis for
profiled router protocol alerts and on a per interface basis for profiled router bandwidth
alerts.
This type of detection generates alerts for IPv4 and IPv6 traffic.
n
Host
Host detection monitors the traffic to a host on all monitored routers. Host detection can be
configured to monitor the traffic of a customer, peer, or profile managed object or the traffic
of a service. It can also be configured to monitor traffic that is not associated with a
customer, peer, profile managed object, or a service. See “About Host Detection” on
page 429.
Host detection can trigger an alert for an enabled misuse type. If excessive traffic is
detected for multiple misuse types that are enabled, then a single alert is created instead of
separate alerts for each misuse type. The alert includes each misuse type that had excessive
traffic. See “Host detection misuse types” on page 434.
Host detection can be configured to trigger a fast flood host alert. A fast flood host alert is
triggered when large amounts of traffic toward a single host are detected for an enabled
misuse type.
The high severity rate is based on the highest rate of traffic at the managed object boundary,
network boundary, or an individual router. See “Configuring Host Detection for Managed
Objects” on page 186 and “Configuring Host Detection for Services” on page 241.
n
Profiled Network
Profiled network detection identifies excessive rates of traffic at a managed object boundary
or service boundary based on baselines that SP has calculated for the managed object. SP
generates a profiled network alert if the rate of the traffic at a managed object boundary or
Proprietary and Confidential Information of Arbor Networks Inc.
427
SP and TMS User Guide, Version 8.0
service boundary exceeds the baseline by the detection percentage for a sustained period of
time. When SP generates a profiled network alert, it gathers details about the alert traffic
that crosses the managed object boundary or service boundary.
The severity rates for profiled network detection are applied on a managed object wide
basis.
When you enable Profiled Network Detection, you can also enable Profiled Country
Detection. If enabled, SP generates alerts when the traffic from a country exceeds the
baseline values for that country. See “Configuring Profiled Network Detection for Managed
Objects” on page 191.
n
Misuse
Important: Misuse detection generates alerts only in a multi-version deployment with
collectors running a version of SP prior to 7.0. When the entire deployment is running SP
7.0 or later, misuse detection no longer generates alerts.
For information about misuse detection, see SP and Threat Management System (TMS)
User Guide, Version 6.0.
428
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
About Host Detection
Introduction
Host detection monitors the IPv4 and IPv6 traffic to a host on all monitored routers. Host
detection can be configured to monitor the traffic of a customer, peer, or profile managed
object or the traffic of a service. It can also be configured to monitor traffic that is not
associated with a managed object or service using host global detection.
Host detection can trigger a standard DoS Host alert or a Fast Flood DoS Host alert. A
standard DoS Host alert is triggered when the traffic on a monitored router towards a single
host exceeds the configured threshold of an enabled misuse type for a specified time period. A
Fast Flood DoS Host alert is triggered when large amounts of traffic toward a single host are
detected for an enabled misuse type in a very short period of time. A Fast Flood DoS Host alert
allows you to auto-mitigate a large burst of traffic that is too brief to otherwise be detected.
If excessive traffic is detected for multiple misuse types that are enabled, then a single alert is
created instead of separate alerts for each misuse type. The alert includes each misuse type
that had excessive traffic. See “Host detection misuse types” on page 434.
For information about the other types of detection, see “About Profiled Network Detection” on
page 451 and “About Profiled Router Detection” on page 447.
Note: Starting with SP 7.0, host detection replaces misuse detection.
Host detection terminology
An understanding of the following terminology is needed to configure host detection:
Trigger rate
n
A traffic rate that must be exceeded before SP generates an alert.
The trigger rate is applied on a per router basis. The trigger rate accounts for all interfaces
on the router.
n
Host detection start latency period
Defines how long traffic must be above the trigger rate before a host alert is generated. This
value is a global setting that is configured on the Configure Global Detection Settings page
(Administration > Detection > DDoS).
Note: SP actually generates an alert during the final 60 seconds of the start latency period.
For example, if the start latency is set at 2 minutes, then SP would generate an alert
between the 1 and 2 minute mark.
n
Severity duration
The length of time that traffic must exceed a given rate before SP escalates the alert’s
severity level. If the traffic exceeds 75% of the high severity rate for the severity duration,
then the alert is classified with a severity of Medium. If the traffic exceeds the high severity
rate for longer than the severity duration, then the alert is classified with a severity of High.
Note: Fast flood host detection ignores this setting, and fast flood alerts always have a high
severity.
n
High severity rate
A traffic rate that SP uses to differentiate between medium and high alert severity. If traffic
exceeds the high severity rate for longer than the severity duration, then the alert severity is
Proprietary and Confidential Information of Arbor Networks Inc.
429
SP and TMS User Guide, Version 8.0
set to high. If traffic exceeds this rate but does not stay there for the severity duration, then
the alert severity is set to medium.
The high severity rate is based on the highest rate of traffic at the managed object boundary,
network boundary, or an individual router.
If traffic exceeds the high severity rate for at least one minute during the start latency period,
then the alert is classified with a medium severity when it starts instead of a low severity.
n
Host detection end latency period
Defines how long traffic must be below the trigger rate before a host alert is ended. This
value is a global setting that is configured on the Configure Global Detection Settings page
(Administration > Detection > DDoS).
n
Fast flood detection
An option that can be enabled to trigger a host alert much faster when large amounts of
traffic toward a single host are detected.
About host detection with managed objects or services
Host detection detects excessive rates of traffic toward a single host that matches a managed
object (customer, peer, or profile) or service. It detects the excessive rates of traffic for the host
misuse types that are enabled.
When you configure host detection for a managed object or service, you can select any set of
host detection settings that is configured on the Shared Host Detection Settings page
(Administration > Detection > Shared Host Detection Settings). You can also create
a custom set of host detection settings for an individual managed object or service. See
“Configuring Host Detection for Managed Objects” on page 186, “Configuring Host Detection
for Services” on page 241, and “Configuring Shared Host Detection Settings” on page 442.
When host detection is enabled for a managed object or service, and the host detection
triggers an alert, the managed object or service is associated with the alert. A host alert has
only one managed object or service associated with it, but it can have multiple misuse types
associated with it.
About host global detection
Host global detection detects excessive rates of traffic toward a single host that does not
match a customer, peer, or profile managed object or a service. It also detects excessive rates
of traffic for dark IP addresses that are configured on the Configure Address Space page
(Administration > Monitoring > Address Space). It detects the excessive rates of traffic
for the host misuse types that are enabled.
You configure host global detection on the Configure Global Detection Settings page
(Administration > Detection > DDoS). When you configure host global detection, you
can select any set of host detection settings that is configured on the Shared Host Detection
Settings page (Administration > Detection > Shared Host Detection Settings). See
“Configuring Shared Host Detection Settings” on page 442.
Note: Prior to SP 7.0, the equivalent type of detection was called misuse “other” detection.
Note: If a customer, peer, or profile managed object or a service matches a host, then host
global detection does not monitor the traffic to that host even if host detection is disabled for
the managed object or service.
When host global detection triggers an alert, a managed object with the name Global
Detection is associated with the alert. The name Global Detection appears in the alert
430
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
wherever the name of a managed object would appear for an alert triggered by host detection
that is configured for a managed object.
About host detection with fast flood detection enabled
When you configure host detection settings for a managed object or service, you can enable
fast flood detection. When fast flood detection is enabled, host detection is able to detect
large amounts of traffic toward a single host for the misuse types that are enabled. Fast flood
detection can then trigger an alert in as little as 1 second if the traffic rate is high enough.
You can use fast flood detection with auto-mitigation to protect a target against a flood of
traffic that lasts just a few minutes. You do this by enabling fast flood detection and
auto-mitigation for a managed object or service. A sudden flood of traffic can then be mitigated
very quickly.
SP can also trigger fast flood host alerts for traffic that is not monitored by a managed object or
service, if the host detection settings that you select for host global detection have fast flood
detection enabled. See “Configuring the global settings for host detection” on page 424,
“Configuring Host Detection for Managed Objects” on page 186, or “Configuring Host
Detection for Services” on page 241.
With fast flood detection, a host alert is triggered when SP detects that the amount of traffic
seen exceeds the amount of traffic that would be received in 60 seconds at the high severity
rate. The following graphs illustrate the difference between standard host detection and fast
flood detection:
Standard Host Detection
Fast Flood Detection
With standard host detection, SP can trigger an alert only after 60 seconds of high traffic.
With fast flood detection, if there is a large amount of traffic, an alert can be triggered after 1 or
more seconds. If fast flood detection is enabled, but the amount of traffic seen does not exceed
the amount of traffic that would be received in 60 seconds at the high severity rate, then SP
uses the standard host detection settings to determine if an alert should be triggered.
Proprietary and Confidential Information of Arbor Networks Inc.
431
SP and TMS User Guide, Version 8.0
For example, the following table displays the results for different traffic rates when fast flood
detection is enabled and the high severity rate is set at 1 Mbps :
Fast flood trigger time examples
Traffic Rate
Result
60 Mbps
SP would trigger a fast flood host alert after 1 second.
10 Mbps
SP would trigger a fast flood host alert after 6 seconds.
1 Mbps
SP would not trigger a fast flood host alert, but trigger a standard host
alert after 60 seconds.
When a fast flood host alert is triggered, the alert has a severity level of high and the severity
level is followed by Fast Flood. See “About DoS Host alerts” on page 473.
Note: Every 60 seconds SP resets its traffic count to 0 so it does not have a moving 60
second window for fast flood detection. When the traffic count is reset to 0, then only the
traffic from that point on is used by SP to determine if a fast flood alert should be triggered.
Before you enable fast flood detection, you should be aware of the following fast flood
detection limitations:
n It can trigger alerts when you have spikes in your legitimate traffic.
432
n
It uses more system resources than standard host detection. If it is used extensively, it might
impact your system performance.
n
It classifies all of the alerts that it triggers with a severity of High when these same alerts
might have a lower severity with standard host detection.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
How SP creates and classifies standard host alerts
A standard host alert occurs when the traffic that is sent to a host for a configured misuse type
exceeds the configured trigger rate. For information about host alerts that are triggered with
fast flood detection enabled, see “About host detection with fast flood detection enabled” on
page 431.
SP creates host alerts and assigns their severity level based on the following conditions:
Host alert severity levels
Severity
Conditions
low
The alert severity is low if the traffic meets the following criteria:
n
n
n
medium
The alert severity is medium if the traffic meets the following criteria:
n
n
n
high
Exceeds the trigger rate for longer than the host detection start latency
period.
Does not exceed 75% of the high severity rate for the severity duration.
Never exceeds the high severity rate.
Exceeds the trigger rate for longer than the host detection start latency
period.
Exceeds the high severity rate for one minute or exceeds 75% of the high
severity rate for the severity duration
Does not exceed the high severity rate for the severity duration.
The alert severity is high if the traffic meets the following criteria:
n
n
Exceeds the trigger rate for longer than the host detection start latency
period.
Exceeds the high severity rate and stays there for the severity duration.
The following are important things to know about host alert classification:
When SP initially classifies a host alert, the severity is based on traffic data from the router
that has the highest rate of alert-triggering traffic.
n
n
After a host alert is triggered, the traffic data that is used to classify the severity of the alert
also includes data from the boundaries that are configured for the managed object or
service.
n
The severity of a host alert can increase, but it can never decrease.
n
The traffic rate used for severity classification is gathered once a minute and is the average
rate per second for the minute.
n
If the severity duration is greater than 60 seconds, a host alert cannot have an initial severity
of high because an alert will be triggered before the end of the severity duration.
For more information about the rates and time periods that control the host alerts, see “Host
detection terminology” on page 429 For more information about the global latency settings,
see “Configuring Global Detection Settings” on page 422
Proprietary and Confidential Information of Arbor Networks Inc.
433
SP and TMS User Guide, Version 8.0
Host detection misuse types
SP uses the following misuse types with host detection:
Host detection misuse types
Misuse Type
Type of Traffic
Can Help Detect
Total Traffic
The total traffic (in
bps or pps) for a
given host
Host attacks that do not follow a known attack
pattern
chargen
Amplification
chargen traffic (in
bps or pps) with the
UDP protocol and
source port 19
chargen (Character Generator Protocol)
reflection/amplification attacks
DNS
DNS traffic (in pps) Floods of DNS traffic
with the TCP and/or
UDP protocol and
destination port 53
traffic
DNS Amplification
DNS traffic (in bps
or pps) with the
UDP protocol and
source port 53
DNS reflection/amplification attacks
ICMP
IPv4 and IPv6
Internet Control
Message Protocol
traffic (in pps)
IPv4 ICMP and ICMPv6 packet-flooding
attacks
IP Fragment
Traffic (in pps) with
the IP fragment flag
TCP and UDP fragmentation attacks
Note: TCP and UDP fragmentation attacks
are often associated with chargen, DNS,
SNMP, SSDP, and MS SQL RS amplification
attacks.
IP Private
Traffic (in pps) for
private IP address
space
Spoofed IP addresses, which are not expected
to be routed over the Internet, that are used in
attacks
Note: SP uses the following IP spaces to
detect this misuse type:
n
n
434
IPv4
l
10.0.0.0/8
l
172.16.0.0/12
l
192.168.0.0/16
IPv6
l
All spaces except 2000::/3
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
Host detection misuse types (Continued)
Misuse Type
Type of Traffic
IPv4 Protocol 0
Traffic (in pps) with Attacks in which the higher-layer transport
the protocol number protocol number is set to 0, which is an invalid
set to 0
protocol number (TCP is protocol 6, UDP is
protocol 17, and ICMP is protocol 1).
Note: The IPv4 Protocol 0 misuse type works
only with IPv4 traffic.
MS SQL RS
Amplification
UDP traffic (in bps
or pps)with source
port 1434
Microsoft SQL Resolution Service
reflection/amplification attacks
NTP Amplification
NTP traffic (in bps
or pps) with the
UDP protocol,
source port 123,
and invalid packet
sizes
NTP reflection/amplification attacks
SNMP Amplification
SNMP traffic (in
bps or pps) with the
UDP protocol and
source port 161
and/or 162.
SNMP reflection/amplification attacks
SSDP Amplification
UDP traffic (in bps
or pps) with source
port 1900
SSDP (Simple Service Discovery Protocol)
reflection/amplification attacks
TCP Null
TCP traffic (in pps)
that contains a
sequence number
but no flags
TCP Null-Flags attacks
TCP RST
TCP traffic (in pps)
with the reset flag
set
TCP reset attacks
TCP SYN
TCP traffic (in pps)
with the
synchronize flag set
Common TCP SYN flood attacks.
UDP
UDP traffic (in pps)
UDP attacks
Proprietary and Confidential Information of Arbor Networks Inc.
Can Help Detect
435
SP and TMS User Guide, Version 8.0
About Shared Host Detection Settings
Introduction
Shared host detection settings were introduced with SP 7.0.2. Shared host detection settings
allow you to configure a set of host detection settings and then use that set when you
configure host detection for managed objects or services, or when you configure host global
detection. You can use the same set of host detection settings with multiple managed objects
or services. For example, if several managed objects are protecting the same type of resource,
you can use the same shared settings with each managed object.
Important things to know about shared host detection settings
The following are important things that you should know about shared host detection settings:
When you edit a set of shared host detection settings, those edits are applied to all the host
detection configurations that use the same set.
n
n
Shared host detection settings are assigned to all managed objects or services when you
upgrade.
When you upgrade from a version of SP prior to SP 7.0.2, sets of shared host detection
settings are automatically created and assigned to your managed objects or services. Each
assigned set of shared host detection settings is given a unique name and has the same
host detection settings that the managed object or service had before you upgraded. How
these shared host detecting settings are assigned depends on the version of SP from which
you are upgrading. See "How Sets of Host Detection Settings Are Assigned During an
Upgrade" in the SP and TMS Advanced Configuration Guide.
Note: If you do not want to use shared host detection settings, you can use CLI commands
to convert all of your managed objects or services to use custom sets of host detection
settings. See "Converting Managed Objects and Services to Use Custom Sets of Host
Detection Settings" in the SP and TMS Advanced Configuration Guide.
Note: If you upgrade from SP 7.0.2 or later, no changes are made to your shared host
detection settings during the upgrade.
n
You can identify and combine duplicate sets of shared host detection settings.
See "Combining Sets of Shared Host Detection Settings" in the SP and TMS Advanced
Configuration Guide.
n
You can use shared host detection settings or custom host detection settings.
With SP 7.5 or later, you can use shared host detection settings or custom host detection
settings. When you use custom host detection settings, the settings apply to an individual
managed object or service.
Because you can use shared settings or custom settings, you have the following options
when you configure host detection for managed objects or services:
l
Always use shared settings
l
Always use custom settings
l
Use shared settings with some managed objects or services and custom settings with the
others.
Arbor recommends that you use shared host detection settings whenever possible.
However, if you have users who need to edit the host detection settings of a managed
object or service on the Host Detection tab, then you must use custom host detection
settings for those managed objects or services. For example, if you want a managed services
436
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
administrator to be able to edit the host detection settings of their profile managed objects,
then you must use custom host detection settings when you configure the parent managed
object. You can also use custom settings if you prefer to be able to edit the host detection
settings for each managed object or service individually.
If a managed object or service has shared host detection settings, you can manually select
to use custom settings. You can also the CLI to convert the shared host detection settings of
existing managed objects or services to custom host detection settings. See “Configuring
host detection using shared settings” on page 186, “Configuring host detection using a
custom set” on page 187, and "Converting Managed Objects and Services to Use Custom
Sets of Host Detection Settings" in the SP and TMS Advanced Configuration Guide.
Shared host detection settings and managed services customers
When you assign a profile managed object to a managed services customer, the managed
services administrator can create child profile managed objects for it. When a managed
services administrator creates a child profile managed object, it inherits the host detection
settings from the parent. If the parent has shared host detection settings, then the child has the
same shared host detection settings and the settings are not editable. If the parent has custom
host detection settings, then the child has the same custom host detection settings and are the
settings are editable.
If you assign multiple managed objects to a managed services customer, then it will be possible
for a managed services administrator to edit the host detection settings of a profile managed
object that has shared host detection settings if another profile managed object has custom
settings. If you do not want a managed services administrator to be able to edit the host
detection settings of any of their profile managed objects, then all of the managed objects
should have shared host detection settings. If you want the managed services administrator to
be able to edit the host detection settings of some of the profile managed objects but not to be
able to edit these settings for other managed objects, then you should do the following:
n Create two managed service administrator accounts.
n
Assign all of the profile managed objects that have shared host detection settings to one
account.
n
Assign all of the profile managed objects that have custom host detection settings to the
other account.
Proprietary and Confidential Information of Arbor Networks Inc.
437
SP and TMS User Guide, Version 8.0
About the Shared Host Detection Settings Page
Introduction
The Shared Host Detection Settings page (Administration > Detection > Shared Host
Detection Settings) lists the sets of shared host detection settings that you can use when
configuring host detection. See “About Shared Host Detection Settings” on page 436.
What you can do on the Shared Host Detection Settings page
You can do the following on the Shared Host Detection Settings page:
Configure new or existing sets of host detection settings
n
See “Configuring Shared Host Detection Settings” on page 442.
n
Search for specific sets of host detection settings
See “About searching on the Shared Host Detection Settings page” on the facing page.
n
Sort the sets of host detection settings by name, status, and the number of managed objects
that use those settings
If you sort by the number of managed objects, the set of host detection settings that is
assigned to host global detection appears at the top of the list when sorting in descending
order and at the bottom of the list when sorting in ascending order.
n
See how many managed objects use each set of host detection settings
n
Access a list of the managed objects that use a set of host detection settings
Each set of host detection settings that is assigned to a managed object has a link in the
Number of Managed Objects column. This link opens the Configure Managed Objects
page, which displays the managed objects that use this set of host detection settings.
The set of host detection settings that is used by host global detection also has a Global
Detection link that opens the Configure Global Detection Settings page.
How shared host detection settings work
After you add a set of shared host detection settings, you can select those settings when you
configure host detection for a managed object or a service and when you configure host global
detection. You can use the same set of host detection settings with multiple managed objects
or services. When you edit a set of host detection settings, those edits are applied to all the
host detection configurations that use the same set. See “Configuring Host Detection for
Managed Objects” on page 186, “Configuring Host Detection for Services” on page 241, and
“Configuring the global settings for host detection” on page 424.
The Shared Host Detection Settings page has two predefined sets of host detection settings:
“Default” and “Disabled.” You can edit the “Default” settings, but you cannot edit the name or
description of these settings. You can use the “Disabled” settings to disable host detection for
a managed object or service or for host global detection. You cannot view or edit the
“Disabled” settings. See “About the “Default” set of host detection settings” on page 440.
438
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
About searching on the Shared Host Detection Settings page
You can use the Search box on the Shared Host Detection Settings page to search for sets of
host detection settings. The following are guidelines for using the Search box:
n You can enter search values with or without keywords.
If you do not enter a keyword, the search finds any text string that matches in the Name or
Description columns.
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific column.
The Host Detection Status column requires the keyword “status.” The values in Number of
Managed Objects column do not appear in search results.
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
If a keyword is followed by more than one value, only the first value is associated with the
keyword. For any additional values, the search looks for those values in the Name or
Description columns of the shared host detection settings. For example, if you type
name:XYZ 123, then the search returns all occurrences of shared host detection settings
that have XYZ in the Name column and 123 in the Name or Description column.
n
A comma between search values creates an OR statement.
n
The comma cannot be followed by a space because a space creates an AND statement.
You can use quotation marks (“) to match a phrase.
For example, to search for the sets of host detection settings that have “The trigger rates
are” in the description, you can type description:”trigger rates”.
See “Acceptable search keywords and values for sets of host detection settings” below.
Acceptable search keywords and values for sets of host detection settings
The following table lists the acceptable keywords and values that you can use to search in the
Search box for sets of host detection settings:
Keywords for the Shared Host Detection Settings Search box
Attribute to
search by
Acceptable keywords and
values
name
n
name:VKDUHG KRVW
GHWHFWLRQ VHWWLQJV
QDPH
n
name:XYZ
description
n
description:VKDUHG
KRVW GHWHFWLRQ
VHWWLQJV GHVFULSWLRQ
desc:VKDUHG KRVW
GHWHFWLRQ VHWWLQJV
GHVFULSWLRQ
n
description:”Trigger rates set at
90% of the default settings”
desc:”Trigger rates set at 110%
of the default settings”
status:KRVW GHWHFWLRQ
VWDWXV
n
n
status
n
Proprietary and Confidential Information of Arbor Networks Inc.
Examples
n
n
status:enabled
status:disabled
439
SP and TMS User Guide, Version 8.0
Deleting a set of host detection settings
The “Default” set and the “Disabled” set of host detection settings cannot be deleted.
To delete a set of host detection settings:
1. Navigate to the Shared Host Detection Settings page (Administration > Detection >
Shared Host Detection Settings).
2. Select the check boxes for the set of host detection settings that you want to delete, and
then click Delete.
If you delete host detection settings that are assigned to one or more managed objects, the
host detection settings for those managed objects revert to using the “Default” host
detection settings. If the host detection settings are used by host global detection, then
host global detection also reverts to using the”Default” host detection settings.
When you try to delete a set of host detection settings that is assigned to a managed
object, a warning message appears that allows you to cancel the deletion.
3. Click Save, and then commit your changes.
About the “Default” set of host detection settings
The Shared Host Detection Settings page has a “Default” set of host detection settings. When
you create a new set of host detection settings, its shared settings are initially populated with
the shared settings from the “Default” host detection settings. If you edit the shared settings of
the “Default” host detection settings, you can use the information in the following tables to
reset them to their initial values.
The following table contains the initial values for the general shared settings of the “Default”
set of host detection settings:
Initial values of the general settings in the Default set of shared host detection
settings
Setting
Value
Host Detection
Enabled
Severity Duration
180 seconds
Fast Flood Detection
Disabled
Enabled check boxes
Selected for all misuse types
The following table contains the initial values for the misuse type settings of the “Default” set of
host detection settings. All of these misuse types, except the Total Traffic misuse type, are
initially enabled.
Initial values for the misuse type settings in the Default set of shared host
detection settings
440
Misuse Type
Trigger Rate
High Severity Rate
Total Traffic (Bytes)
200 Mbps
4 Gbps
Total Traffic (Packets)
50 Kpps
1 Mpps
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
Initial values for the misuse type settings in the Default set of shared host
detection settings (Continued)
Misuse Type
Trigger Rate
High Severity Rate
chargen Amplification (Bytes)
200 Mbps
4 Gbps
chargen Amplification (Packets)
30 Kpps
600 Kpps
DNS
10 Kpps
30 Kpps
DNS Amplification (Bytes)
200 Mbps
4 Gbps
DNS Amplification (Packets)
30 Kpps
600 Kpps
ICMP
2.5 Kpps
10 Kpps
IP Fragment
2.5 Kpps
10 Kpps
IPv4 Protocol 0
2.5 Kpps
10 Kpps
IP Private
2.5 Kpps
10 Kpps
MS SQL RS Amplification (Bytes)
200 Mbps
4 Gbps
MS SQL RS Amplification (Packets)
100 Kpps
2 Mpps
NTP Amplification (Bytes)
200 Mbps
4 Gbps
NTP Amplification (Packets)
100 Kpps
2 Mpps
SNMP Amplification (Bytes)
200 Mbps
4 Gbps
SNMP Amplification (Packets)
30 Kpps
600 Kpps
SSDP Amplification (Bytes)
200 Mbps
4 Gbps
SSDP Amplification (Packets)
100 Kpps
2 Mpps
TCP null
2.5 Kpps
10 Kpps
TCP RST
2.5 Kpps
10 Kpps
TCP SYN
2.5 Kpps
10 Kpps
UDP
50 Kpps
100 Kpps
Proprietary and Confidential Information of Arbor Networks Inc.
441
SP and TMS User Guide, Version 8.0
Configuring Shared Host Detection Settings
Introduction
On the Shared Host Detection Settings page (Administration > Detection > Shared
Host Detection Settings), you can configure new or existing sets of host detection settings.
See “About the Shared Host Detection Settings Page” on page 438 and “About Shared Host
Detection Settings” on page 436.
Adding and editing a set of host detection settings
To add or edit a set of host detection settings:
1. Navigate to the Shared Host Detection Settings page (Administration > Detection >
Shared Host Detection Settings).
2. Choose one of the following steps:
l
l
To add a set of host detection settings, click Add Shared Settings.
To edit a set of host detection settings, click the name link of the host detection
settings.
3. On the Create Shared Host Detection Settings page or the Edit Shared Host Detection
Settings page, configure the following settings:
Setting
Description
Name box
Type a unique QDPH for the set of host detection settings.
Description box
Type a GHVFULSWLRQ that can help you easily identify the set of
host detection settings in a list.
4. To see the list of managed objects using the shared set, click the View Managed
Objects link on the Edit Shared Host Detection Settings page. If you made changes on
the page without saving them, you will be prompted to either click the Continue
Editingor Save & Go to Managed Objects button.
5. In the Shared Settings section, configure the shared host detection settings. See “Shared
host detection settings” on the facing page.
6. Click Save, and then commit your changes.
442
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
Shared host detection settings
The following are the shared host detection settings that you can configure in the Shared
Settings section on the Configuration pane:
Shared host detection settings
Setting
Description
Host Detection
options
Select Enabled or Disabled.
When host detection is enabled, it monitors the traffic to a host on all
monitored routers. A host alert is triggered when the traffic on a
monitored router towards a single host exceeds the configured
threshold of an enabled misuse type for a specified time period. See
“About Host Detection” on page 429.
Note: The other shared settings for host detection appear and can be
configured only if host detection is enabled.
Severity
Duration box
Type the QXPEHU RI VHFRQGV that you want the system to wait
before it classifies an alert as high severity. An alert must exceed the
high severity rate for this amount of time before SP escalates the
severity. The default value is 180 seconds. For information about
severity duration, see “Host detection terminology” on page 429.
Note: If you enter a value for severity duration that is less than a whole
minute, SP rounds that value up to the next minute when determining
the severity duration. For example, if you set the severity duration to 10
seconds, SP uses a value of 1 minute for the severity duration.
Note: Fast flood host detection ignores this setting, and fast flood
alerts always have a high severity.
Fast Flood
Detection options
Select Enabled or Disabled.
When host fast flood detection is enabled, SP detects large amounts
of traffic toward a single host for the misuse types that are enabled.
See “About host detection with fast flood detection enabled” on
page 431.
Enabled column
Select the check boxes of the host misuse types that you want to
enable. Host detection detects excessive rates of traffic for the host
misuse types that are enabled. See “Host detection misuse types” on
the next page.
To disable or enable a host detection misuse type in every set of
shared host detection settings, see "Disabling and Enabling Host
Detection Misuse Types" in the SP and TMS Advanced Configuration
Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
443
SP and TMS User Guide, Version 8.0
Shared host detection settings (Continued)
Setting
Description
Trigger Rate
column
For each misuse type that you enable, type the WULJJHU UDWH in the
Trigger Rate box, and then select the appropriate units from the
Trigger Rate list. For information about the trigger rate, see “Host
detection terminology” on page 429.
The total traffic misuse type and the amplification misuse types have
trigger rate settings for bits per second and packets per second. If
either of these settings is exceeded, SP generates an alert. The trigger
rate for the other misuse types is always in packets per second.
Note: If you clear a trigger rate value that has not been saved, it
reverts to the previously saved value.
High Severity Rate
column
For each misuse type that you enable, type the KLJK VHYHULW\
UDWH in the High Severity box, and then select the appropriate unit
from the High Severity list. For information about high severity rate,
see “Host detection terminology” on page 429.
The total traffic misuse type and the amplification misuse types have
separate settings for bits per second and packets per second. The high
severity rate for the other misuse types is always in packets per
second.
Note: If you clear a high severity rate value that has not been saved, it
reverts to the previously saved value.
Host detection misuse types
SP uses the following misuse types with host detection:
Host detection misuse types
444
Misuse Type
Type of Traffic
Can Help Detect
Total Traffic
The total traffic (in
bps or pps) for a
given host
Host attacks that do not follow a known attack
pattern
chargen
Amplification
chargen traffic (in
bps or pps) with the
UDP protocol and
source port 19
chargen (Character Generator Protocol)
reflection/amplification attacks
DNS
DNS traffic (in pps) Floods of DNS traffic
with the TCP and/or
UDP protocol and
destination port 53
traffic
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
Host detection misuse types (Continued)
Misuse Type
Type of Traffic
Can Help Detect
DNS Amplification
DNS traffic (in bps
or pps) with the
UDP protocol and
source port 53
DNS reflection/amplification attacks
ICMP
IPv4 and IPv6
Internet Control
Message Protocol
traffic (in pps)
IPv4 ICMP and ICMPv6 packet-flooding
attacks
IP Fragment
Traffic (in pps) with
the IP fragment flag
TCP and UDP fragmentation attacks
Note: TCP and UDP fragmentation attacks
are often associated with chargen, DNS,
SNMP, SSDP, and MS SQL RS amplification
attacks.
IP Private
Traffic (in pps) for
private IP address
space
Spoofed IP addresses, which are not expected
to be routed over the Internet, that are used in
attacks
Note: SP uses the following IP spaces to
detect this misuse type:
n
n
IPv4
l
10.0.0.0/8
l
172.16.0.0/12
l
192.168.0.0/16
IPv6
l
All spaces except 2000::/3
IPv4 Protocol 0
Traffic (in pps) with Attacks in which the higher-layer transport
the protocol number protocol number is set to 0, which is an invalid
set to 0
protocol number (TCP is protocol 6, UDP is
protocol 17, and ICMP is protocol 1).
Note: The IPv4 Protocol 0 misuse type works
only with IPv4 traffic.
MS SQL RS
Amplification
UDP traffic (in bps
or pps)with source
port 1434
Microsoft SQL Resolution Service
reflection/amplification attacks
NTP Amplification
NTP traffic (in bps
or pps) with the
UDP protocol,
source port 123,
and invalid packet
sizes
NTP reflection/amplification attacks
Proprietary and Confidential Information of Arbor Networks Inc.
445
SP and TMS User Guide, Version 8.0
Host detection misuse types (Continued)
446
Misuse Type
Type of Traffic
Can Help Detect
SNMP Amplification
SNMP traffic (in
bps or pps) with the
UDP protocol and
source port 161
and/or 162.
SNMP reflection/amplification attacks
SSDP Amplification
UDP traffic (in bps
or pps) with source
port 1900
SSDP (Simple Service Discovery Protocol)
reflection/amplification attacks
TCP Null
TCP traffic (in pps)
that contains a
sequence number
but no flags
TCP Null-Flags attacks
TCP RST
TCP traffic (in pps)
with the reset flag
set
TCP reset attacks
TCP SYN
TCP traffic (in pps)
with the
synchronize flag set
Common TCP SYN flood attacks.
UDP
UDP traffic (in pps)
UDP attacks
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
About Profiled Router Detection
Introduction
Profiled router detection identifies traffic rates on a router that exceed expected levels for a
managed object or service. The traffic rate that SP expects for a managed object or service is
referred to as the baseline. A baseline is the learned traffic rate for a managed object or
service. When SP detects a profiled router anomaly, it gathers details about the anomalous
traffic on the affected routers. When the traffic significantly exceeds the baseline for a
sustained period of time, SP triggers an alert.
For information about configuring profiled router detection, see “Configuring Profiled Router
Detection for Managed Objects” on page 182 and “Configuring Profiled Router Detection for
Services” on page 237.
For more information about each of the detection types, see “About detection types” on
page 427.
Profiled router detection terminology
An understanding of the following terminology is needed to configure profiled router detection:
Baseline
n
The expected or normal rate of traffic.
Note: Baselines are not used with the interface groups match type.
n
Sensitivity threshold
How far traffic must be above the baseline before it is considered anomalous.
Note: Sensitivity thresholds are not used with the interface groups match type.
n
Profiled router latency period
The length of time that traffic must remain above the sensitivity threshold before an alert is
generated. It is also used to determine when an alert has ended. This value is a global
setting that is configured on the Configure Global Detection Settings page
(Administration > Detection > DDoS).
n
Severity duration
The length of time that traffic must exceed a given threshold before SP escalates its severity
level.
n
Severity threshold
A threshold that SP uses to differentiate between medium and high alert severity. If traffic
exceeds the severity threshold for the severity duration, then the alert is classified as high. If
traffic exceeds this threshold but does not stay there for the severity duration, then the alert
is classified as medium.
n
Middle line
A calculated value that is approximately 50% of the way between the sensitivity threshold
and the severity threshold. It is used to differentiate between low and medium levels of
severity.
n
Ignore rate
A traffic rate that must be exceeded before SP generates an alert. An ignore rate imposes a
floor to the baseline for the configured type (bps or pps). The ignore rate is not affected by
the baseline.
Proprietary and Confidential Information of Arbor Networks Inc.
447
SP and TMS User Guide, Version 8.0
Note: Ignore rates are not used with the interface groups match type.
n
Forced alert threshold
A threshold that causes SP to generate an alert when traffic exceeds it for the profiled
router latency period. This threshold is manually configured.
For information about match types, see “About match types” on page 168.
About profiled router detection baselines
Baselines are learned traffic rates of normal traffic for a managed object or service. Each
collector keeps a separate set of baselines for each managed object or service. Each collector
compares real-time flow information with its stored baselines. A profiled router alert is
generated when traffic is significantly above the baseline for a sustained period of time. The
sensitivity threshold defines how far traffic must be above the baseline before it is considered
anomalous. For information about the types of traffic that are tracked for baselines, see “Types
of profiled router detection” below.
Note: Profiled router detection does not use baselines with the interface groups match type.
For information about match types, see “About match types” on page 168.
For each managed object or service, data is collected per interface on the total traffic (bps and
pps) and per router on the traffic for each IP protocol (bps and pps). From this data, baseline
traffic rates are calculated using the average traffic rate from each of the following 30 minute
periods:
n Previous 30 minutes
n
Equivalent 30 minute period 24 hours ago
n
Equivalent 30 minute period 7 days ago
When computing the baseline, the older information is weighted more heavily in order to
reduce the effect of recent changes.
Types of profiled router detection
SP tracks baselines on a per router basis for the following types of traffic that match a
managed object that has profiled router detection enabled:
n total bandwidth
n
total per protocol
l
ESP
l
GRE
l
ICMP
l
ICMPv6
l
TCP
l
UDP
l
multi (all traffic that has an internal protocol number that is not explicitly tracked by the
preceding protocols)
How SP creates and classifies profiled router detection alerts
A profiled router detection alert is generated when traffic exceeds the baseline or a forced alert
threshold for a sustained period of time.
448
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
See “About profiled router detection baselines” on the previous page and “About the use of
forced alert thresholds” below.
SP creates a profiled router detection alert when the following occurs:
Traffic goes above the ignore rate (except with the interface groups match type that does
not use ignore rates).
n
n
Traffic goes above a forced alert threshold or the baseline plus the sensitivity threshold and
stays there for longer than the profiled router latency period.
SP then assigns a severity to the alert based on the following conditions:
Profiled router alert severity levels
Severity
Conditions
low
Traffic does not stay above the middle line for the severity duration and the
traffic never goes above a severity threshold.
medium
Traffic goes above the middle line and stays there for the severity duration or
traffic goes above a severity threshold but does not stay there for the severity
duration.
high
Traffic goes above a severity threshold and stays there for the severity duration.
About the use of forced alert thresholds
A forced alert threshold is a manually configured threshold for profiled router detection. If traffic
exceeds this threshold for the profiled router latency period, then SP generates an alert.
To generate alerts with an interface groups match type, you must configure forced alert
thresholds because baselines are not used with interface groups.
To generate alerts with any other match type, you can also use forced alert thresholds. For
example, with a managed object that has a fairly constant rate of traffic, you don’t really need
to use baselines to trigger alerts. You can then configure profiled router detection so that the
forced alert thresholds trigger the alerts instead of the baselines. If you set the alert ignore rates
to the same value as the forced alert thresholds, then alerts are generated only when the
forced alert thresholds are exceeded.
You can also use forced alert thresholds with baselines to ensure that alerts are generated
when traffic rates exceed certain thresholds. With a baseline, the rate of traffic that is required
to generate an alert can increase over time. If you configure forced alert thresholds, then an
alert is generated when a forced alert threshold is exceeded even when an alert would not be
generated because of the baseline.
About automatic rate calculation for profiled router detection
When you enable profiled router detection for a managed object or service, you can configure
the ignore rates and severity thresholds manually or you can enable automatic rate calculation.
Arbor recommends that you use the automatic rate calculation whenever possible, because
the calculated rates automatically adjust to changes in traffic patterns. As a result, the
calculated rates are less likely to produce false anomalies.
For more information about configuring automatic rate detection, see “Profiled router detection
configuration settings” on page 183.
Note: Automatic rate calculation is not available with the interface groups match type.
Proprietary and Confidential Information of Arbor Networks Inc.
449
SP and TMS User Guide, Version 8.0
Automatic rate calculation is based on rate settings that you configure and the last 30 days of
a managed object’s or service’s actual traffic. When the calculated ignore rates and severity
thresholds become available, they override your configured rates. SP calculates rates every
day at 00:35 GMT, 08:35 GMT, and 16:35 GMT.
Allow SP to monitor a managed object’s or service’s traffic for at least 24 hours before you
enable automatic rate calculation for that object. SP can calculate rates in less time, but
gathering a larger sample size of data ensures better accuracy.
When automatic rate calculation is enabled, the automatic rate calculation results for a
managed object or service appear in a graph and tables in the Profiled Router Detection
Configuration window. The graph displays traffic rates for the past 30 days and the current
calculated ignore rates and severity thresholds.
450
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
About Profiled Network Detection
Introduction
Profiled network detection identifies excessive rates of traffic that cross a managed object
boundary or service boundary. While host detection monitors the traffic to a single host, and
profiled router detection monitors the traffic at routers, profiled network detection monitors all
of the traffic that crosses a managed object boundary or service boundary. You can therefore
use profiled network detection to monitor the traffic of an arbitrarily defined network space.
For more information about each of the detection types, see “About detection types” on
page 427.
How profiled network detection works
With profiled network detection enabled for a managed object or service, SP triggers an alert
when it identifies excessive rates of traffic at the managed object boundary or service
boundary, based on baselines that SP has calculated. The rate of traffic must exceed the
baseline by the detection percentage for a sustained period of time. When SP generates a
profiled network detection alert, it classifies the severity of the alert as low, medium, or high.
For more information about baselines and detection percentage, see “Profiled network
detection terminology” below.
A profiled network alert can only be triggered by traffic that crosses a managed object
boundary or service boundary. However, traffic that crosses the network boundary and that is
going in the same direction as the traffic that triggered the alert (incoming or outgoing) can
keep a profiled network alert ongoing. By monitoring the traffic at the network boundary, SP
can keep an alert ongoing when the traffic at the managed object boundary or service
boundary would indicate that it should be ended. For example, if you mitigate the attack traffic
of a profiled network alert, the traffic at the managed object boundary might indicate that the
alert should be ended, while the traffic at the network boundary might indicate that the alert
should continue to be ongoing.
When SP detects a profiled network alert, it gathers details about the alert traffic from across
the entire network. It combines all protocols for which attacks have been detected on the same
managed object or service into one alert. It also provides the source ASN.
Profiled network detection terminology
An understanding of the following terminology is needed to configure profiled network
detection:
n Baseline
The expected or normal rate of traffic.
See “About profiled network detection baselines” on the next page.
n
Detection percentage
The percentage above the baseline that the rate of traffic must reach before SP can
generate an alert. The traffic must maintain this rate for the profiled network start latency
period before an alert is generated.
n
Trigger rate
A traffic rate that must be exceeded before SP generates an alert. This rate is the baseline
plus the detection percentage.
Proprietary and Confidential Information of Arbor Networks Inc.
451
SP and TMS User Guide, Version 8.0
n
Profiled network start latency period
The length of time that the rate of traffic must exceed the trigger rate before SP generates
an alert. This value is a global setting that is configured on the Configure Global Detection
Settings page (Administration > Detection > DDoS).
Note: If the rate of traffic exceeds the baseline by the high severity percentage for at least a
minute, an alert is generated even if the profiled network start latency period has not
elapsed.
n
High severity duration
The length of time that the rate of traffic must exceed the baseline by a specified percentage
before SP classifies an alert as medium or high. An alert is classified as medium severity if
the rate of traffic exceeds the baseline by at least 75 percent of the high severity
percentage for the high severity duration. An alert is classified as high severity if the rate of
traffic exceeds the baseline by the high severity percentage for the high severity duration.
n
High severity percentage
The percentage above the baseline that the rate of traffic must reach before SP can classify
an alert as medium or high. If the rate of traffic exceeds the baseline by the high severity
percentage for at least one minute but for less than the high severity duration, the alert is
classified as medium. If the rate of traffic exceeds the baseline by the high severity
percentage for the high severity duration, then the alert is classified as high.
n
Ignore rate
A traffic rate that must be exceeded before SP generates an alert. An ignore rate imposes a
floor to the baseline for the configured type (bps or pps). The ignore rate is not affected by
the baseline.
n
Profiled network end latency period
The length of time that the rate of traffic must remain below the trigger rate before SP ends
an alert. The profiled network end latency period is a global setting that is configured on the
Configure Global Detection Settings page (Administration > Detection > DDoS).
For more information about the ending of profiled network alerts, see “How SP determines if
a DoS alert should be ended or ongoing” on page 496.
About profiled network detection baselines
Baselines are learned traffic rates of normal traffic. SP generates an alert for a managed object
when the rate of traffic exceeds the baseline by a specified percentage (detection percentage)
for a sustained period of time.
SP starts collecting baseline data as soon as profiled network detection is turned on for that
managed object. However, baseline data does not appear in the reports for about 24 hours.
Baselines are updated every 30 minutes at 15 and 45 minutes past the hour.
452
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 16: About DoS Detection
How SP creates and classifies profiled network alerts
SP creates profiled network alerts and assigns their severity level based on the following
conditions:
Profiled network alert severity levels
Severity
Conditions
low
An alert has a low severity level if the following conditions are true:
n
n
n
medium
An alert has a medium severity level if the following conditions are true:
n
n
n
n
high
Traffic exceeds the ignore rate.
Traffic exceeds the baseline by the detection percentage and stays there for
the profiled network start latency period.
Traffic exceeds the baseline by 75 percent of the high severity percentage
and has a duration that is less than the high severity duration or the traffic
exceeds the baseline by the high severity percentage and has a duration that
is less than a minute and less than the high severity duration.
Traffic exceeds the ignore rate.
Traffic exceeds the baseline by the detection percentage and stays there for
the profiled network start latency period, or traffic exceeds the baseline by the
high severity percentage for at least a minute.
Traffic exceeds the baseline by at least 75 percent of the high severity
percentage for the severity duration.
Traffic does not exceed the baseline by the high severity percentage for the
high severity duration.
An alert has a high severity rate if the following conditions are true:
n
n
n
Traffic exceeds the ignore rate.
Traffic exceeds the baseline by the detection percentage and stays there for
the profiled network start latency period.
Traffic exceeds the baseline by the high severity percentage and stays there
for the high severity duration.
Proprietary and Confidential Information of Arbor Networks Inc.
453
SP and TMS User Guide, Version 8.0
454
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17:
About Alerts
Introduction
This section describes how to use SP alerts to investigate anomalous network activity.
User access
Administrators and non-administrative users have access to these features.
In this section
This section contains the following topics:
How Alerts Work
456
About Alert Classes and Alert Types
458
About the Alert Listing Pages
465
About the Security Status Page
471
About the Activity Report
472
About the DoS Alert Pages
473
About the Fingerprint Threshold Alert Pages
475
About the Service Threshold Alert Pages
477
About the Cloud Signaling Request Alert Pages
480
About the BGP Instability Alert Pages
483
Adding Annotations to an Alert
486
About Alert Classification
488
SP and TMS User Guide, Version 8.0
455
SP and TMS User Guide, Version 8.0
How Alerts Work
Introduction
SP sends a variety of alerts for different network behaviors. It triggers DoS alerts based on
detection settings. See “About Detection Settings for Managed Objects and Services” on
page 427.
SP alerts are categorized by class and type. Each alert class contains one or more types of
alerts. For information about alert classes and types, see “About Alert Classes and Alert Types”
on page 458.
For information about the different alert pages, see “About the Alert Listing Pages” on
page 465.
For information about navigating the alerts pages, see “Navigating the SP Web UI” on page 28.
How SP uses samples to collect data for alerts
SP aggregates data into statistically significant groupings, such as subnets and port ranges.
SP uses one-minute samples to collect the data for alerts. Flow records that match the alert
are gathered from all SP systems every 60 seconds. These flow records are parsed networkwide for the following information:
n ingress and egress interfaces
n
protocols
Note: With a Fast Flood DoS Host alert, SP bypasses this method of collecting data in order
to trigger the alert more quickly.
Alert levels of importance
SP assigns each alert one of the following levels of importance, based on its severity:
Alert importance levels
Importance
Color
Recommended action
High
Red
Address the alert immediately.
Medium
Orange
Analyze the alert to determine whether it is an
attack.
Low
Green
Ignore if it is not worth your time to address
them.
For a DoS alert, SP uses the default thresholds or the thresholds that you set to determine the
levels of importance. For additional information, see the following:
n “How SP creates and classifies standard host alerts” on page 433
456
n
“How SP creates and classifies profiled network alerts” on page 453
n
“How SP creates and classifies profiled router detection alerts” on page 448
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
Notification settings for alerts
You can configure SP to use rules to notify you and particular groups when it triggers an alert.
To configure the different alert notification settings, see the following references:
Alert notification settings
Settings
Navigation path
Reference
Global settings for alert
notification on the Global
Notification Settings page
Administration >
Notification > Global
Settings
“Configuring Global Notification
Settings for Alerts” on page 260
Notification groups on the
Notification Groups page
Administration >
Notification > Groups
“Configuring Notification
Groups” on page 263
Notification rules on the
Rule-Based Notification
page
Administration >
Notification > Rules
“Configuring Alert Notification
Rules” on page 270
Proprietary and Confidential Information of Arbor Networks Inc.
457
SP and TMS User Guide, Version 8.0
About Alert Classes and Alert Types
Introduction
In SP, alerts are categorized by class and type. Each alert class contains one or more types of
alerts. You can view the alerts organized by class on the Alert Classes tab on the Security
Status page (Alerts > Summary). You can also search for alerts by class and by type on the
All Alerts and Alerts Ongoing pages, using the Search box or the search wizard. See “About
searching for alerts on the alert listing pages” on page 466.
For additional information about alerts, see the following topics:
“How Alerts Work” on page 456
n
n
“About the Alert Listing Pages” on page 465
n
“Introduction to DoS Alerts” on page 492
n
“About the Security Status Page” on page 471
Alert classes
SP alerts are categorized by the following classes:
Alert classes
Alert class
Description
BGP
BGP traps and policy violations
Cloud Signaling
Cloud Signaling mitigation requests and Cloud Signaling faults
Data
BGP, flow records, and SNMP interruptions
DoS
Potential DoS attacks
System Error
SP appliance faults
System Event
Configuration changes
TMS
n
n
Traffic
458
DNS misuse or traffic rate violations that are detected by TMS
appliances
Notifications about TMS appliances
Traffic rate violations
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
Alert types
The following are the different alert types with their class and triggering event:
Alert types and triggers
Alert type
Alert
class
Alert trigger
BGP Down
Data
The BGP peering session is down for a specified router.
BGP Instability
BGP
The number of BGP updates in five minutes exceeds the BGP instability
threshold. The default threshold is 8,000.
BGP instability is typically caused by misconfigurations by a peer.
BGP Route Hijack
BGP
SP detects a BGP route announcement from an external ASN for a prefix
within the defined local address space. This occurs while autoconfiguration takes place. This alert indicates either a potential hijacking of
local address space or a misconfiguration of the local address space.
BGP Trap
BGP
The BGP attributes change for a specified prefix or prefixes. SP monitors the
following attributes:
n
n
n
AS path
up and down
nexthop change
Cloud Signaling
Fault
Cloud
Communication is lost between the APS deployment and its SP manager.
Signaling
Cloud Signaling
Mitigation Request
Cloud
A customer’s APS deployment requests mitigation.
Signaling Note: For managed objects that are associated with multiple APS
deployments, if a Cloud Signaling request is generated by a APS
deployment, then any additional requests from other APS deployments in
the same managed object are added to the ongoing alert.
DNS Baseline
Alert
TMS
One of the following events occurs:
n
n
Interface traffic deviates significantly from the baseline traffic level of a
DNS name.
SP adds a DNS name to the top talkers list, and the query count exceeds
a configured percentage of the total queries.
Important: For TMS DNS Baseline alerting to be enabled, the TMS
appliance must be managed by the leader.
This alert applies to the interfaces that the TMS appliances monitor.
The global DNS baseline alert settings are configured on the Configure
Global Detection Settings page (Administration > Detection >
DDoS).
DoS Alert
DoS
A potential DoS attack is detected. See “Introduction to DoS Alerts” on
page 492.
Fingerprint
Threshold
Traffic
The traffic matching a fingerprint exceeds the high threshold or drops below
the low threshold.
Proprietary and Confidential Information of Arbor Networks Inc.
459
SP and TMS User Guide, Version 8.0
Alert types and triggers (Continued)
Alert type
Alert
class
Alert trigger
Flow Down
Data
A router does not receive flow records for at least two minutes.
GRE Down
TMS
A TMS GRE tunnel is down. The alert includes the endpoint IP address and
the name of the GRE tunnel.
Hardware Failure
System
Error
A hardware failure alert is triggered for each of the following hardware
failure subtypes:
n
n
n
Power Supply Failure: A problem occurs with a power supply unit.
RAID Battery Failure: The battery on the RAID card can no longer hold an
adequate charge to commit data in the event of a power loss and
switches to write-through mode from write-back mode.
RAID Failure: A problem occurs with a disk in the RAID array.
Interface Usage
Traffic
The interface traffic exceeds the threshold.
License Alert
System
Error
A license alert can be triggered only if you have uploaded a flexible license
or connected to a cloud-based license server. A license alert is triggered
when either of the following conditions are met:
n
n
Your deployment approaches or exceeds licensed capacities. See
“Conditions that trigger a license alert for licensed capacities” on the
facing page.
(Cloud-based licensing only) SP is unable to refresh the local copy of the
cloud-based license, and this copy will expire in 9 or fewer days. See
“Conditions that trigger a license alert with cloud-based licensing” on
page 462.
Managed Object
Threshold
Traffic
The traffic for a managed object exceeds the high threshold or drops below
the low threshold.
Mobile Analysis
Fault
Mobile
Analysis
A Mobile Analysis appliance issue occurs, such as an interface link is down,
a power supply has failed, or the Mobile Analysis appliance is effectively
down (this is a system status alert).
SP/TMS
Appliance Down
System
Error
This alert is triggered when any of the following occurs:
n
n
n
The leader appliance does not receive a heartbeat from an appliance for
over two minutes.
A TMS appliance does not communicate with its non-leader manager for
over two minutes.
The non-leader manager of a TMS appliance does not communicate with
the TMS appliance for over two minutes.
For a description of what the alert identifies, see “SP/TMS Appliance Down
alert ” on page 462.
SP System
Monitoring
460
System
Error
A problem has occurred for an SP appliance. For example, for a process
error alert, “process error detected: zoned” appears.
See “Configuring SP System Monitoring Alerts” on page 266.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
Alert types and triggers (Continued)
Alert type
Alert
class
Alert trigger
Routing Failover
Event
System
Error
A failover from one interface to another has occurred. The Routing Failover
Interfaces alert identifies the interface that failed.
Routing Failover
Interfaces
System
Error
When an interface fails over, this alert is generated to identify the interface
that failed.
Service Threshold
Traffic
The traffic for a service exceeds the high threshold or drops below the low
threshold.
SNMP Down
Data
SNMP access fails for a router.
SPCOMM Failure
System
Error
A communication failure occurs between appliances.
System
Configuration
Update
System
Event
A user commits configuration changes.
TMS Fault
TMS
A TMS appliance issue occurs, such as a router has failed or the TMS
appliance is effectively down. Each TMS Fault alert includes a description
of what caused the alert.
For information about some of the different TMS Fault alerts, see “TMS
Fault alert descriptions” on page 463.
Traffic-Triggered
Auto-Mitigation
Traffic
SP initiates a traffic-triggered auto-mitigation for a managed object. See
“About traffic-triggered auto-mitigation” on page 199.
Conditions that trigger a license alert for licensed capacities
A license alert can be triggered only if you have uploaded a flexible license. A license alert for
licensed capacities is triggered when the following usage categories approach or exceed their
licensed capacities:
n Active users
A license alert is triggered with an importance level of medium when the deployment-wide
usage on appliances in flexible license mode exceeds 90% of the licensed capacity. The
alert is raised to an importance level of high when the licensed capacity is reached or
exceeded.
n
Managed objects
A license alert is triggered with an importance level of medium when the deployment-wide
usage exceeds 90% of the licensed capacity. The alert is raised to an importance level of
high when the licensed capacity is reached or exceeded.
n
Flows per second for core or edge routers
A license alert is triggered with an importance level of medium when the deployment wide
usage on core or edge routers that are managed by appliances in flexible license mode
exceeds 90% of the licensed capacity for 5 minutes. The alert is raised to an importance
level of high when the number of flows per second exceeds the capacity for 5 minutes.
Proprietary and Confidential Information of Arbor Networks Inc.
461
SP and TMS User Guide, Version 8.0
n
Core or edge routers
A license alert is triggered only if the number of routers managed by appliances in flexible
license mode exceeds the licensed capacity when you convert an appliance to flexible
license mode.
n
AIF
A license alert is triggered with an importance level of medium when the AIF licensing is
within 30 days of expiration. An alert with an importance level of high is triggered when the
TMS appliances in your deployment exceed the AIF licensed capacity.
Except for managed objects, license alerts are triggered only for licensed capacities that are
monitored by SP appliances in flexible license mode. With managed objects, a license alert is
triggered when the number of managed objects in your entire deployment approaches or
exceeds the licensed capacity. The licensed capacity for managed objects is the sum of the
base licensed capacity (1,000 managed objects), the flexible-licensed capacity, and the
licensed capacity of each appliance in appliance-based license mode that has the data
storage role.
For information about how SP enforces flexible-licensed capacity, see “About Flexible
Licensing Enforcement” on page 93.
Conditions that trigger a license alert with cloud-based licensing
With cloud-based licensing, SP tries to communicate with the license server on a regular basis
throughout each day to refresh the local copy of the cloud-based license. If SP cannot
communicate with the license server to refresh the local copy, the local copy remains valid for
10 days. After 10 days, the local copy expires, and the ability to access and use SP is severely
limited. For information about cloud-based licensing and how it is enforced, see “About Cloudbased Licensing” on page 96.
SP generates the following license alerts for cloud-based licensing:
An alert with an importance level of medium when the copy of the cloud license will expire in
the next 1 to 9 days.
n
n
An alert with an importance level of high when the copy of the cloud license will expire in
less than 1 day or has already expired.
If the local copy of the cloud-based license has not expired, these alerts include the number of
days until it expires.
SP/TMS Appliance Down alert
The SP/TMS Appliance Down alert identifies the appliance that is down and the appliance that
detected the problem.
For example, if a non-leader manager of a TMS appliance does not communicate with the TMS
appliance for over two minutes, then an alert is triggered. The alert identifies the manager of
the TMS appliance as the down appliance. It also identifies the TMS appliance as the
appliance that detected the problem. You then know that you need to determine why the
manager of the TMS appliance is not able to communicate with the TMS appliance.
This alert might indicate a connectivity or appliance issue.
462
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
TMS Fault alert descriptions
The following are some of the TMS Fault alert descriptions with an explanation of what
triggered the alert:
TMS Fault alert descriptions and triggers
Alert description
Alert trigger
Example
Filesystem ‘QDPH’
(‘PRXQW SRLQW’)
transitioned from
‘1RPLQDO’ to
‘&ULWLFDO’
A file system on the TMS is more than 98%
full.
The value QDPH is the name of the file
system and the value PRXQW SRLQW is
where the file system is mounted.
Filesystem ‘Root (‘/’)’
transitioned from
‘Nominal’ to ‘Critical’
(99% used (127.78G
/ 128.85G))
Hardware Device
‘KDUGZDUH
GHYLFH’ is ‘Error’
An error is detected with a hardware device,
including a disk in the RAID array.
Hardware Device
‘Power Supply PS2’ is
‘Error’ (Presence
detected, Power
Supply AC lost)
Hardware Sensor
‘KDUGZDUH
VHQVRU’ is ‘Critical’
A hardware sensor, such as a temperature
sensor, reports a situation outside the
operating range.
Hardware Sensor
‘Temperature (Slot
CPU 0)’ is ‘Critical’
(60C / 140F)
Interface Link ‘QDPH’
is ‘Down’
An interface goes down. In the case of
logical interfaces, the alert is not generated
unless all of the physical members of the
LACP (Link Aggregation Control Protocol)
bundle are down.
Interface Link ‘tms0’ is
‘Down’
Mitigation
‘PLWLJDWLRQ
QDPH’ is ‘Out of
Service’
A mitigation has been removed from service
because a fate sharing condition is not met.
For more information about the fate sharing
options on the Deployment tab, see
“Deployment settings for a TMS appliance,
TMS-ISA, or TMS-VSM” on page 536.
Mitigation ‘mariner30406’ is ‘Out of
Service’ (Interface
tms0 (Down))
Nexthop ‘DGGUHVV’
is ‘Unreachable’
The nexthop address for a given interface
cannot be resolved.
Nexthop
‘tms0:11.22.33.44’ is
‘Unreachable’
Proprietary and Confidential Information of Arbor Networks Inc.
463
SP and TMS User Guide, Version 8.0
TMS Fault alert descriptions and triggers (Continued)
464
Alert description
Alert trigger
Example
Rate Limit ‘Licensed
Limit’ is ‘Over Limit’
(For TMS appliances with licensed rate
limits only) When the traffic rate on the
TMS appliance exceeds the licensed rate
limit, the TMS appliance starts dropping
enough packets to remain below the
licensed limit. When this alert is enabled for
a TMS appliance, it triggers after the
appliance has been dropping packets for 60
consecutive seconds to remain below the
licensed limit.
For information on how to enable this alert,
see “Enabling and Disabling the Rate Limit
Alert for a TMS Appliance” in the SP and
TMS Advanced Configuration Guide.
Rate Limit ‘Licensed
Limit’ is ‘Over Limit’
(System over licensed
limit: offered rate of
3.44 Gbps exceeds
limit)
Subhost ‘VXEKRVW’
is ‘Inactive’
A subhost goes offline.
Subhost ‘apm0-0’ is
‘Inactive’
System Status
‘QDPH’ is ‘{Degraded
| Critical}’
The system is in a degraded or inoperable
state.
When a TMS Fault alert has this
description, SP stops any other TMS Fault
alerts and related mitigations for that
appliance.
System Status
‘License’ is
‘Degraded’ (Invalid
license key)
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the Alert Listing Pages
Introduction
The alert listing pages display information about the alerts that are triggered by SP. To search
for alerts on the alert pages, you can use the Search box and the Alert Search Wizard.
The All Alerts page (Alerts > All Alerts) displays all current and past alert activity. You can
also use the following pages to view the same information for specific types of alerts:
n Ongoing Alerts (Alerts > Ongoing)
n
Alerts Recent (Alerts > Summary > 5HFHQW DOHUW OLQN on the All Alerts tab)
n
DoS Alerts (Alerts > DoS)
n
Fingerprint Threshold Alerts (Alerts > Fingerprints)
n
Service Threshold Alerts (Alerts > Services)
n
System Error Alerts (Alert > System Error)
For additional information, see the following:
“About Alert Classes and Alert Types” on page 458
n
n
“How Alerts Work” on page 456
n
“Introduction to DoS Alerts” on page 492
n
“Navigating multiple pages” on page 30
n
“About searching for alerts on the alert listing pages” on the next page
About the layout of the alert listing pages
The alert listing pages contain the following information:
Alert listing pages information
Information
Description
Search box
Use to search for alerts, with or without keywords.
See “About searching for alerts on the alert listing pages” on the next
page.
Wizard button
Click to search for alerts by using the Alert Search Wizard.
See “About searching for alerts on the alert listing pages” on the next
page.
ID
The unique number that is assigned to each alert. If the ID is a link, you
can click the link to navigate to the alert’s detail page.
Graph
For traffic alerts, a minigraph of the traffic that is a visual depiction of
an alert’s ongoing activity. You can click the graph to navigate to the
Summary tab of the alert.
Proprietary and Confidential Information of Arbor Networks Inc.
465
SP and TMS User Guide, Version 8.0
Alert listing pages information (Continued)
Information
Description
Importance
The alert’s severity level (high, medium, or low), and with DoS alerts,
the maximum severity percent and the maximum impact of alert traffic
values. Maximum severity percent is the highest single-minute ratio of
the rate of the alert traffic to the high severity rate over the lifetime of
the alert. Maximum impact of alert traffic is the maximum single minute
of network bandwidth consumed by the alert.
Note: The maximum severity percent and the maximum impact of alert
traffic values will not always match. See “Why maximum severity
percent, maximum impact of alert traffic, and maximum observed
values might not match” on page 496.
By default, SP sorts alerts in the Importance column first by severity
level and then by the maximum severity percent value. You can change
how SP sorts alerts in the Importance column. See “Changing How
SP Sorts Alerts by Importance” in the SP and TMS Advanced
Configuration Guide.
Alert
The type of alert with key information about the alert. This information
includes the resource associated with the alert. It can also include a
link to the managed object or service associated with an alert.
Start Time
The time at which the alert activity was first detected, followed by the
duration of the alert in days, hours, and minutes (DD d, HH:MM). If the
alert has not ended, SP displays Ongoing.
Classification &
Annotations
The classifications and annotations that are applied to an alert. SP
automatically annotates DoS alerts when they cannot trigger automitigation or when certain events occur that change an alert’s
importance. You can also click the icon to apply an annotation to an
alert.
See “About Alert Classification” on page 488.
See “Adding Annotations to an Alert ” on page 486.
Ticket
A link to edit an alert’s corresponding ticket, if you integrate a Webbased ticketing system with SP.
See “Configuring Ticketing” on page 280.
page navigation
links
Click to navigate to other Alerts pages. See “Navigating multiple
pages” on page 30.
About searching for alerts on the alert listing pages
You can use the Search box to search on the alert listing pages. The following are some
guidelines for using the Search box:
n You can enter search values with or without keywords.
466
n
Search values and keywords are case-insensitive.
n
Keywords allow you to search on a specific attribute.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
n
When you enter a keyword followed by a value, do not put a space between the colon and
the value that you enter.
n
A match occurs when a search value matches any part of a text string.
n
A space between search values creates an AND statement.
n
A comma between search values creates an OR statement.
You can enter the search values “fast,” “flood,” or “fast flood” to search for all DoS Host
alerts that are triggered by fast flood detection.
n
n
If you do not enter a keyword, then SP tries to match your search entry to specific elements
in the list of alerts. These elements include the alert ID (if you entered a positive integer),
alert type, severity level, status, and resource.
A resource is a service, fingerprint, or managed object.
n
You can use quotation marks (“) to match a phrase. For example, to search for an annotation
that contains “This attack is crippling,” you can type ann:”This attack is
crippling”.
See “Acceptable search keywords and values for alerts” below.
If you want to add time search criteria to your search, use the Alert Search Wizard. See “Using
the Alert Search Wizard” on page 469.
Acceptable search keywords and values for alerts
The following table describes the acceptable keywords and values that you can use to search
for alerts in the Search box:
Search keywords for attributes
Attribute to
search by
Acceptable keywords
and values
resource (a
service,
fingerprint, or
managed object)
n
n
n
n
router name
n
n
alert ID
n
n
Examples
resource:PDQDJHG
REMHFW
ILQJHUSULQW
DQGRU VHUYLFH
QDPH
mo:PDQDJHG REMHFW
QDPH
fingerprint:
ILQJHUSULQW QDPH
service:VHUYLFH
QDPH
n
ro:URXWHU QDPH
router:URXWHU
QDPH
n
,' QXPEHU
alert_id:,'
QXPEHU
n
Proprietary and Confidential Information of Arbor Networks Inc.
n
n
resource:object3,example_service
mo:object1
service:new_serv1
The “resource” keyword searches for alerts
that involve services, fingerprints, and
managed objects.
This search is case-insensitive, and SP
matches on partial resources.
n
n
n
router:789xyz
ro:router123
router:routerabc
12345
alert_id:23456
467
SP and TMS User Guide, Version 8.0
Search keywords for attributes (Continued)
Attribute to
search by
Acceptable keywords
and values
alert class
n
n
severity level
n
n
n
alert type
n
n
n
alert status
n
n
n
classification
n
n
annotation
n
n
n
n
prefix
n
Examples
ac:DOHUW FODVV
alert_class:DOHUW
FODVV
n
VHYHULW\
sev:VHYHULW\
severity:VHYHULW\
n
DOHUW W\SH
at:DOHUW W\SH
alert_type:DOHUW
W\SH
n
DOHUW VWDWXV
sts:DOHUW VWDWXV
status:DOHUW
VWDWXV
n
classification:
FODVVLILFDWLRQ
ax:FODVVLILFDWLRQ
n
DQQRWDWLRQ
ann:DQQRWDWLRQ
alert_
annotation:
DQQRWDWLRQ
comment:
DQQRWDWLRQ
n
n
Critical
ann:Critical
alert_annotation:Critical
comment:”this is critical”
prefix:&,'5 EORFN
n
prefix:10.0.0.0/8
n
ac:TMS
alert_class:TMS
See “Alert classes” on page 458.
n
n
n
n
low
sev:low
severity:high,low
“BGP Trap”
at:“BGP Trap”
alert_type:“BGP Trap”
This search is case-insensitive, and SP
matches on partial alert types. For example,
if you type at:udp in the Search box, SP
returns all the alerts that have UDP in the
Alert column.
See “Alert types” on page 459.
n
n
ongoing
sts:recent
status:all
You can type all, ongoing, recent,
ended, stopped, done, or completed for
the alert status.
n
classification:“Possible Attack”
ax:“network failure”
See “About Alert Classification” on
page 488.
n
n
Note: If an alert is very short-lived, you
might not be able to find it by using the
prefix keyword.
468
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the search results
By default, the search returns the top 100 results in order of relevance. You can change the
system default setting by using the CLI. See “Changing the Search Result Settings on the
Alerts Pages” in the SP and TMS Advanced Configuration Guide.
You can override the default setting for specific searches by using the Alert Search Wizard.
See “Using the Alert Search Wizard” below.
Using the Alert Search Wizard
To search for alerts from the Alert Search Wizard:
1. From the Alerts menu, navigate to any alert listing page, except the Security Status page,
and then click Wizard.
2. In the Alert Search Wizard, configure the search settings.
See “Settings in the Alert Search Wizard” below.
When you configure multiple settings, SP combines them using AND statements.
3. Click Search.
4. (Optional) If you searched by the start or stop time, you can configure the time controls
that appear, and then click Search.
These time controls further refine the search, based on the initial search results.
5. (Optional) If you do not click away from the page, then you can repeat these steps to add
or change the search criteria.
Settings in the Alert Search Wizard
Use the following table to configure the Alert Search Wizard settings:
Alert Search Wizard settings
Setting
Description
Severity level check
boxes
Select the check boxes for the severity levels by which to search.
The severity levels are High, Medium, and Low.
Alert Class list
Select the alert class by which to search.
See “Alert classes” on page 458.
Alert Type list
Select the alert type by which to search.
See “Alert types” on page 459.
Classification list
Select the classification by which to search.
See “About Alert Classification” on page 488.
Search Limit box
Type the maximum QXPEHU of results to return.
Items per Page box
Type the QXPEHU of results to view per page.
Status check boxes
Select the check boxes for the alert statuses to include in the
search. The statuses are Ongoing and Recent.
Start and Stop
settings
Configure the start and stop times by which to search.
Proprietary and Confidential Information of Arbor Networks Inc.
469
SP and TMS User Guide, Version 8.0
Alert Search Wizard settings (Continued)
Setting
Description
Maximum Impact of
Alert Traffic boxes
Type the bps and pps values for the maximum impact of alert traffic
data by which to search. You can search using both a low and
high value, just a low value, or just a high value.
Maximum impact of alert traffic is the maximum single minute of
network bandwidth consumed by the alert.
Maximum Severity
Percent boxes
Type the maximum severity percent values by which to search. You
can search using both a low and high value, just a low value, or
just a high value.
Maximum severity percent is the highest single-minute ratio of the
alert traffic to the high severity rate over the lifetime of the alert.
The traffic can be on an individual router, the network boundary, or
the managed object boundary.
About deleting alerts
To manage the alert pages, you can delete alerts manually or schedule SP to delete alerts
automatically after a specified number of days. See “Deleting Alerts” on page 411.
470
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the Security Status Page
Introduction
You can view a summary of alerts, ongoing mitigations, and the general health of your SP
appliances on the Security Status page (Alerts > Summary).
Note: For non-administrator users, this page displays only DoS alerts. To view all alerts, users
must have administrator privileges.
About the Alert Activity tab
The Alert Activity tab includes a graph that displays the alert activity over the last 24 hours. The
time is graphed on the X-axis and the severity percentage is graphed on the Y-axis. Alerts are
color coded according to their type.
Note: Managed services users can view a graph of traffic on their network.
You can also view alert activity for DoS alerts on the Activity Report. See “About the Activity
Report” on the next page.
About the All Alerts and Alert Classes tabs
The All Alerts tab and the Alert Classes tab display the number of ongoing alerts, recent
alerts, and alerts in the last 24 hours. Recent alerts are all alerts that are not ongoing. The All
Alerts tab organizes these totals by alert importance (severity) level, and the Alert Classes
tab organizes the totals by alert class. You can click the number links on these tabs to navigate
to the corresponding Alerts Ongoing or Alerts Recent page. The page includes only the alerts
that have the importance level or alert class of the selected link.
About the Ongoing Alerts, Ongoing Mitigations, and Appliances tabs
The Ongoing Alerts, Ongoing Mitigations, and Appliances tabs contain the following
information:
Ongoing Alerts, Ongoing Mitigations, and Appliances tabs
Tab
Description
Ongoing Alerts
Displays the five most severe ongoing alerts that have a high or
medium severity and are still active. The information on this tab is the
same as the information that appears on the Alerts Ongoing page
(Alerts > Ongoing).
For information about alert severity, see “Alert levels of importance” on
page 456.
Ongoing
Mitigations
Displays the five most recent mitigations. The information on this tab is
the same as the information that appears on the All Mitigations page
(Mitigation > All Mitigations). See “About the All Mitigations
Page” on page 727.
Appliances
Displays the status of your SP appliances. The information on this tab
is the same as the information that appears on the General tab of the
Appliance Status page (System > Status > Appliance Status).
See “Viewing General Appliance Statistics” on page 344.
Proprietary and Confidential Information of Arbor Networks Inc.
471
SP and TMS User Guide, Version 8.0
About the Activity Report
Introduction
The Activity Report page displays alert activity for DoS alerts for the time period that you
select. It displays the alert activity in graphs and corresponding tables for incoming and
outgoing alerts. It displays graphs and tables for alerts by:
n Severity
n
Misuse types
An alert can be triggered by one or more misuse types.
n
Affected prefixes (top 10)
n
Routers (top 10)
n
Severity percentage (top 10)
The top 10 affected prefixes tables include links to the configuration page of the managed
object that triggered each alert. The top 10 routers tables include links to the configuration
page of each router. The top 10 alerts by severity percentage tables include links to the DoS
alert page for each alert and to the configuration page for the managed object or global
detection that triggered the alert.
Viewing the Activity Report
To view the Activity Report:
1. Navigate to the Activity Report page (Alerts > Activity Report).
2. From the Period list, select the time period for which you want to display alert activity.
If you select Other, you can specify the date and time for starting and ending the alert
activity that you want to view.
For the start and end times of the predefined time periods, see “Predefined time periods”
below.
3. Click Update.
Predefined time periods
The predefined time periods have the following start and end times:
Predefined time period start and end times
472
Time Period
Start Time
End Time
Today
24 hours ago
Now
Yesterday
00:00 1 day ago
23:59 1 day ago
This Week
7 days ago
Now
This Month
28 days ago
Now
This Year
52 weeks ago
Now
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the DoS Alert Pages
Introduction
The DoS alert pages can display the following types of alerts:
DoS Host
n
A DoS Host alert is triggered when the traffic to a host on all monitored routers exceeds the
configured threshold of an enabled misuse type for a sustained period of time.
n
DoS Profiled Router
A DoS Profiled Router alert is triggered when traffic on a router significantly exceeds the
expected levels for a sustained period of time.
n
DoS Profiled Network
A DoS Profiled Network alert is triggered when traffic at a managed object boundary or
service boundary significantly exceeds the expected baseline for a sustained period of time.
A DoS alert provides details about a DoS attack and how it affects your network. It displays
breakdowns of what triggered an alert and the routers and interfaces that detected the traffic.
For additional information about DoS alerts, see the following topics:
n “Introduction to DoS Alerts” on page 492
n
“About the Summary Tab on a DoS Alert Page” on page 498
n
“About the Traffic Details Tab on a DoS Alert Page” on page 507
n
“About the Routers Tab on a DoS Alert Page” on page 510
n
“About the Annotations Tab on a DoS Alert Page” on page 513
Navigating to a DoS alert page
To navigate to a DoS alert page:
1. Navigate to the DoS Alerts page (Alerts > DoS).
2. In the Search box, type one of the following, depending on the type of DoS alert you want
to view, and then click Search.
l
host
l
profiled router
l
profiled network
3. Click the graph or ID link for the DoS alert.
About DoS Host alerts
DoS Host alerts are triggered by host detection. Host detection can trigger a standard DoS
Host alert or a Fast Flood DoS Host alert. A standard DoS Host alert is triggered when the
traffic on a monitored router towards a single host exceeds the configured threshold of an
enabled misuse type for a specified time period. See “About Host Detection” on page 429.
A Fast Flood DoS Host alert is triggered when large amounts of traffic toward a single host are
detected for an enabled misuse type. A Fast Flood DoS Host alert always has a severity of
High, and the severity is always followed by Fast Flood. When the alert is triggered, an
annotation is added to the alert that indicates that the alert was triggered by fast flood
detection. See “About host detection with fast flood detection enabled” on page 431.
Note: You can enter the search values “fast,” “flood,” or “fast flood” in the Search box on an
alert listing page to search for Fast Flood DoS Host alerts.
Proprietary and Confidential Information of Arbor Networks Inc.
473
SP and TMS User Guide, Version 8.0
If excessive traffic is detected for multiple misuse types that are enabled, then a single DoS
Host alert is created instead of separate alerts for each misuse type. The alert includes each
misuse type that had excessive traffic. See “Host detection misuse types” on page 434.
About DoS Profiled Router alerts
DoS Profiled Router alerts are triggered by profiled router detection. A DoS Profiled Router
alert is triggered for a managed object or service when traffic on a router significantly exceeds
the expected levels for a sustained period of time. The traffic rate that SP expects for a
managed object or service is referred to as the baseline. A baseline is the learned traffic rate
for a managed object or service. See “About Profiled Router Detection” on page 447.
About DoS Profiled Network alerts
DoS Profiled Network alerts are triggered by profiled network detection. SP triggers a profiled
network alert if the rate of the traffic at a managed object or service boundary exceeds the
baseline by the detection percentage for a sustained period of time. Because profiled network
detection monitors all of the traffic that crosses a managed object boundary or service
boundary, it can be used to monitor the traffic of an arbitrarily defined network space. See
“About Profiled Network Detection” on page 451.
474
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the Fingerprint Threshold Alert Pages
Introduction
You can use a Fingerprint Threshold Alert page to view more details about a Fingerprint
Threshold alert, including how long it remains over or under the configured threshold as well as
individual host data.
You can use the icons on the Arbor Smart Bar to download or email this page. See “About the
Arbor Smart Bar ” on page 28.
Navigating to a Fingerprint Threshold Alert page
To navigate to a Fingerprint Threshold Alert page:
1. Navigate to one of the following pages:
l
All Alerts (Alerts > All Alerts)
l
Fingerprint Threshold Alerts (Alerts > Fingerprints)
2. Click the ID link for a Fingerprint Threshold alert.
About the information in the header of a Fingerprint Threshold Alert page
The header above the tabs of a Fingerprint Threshold Alert page displays the following
information:
Fingerprint Threshold Alert page header information
Information Type
Description
Alert type and alert
ID
The page title includes the alert type and the alert ID.
Example: Fingerprint Threshold Alert 84357
Alert timeframe
The alert’s timeframe appears below the title of the page. The
timeframe includes the start time, the end time (or “Ongoing” if the
alert is still active), and the duration.
Example: Apr 22 04:07 - Apr 23 21:42 (1d, 17:35) or Apr 9 20:0821:06 (0:58)
Ticket (if
configured)
If the ticketing feature is configured, then a ticket icon appears in the
upper-right corner of the page. You can click the ticket icon to enter
the ticket number to associate with the alert. After you assign a ticket
number to an alert, a ticket number link appears. You can click the
ticket number link to navigate directly to the corresponding entry in
your ticketing system. See “Configuring Ticketing” on page 280.
About the Summary tab on a Fingerprint Threshold Alert page
About the traffic data displayed on the Summary tab
On the Summary tab of a Fingerprint Threshold Alert page, you can use the Period list to
control the set of traffic data that is displayed in the graph. After you make changes to the
Period list, you must click Update to change the timeframe for the alert.
The Period list allows you to look at an alert for a selected period of time. You might look at a
subset of the timeframe of an alert for purposes of forensics. If you select Other from this list,
Proprietary and Confidential Information of Arbor Networks Inc.
475
SP and TMS User Guide, Version 8.0
you can then specify a start and end time. You can type the time in the Start and End boxes or
you can click the calendar icon to select the date and time. You can also type entries like “2
weeks ago,” “100 hours ago,” “last Monday,” or “5 May” in the Start and End boxes.
By default, the displayed timeframe of an alert is set to the duration of the alert. If you change
the timeframe of an alert, you can select Alert Timeframe from the Period list to redisplay
the data for the alert’s duration.
About key alert information on the Summary tab
The following information is displayed above the traffic graph on the Summary tab of a
Fingerprint Threshold Alert page:
Fingerprint Threshold Alert page Summary tab information
Information Type
Description
Severity Level
The severity level of a Fingerprint Threshold alert is always Medium.
Fingerprint Name
The name given to the fingerprint when it was configured.
Type
The type can be High Threshold or Low Threshold.
Observed
The Observed column displays the highest single-minute rate of alert
traffic and the ratio of the alert traffic to the high threshold traffic rate
for the fingerprint, over the life of the alert.
About the graphs and data tables on the Summary tab
The Summary tab of a Fingerprint Threshold Alert page includes the following graphs and
data tables:
n a graph of the alert traffic over time
n
graphs and data tables of the alert’s traffic, broken down by customer and peer
About the Hosts tab on a Fingerprint Threshold Alert page
The Hosts tab displays a list of the top hosts involved in an alert’s traffic. You can click
Details to view raw flows for a specific host.
SP tracks large amounts of host data across your deployment to calculate the peak traffic rate
of each host during several common time periods. The peak traffic time that is associated with
hosts in a Fingerprint Threshold alert might not always fall exactly within the alert’s time period.
About the Annotations tab of a Fingerprint Threshold Alert page
On the Annotations tab, you can do the following:
Change an alert’s classification
n
To change an alert’s classification, select a classification from the Alert Classification
list, and then click Save. For a description of the different classifications, see “Alert
classification types” on page 488
n
Add annotations to an alert
See “Adding an annotation to an alert on the details page of the alert ” on page 486.
n
476
View annotations that have been added to an alert
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the Service Threshold Alert Pages
Introduction
A Service Threshold Alert page displays details about the alert and a graph of the service alert
traffic. You can also use the Service Threshold Alert page to classify an alert and add
annotations (comments) to it.
You can use the icons on the Arbor Smart Bar to download or email this page. See “About the
Arbor Smart Bar ” on page 28.
Navigating to a Service Threshold Alert page
To navigate to a Service Threshold Alert page:
1. Navigate to one of the following pages:
l
All Alerts (Alerts > All Alerts)
l
Service Threshold Alerts (Alerts > Services)
2. Click the ID link for a Service Threshold alert.
About the information in the header of a Service Threshold Alert page
The header above the Summary pane on a Service Threshold Alert page displays the following
information:
Service Threshold Alert page header information
Information Type
Description
Alert type and alert
ID
The page title includes the alert type and the alert ID.
Example: Severity Threshold Alert 226572
Alert timeframe
The alert’s timeframe appears below the title of the page. The
timeframe includes the start time, the end time (or “Ongoing” if the
alert is still active), and the duration.
Example: Apr 22 04:07 - Apr 23 21:42 (1d, 17:35) or Apr 9 20:0821:06 (0:58)
Ticket (if
configured)
If the ticketing feature is configured, then a ticket icon appears in the
upper-right corner of the page. You can click the ticket icon to enter
the ticket number to associate with the alert. After you assign a ticket
number to an alert, a ticket number link appears. You can click the
ticket number link to navigate directly to the corresponding entry in
your ticketing system. See “Configuring Ticketing” on page 280.
About the Summary pane on a Service Threshold Alert page
About the traffic data displayed on the Summary pane
You can use the Period list to control the set of traffic data that is displayed in the graph. After
you make changes to the Period list, you must click Update to change the timeframe for the
alert.
The Period list allows you to look at an alert for a selected period of time. You might look at a
subset of the timeframe of an alert for purposes of forensics. If you select Other from this list,
Proprietary and Confidential Information of Arbor Networks Inc.
477
SP and TMS User Guide, Version 8.0
you can then specify a start and end time. You can type the time in the Start and End boxes or
you can click the calendar icon to select the date and time. You can also type entries like “2
weeks ago,” “100 hours ago,” “last Monday,” or “5 May” in the Start and End boxes.
By default, the displayed timeframe of an alert is set to the duration of the alert. If you change
the timeframe of an alert, you can select Alert Timeframe from the Period list to redisplay
the data for the alert’s duration.
About key alert information on the Summary pane
The following information is displayed above the traffic graph on the Summary pane of a
Service Threshold Alert page:
Service Threshold Alert page Summary pane information
Information
Type
Description
Severity Level
The severity level of a Service Threshold alert is always Medium.
Type
The type can be “High usage” or “Low usage.” A high usage service
threshold alert is triggered when the total traffic exceeds any of the
configured high threshold settings for the service or when application
specific traffic exceeds the high threshold bps or pps settings. A low
usage service threshold alert is triggered when the total traffic or
application specific traffic goes below either of the low threshold
settings. For information about the threshold settings, see “Configuring
threshold alerting settings for services” on page 235.
Observed
The Observed column displays the highest single-minute rate of alert
traffic and the ratio of the alert traffic to the high threshold traffic rate
for the service, over the life of the alert.
Affected
The Affected column displays a link to the affected service. Click this
link to display the service’s configuration page.
Application
If a specific application triggered the alert, the Application column
displays a link to the application involved in the alert. Click this link to
display the application’s configuration page. If the alert was triggered
by the total traffic, then the Application column displays Total Traffic.
About the Alert Traffic graph on the Summary pane
The Summary pane on the Service Threshold Alert page has an Alert Traffic graph below the
alert details table. The Alert Traffic graph displays the total alert traffic for the selected
timeframe. To see a more detailed view of the traffic in the Alert Traffic, click and drag across
the graph to select the timeframe that you want to view.
478
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the Annotations pane on a Service Threshold Alert page
In the Annotations pane at the bottom of a Service Threshold Alert page, you can do the
following:
n Change an alert’s classification
To change an alert’s classification, select a classification from the Alert Classification
list, and then click Save. For a description of the different classifications, see “Alert
classification types” on page 488
n
Add annotations to an alert
See “Adding an annotation to an alert on the details page of the alert ” on page 486.
n
View annotations that have been added to an alert
Proprietary and Confidential Information of Arbor Networks Inc.
479
SP and TMS User Guide, Version 8.0
About the Cloud Signaling Request Alert Pages
Introduction
A Cloud Signaling Request Alert page contains details about an alert generated by an APS
mitigation request.
You can use the icons on the Arbor Smart Bar to download or email this page. See “About the
Arbor Smart Bar ” on page 28.
Navigating to a Cloud Signaling Request Alert page
To navigate to a Cloud Signaling Request Alert page, click the alert ID link of a Cloud Signaling
Mitigation Request alert on one of the following pages:
n Alerts Summary (Alerts > Summary)
n
All Alerts (Alerts > All Alerts)
n
Ongoing Alerts (Alerts > Ongoing Alerts)
n
Cloud Signaling Status (System > Status > Cloud Signaling Status)
n
TMS Mitigation Status (Mitigation > Threat Management > QDPH OLQN IRU D 706
&ORXG 6LJQDOLQJ 0LWLJDWLRQ > Summary tab)
About the information in the header of a Cloud Signaling Request Alert page
The header above the tabs on a Cloud Signaling Request Alert page displays the following
information:
Cloud Signaling Request Alert page header information
480
Information Type
Description
Alert type, alert ID,
and managed
object
The page title includes the alert type, the alert ID, and the managed
object associated with the alert.
Example: Cloud Signaling Request Alert 183064 for Managed
Object XYZ
Alert timeframe
The alert’s timeframe appears below the title of the page. The
timeframe includes the start time, the end time (or “Ongoing” if the
alert is still active), and the duration.
Example: Apr 22 04:07 - Apr 23 21:42 (1d, 17:35) or Apr 9 20:0821:06 (0:58)
Ticket (if
configured)
If the ticketing feature is configured, then a ticket icon appears below
the Mitigate Alert button in the upper-right corner of the page. You
can click the ticket icon to enter the ticket number to associate with
the alert. After you assign a ticket number to an alert, a ticket number
link appears. You can click the ticket number link to navigate directly
to the corresponding entry in your ticketing system. See “Mitigating an
attack from a Cloud Signaling Request Alert page” on the facing page.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
Mitigating an attack from a Cloud Signaling Request Alert page
After SP generates an alert, you can analyze the alert's statistics and perform a mitigation to
reduce or stop the impact of the attack. If the customer managed object associated with the
alert was configured to mitigate the attack automatically, then you should not have to mitigate
the attack manually. For information about automatic and manual mitigation for Cloud
Signaling Request alerts, see “About Configuring Cloud Signaling” on page 605.
To mitigate an attack from a Cloud Signaling Request Alert page:
1. On Cloud Signaling Request Alert page, click Mitigate Alert: Threat Management.
2. On the Create TMS Mitigation page, configure the settings for the mitigation.
See “Configuring and Deleting TMS Mitigations” on page 618.
About the Summary tab on a Cloud Signaling Request Alert page
About the key alert information on the Summary tab
The following information is displayed above the traffic graph on the Summary tab of a Cloud
Signaling Request Alert page:
Cloud Signaling Request Alert page Summary tab information
Information
Type
Description
Severity Level
column
SP always assigns a Cloud Signaling alert a High severity.
Managed Object
column
Click the managed object name link to view the Customer Summary
report for that managed object.
Click the
(edit) icon to edit the managed object.
APS appliances
column
Displays the following information:
n
n
n
APS ID that requested mitigation
Initial start time of the request
The timeframe of a mitigation including the start time, the end time
(or “Ongoing” if the alert is still active), and the duration.
To view status information for an APS appliance, you can click the
APS name link to navigate to the Cloud Signaling Status page. SP
automatically loads the status page with the SP appliance that
manages the APS appliance selected in the Manager list, and with
the name of the APS appliance in the Search box. If multiple SP
appliances manage an APS appliance, then All is selected in the
Manager list.
Proprietary and Confidential Information of Arbor Networks Inc.
481
SP and TMS User Guide, Version 8.0
Cloud Signaling Request Alert page Summary tab information (Continued)
Information
Type
Mitigations column
Description
Lists all TMS mitigation names and the mitigation type. You can click
the mitigation name link to navigate to the TMS Mitigation Status page
and view real-time mitigation status details.
The mitigation type can be one of the following:
n
n
n
IPv4 TMS Cloud Signaling Mitigation—This type of mitigation
occurs when SP automatically initiates a TMS mitigation as a result
of a request from an APS appliance.
IPv4 TMS Auto-Mitigation—This type of mitigation occurs when SP
automatically initiates a TMS mitigation from a DoS alert, and you
manually change the alert ID to this Cloud Signaling mitigation
request alert ID.
IPv4 TMS—This type of mitigation occurs when you manually
create a TMS mitigation (possibly through the Mitigate Alert:
Threat Management button at the top of the page), where the
alert ID is the ID of this Cloud Signaling request alert.
Note: The Mitigations column will remain empty if you do not have the
ability to view TMS mitigations based on your user capabilities.
Graphs
These graphs display the total dropped and passed traffic for the
mitigation in bps and pps.
In the following cases, SP does not generate graph data and displays
the message “No Data”:
n
n
If no mitigation is associated with the alert.
If your user capabilities do not allow you to view TMS mitigations.
About the Alert Traffic graph on the Summary tab
The graphs on the Summary tab of a Cloud Signaling Request Alert page display the total
dropped and passed traffic for the mitigation in bps and pps.
In the following cases, SP displays the message “No Data” instead of a graph:
If no mitigation is associated with the alert.
n
n
If you do not have the ability to view TMS mitigations based on your user capabilities.
About the Annotations tab on a Cloud Signaling Request Alert page
On the Annotations tab of a Cloud Signaling Request Alert page, you can do the following:
Change an alert’s classification
n
To change an alert’s classification, select a classification from the Alert Classification
list, and then click Save. For a description of the different classifications, see “Alert
classification types” on page 488
n
Add annotations to an alert
See “Adding an annotation to an alert on the details page of the alert ” on page 486.
n
482
View annotations that have been added to an alert
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
About the BGP Instability Alert Pages
Introduction
A BGP Instability Alert page displays information about a BGP Instability alert. A BGP
Instability alert is triggered when the threshold for the number of BGP updates in a 5 minute
period is exceeded. The default threshold for the maximum BGP updates in a 5 minute period is
5,000. This threshold can be configured on the Configure BGP Instability page
(Administration > Detection > BGP Instability). See “Configuring BGP Thresholds,
Hijacking, and Traps” on page 255.
You can use the icons on the Arbor Smart Bar to download or email this page. See “About the
Arbor Smart Bar ” on page 28.
Navigating to a BGP Instability Alert page
To navigate to the BGP Instability Alert page:
1. Navigate to All Alerts page (Alerts > All Alerts).
2. In the Search box, type BGP Instability, and then click Search.
3. Click the ID link for a BGP Instability alert.
About the information in the header of a BGP Instability Alert page
The header above the Summary pane on a BGP Instability Alert page displays the following
information:
BGP Instability Alert page header information
Information Type
Description
Alert type, alert ID,
and router
The page title includes the alert type, the alert ID, and the router
associated with the alert.
Example: BGP Instability Alert 183341 for router_xyz
Alert timeframe
The alert’s timeframe appears below the title of the page. The
timeframe includes the start time, the end time (or “Ongoing” if the
alert is still active), and the duration.
Example: Mar 27 09:55 -10:00 (Less than one minute)
Ticket (if
configured)
If the ticketing feature is configured, then a ticket icon appears in the
upper-right corner of the page. You can click the ticket icon to enter
the ticket number to associate with the alert. After you assign a ticket
number to an alert, a ticket number link appears. You can click the
ticket number link to navigate directly to the corresponding entry in
your ticketing system. See “Configuring Ticketing” on page 280.
About the panes on a BGP Instability Alert page
The following panes appear on a BGP Instability Alert page:
Summary
n
The Summary pane on a BGP Instability Alert page displays a graph of the number of BGP
updates that occurred during the duration of the alert.
Proprietary and Confidential Information of Arbor Networks Inc.
483
SP and TMS User Guide, Version 8.0
The graph on the Summary pane can include the following types of data:
BGP Instability Alert page Summary pane information
Data type
Description
ANN
The number of announcement updates.
AADIFF
The number of routes implicitly withdrawn and replaced by an
alternate route to the same prefix.
This data type indicates forwarding instability.
n
AADUP
The number of routes implicitly withdrawn and replaced by a
duplicate of the original route.
TUP
The number of new, previously unseen prefixes being announced.
TDOWN
The number of routes being withdrawn.
UPDATES
The total number of BGP updates.
WWDUP
The number of duplicate withdrawn updates.
WITH
The total number of withdrawals.
Instability
The Instability pane on a BGP Instability Alert page allows you to view the most significant
sources of BGP updates and BGP instability for a router. This pane has the 3 tabs. The
following table describes the information that appears on each of these tabs:
BGP Instability Alert page Instability pane information
Tab
Information
Description
Summary
Withdraws
The number of BGP withdrawals.
Announces
The number of BGP announcements.
Number Unique
Prefixes
The number of unique prefixes.
ASN
The origin ASN.
Number of
Updates
The number of BGP updates for this ASN over the alert
timeframe.
Percentage
The percentage of BGP updates that the system
applied to an ASN in the alert timeframe.
Prefix
The BGP prefix.
Number of
Updates
The number of BGP updates for a prefix over the alert
timeframe.
Percentage
The percentage of BGP updates in the alert timeframe
that the system applied to a prefix.
Top ASNs
Top
Prefixes
484
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
n
Diff
The Diff pane on a BGP Instability Alert page allows you to determine changes in a router’s
routing table during an alert’s duration. This view allows you to investigate spikes or drops in
routing table size and investigate unexpected or unusual changes in routing paths. This pane
has 6 tabs that display different route data.
n
Annotations
The Annotations pane at the bottom of a BGP Instability Alert page allows you to do the
following:
l
Change an alert’s classification.
To change an alert’s classification, select a classification from the Alert Classification
list, and then click Save. For a description of the different classifications, see “Alert
classification types” on page 488.
l
Add annotations to an alert.
See “Adding an annotation to an alert on the details page of the alert ” on the next page.
l
View annotations that have been added to an alert.
Proprietary and Confidential Information of Arbor Networks Inc.
485
SP and TMS User Guide, Version 8.0
Adding Annotations to an Alert
Introduction
You can add annotations to an alert to help you track the history of the actions that are taken
on it. You can add annotations to an alert on an alert listing page or on the details page of the
alert.
You can also add annotations to mitigations. See See “Adding Annotations to a Mitigation” on
page 731.
Adding an annotation to an alert on an alert listing page
To add an annotation to an alert on an alert listing page:
1. Navigate to one of the following alert listing pages:
l
All Alerts (Alerts > All Alerts)
l
Ongoing Alerts (Alerts > Ongoing)
l
Alerts Recent (Alerts > Summary >5HFHQW DOHUW OLQN on the All Alerts tab)
l
DoS Alerts (Alerts > DoS)
l
Fingerprint Threshold Alerts (Alerts > Fingerprints)
l
Service Threshold Alerts (Alerts > Services)
l
System Error Alerts (Alert > System Error)
2. Click
(annotation) in the Classifications & Annotations column for the alert that you
want to annotate.
3. In the first Annotations window, click Add Annotation.
4. In the second Annotations window, configure the following settings:
Setting
Description
box
Type your DQQRWDWLRQ.
Customer called,
(Optional) Select one or more of these check boxes to indicate
why you added the annotation.
Crippling attack,
and
Escalated check
boxes
5. Click Save.
Adding an annotation to an alert on the details page of the alert
To add an annotation to an alert on the details page of the alert:
1. Navigate to the All Alerts page (Alerts > All Alerts).
2. Click the ID link of the alert.
If the alert does not have an ID link, then you can only add an annotation to the alert on the
alert listing page.
3. Do one of the following depending on the type of alert:
486
l
Click the Annotations tab at the top of the page.
l
Locate the Annotations pane at the bottom of the page.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
A Service Threshold alert and a BGP Instability alert have an Annotations pane at the
bottom of the page. The other alerts have an Annotations tab.
4. Click Add Annotation.
5. In the Add an Alert Comment window, configure the following settings:
Setting
Description
box
Type your DQQRWDWLRQ.
Customer called,
(Optional) Select one or more of these check boxes to indicate
why you added the annotation.
Crippling attack,
and
Escalated check
boxes
6. Click Save.
Proprietary and Confidential Information of Arbor Networks Inc.
487
SP and TMS User Guide, Version 8.0
About Alert Classification
Introduction
Alert classifications allow you to track whether an alert has been addressed and to determine
what action you should take concerning the alert. You can classify alerts on any alert listing
page or on the Annotations tab or Annotation pane of an alert’s details page.
SP includes alert classifications in anonymous statistics reports. These reports allow you to
view an end-of-year summary of the percentages of different alert classifications.
Alert classification types
You can apply the following classifications to an alert:
Alert classifications
Classification
Description
False Positive
The traffic involved in this alert is not malicious or is a symptom of a
network problem.
When you classify an alert as False Positive, the alert no longer
appears on the Security Status page or All Alerts page. If you want to
view False Positive alerts, you can search for them using the Alert
Search Wizard. See “Using the Alert Search Wizard” on page 469.
Flash Crowd
This alert is the result of an unexpected spike in legitimate traffic.
Network Failure
This alert is the result of a problem with the network infrastructure.
Possible Attack
The traffic involved in this alert might be malicious, but its nature is still
under investigation.
Trivial
The traffic involved in this alert had no impact on resources.
Example: Traffic may have triggered an alert because the traffic
threshold is set too low.
Verified Attack
The traffic involved in this alert is malicious.
If you mitigate an alert and do not annotate it, then SP automatically
classifies the alert as a Verified Attack.
Classifying an alert on an alert listing page
To classify an alert on an alert listing page:
1. Navigate to one of the following alert listing pages.
488
l
All Alerts (Alerts > All Alerts)
l
Ongoing Alerts (Alerts > Ongoing)
l
Alerts Recent (Alerts > Summary >5HFHQW DOHUW OLQN on the All Alerts tab)
l
DoS Alerts (Alerts > DoS)
l
Fingerprint Threshold Alerts (Alerts > Fingerprints)
l
Service Threshold Alerts (Alerts > Services)
l
System Error Alerts (Alert > System Error)
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 17: About Alerts
2. In the Classifications & Annotations column, click the
icon in the column for the alert
that you want to classify.
3. In the Annotations window, from the Classification list, select the classification to apply
to the alert. See “Alert classification types” on the previous page.
4. Click Apply Classification, and then click Close.
Classifying an alert on the details page of the alert
To classify an alert on the details page of the alert:
1. Navigate to one of the following alert listing pages.
l
All Alerts (Alerts > All Alerts)
l
Ongoing Alerts (Alerts > Ongoing)
l
Alerts Recent (Alerts > Summary >5HFHQW DOHUW OLQN on the All Alerts tab)
l
DoS Alerts (Alerts > DoS)
l
Fingerprint Threshold Alerts (Alerts > Fingerprints)
l
Service Threshold Alerts (Alerts > Services)
l
System Error Alerts (Alert > System Error)
2. Click the ID link of the alert that you want to classify.
3. Do one of the following depending on the type of alert:
l
Click the Annotations tab at the top of the page.
l
Locate the Annotations pane at the bottom of the page.
A Service Threshold alert and a BGP Instability alert have an Annotations pane at the
bottom of the page. The other alerts have an Annotations tab.
4. From the Alert Classification list, select the classification to apply to the alert, and then
click Save. For a description of the different classifications, see “Alert classification
types” on the previous page.
Proprietary and Confidential Information of Arbor Networks Inc.
489
SP and TMS User Guide, Version 8.0
490
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18:
About DoS Alerts
Introduction
This section describes how to use SP to investigate DoS alerts. SP tracks the activity based on
user-configured thresholds and can alert you to any anomalous activity in your network.
User access
Administrators and non-administrative users have access to these features.
In this section
This section contains the following topics:
Introduction to DoS Alerts
492
About the Summary Tab on a DoS Alert Page
498
About the Traffic Details Tab on a DoS Alert Page
507
About the Routers Tab on a DoS Alert Page
510
About the Annotations Tab on a DoS Alert Page
513
About the Top Traffic Patterns Table
514
About the Alert Scratchpad
517
Performing a Whois Lookup for an IP Address on a DoS Alert Page
521
Recognizing a Potential DoS Attack
522
SP and TMS User Guide, Version 8.0
491
SP and TMS User Guide, Version 8.0
Introduction to DoS Alerts
Introduction
A DoS alert provides details about a possible DoS attack and how it affects your network. It
displays breakdowns of what triggered an alert and the routers and interfaces where the traffic
was detected.
You can access a DoS alert to perform the following tasks:
determine if an alert represents an attack
n
n
determine how to mitigate an attack
n
add traffic data to an Alert Scratchpad for use in a mitigation
n
add alert annotations
n
initiate a mitigation
You can use the icons on the Arbor Smart Bar to download or email the information in a DoS
alert. See “About the Arbor Smart Bar ” on page 28.
About the information in the header of a DoS alert
The header above the tabs of a DoS alert displays the following information:
DoS alert header information
Information Type
Description
Alert type and alert
ID
The page title includes the alert type and the alert ID.
Example: DoS Host Alert 35803
Alert timeframe
The alert timeframe appears below the page title. The timeframe
includes the start time, the end time (or Ongoing if the alert is still
active), and the duration.
Examples:
n
n
Apr 22 04:07 - Apr 23 21:42 (1d, 17:35)
Apr 9 20:08-21:06 (0:58)
See “How SP determines if a DoS alert should be ended or ongoing”
on page 496.
492
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
DoS alert header information (Continued)
Information Type
Description
Ticket (if
configured)
If the ticketing feature is configured, then a
(ticket) icon appears
below the Mitigate Alert button in the upper-right corner of a DoS
alert. You can click to enter the ticket number to associate with the
alert. After you assign a ticket number to an alert, a ticket number link
appears. You can click the ticket number link to navigate directly to the
corresponding entry in your ticketing system. See “Configuring
Ticketing” on page 280.
Mitigations
For each type of mitigation that has been applied to a DoS alert, a
mitigation type link appears below the Mitigate Alert button in the
upper-right corner of a DoS alert. The mitigation type link includes the
number of mitigations of that type.
If you click a mitigation type link, a list of the mitigations of that type
appears. The name of each mitigation in the list is a link that opens
that mitigation. For each TMS mitigation, a summary of the traffic that
is passed or dropped by that mitigation is displayed. For more
information about initiating a mitigation from a DoS alert, see
“Initiating a Mitigation from a DoS Alert” on page 622.
Note: You must have the proper user privileges for the mitigations
information to appear.
About the Alert Scratchpad of a DoS alert
You can add traffic data from a DoS alert to an Alert Scratchpad and then copy the data from
the scratchpad and paste it into a mitigation that is associated with the alert. The Alert
Scratchpad opens when you click the View Scratchpad button at the top of a DoS alert
page. The number of items that you have added to the Alert Scratchpad is in parentheses on
the View Scratchpad button. For information about using the Alert Scratchpad, see “About
the Alert Scratchpad” on page 517.
About initiating a mitigation from a DoS alert
You can click the Mitigate Alert button to initiate a mitigation from a DoS alert page. See
“Initiating a Mitigation from a DoS Alert” on page 622.
Note: You must have the proper user privileges for the Mitigate Alert button to appear.
About the traffic data displayed for a DoS alert
You can use the Period, Units, and View lists to control the traffic data that is displayed on
the Summary and Traffic Details tabs of a DoS alert. These lists appear on the Summary,
Traffic Details, and Routers tabs. However, the View list only appears on the Routers tab
for DoS Profiled Network alerts. After you make changes to any of these lists, click Update to
update the display of the traffic data. When you make any changes to these lists on one tab,
the same changes are made on the other tabs.
The Period list allows you to look at the alert’s traffic data for a selected period of time. You
might look at a subset of the timeframe of an alert for purposes of forensics. If you select Other
from this list, you can then specify a start and end time. You can type the time in the Start and
End boxes or you can click the calendar icon to select the date and time. You can also type
Proprietary and Confidential Information of Arbor Networks Inc.
493
SP and TMS User Guide, Version 8.0
entries like “2 weeks ago,” “100 hours ago,” “last Monday,” or “5 May” in the Start and End
boxes.
By default, the displayed timeframe of a DoS alert is set to the duration of an alert. If you
change the timeframe of a DoS alert, you can select Alert Timeframe from the Period list to
redisplay the data for the alert’s duration.
The View list allows you to constrain the traffic that is displayed in the following places:
The Summary tab for all DoS alerts
n
This does not include the traffic data above the Alert Traffic graph nor does it include the
Top Interfaces data for DoS Host alerts and DoS Profiled Network alerts. The Top Traffic
Patterns table is only constrained when the view is Router and is only constrained by the
selected router.
n
The Traffic Details tab for all DoS alerts
The Top Traffic Patterns table is only constrained when the view is Router and is only
constrained by the selected router.
n
The Routers tab for DoS Network Profiled alerts.
See “How the selected view constrains the traffic data that is displayed” below.
The Router view is the default view for DoS Profiled Router alerts. DoS Host alerts and DoS
Profiled Network alerts will by default display data from the first view that contains data in the
following order: Network Boundary, Managed Object Boundary and Router (only for
DoS Host alerts).
For all types of DoS alerts, you can select Network Boundary or Managed Object
Boundary from the View list. For DoS Host alerts and DoS Profiled Router alerts, you can
also select Router.
When Router is selected from the View list, then a Router (Severity) list appears that
allows you to select a router that is associated with the alert traffic. For managed services
customers, the name of the router is replaced with "router-URXWHUB*,'." By default, the router
with the highest maximum severity percent is selected in the Router (Severity) list. The
routers in the list are also sorted by the maximum severity percent value. For a definition of
maximum severity percent, see “About key alert information on the Summary tab” on page 498.
How the selected view constrains the traffic data that is displayed
The Network Boundary view constrains the data to traffic which traversed a network
boundary interface and also matched the alert criteria. This view will include data from all
routers monitored by the deployment.
The Managed Object view constrains the data to traffic which traversed a managed object
boundary interface and also matched the alert criteria. This view will include data from all
routers monitored by the deployment.
The Router view constrains the data to traffic which traversed any interface on the selected
router and also matched the alert criteria. Only routers which saw traffic that exceeded a
trigger rate for the alert will be able to be selected.
494
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
About the aggregation of IP addresses and ports in a DoS alert
SP aggregates IP addresses and ports in a DoS alert to help identify attack traffic.
About the aggregation of IP addresses in a DoS alert
SP aggregates IP addresses to consolidate the data and make it more useful. These
aggregated IP addresses can help you identify the source and destination IP addresses of
potential attack traffic.
During each minute of a DoS alert, SP collects data on the source and destination IP
addresses of the alert traffic and aggregates them as follows:
n Aggregates the IP addresses until it identifies an IP prefix that represents at least 10% of the
alert traffic.
n
Continues to aggregate IP addresses until it identifies an IP prefix that represents at least
10% of the alert traffic in addition to the traffic of the previously identified prefix.
n
Continues this process of aggregation as long as it can identify IP prefixes that represent at
least 10% of the alert traffic in addition to the traffic of previously identified prefixes.
After SP aggregates the source and destination IP addresses of a DoS alert, it can display
these aggregated IP addresses in the following locations of a DoS alert page:
n Top Traffic Patterns (last 5 min of selected timeframe) table and the CSV file of all traffic
patterns
See “About the Top Traffic Patterns Table” on page 514.
n
Alert Characterization table
See “About the Alert Characterization table on the Summary tab” on page 504.
n
Source IP Addresses and Destination IP Addresses tables and the View More Details
window for source and destination IP addresses
See “About the traffic statistics tables on the Traffic Details tab” on page 507.
Note: The IP Addresses tables and the View More Details window for IP addresses can
also display top individual IP addresses even if they do not represent at least 10% of the
alert traffic during any minute of the alert. SP displays these individual addresses if it
identifies them as top IP addresses for the alert for the selected timeframe.
When SP displays aggregated IPv4 addresses, it can use any CIDR block from “/32” to “/8.”
When SP displays aggregated IPv6 addresses, it uses every fourth CIDR block from “/128” to
“/8” (for example: “/124,” “/120,” and “/116”). If SP aggregates IP addresses above “/8,” it
displays Highly Distributed for the name of the aggregated IP prefix, which represents any IP
address.
When SP displays the percentage of the traffic that an aggregated IP address represents, it is
the percentage of the overall traffic of the alert for the selected timeframe. Consequently, an
aggregated IP address that represents at least 10% of the traffic during any minute of an alert
may only represent 2% of the overall traffic of the alert.
Note: Although the aggregation of IP addresses is enabled by default, you can use the CLI to
disable it. See “Configuring Prefix Aggregation of IP Addresses for DoS Alerts” in the SP and
TMS Advanced Configuration Guide.
Proprietary and Confidential Information of Arbor Networks Inc.
495
SP and TMS User Guide, Version 8.0
About the aggregation of ports in a DoS alert
SP gathers the source and destination ports of the TCP and UDP traffic of a DoS alert. These
ports can help determine if the traffic is normal traffic or attack traffic.
SP displays data on individual ports that represent at least 10% of the alert traffic during any
minute of the alert. SP also aggregates system and dynamic ports and displays the port range
with the name of the range, as follows:
n 1-1023 (System)
n
1024-65535 (Dynamic)
Note: In the traffic statistic tables for ports on the Traffic Details tab, the name of the port
range is in its own column.
SP can display individual and aggregated ports in the following tables of a DoS alert:
Top Traffic Patterns (last 5 min of selected timeframe) table
n
See “About the Top Traffic Patterns Table” on page 514.
n
Alert Characterization table
See “About the Alert Characterization table on the Summary tab” on page 504.
n
TCP and UDP source and destination port tables and the View More Details window for
ports
See “About the traffic statistics tables on the Traffic Details tab” on page 507.
Note: The source and destination port tables and the View More Details window for ports can
also display top individual ports even if they do not represent at least 10% of the alert traffic
during any minute of the alert. SP displays these individual ports if it identifies them as top ports
for the alert for the selected timeframe.
How SP determines if a DoS alert should be ended or ongoing
After a DoS alert is triggered, SP continues to monitor all of the sources of traffic associated
with the alert. If the traffic at the source that triggered the alert indicates that the alert should
be ended, but another source indicates that the alert should be ongoing, then the alert remains
ongoing.
For example, with a DoS Host alert, if an attack is triggered at the managed object boundary
and the attack traffic is being mitigated, then the traffic at the managed object boundary might
indicate that the alert should be ended. However, if the attack is still in progress, then the data
from the network boundary or from an individual router would indicate that the alert should
remain ongoing. Because the data from the network boundary or an individual router most
accurately reflects the state of the attack, the alert remains ongoing.
Why maximum severity percent, maximum impact of alert traffic, and maximum
observed values might not match
The maximum severity percent, maximum impact of alert traffic, and maximum observed values
of the affected router will not always match. Non-matching values can usually be attributed to
differences between when the measurements are taken for each of the values. The
measurements for the maximum severity percent and the maximum impact of alert traffic values
can be taken both during the latency period and after an alert has been generated. The
measurements for the maximum observed values of affected router are only taken after an alert
has been generated. If the highest rate of traffic for an alert occurs during the latency period,
then the maximum severity percent and the maximum impact of alert traffic values can be
higher than the affected router maximum observed values.
496
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
With DoS Host alerts, the maximum severity percent and the maximum impact of alert traffic
values can be based on the traffic of different misuse types which can cause these values not
to match. The maximum impact of alert traffic value is always based on the total traffic, while
the maximum severity percent value is based on the traffic of the misuse type that triggered the
alert. If the misuse type that triggered the alert is total traffic, then the maximum impact of alert
traffic value and the maximum severity percent value are both based on total traffic. However, if
the alert was not triggered by total traffic, then the maximum impact of alert traffic value would
be based on total traffic, while the maximum severity percent value would be based on the
traffic of another misuse type. For more information about maximum severity percent and
maximum impact of alert traffic, see “About key alert information on the Summary tab” on the
next page.
Additional information about DoS alerts
n
“About the DoS Alert Pages” on page 473
n
“About the Summary Tab on a DoS Alert Page” on the next page
n
“About the Traffic Details Tab on a DoS Alert Page” on page 507
n
“About the Routers Tab on a DoS Alert Page” on page 510
n
“About the Annotations Tab on a DoS Alert Page” on page 513
n
“About the Top Traffic Patterns Table” on page 514
n
“Recognizing a Potential DoS Attack” on page 522
Proprietary and Confidential Information of Arbor Networks Inc.
497
SP and TMS User Guide, Version 8.0
About the Summary Tab on a DoS Alert Page
Introduction
The Summary tab on a DoS alert page displays a summary of the information concerning a
DoS alert for the selected timeframe.
For general information about a DoS alert page including how to control the traffic data that is
displayed, see “Introduction to DoS Alerts” on page 492. For information about the
Annotation tab, see “About the Annotations Tab on a DoS Alert Page” on page 513.
About key alert information on the Summary tab
The following information is displayed above the traffic graph on the Summary tab of a DoS
alert page:
DoS alert page Summary tab information
Information
Type
498
Description
Severity Level
The Severity Level column displays the severity of the alert, which can
be Low, Medium, or High. For information on how SP classifies the
severity level of DoS alerts, see the following: “How SP creates and
classifies standard host alerts” on page 433, “How SP creates and
classifies profiled router detection alerts” on page 448, and “How SP
creates and classifies profiled network alerts” on page 453.
Note: If a DoS Host alert is triggered by fast flood detection, then the
alert always has a severity of High and “ Fast Flood” appears below
the severity level.
Max Severity
Percent
The Max Severity Percent column displays the highest single-minute
ratio of the rate of the alert traffic to the high severity rate over the
lifetime of the alert. With a DoS Host alert, the Max Severity Percent
column also displays the top misuse type that is used to determine the
maximum severity percent value
Example: If an alert has a high severity rate of 500 Kbps and the
highest traffic level observed for a one-minute period is 550 Kbps,
then the alert’s severity is 110% of 500 Kbps.
For a DoS Profiled Router alert, the maximum severity percent value is
based on the highest single-minute of traffic at an individual router. For
a DoS Profiled Network alert, it is based on the highest single-minute
of traffic at the network boundary or managed object boundary. For a
DoS Host alert, it is based on the highest single-minute of traffic for
any misuse type at the network boundary, managed object boundary,
or an individual router.
Note: The maximum severity percent, maximum impact of alert traffic,
and maximum observed router values will not always match. See “Why
maximum severity percent, maximum impact of alert traffic, and
maximum observed values might not match” on page 496.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
DoS alert page Summary tab information (Continued)
Information
Type
Max Impact of
Alert Traffic
Description
The Max Impact of Alert Traffic column displays the maximum single
minute of network bandwidth consumed by the alert.
Note: This minute can occur during the alert latency period. If it does,
it will not be represented in the alert traffic graph, which begins after
the alert latency period for DoS Host alerts and DoS Profiled Router
alerts.
The maximum impact of alert traffic value calculation varies based on
the alert type detected as follows:
n
n
n
DoS Host alert
The maximum single minute of traffic for the enabled misuse types
that exceeded their trigger rate. This traffic traverses one of the
following:
l
Any interfaces marked as managed object boundary on all
detecting routers
l
Any interfaces marked as network boundary on all detecting
routers
l
All the interfaces on any one individual detecting router
DoS Profiled Router alert
The maximum single minute of traffic of profiled router detection
types at the interfaces of the managed object boundary, the
network boundary, or any one individual router for routers detecting
traffic that exceeds any profiled router baselines or forced alert
thresholds. See “Types of profiled router detection” on page 448.
DoS Profiled Network alert
The maximum single minute of traffic at all managed object
boundary or network boundary interfaces on all routers.
With a DoS Host alert and a DoS Profiled Network alert, this column
also displays where the impact data was recorded. With a DoS Host
alert, the impact data can be recorded at the managed object
boundary, the network boundary, or an individual router. With a DoS
Profiled Network alert, the impact data can be recorded at the
managed object boundary or the network boundary.
Note: The maximum severity percent, maximum impact of alert traffic,
and maximum observed router values will not always match. See “Why
maximum severity percent, maximum impact of alert traffic, and
maximum observed values might not match” on page 496.
Direction
The Direction column displays the direction of the alert traffic in the
local network (incoming or outgoing).
For DoS Host alerts, traffic is designated as outgoing only with host
global detection, peer managed objects, and with managed objects
whose router boundary is manually configured to an external locality.
Proprietary and Confidential Information of Arbor Networks Inc.
499
SP and TMS User Guide, Version 8.0
DoS alert page Summary tab information (Continued)
Information
Type
Description
Misuse Types
The Misuse Types column appears only with a DoS Host alert. It
displays the misuse types that had traffic that exceeded the configured
trigger rate threshold for that type of traffic.
Type
The Type column appears only with a DoS Profiled Router alert. It
displays the alert’s type. The type can be Bandwidth, Multi-Protocol, or
an individual protocol. The type includes IPv4 or IPv6. For a list of the
types of traffic that is tracked with profiled router detection, see "Types
of profiled router detection" on page 448.
Managed Object
The Managed Object column displays the managed object that is
associated with the alert.
Note: With host global detection, a managed object with the name
Global Detection is associated with the alert. For more information
about host global detection, see “About host global detection” on
page 430.
A
(context menu) icon is to the left of the name of the managed
object. The icon becomes more visible when you hover your mouse
pointer over it. Click this icon, and then select one of the following
options:
n View Summary Report
Allows you to view the traffic data for the managed object in its
summary report.
Note: With host global detection, the summary report is the
Network Summary report.
n
View Configuration
Allows you to view and edit the configuration of the managed
object on its configuration page.
Note: With host global detection, the configuration page is the
Configure Global Detection Settings page.
Note: The context menus that appear depend on your user privileges.
Target
500
The Target column appears only with a DoS Host alert. It displays the
IP address of the host that is the target of the traffic that triggered the
DoS Host alert.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
DoS alert page Summary tab information (Continued)
Information
Type
Description
Top 5 Triggering
Sources
or
Top 5 Triggering
Destinations
The Top 5 Triggering Sources or Top 5 Triggering Destinations column
appears only with a DoS Profiled Network alert. Top 5 Triggering
Sources appears with incoming traffic, and Top 5 Triggering
Destinations appears with outgoing traffic. This column appears only if
Enable Profiled Country Detection was selected when profiled
network detection was configured for the managed object. This
column lists the top 5 countries that triggered the alert. See
“Configuring Profiled Network Detection for Managed Objects” on
page 191.
To view any additional countries that triggered the alert or to view the
percentage by which each country’s traffic exceeds the threshold,
click the More info link.
View Raw Flows
link
Displays the raw flows data for the major traffic events associated with
this alert. With an IPv4 alert, the View Raw Flows link opens the
Explore Forensics page, and with an IPv6 alert, the link opens the
Explore Forensics IPv6 page. The IP address is used to create the
fingerprint to filter the raw flows data.
After you access the raw flows data, you can add another fingerprint
to further filter the raw flows data. You can also save the raw flows
data as a report. See “Using the Explore Forensics Page” on page 836
and “Using the Explore Forensics IPv6 Page” on page 838.
Note: Whether the View Raw Flows link appears depends on your
user privileges.
About the Alert Traffic graph on the Summary tab
The Alert Traffic graph displays different data for each of the different types of DoS alerts.
About the Alert Traffic graph on the Summary tab of a DoS Host Alert page
The Summary tab on a DoS Host Alert page has an Alert Traffic graph that can display the
following information about the traffic of an alert for the selected timeframe:
n Traffic for each misuse type that is part of the alert, including the total traffic misuse type
n
The traffic and trigger rate of a single misuse type
n
Traffic that is dropped by any TMS mitigations associated with the alert
If you move your mouse across a line on an Alert Traffic graph, the amount of traffic at that
point on the line is displayed along with the time.
Colored selectors appear above the graph for the different types of alert traffic. A black trigger
rate selector can also appear that allows you to display the trigger rate threshold for a misuse
type. The misuse type selectors hide or display lines or areas on the Alert Traffic graph for each
misuse type of alert traffic including total traffic. The following table describes the different
selectors that can appear above the graph:
Proprietary and Confidential Information of Arbor Networks Inc.
501
SP and TMS User Guide, Version 8.0
DoS Host Alert page Alert Traffic graph selectors
Selector
Description
Misuse Types
These selectors hide or display lines or areas on the Alert Traffic graph
for each misuse type of alert traffic including total traffic. For
information about the different misuse types, see “Host detection
misuse types” on page 189.
When the Total Traffic selector is selected, a gray background
represents all of the alert traffic if the graph does not include traffic that
is being dropped by a TMS mitigation. If the graph includes traffic that
is being dropped by a TMS mitigation, then the gray background
represents traffic that is passed, and a red line represents traffic that is
dropped.
Trigger Rate
This selector appears only when Router is selected in the View list
and only when the traffic of a single misuse type is displayed. With
total traffic, the trigger rate selector appears for both bps and pps
traffic. For the other misuse types, the trigger rate selector appears only
for pps traffic. You must click the trigger rate selector to display the
trigger rate threshold on the Alert Traffic graph.
Dropped Traffic
This selector appears only when Network Boundary is selected in
the View list and only when a TMS mitigation associated with the alert
is dropping traffic. This selector hides or displays the traffic that is
being dropped by any TMS mitigations. A red line represents the traffic
that is being dropped.
A selector is a solid-colored circle when what it represents is displayed in the graph, and it
appears as an empty circle when the traffic it represents is hidden. When the traffic for a
misuse type exceeds its configured trigger rate, then the text of its misuse type selector is red
and is followed by an asterisk (*).
You can click a misuse type selector to hide or display its traffic or a trigger rate selector to hide
or display the trigger rate. You can double-click a misuse type selector to display just the traffic
for that misuse type. If only one type of traffic is selected, you can click its selector to display all
the types of traffic that are associated with the alert.
About the Alert Traffic graph on the Summary tab of a DoS Profiled Router Alert
page
The Summary tab on a DoS Profiled Router Alert page has an Alert Traffic graph that can
display the following types of traffic for the selected timeframe:
n Total traffic for the alert
n
502
Traffic that is dropped by any TMS mitigations associated with the alert
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
The following table describes the different selectors that appear above the graph:
DoS Profiled Router Alert page Alert Traffic graph selectors
Selector
Description
Total Traffic
This selector always appears above the graph, but it only functions as a
selector when the Dropped Traffic selector is also present.
When the Total Traffic selector is selected, a gray background
represents all of the alert traffic if the graph does not include traffic that
is being dropped by a TMS mitigation. If the graph includes traffic that
is being dropped by a TMS mitigation, then the gray background
represents traffic that is passed, and a red background represents
traffic that is dropped.
Dropped Traffic
This selector appears only when Network Boundary is selected in
the View list and only when a TMS mitigation associated with the alert
is dropping traffic. This selector hides or displays the traffic that is
being dropped by any TMS mitigations. A red background represents
the traffic that is being dropped.
A selector is a solid-colored circle when what it represents is displayed in the graph, and an
empty circle when the traffic it represents is hidden. You can click a selector to hide or display
the traffic that the selector represents. You can double-click a selector to display just that type
of traffic. If only one type of traffic is selected, you can click its selector to display both types of
traffic that are associated with the alert.
About the Alert Traffic graph on the Summary tab of a DoS Profiled Network
Alert page
The Summary tab on a DoS Profiled Network Alert page has an Alert Traffic graph that
displays the following information about the alert for the selected timeframe:
n Traffic
The total incoming or outgoing traffic observed for the alert for the selected timeframe. If
profiled country detection is enabled for the managed object or service associated with the
alert, then a tab appears for each of the top 5 countries for which traffic is detected. Each of
these tabs displays the traffic observed for that country. If traffic is detected for more than
one country, then a Stacked Countries tab appears that displays the traffic for each of the
top five countries. For information about enabling country detection, see “Configuring
Profiled Network Detection for Managed Objects” on page 191.
Note: If both the incoming and outgoing traffic of a managed object trigger an alert, then
two separate alerts are triggered.
n
Baseline
The learned traffic rate for normal traffic. See “About profiled network detection baselines”
on page 452.
n
Detection threshold
The threshold that traffic must exceed before a DoS Profiled Network alert can be triggered.
The detection threshold is determined by adding a percentage of the baseline to the
baseline. The percentage that is added is configured when the managed object or service is
Proprietary and Confidential Information of Arbor Networks Inc.
503
SP and TMS User Guide, Version 8.0
configured. See “Configuring Profiled Network Detection for Managed Objects” on
page 191.
The following vertical colored lines can appear on the Alert Traffic graph of a DoS Profiled
Network alert:
DoS Profiled Network Alert page Alert Traffic graph line colors
Line Color
Description
gray
Indicates when an annotation was applied to an alert.
yellow
Indicates when an alert was changed to medium importance.
red
Indicates when an alert was changed to high importance.
green
Indicates when an alert started.
black.
Indicates when an alert stopped.
To see a more detailed view of the traffic in the Alert Traffic graph of a DoS Profiled Network
alert, click and drag across the graph to select the timeframe that you want to view.
About the Alert Characterization table on the Summary tab
The Alert Characterization table lists different elements associated with the alert. For each
element, it lists the items that contributed at least 25% of the traffic of the alert. For each
element that appears in this table, a data table appears on the Traffic Details page.
A
(context menu) icon appears to the left of each element in the Alert Characterization
table. When you click , the options that you can select depend on the traffic item. The
following options can appear:
n Add Item to Alert Scratchpad
See “Adding traffic items to an Alert Scratchpad” on page 519.
n
Lookup IP Address (Whois) (IP addresses only)
See “Performing a Whois Lookup for an IP Address on a DoS Alert Page” on page 521.
The data for each item is the total for that item from all of the traffic of the alert. For example, if
an alert has the following amounts and types of traffic:
n 40% to TCP port 80
n
40% to UDP port 53
n
20% to UDP port 80
then the Alert Characterization table would include the following data:
Alert Characterization table data
504
Protocols
udp
60%
Protocols
tcp
40%
Destination TCP Ports
80
40%
Destination UDP Ports
53
40%
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
The 20% to UDP port 80 would not appear in the table because it was less than 25% of the
alert traffic.
Note: By default, SP aggregates IP prefixes. For information about how SP aggregates IP
prefixes, see “About the aggregation of IP addresses and ports in a DoS alert” on page 495.
Note: The Alert Characterization table displays data for individual items of the traffic of an
alert, while the Top Traffic Patterns (last 5 minute) table displays traffic that shares a 5-tuple
pattern. See “About the Top Traffic Patterns Table” on page 514.
About the Packet Size Distribution graph on the Summary tab
The Summary tab on a DoS alert page has a histogram that displays the distribution of the
packet sizes for the alert for the selected timeframe. The left side of the graph lists groups of
packet size ranges of 150 bytes each. Each horizontal bar shows the number of packets within
that 150-byte range. A jumbo frames bar appears at the bottom of the graph for packets that
are larger than 1500 bytes.
The Packet Size Distribution graph can often help you determine if an alert represents an
attack. You can use the graph to identify whether packet sizes are spread out or concentrated.
If the packet sizes are concentrated, you can then use the graph to determine if the areas of
concentration are what would be expected for that type of traffic.
For example, if you receive a UDP flood alert for packets sourced from port 123 (NTP), and the
majority of the packets are large (400 bytes or larger), you are probably looking at a reflection
attack because these NTP packets would normally be much smaller.
The Packet Size Distribution graph can also be used for post-attack forensic analysis to
identify patterns in packet size distribution for different types of attacks. You can then use this
information to help you identify future attacks.
About the Top Traffic Patterns (last 5 min of selected timeframe) table on the Summary
tab
The Top Traffic Patterns table appears on the Summary tab and Traffic Details tab of a
DoS Host alert or a DoS Profiled Router alert. SP looks at the traffic in an alert and aggregates
the src/dst CIDRs and the src/dst port ranges to identify groups of flows that have the same 5tuple traffic pattern (src/dst IP, src/dst port, and protocol). SP then populates this table with
traffic patterns for the alert that represent at least 10% of the traffic during the last 5 minutes
of the selected timeframe. See “About the Top Traffic Patterns Table” on page 514.
About the Top Interfaces table on the Summary tab
The Top Interfaces table displays the interfaces that were most impacted by the traffic of this
alert. It can display up to 5 interfaces. If the alert includes egress traffic that a router has
dropped, then SP displays Filtered by Router for that traffic instead of an interface name. The
interfaces are sorted by the Average Observed bps value.
If the name of an item in the Top Interfaces table is truncated, you can hover your mouse over
the name to display the full name.
Each interface is preceded by
(context menu), except when Filtered by Router is displayed
instead of an interface name. The options available from are the same options that are
available for the interfaces in the routers table on the Routers tab. For a description of the
options and the information that is displayed for each interface, see “About the routers table on
the Routers tab of a DoS alert page” on page 510.
Proprietary and Confidential Information of Arbor Networks Inc.
505
SP and TMS User Guide, Version 8.0
About the Recent Annotations section on the Summary tab
The Recent Annotations section lists the most recent annotations that have been added to an
alert. It can display up to 3 annotations.
This section also includes a View All Annotations link that opens the Annotations tab,
where you can view all of the annotations for the alert. See “About the Annotations Tab on a
DoS Alert Page” on page 513.
506
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
About the Traffic Details Tab on a DoS Alert Page
Introduction
The Traffic Details tab on the DoS Alert pages displays data graphs and tables about the
most significant elements that contributed to an alert during a selected timeframe. The element
whose data appears in the tab’s main graph is highlighted with a blue background.
The Traffic Details tab also includes the Top Traffic Patterns (5-tuple) section. See “About
the Top Traffic Patterns Table” on page 514.
A
(context menu) icon appears next to most traffic items on the Traffic Details tab. You
can click to add the item to the Alert Scratchpad or to perform a whois lookup for source
and destination IP addresses. For additional information, see:
n “Adding traffic items to an Alert Scratchpad” on page 519
n
“Adding a 5-tuple traffic pattern to an Alert Scratchpad” on page 517
n
“Performing a Whois Lookup for an IP Address on a DoS Alert Page” on page 521
For general information about a DoS alert page including how to control the traffic data that is
displayed, see “Introduction to DoS Alerts” on page 492.
Displaying and viewing data on the Traffic Details tab
The following are different options for displaying and viewing data on the Traffic Details tab:
Change the traffic data displayed on the Traffic Details tab
n
You can use Period, Units, and View lists at the top of the Traffic Details tab to change
the traffic data displayed on this tab. See “About the traffic data displayed for a DoS alert”
on page 493.
In addition to using the Period list to change the timeframe for the alert traffic, you can also
click and drag across the graph to select the timeframe that you want to view.
n
Display the data of a statistics table in the traffic graph
You can click any table or View Graph below a table to display that table’s data in the
traffic graph.
n
View additional data that does not appear in a traffic statistics table
If a contributing element has more than 5 entries, you can click the View More link below
the statistics table to view more of the entries for that contributing element. For source and
destination IP addresses, the View More Details window that appears displays up to 100
aggregated IP addresses.
n
Download all the source IP addresses
If an alert has more than 5 source IP address, you can view all of its source IP addresses.
When you click View More below a source IP address table, the View More Details
window that appears has a Download All button. When you click the Download All
button, SP downloads a CSV file of all the source IP addresses that are associated with the
alert.
About the traffic statistics tables on the Traffic Details tab
The Traffic Details tab displays traffic statistics tables and allows you to investigate the
traffic to determine if it is malicious. For information about viewing more information than is
displayed in these tables, see “Displaying and viewing data on the Traffic Details tab” above.
For information about the Top Traffic Patterns (last 5 minutes) table, see “About the Top Traffic
Proprietary and Confidential Information of Arbor Networks Inc.
507
SP and TMS User Guide, Version 8.0
Patterns Table” on page 514.
SP gathers the data that is displayed in these tables every minute. SP updates the data in the
tables whenever the DoS alert is manually updated. Each table displays the rate and
percentage of the traffic for the items listed in the table. The rate displayed for each item in a
table (for example, source IP addresses) is the maximum value seen for that item over the
selected timeframe of the alert. The percentage is based on the overall traffic of the alert for
the selected timeframe.
For the IP address tables and the port tables, SP aggregates the IP addresses and the ports.
Because SP displays aggregated data for IP addresses and ports, some of the IP addresses
and ports can be subsets of more aggregated data. For information on how SP aggregates IP
addresses, see “About the aggregation of IP addresses and ports in a DoS alert” on page 495.
The Traffic Details tab contains the following data tables:
Traffic Details tab data tables
508
Table
Description
Source IP
Addresses
Displays the top 5 aggregated source IP addresses of the alert traffic.
By default, SP aggregates IP addresses.
Note: Attackers can forge source IP addresses. Do not rely on these
statistics to identify the actual source of traffic.
Destination IP
Addresses
Displays the top 5 aggregated destination IP addresses of the alert
traffic. By default, SP aggregates IP addresses.
This table can help you determine the destination of potential attack
traffic and the volume of this traffic.
Source TCP Ports
Displays the top 5 source ports or aggregated ports for the TCP
packets. A port is followed by the service name, and an aggregated
port is followed by the aggregated port name.
This table can sometimes help you determine if the traffic is normal
traffic or attack traffic.
Destination TCP
Ports
Displays the top 5 destination ports or aggregated ports for the TCP
packets. A port is followed by the service name, and an aggregated
port is followed by the aggregated port name.
This table can help you determine the type of ports that are likely to be
affected by this traffic.
Example: If most of the traffic has a destination (DST) port of 80 and
the protocol is TCP, then the HTTP service on one or more hosts is the
target service for most of the traffic. If the destination ports are listed
as 0-65535, this is most likely an attack against all services on the
destination host. Consult the destination address table to determine
which hosts might be the target.
Source UDP Ports
Displays the top 5 source ports or aggregated ports for the UDP
packets. A port is followed by the service name, and an aggregated
port is followed by the aggregated port name.
This table can sometimes help you determine if the traffic is normal
traffic or attack traffic.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
Traffic Details tab data tables (Continued)
Table
Description
Destination UDP
Ports
Displays the top 5 destination ports or aggregated ports for the UDP
packets. A port is followed by the service name, and an aggregated
port is followed by the aggregated port name.
This table can help you determine the type of ports that are likely to be
affected by this traffic.
Source Countries
Displays the top 5 source countries for the alert traffic. The country’s
flag is followed by its name.
Source ASNs
Displays the top 5 ASNs for the alert traffic. The ASN number is
followed by the ASN name.
Protocols
Displays the top 5 protocols for the alert traffic.
The most common protocols are as follows:
n
n
n
TCP — usually legitimate traffic
UDP — usually legitimate traffic
ICMP or IPv6-ICMP— large amounts of ICMP traffic usually
indicates a problem
Other protocols can appear here if your network uses or provides
service for customers who are using GRE tunnels, IPSec tunnels,
OSPF, or other facilities that use their own protocol number.
TCP Flags
Displays the top 5 sets of TCP flags for the alert traffic. It displays the
TCP flags that have been set to 1. The letter or letters for the TCP flag
are followed by the name or names of the TCP flag.
TCP uses the TCP flags to signal the beginning and end of
connections and other conditions. The individual letters that appear for
the flags indicate which flags are set to 1 in the associated flows. Not
all packets associated with the listed flag sets have all of the flags set
to 1. Instead, it indicates that at least one packet in each flow has the
associated flag set to 1.
ICMP Types
Displays counts and rates for ICMP packets with the specified ICMP
type. If ICMP packets were not seen during the sampling process, then
this table might be empty.
You can use this information to determine the ratio of ICMP Echo
Request packets to ICMP Destination Unreachable packets.
Misuse Types
Displays the top 5 misuse types for the alert traffic.
Proprietary and Confidential Information of Arbor Networks Inc.
509
SP and TMS User Guide, Version 8.0
About the Routers Tab on a DoS Alert Page
Introduction
The Routers tab on a DoS alert page displays a graph of the alert traffic for the selected
timeframe for the routers that are selected in the table below the graph. You can display the
alert traffic for up to 10 routers. The table below the graph lists the routers and their interfaces
that are associated with the alert. For information about changing the traffic data that is
displayed on this page, see “About the traffic data displayed for a DoS alert” on page 493.
Note: The View list appears on this page for DoS Profiled Network alerts. It does not appear
for DoS Host alerts and DoS Profiled Router alerts because it does not affect which routers are
displayed on this page.
For details about the information and options that appear above the tabs on a DoS alert page,
see “Introduction to DoS Alerts” on page 492.
About the routers table on the Routers tab of a DoS alert page
The routers table lists the routers where the alert traffic was observed and displays the impact
of that traffic on those routers and their interfaces for the selected timeframe.
The table displays the following information for each router:
Routers table information
Column
(expand) icon or
(collapse) icon
Click (expand) icon to display the interfaces of a router and click
(collapse) icon to hide the interfaces.
check box
Click to select the routers that you want to display in the Alert Traffic
graph. After you select routers, click Update to update the graph to
display the selected routers.
Name (#
Interfaces)
510
Description
The name of the router with the number of affected interfaces, or the
name of the interface. If the alert includes egress traffic that a router
has dropped, then SP displays Filtered by Router for that traffic instead
of the name of the router or interface.
If the name of a router or interface is truncated, you can hover your
mouse over the name to display the full name.
A
(context menu) icon is to the left of the name of the router or
interface, except when Filtered by Router is displayed instead of a
router or interface name. For information about the context menu
options, see “About the context menu options in the routers table” on
the facing page.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
Routers table information (Continued)
Column
Description
Severity
The severity of the alert traffic on the router for the life of the alert. The
severity can be Low, Medium, or High. For information on how SP
classifies the severity level of alerts, see the following:
n
n
“How SP creates and classifies standard host alerts” on page 433
“How SP creates and classifies profiled router detection alerts” on
page 448
Note: This column does not appear for DoS Profiled Network alerts.
Interface Direction
The direction (ingress or egress) of the traffic on the interface.
Interface
Boundary
The interface boundary can be Network, Managed Object, Network
and Managed Object, or None.
Network boundary refers to the set of interfaces in the deployment that
are classified as external. Managed Object boundary refers to the set
of interfaces that were selected when the managed object that is
associated with the alert was configured.
Interface ASNs
The ASNs or the number of ASNs associated with the interface. If
there are 3 or fewer ASNs, then the ASNs are listed. If there are more
than 3 ASNs, then the number of ASNs is displayed.
Avg. Packet Size
The average packet size of the alert traffic on the router for the
selected timeframe.
Threshold
The threshold that alert traffic must exceed before an alert can be
triggered.
Note: This column appears only for DoS Profiled Router alerts.
Max Observed
The highest bps and pps of alert traffic observed on the router or
interface during any minute of the selected timeframe.
Note: The maximum observed values might not match the maximum
severity percent or maximum impact of alert traffic values. For an
explanation, see “Why maximum severity percent, maximum impact of
alert traffic, and maximum observed values might not match” on
page 496.
Average Observed
The average bps and pps rate of alert traffic observed on the router or
interface for the life of the alert.
About the context menu options in the routers table
In the routers table, a
(context menu) icon is to the left of the name of the router or interface.
The icon becomes more visible when you hover your mouse pointer over it. Click , and then
select one of the following options:
n Add Router to Alert Scratchpad or Add Interface to Alert Scratchpad
Adds the router or interface to the Alert Scratchpad for this DoS alert. See “About the Alert
Scratchpad” on page 517.
Proprietary and Confidential Information of Arbor Networks Inc.
511
SP and TMS User Guide, Version 8.0
n
View Alert Traffic Details
Allows you to view the traffic details for this alert on the Traffic Details tab with this router
selected in the Router (Severity) list. For information about the Router (Severity) list,
see “About the traffic data displayed for a DoS alert” on page 493.
Note: This option does not appear for Profiled Network alerts.
n
View Summary Report
Allows you to view the different types of traffic for the router or interface in the Router
Summary report .
n
View Configuration
Allows you to view and edit the configuration of the router or interface on its configuration
page.
512
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
About the Annotations Tab on a DoS Alert Page
Introduction
The Annotations tab displays all of the annotations that have been added to a DoS alert. On
the Annotations tab, you change the classification of a DoS alert and add annotations to the
alert.
You can also add annotations to a DoS alert on the alert listing page. See “Adding an
annotation to an alert on an alert listing page” on page 486.
Changing the classification of a DoS alert
To change the classification of a DoS alert:
1. Navigate to the DoS alert page.
2. Click the Annotations tab.
3. From the Alert Classification list, select a classification.
For a description of the different classifications, see “Alert classification types” on
page 488.
Adding an annotation to a DoS alert on the Annotations tab
To add an annotation to a DoS alert on the Annotations tab:
1. Navigate to the DoS alert page.
2. Click the Annotations tab.
3. Click Add Annotation.
4. In the Add Annotation window, configure the following settings:
Setting
Description
box
Type your DQQRWDWLRQ.
Customer called,
(Optional) Select one or more of these check boxes to indicate
why you added the annotation.
Crippling attack,
and
Escalated check
boxes
5. Click Save.
How SP annotates the change of the severity level of a DoS Host alert
If the severity level of a host alert increases because of the traffic at a managed object
boundary or a network boundary, then “(boundary: managed object)” or “(boundary: network)”
is appended to the annotation that describes this change of severity level.
If the traffic at the managed object boundary and the network boundary causes the severity
level to increase, then the description identifies the boundary with the most traffic. If the traffic
at the managed object boundary and the network boundary is the same, then “(boundary:
managed object)” is appended.
For information about how SP assigns the severity level to a DoS Host alert, see “How SP
creates and classifies standard host alerts” on page 433.
Proprietary and Confidential Information of Arbor Networks Inc.
513
SP and TMS User Guide, Version 8.0
About the Top Traffic Patterns Table
Introduction
The Top Traffic Patterns (last 5 min of selected timeframe) table appears on the Summary
tab and Traffic Details tab of a DoS Host alert or a DoS Profiled Router alert. This table
displays the top traffic patterns identified in the traffic of an alert.
How SP populates the Top Traffic Patterns table
SP looks at the traffic in an alert and aggregates the src/dst CIDRs and the src/dst port ranges
to identify groups of flows that have the same 5-tuple traffic pattern (src/dst IP, src/dst port,
and protocol). SP then populates this table with traffic patterns for the alert that represent at
least 10% of the traffic during the last 5 minutes of the selected timeframe.
Note: The Top Traffic Patterns table displays traffic that shares a 5-tuple pattern, while the
Alert Characterization table displays data for individual items of the traffic of an alert. See
“About the Alert Characterization table on the Summary tab” on page 504.
How to use the top traffic patterns
The traffic patterns can help you determine if an alert represents an attack. If you determine
that a traffic pattern represents an attack, you can then add data from the traffic pattern to an
Alert Scratchpad, and then copy the data into a mitigation.
Top traffic patterns represent interesting traffic, but not necessarily bad traffic. You should look
for top traffic patterns that stand out because they are in some way abnormal for your network.
An abnormal traffic pattern could have a protocol that you normally do not see or a high volume
of traffic when that pattern usually has a low volume of traffic.
About the display of top traffic patterns
When a DoS alert is initially triggered, SP does not display any top traffic patterns. It can only
display top traffic patterns 2 to 3 minutes after an alert is triggered.
SP can display up to 10 top traffic patterns in the Top Traffic Patterns table. You can also click
the Download All Patterns button to view all of the traffic patterns that are associated with
an alert. When you click Download All Patterns, a CSV file is generated that lists the traffic
patterns.
If an alert is displaying data for a specific router, then the Top Traffic Patterns table displays
only patterns for the alert traffic associated with that router. If an alert is displaying data for a
network boundary or a managed object boundary, then this table displays patterns for the alert
traffic of all the routers associated with the alert. See “About the traffic data displayed for a
DoS alert” on page 493.
SP updates the top traffic pattern data every minute, but it does not automatically update the
Top Traffic Patterns table. To update this table, you must refresh the DoS alert page or click
Update.
SP does not display top traffic patterns if any of the following occur:
an SP appliance does not have enough system resources to generate the traffic patterns for
every alert.
n
514
n
The alert had no traffic in the last 5 minutes.
n
The alert is a DoS Profiled Network alert.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
n
The alert is triggered on one of the following:
l
An appliance with a serial number that begins with AZLR
l
A virtual machine with less than 4 processors
l
A virtual machine running Xen
Note: Because the generation of traffic patterns is very processor intensive, it is disabled
on appliances or VMs where it would significantly disrupt the normal operation of SP.
Information that appears in a traffic pattern
For each traffic pattern, the following information is listed:
Traffic pattern information
Information
Decription
Source
The source IP addresses of the alert traffic in this traffic pattern. By
default, SP aggregates IP prefixes. For information about how
SP aggregates IP prefixes, see “About the aggregation of IP addresses
and ports in a DoS alert” on page 495.
If the name of an IP address is truncated, you can hover your mouse
over the name to display the full name.
Protocol
The protocol of the alert traffic in this traffic pattern.
Flags
For the TCP protocol, the TCP flags of the alert traffic in this traffic
pattern.
Src Port
The source port or aggregated source port of the alert traffic in this
traffic pattern. A port is followed by the service name, and an
aggregated port is followed by the aggregated port name. If no ports
are displayed, then the ports have been aggregated to include all ports.
For information about how SP aggregates ports, see “About the
aggregation of IP addresses and ports in a DoS alert” on page 495.
Destination
The destination IP addresses of the alert traffic in this traffic pattern.
By default, SP aggregates IP prefixes. For information about how
SP aggregates IP addresses, see “About the aggregation of IP
addresses and ports in a DoS alert” on page 495.
If the name of an IP address is truncated, you can hover your mouse
over the name to display the full name.
Dest Port
The destination port or aggregated destination port of the alert traffic
in this traffic pattern. A port is followed by the service name, and an
aggregated port is followed by the aggregated port name. If no ports
are displayed, then the ports have been aggregated to include all ports.
For information about how SP aggregates ports, see “About the
aggregation of IP addresses and ports in a DoS alert” on page 495.
Proprietary and Confidential Information of Arbor Networks Inc.
515
SP and TMS User Guide, Version 8.0
Traffic pattern information (Continued)
Information
Decription
Router
The router where the traffic for this traffic pattern was observed.
Note: If the same traffic pattern is observed on more than one router,
then the same traffic pattern is displayed for each router.
Alert Traffic
The rate of traffic represented by this traffic pattern during the last 5
minutes of the selected timeframe. A
icon appears in this column to
indicate that the traffic patterns are sorted by the data in this column.
About the context menu icons in a top traffic pattern
A
(context menu) icon appears to the left of each traffic pattern, and additional
icons
appear for individual traffic items when you hover your mouse pointer to the right of the item
(except for items in the Alert Traffic column). When you click , the options that you can
select depend on the traffic item. The following options can appear:
n Add Pattern to Alert Scratchpad (traffic patterns only)
Adds a traffic pattern to the Alert Scratchpad. See “Adding a 5-tuple traffic pattern to an
Alert Scratchpad” on the facing page.
n
Add Item to Alert Scratchpad
Adds a traffic item to the Alert Scratchpad. See “Adding traffic items to an Alert
Scratchpad” on page 519.
n
Lookup IP Address (Whois) (IP addresses only)
Performs a whois lookup on a source or destination IP address or aggregated IP address.
See “Performing a Whois Lookup for an IP Address on a DoS Alert Page” on page 521.
n
View Alert Traffic Details (routers only)
Displays the Traffic Details tab for this alert with this router selected in the Router
(Severity) list and with the data on the page updated. For information about the Router
(Severity) list, see “About the traffic data displayed for a DoS alert” on page 493.
516
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
About the Alert Scratchpad
Introduction
You can add traffic data from a DoS alert page to an Alert Scratchpad and then copy the data
from the scratchpad and paste it into a mitigation that is associated with the DoS alert.
Important things to know about the Alert Scratchpad
The following are important things that you should know about the Alert Scratchpad:
Each alert has its own Alert Scratchpad.
n
n
Alert Scratchpads are user-specific.
Any traffic data that you add to the Alert Scratchpad of a DoS alert does not appear in the
Alert Scratchpad when another user accesses that DoS alert.
n
The
(context menu) icon next to traffic data on a DoS Alert page is used to add traffic
data to the Alert Scratchpad for that alert.
n
The Alert Scratchpad for a DoS alert opens when you click the View Scratchpad button
at the top of a DoS alert page or a mitigation page.
n
An Alert Scratchpad can be moved anywhere on a DoS alert or mitigation page.
n
The number of traffic items that you have added to an Alert Scratchpad appears in
parentheses on the View Scratchpad button and at the end of the title of the Alert
Scratchpad window.
n
The traffic data that you add to an Alert Scratchpad remains in the scratchpad when you log
out.
n
A downloaded PDF of a DoS alert includes any traffic data that you have added to the Alert
Scratchpad for that alert.
Traffic data that you can add to an Alert Scratchpad
You can add the following types of traffic data to an Alert Scratchpad from a DoS alert page:
Traffic patterns
n
You can add a 5-tuple traffic pattern (src/dst IP, src/dst port, and protocol) to an Alert
Scratchpad from the Top Traffic Patterns (last 5 minutes) table on the Summary tab and
the Traffic Details tab of a DoS alert page. See “Adding a 5-tuple traffic pattern to an
Alert Scratchpad” below.
n
Traffic elements
Traffic elements include routers, interfaces, and other traffic items that appear on the DoS
alert pages. See “Adding routers and interfaces to an Alert Scratchpad” on the next page
and “Adding traffic items to an Alert Scratchpad” on page 519.
Traffic patterns are added to the Traffic Patterns section of an Alert Scratchpad and traffic
elements are added to the Traffic Elements section. When traffic items are added to the Traffic
Elements section, they are arranged in the same order that they appear on the Traffic Details
tab. They are then followed by any routers and interfaces that you have added to the Alert
Scratchpad.
Adding a 5-tuple traffic pattern to an Alert Scratchpad
You can add a 5-tuple traffic pattern (src/dst IP, src/dst port, and protocol) from the Top Traffic
Patterns (last 5 minutes) table to an Alert Scratchpad. A traffic pattern is added to an Alert
Scratchpad as an FCAP expression so that it is in a format that can be pasted into a mitigation.
Proprietary and Confidential Information of Arbor Networks Inc.
517
SP and TMS User Guide, Version 8.0
To add a specific traffic item from the Top Traffic Patterns (last 5 minutes) table to an Alert
Scratchpad, see “Adding traffic items to an Alert Scratchpad” on the facing page.
To add a 5-tuple traffic pattern to an Alert Scratchpad:
1. Navigate to the DoS alert page (Alerts > DoS > DOHUW ,' OLQN).
2. Click the Summary tab or the Traffic Details tab.
3. In the Top Traffic Patterns (last 5 minutes) table, hover your mouse pointer over the
(context menu) icon to the left of a traffic pattern.
When you hover your mouse pointer over the
visible.
4. Click
(context menu) icon, it becomes more
(context menu), and then click Add Pattern to Alert Scratchpad.
Adding routers and interfaces to an Alert Scratchpad
You can add routers or interfaces to an Alert Scratchpad as follows:
Procedures to add routers or interfaces to an Alert Scratchpad
518
To Add
Procedure
Routers or
interfaces
1. Navigate to the DoS alert page (Alerts > DoS > DOHUW ,'
OLQN).
2. Click the Routers tab.
3. Hover your mouse pointer over the
(context menu) icon to the
left of the router or interface.
When you hover your mouse pointer over , it becomes more
visible.
If the interfaces associated with a router are not displayed, click
the (expand) icon to the left of the name of a router to display
them.
4. Click (context menu), and then click Add Router to Alert
Scratchpad or Add Interface to Alert Scratchpad.
Interfaces only
1. Navigate to the DoS alert page (Alerts > DoS > DOHUW ,'
OLQN).
2. Click the Summary tab.
3. In the Top 5 Interfaces table, hover your mouse pointer over the
(context menu) icon to the left of a traffic pattern.
When you hover your mouse pointer over . it becomes more
visible.
4. Click (context menu), and then click Add Interface to Alert
Scratchpad.
Routers only
1. Navigate to the DoS alert page (Alerts > DoS > DOHUW ,'
OLQN).
2. Click the Summary tab or the Traffic Details tab.
3. In the Top Traffic Patterns (last 5 minutes) table, hover your
mouse pointer behind the router name in a 5-tuple traffic pattern
to display
(context menu).
4. Click (context menu), and then click Add Item to Alert
Scratchpad.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
Note: When you add an interface to an Alert Scratchpad, the name of its router is appended
to the name of the interface.
Adding traffic items to an Alert Scratchpad
In addition to traffic patterns, routers, and interfaces, you can also add most of the other traffic
items that appear on a DoS alert page to an Alert Scratchpad.
You can use the
(context menu) icon to add traffic items to an Alert Scratchpad from the
following locations on a DoS alert page:
n Alert Characterization table on the Summary tab
Note: Any information that you can add to an Alert Scratchpad from the Alert
Characterization can also be added from the data tables on the Traffic Details tab.
n
Data tables on the Traffic Details tab
n
View More Details window on the Traffic Details tab
You access this window by clicking View all below the data table. If a data table has 5 or
fewer items, View all does not appear.
n
Top Traffic Patterns (5-tuple) table on the Summary tab or the Traffic Details tab
You can add items to an Alert Scratchpad from every column in the table except the % Alert
Traffic column.
Important: The
(context menu) icon for individual items in the Top Traffic Patterns
(5-tuple) is to the right of the item and does not appear until you hover you mouse pointer
over it.
Deleting traffic data from an Alert Scratchpad
If you see items in an Alert Scratchpad that no longer apply to your mitigation strategy, you can
delete them. You can delete items from an Alert Scratchpad on a DoS alert page or on a
mitigation page. You can delete individual items or all of the items in the Traffic Patterns or the
Traffic Elements sections of an Alert Scratchpad. When you delete all of the items from an
Alert Scratchpad on a mitigation page, the Alert Scratchpad and the View Scratchpad
button disappear from the mitigation page.
To delete traffic data from an Alert Scratchpad:
1. Navigate to a DoS alert page (Alerts > DoS > DOHUW ,' OLQN) or the mitigation page
for the DoS alert.
When you initiate a mitigation from a DoS alert page, you are taken to the mitigation page.
For a mitigation that already exists, you can access the mitigation from the mitigation type
link that appears in the upper right corner of the DoS alert. For information about the
mitigation type link, see “About the information in the header of a DoS alert ” on page 492.
2. At the top of the page, click View Scratchpad to open the Alert Scratchpad.
On the TMS Mitigation Status page, View Scratchpad is in the header of the
Countermeasures pane.
3. To delete a single item, click the X to the left of the item.
4. To delete all of the items in the Traffic Patterns section or the Traffic Elements section,
click Clear All in the heading of that section.
Proprietary and Confidential Information of Arbor Networks Inc.
519
SP and TMS User Guide, Version 8.0
Copying traffic data from an Alert Scratchpad into a mitigation
When a mitigation is associated with a DoS alert for which you have added traffic data to its
Alert Scratchpad, you can access the Alert Scratchpad and its traffic data from the mitigation
page. You can then copy and paste the traffic data into the mitigation settings. See “Initiating a
Mitigation from a DoS Alert” on page 622.
You can copy traffic data from the Alert Scratchpad into the mitigation settings for the
following types of mitigations:
n TMS
n
Flow Specification
n
Blackhole
To copy traffic data from an Alert Scratchpad into the mitigation settings:
1. Navigate to the mitigation page for the DoS alert.
When you initiate a mitigation from a DoS alert page, you are taken to the mitigation page.
For a mitigation that already exists, access it from the Mitigation menu.
2. At the top of the page, click View Scratchpad to open the Alert Scratchpad.
On the TMS Mitigation Status page, View Scratchpad is in the header of the
Countermeasures pane.
If View Scratchpad does not appear on the mitigation page, then you have not added
any traffic data to the Alert Scratchpad for the alert associated with the mitigation.
3. In the Alert Scratchpad, copy the traffic data that you want to use in the mitigation.
4. On the mitigation page, navigate to where you want to insert the data and paste it into the
appropriate settings box.
520
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
Performing a Whois Lookup for an IP Address on a DoS Alert Page
Introduction
You can perform a whois lookup to view ASN information about any source or destination IP
address on a DoS alert page. The information that a whois lookup provides includes the
company name, contact information, and AS data. You use the
(context menu) icon of an IP
address to perform a whois lookup.
Performing a whois lookup
You can perform a whois lookup on a source or destination IP address in any of the following
tables or windows on a DoS alert page:
n Top Traffic Patterns (5-tuple) table on the Summary tab or the Traffic Details tab
n
Alert Characterization table on the Summary tab
n
Source and destination addresses tables on the Traffic Details tab
n
View More Details window for source or destination addresses
To access the View More Details window, click View More below the source and
destination addresses tables on the Traffic Details tab.
To perform a whois lookup:
1. Hover your mouse pointer over the
want to do a whois lookup.
(context menu) icon of the address for which you
In the Top Traffic Patterns (5-tuple) table, the
(context menu) icon is to right of the
address and appears when you hover your mouse pointer over it. For all the other
addresses, the
(context menu) icon is to the left of the IP address and becomes more
visible when you hover your mouse pointer over it.
2. Click
(context menu), and then click Look Up IP Address (Whois).
3. In the Whois Lookup window, you can use the ARIN, RIPE, or APNIC registries to find
information about the IP address.
If you do not select the correct registry, the whois lookup will indicate that you need to use
one of the other registries.
Proprietary and Confidential Information of Arbor Networks Inc.
521
SP and TMS User Guide, Version 8.0
Recognizing a Potential DoS Attack
Introduction
The following example workflow describes some of the key traffic data that you can use to
determine if a DoS Host alert represents an attack. Most of this same traffic data can also be
used to determine if a DoS Profiled Router alert or DoS Profiled Network alert represents an
attack.
Example workflow for recognizing an attack from a DoS Host alert
The following example describes how to recognize an attack from a DoS Host alert:
1. Do the following to navigate to the DoS Host alert:
l
l
On the Alerts Ongoing page (Alerts > Ongoing), type host in the Search box, and
then click Search.
Look for a DoS Host alert with an importance level of High that has been ongoing for
more than 5 minutes.
This type of alert is alarming because of its high importance level and the duration of the
attack.
l
Click the ID link of the alert to access the DoS Host Alert page to view more
information about the traffic of the alert and to determine if it represents an attack.
2. In the key alert information that is above the Alert Traffic graph on the Summary tab, look
at the maximum severity percent and the maximum impact of alert traffic values, and do the
following:
l
From the maximum severity percent value, make sure the alert is using a reasonable
threshold.
If the threshold is too low, then the alert might represent traffic that does not need your
attention.
l
Use the maximum severity percent and the maximum impact of alert traffic values
combined with your understanding of your network to determine if the alert deserves
further attention.
Maximum severity percent is the highest single-minute ratio of the rate of the alert
traffic to the high severity rate over the lifetime of the alert. Maximum impact of alert
traffic is the bandwidth that an alert consumes in your network and where this impact
data was recorded.
See “About key alert information on the Summary tab” on page 498.
Note: The maximum severity percent and the maximum impact of alert traffic values will
not always match. See “Why maximum severity percent, maximum impact of alert traffic,
and maximum observed values might not match” on page 496.
3. In the Alert Traffic graph on the Summary tab, look for anything that is unusual about the
traffic displayed.
Base your analysis on your knowledge of normal peaks in your network as well as known
events that could cause spikes in the traffic.
522
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 18: About DoS Alerts
4. On the Alert Traffic graph on the Summary tab, display the trigger rate for each misuse
type that exceeded the trigger rate.
This trigger rate can then help you determine if the rate of traffic can be explained by
known events or if it represents attack traffic. To display the trigger rates, do the following:
a. Select Router from the View list, and then click Update.
b. Double-click the selector of a misuse type that exceeds the trigger rate so that only the
traffic of that misuse type is displayed.
c. Click the trigger rate selector for that misuse type to display the trigger rate.
See “About the Alert Traffic graph on the Summary tab of a DoS Host Alert page” on
page 501.
5. Use the following tables on the Summary tab to look for additional traffic data that can
help you determine if the alert traffic represents an attack, as follows:
Table
Traffic Data to Look For
Top Traffic
Patterns (last 5
minutes)
n
n
n
n
n
Traffic to an unexpected destination IP address.
Traffic to a destination port that normally does not see traffic.
A traffic pattern that is abnormal in terms of the elements that
make up the pattern.
A traffic pattern that is abnormal in terms of its volume.
Whois lookup data of a source IP address to determine where
the traffic is coming from. You use the
(context menu) icon to
the right of a source IP address to perform a whois lookup.
See “About the Top Traffic Patterns Table” on page 514.
Packet Size
Distribution
Packet size distribution that differs significantly from the normal
distribution.
See “About the Packet Size Distribution graph on the Summary
tab” on page 505.
Top Interfaces
Interfaces that have unusually high volumes of traffic.
From each interface, you can also access the summary report for
the interface. The summary report can give you an historical
perspective to help you determine if the traffic on this interface is
really that unusual. To view the summary report, click the
(context menu) icon to the left of the interface name, and then click
View Summary Report.
See “About the Top Interfaces table on the Summary tab” on
page 505.
6. If the top traffic patterns do not help you identify a potential attack, then see if you can
correlate any unusual data in the tables on the Traffic Details tab to identify a potential
attack. The following table lists some of the things you can look for in these tables:
Proprietary and Confidential Information of Arbor Networks Inc.
523
SP and TMS User Guide, Version 8.0
Table
Traffic Data to Look For
Source IP
Addresses
Unexpected high traffic volumes from a source IP address.
Destination
IP Addresses
The IP address where the traffic is going.
Source TCP Ports
or
Source UDP Ports
Whether the source ports represent normal traffic.
Destination TCP
Ports
or
Destination UDP
Ports
Whether the levels of the traffic that are sent to these destination
ports are normal.
Source Countries
or
Source ASNs
High volumes of traffic from unexpected sources.
TCP Flags
A flag that can help you determine the type of the attack.
Example: Normal traffic might be 1-1023 (System) and attack
traffic might be 1024-65535 (Dynamic).
Example: If you see that the packets that were sent to port TCP
80 were 40 bytes each, then this is an attack and not normal
traffic.
Note: You can click on any of these tables to display its data in traffic graph at the top of
the Traffic Details tab.
See “About the traffic statistics tables on the Traffic Details tab” on page 507.
If you determine that the traffic of an alert represents an attack, you can then add the traffic
data to the Alert Scratchpad to use when you configure a mitigation for the attack. See “About
the Alert Scratchpad” on page 517.
524
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19:
Configuring TMS Models
Introduction
This section describes how to complete the basic configuration of TMS models.
Note: In the documentation, “TMS appliance” is used to refer to a physical appliance that is
sold by Arbor, while “TMS model” is used to refer to all TMS devices including TMS-ISAs,
TMS-CGSEs, TMS-VSMs, and TMS appliances.
User access
Administrators can perform all actions in this section. Non-administrative users cannot make
configuration changes.
In this section
This section contains the following topics:
About Configuring TMS Models
526
Adding, Editing, and Deleting a TMS Model
528
Configuring Appliance Settings for a TMS Model
531
Configuring SNMP Settings for a TMS Appliance or TMS-VSM
533
Configuring Deployment Settings for a TMS Appliance, TMS-ISA, or TMS-VSM
535
Configuring ArborFlow Settings for a TMS Appliance
540
Configuring Patch Panel Settings for a TMS Appliance or TMS-VSM
542
Configuring IP Forwarding Settings for a TMS Appliance
549
Configuring Subinterfaces for a TMS Appliance or TMS-VSM
550
Configuring Port Settings for a TMS Appliance or TMS-VSM
552
Configuring GRE Settings for a TMS Appliance or TMS-VSM
554
Configuring Blacklist Offloading Settings for a TMS-VSM
557
Configuring Advanced Settings for a TMS Model
560
Configuring TMS-CGSE Clusters
561
Configuring TMS-ISA Clusters
563
Configuring Diversion Settings for a TMS Cluster
565
Configuring TMS Groups
567
SP and TMS User Guide, Version 8.0
525
SP and TMS User Guide, Version 8.0
About Configuring TMS Models
Introduction
You can view and delete TMS models on the Configure Appliances page (Administration >
Appliances). This topic describes the Configure Appliances page and the different tasks for
configuring TMS appliances, TMS-ISAs, and TMS-CGSEs.
Note: In the documentation, “TMS appliance” is used to refer to a physical appliance that is
sold by Arbor, while “TMS model” is used to refer to all TMS devices including TMS-ISAs,
TMS-CGSEs, TMS-VSMs, and TMS appliances.
For similar information for SP appliances, see “About Configuring SP Appliances” on
page 102.
For information about securing your Arbor Networks appliances, see “Securing Your Arbor
Networks Appliances” in the SP and TMS Advanced Configuration Guide.
About the Configure Appliances page
The Configure Appliances page contains the following information:
Configure Appliances page details
Column
Description
Select if you want to delete a non-leader appliance.
You cannot delete the leader.
526
Name
The hostname, type, and description of an appliance.
License
Mode
The license mode of the appliance. The license mode of a TMS model is
always Appliance.
This column only appears if a flexible license has been uploaded to your
deployment. See “Uploading a Flexible License” on page 92.
Tags
The tags applied to a configured appliance.
Tags can help you categorize and search for appliances in your deployment.
For example, if you are staging new appliances, you might tag them with
“staged.”
IP Address
The IP address of an appliance.
Configuration
Any devices that peer with or forward flow information to an appliance.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuration task overview for TMS models
The following table lists the different tasks for configuring TMS appliances, TMS-ISAs,
TMS-CGSEs, and TMS-VSMs:
TMS configuration task overview by model
TMS
Model
Task Overview
TMS
appliance
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Add/edit the appliance settings.
(Optional) Configure TMS appliance SNMP settings.
Configure TMS appliance deployment settings.
Configure TMS appliance ArborFlow settings.
Configure the TMS appliance patch panel settings.
(Optional) Configure IP forwarding
Configure TMS appliance subinterfaces.
Configure TMS appliance ports.
Configure TMS appliance GRE settings.
Configure TMS appliance advanced settings.
TMS-CGSE
1. Add/edit the TMS-CGSE appliance settings.
2. Configure the TMS-CGSE advanced settings.
3. Add the TMS-CGSE to a TMS-CGSE Cluster.
See “Configuring TMS-CGSE Clusters” on page 561.
4. Configure the diversion settings for the TMS-CGSE cluster.
See “Configuring Diversion Settings for a TMS Cluster” on page 565.
TMS-ISA
1.
2.
3.
4.
TMS-VSM
1.
2.
3.
4.
5.
6.
7.
8.
9.
Add/edit the TMS-ISA appliance settings.
Configure the TMS-ISA deployment setting.
Configure the TMS-ISA advanced settings.
Add the TMS-ISA to a TMS-ISA Cluster.
See “Configuring TMS-ISA Clusters” on page 563.
5. Configure the diversion settings for the TMS-ISA cluster.
See “Configuring Diversion Settings for a TMS Cluster” on page 565.
Add/edit the TMS-VSM.
(Optional) Configure TMS-VSM SNMP settings.
Configure TMS-VSM deployment settings.
Configure the TMS-VSM patch panel settings.
Configure TMS-VSM subinterfaces.
Configure TMS-VSM ports.
Configure TMS-VSM GRE settings.
(Optional) Configure blacklist offloading.
Configure TMS-VSM advanced settings.
Proprietary and Confidential Information of Arbor Networks Inc.
527
SP and TMS User Guide, Version 8.0
Adding, Editing, and Deleting a TMS Model
Introduction
You can configure and delete a TMS model on the Configure Appliances page
(Administration > Appliances).
Note: In the documentation, “TMS appliance” is used to refer to a physical appliance that is
sold by Arbor, while “TMS model” is used to refer to all TMS devices including TMS-ISAs,
TMS-CGSEs, TMS-VSMs, and TMS appliances.
For similar information for SP appliances, see “Adding, Editing, and Deleting an SP Appliance”
on page 104.
Adding and editing a TMS model
To add or edit a TMS model:
1. Verify that you have added the TMS appliance, TMS-CGSE, TMS-ISA, or TMS-VSM by
using the CLI.
For more information about adding TMS models, see the following:
l
l
l
l
Arbor Networks TMS Quick Start Cards, available from the Arbor Technical Assistance
Center (https://support.arbor.net)
TMS-CGSE Configuration Guide, available from Cisco
TMS-VSM Configuration Guide, available from the Arbor Technical Assistance Center
(https://support.arbor.net)
Your router’s documentation for a TMS-ISA
2. Navigate to the Configure Appliances page (Administration > Appliances).
3. Do one of the following:
l
To add a new TMS model, click Add Appliance.
l
To edit an existing TMS model, click a name link.
4. Configure the settings for each of the tabs that appear for your TMS model.
See “Tabs on the Appliance pages for TMS models” on the facing page.
For a task overview of the appliance that you are configuring, see “Configuration task
overview for TMS models” on the previous page.
5. Click Save, and then commit your changes.
528
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Tabs on the Appliance pages for TMS models
The following table lists the different tabs that can appear on the Add Appliance page and the
Edit Appliance page:
Tabs on the Appliance pages for TMS models
Tab
Description
Appliance
Allows you to configure the settings for your TMS model. See
“Configuring Appliance Settings for a TMS Model” on page 531.
SNMP
(TMS appliances and TMS-VSMs only) Allows you to configure
optional SNMP settings for a TMS appliance or TMS-VSM. See
“Configuring SNMP Settings for a TMS Appliance or TMS-VSM” on
page 533.
Deployment
(TMS appliances and TMS-VSMs only) Allows you to configure
various settings specific to the mode in which you deploy your TMS
appliance, TMS-ISA, or TMS-VSM. See “Configuring Deployment
Settings for a TMS Appliance, TMS-ISA, or TMS-VSM” on page 535.
ArborFlow
(TMS appliances only) Allows you to configure the flow that the TMS
appliance sends to its managing appliance. See “Configuring
ArborFlow Settings for a TMS Appliance” on page 540.
Patch Panel
(TMS appliances and TMS-VSMs only) Allows you to configure the
diversion settings for a diversion deployment of a TMS appliance or for
a TMS-VSM. It also allows you to configure the interfaces for a TMS
appliance and the backplane channel group settings for a TMS-VSM.
See “Configuring Patch Panel Settings for a TMS Appliance or
TMS-VSM” on page 542.
IP Forwarding
(TMS appliances only) Allows you to configure the forwarding of the
output using layer 3 forwarding. See “Configuring IP Forwarding
Settings for a TMS Appliance” on page 549.
Subinterfaces
(TMS appliances and TMS-VSMs only) Allows you to configure
subinterfaces for a diversion deployment of a TMS appliance or for a
TMS-VSM. See “Configuring Subinterfaces for a TMS Appliance or
TMS-VSM” on page 550.
Ports
(TMS appliances and TMS-VSMs only) Allows you to configure logical
and physical port settings. For a TMS-VSM, you can configure only the
description and MTU of logical ports. See “Configuring Port Settings
for a TMS Appliance or TMS-VSM” on page 552.
GRE
(TMS appliances and TMS-VSMs only) Allows you to configure GRE
tunnels. See “Configuring GRE Settings for a TMS Appliance or
TMS-VSM ” on page 554.
Proprietary and Confidential Information of Arbor Networks Inc.
529
SP and TMS User Guide, Version 8.0
Tabs on the Appliance pages for TMS models (Continued)
Tab
Description
Blacklist
Offloading
(TMS-VSMs only) Allows you to enable or disable OpenFlow blacklist
offloading and to edit settings for OpenFlow blacklist offloading. See
“Configuring Blacklist Offloading Settings for a TMS-VSM” on
page 557.
Advanced
Allows you to configure advanced SPAN port deployment settings,
adjust the maximum number of ongoing mitigations, and, (for
TMS 5000 appliances only) configure the blocking method for
blacklist offloading. See “Configuring Advanced Settings for a TMS
Model” on page 560.
For a task overview of the appliance that you are configuring, see “Configuration task overview
for TMS models” on page 527.
Deleting a TMS model
If you want to delete a TMS-CGSE or TMS-ISA, you should first remove it from the
TMS-CGSE cluster or TMS-ISA cluster to which it is assigned. If you do not remove it from the
cluster first, SP does not properly update the status for any mitigations associated with the
cluster.
To delete a TMS model:
1. Navigate to the Configure Appliances page (Administration > Appliances).
2. Select the check boxes for the TMS models that you want to delete, and then click
Delete.
530
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring Appliance Settings for a TMS Model
Introduction
On the Add Appliance and Edit Appliance page, you can use the Appliance tab to add or edit
basic TMS model settings. See “Adding, Editing, and Deleting a TMS Model” on page 528.
Note: In the documentation, “TMS appliance” is used to refer to a physical appliance that is
sold by Arbor, while “TMS model” is used to refer to all TMS devices including TMS-ISAs,
TMS-CGSEs, TMS-VSMs, and TMS appliances.
Configuring appliance settings for a TMS model
To configure appliance settings for a TMS model:
1. Navigate to the Add Appliance page or the Edit Appliance page.
See “Adding and editing a TMS model” on page 528.
2. Click the Appliance tab and configure the appliance settings.
See “Appliance tab settings” below.
3. Click Save.
Appliance tab settings
Use the following table to configure the Appliance tab settings:
Appliance tab settings
Setting
Description
Name box
Type a QDPH for the TMS model.
Description box
Type a GHVFULSWLRQ of the TMS model.
Tags box
Type any WDJV that you want to apply to the TMS model. After you
type a tag, press COMMA, TAB, or ENTER to set the tag and to
continue.
Tags can help you categorize and search for appliances in your
deployment. For example, if you are staging new appliances, you
might tag them with “staged.”
IP Address box
Type the ,3 DGGUHVV of the TMS model.
Appliance list
Select the TMS model.
Proprietary and Confidential Information of Arbor Networks Inc.
531
SP and TMS User Guide, Version 8.0
Appliance tab settings (Continued)
Setting
Description
License Key boxes
Type the PRGHO QXPEHU and OLFHQVH NH\ for the appliance.
You must type the full license key, including the model number (for
example, TMS-3100).
You can obtain the license key from Arbor Technical Assistance
Center.
Note: This setting does not apply to TMS-CGSEs, TMS-ISAs, or
TMS-VSMs.
Manager list
Select the manager appliance of the TMS model that you are
adding.
Important: To enable TMS DNS Baseline alerting, the TMS
appliance must be managed by the leader.
Note: This setting does not apply to TMS-CGSEs or TMS-ISAs.
For TMS-CGSEs or TMS-ISAs, you select the manager appliance
in the TMS-CGSE Cluster or TMS-ISA Cluster settings. See
“Configuring TMS-CGSE Clusters” on page 561 and “Configuring
TMS-ISA Clusters” on page 563.
532
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring SNMP Settings for a TMS Appliance or TMS-VSM
Introduction
You can use the SNMP tab to add or edit the SNMP settings when you configure a TMS
appliance or a TMS-VSM. SNMP settings are optional. The SNMP agent runs only when SP
services run. When you stop services or if you do not install the package, SNMP is not
available.
Note: These settings do not apply to TMS-CGSEs or TMS-ISAs.
See “Adding, Editing, and Deleting a TMS Model” on page 528.
About SNMP community strings
If you use SNMP version 1 or 2c, then you must set a community string so that you can access
SNMP data on the TMS appliance or TMS-VSM. The community string can contain up to 32
characters and can include any characters except the following:
n quotation mark (“)
n
apostrophe (‘)
n
backslash (\)
n
pipe (|)
n
tab
Configuring SNMP settings for a TMS appliance or TMS-VSM
To configure SNMP settings for a TMS appliance or TMS-VSM:
1. Navigate to the Add Appliance page or the Edit Appliance page.
See “Adding and editing a TMS model” on page 528.
2. Click the SNMP tab, and configure the SNMP settings.
See “SNMP settings for a TMS appliance or TMS-VSM” below.
3. Click Save.
SNMP settings for a TMS appliance or TMS-VSM
Use the following table to configure the SNMP settings for a TMS appliance or TMS-VSM:
TMS appliance/TMS-VSM SNMP settings
Setting
Description
SNMP Version (v1/v2c
and v3) check boxes
Select the SNMP version that you use.
SNMP System Contact
box
Type the HPDLO DGGUHVV of the administrator.
SNMP System Location
box
Type the ORFDWLRQ of the TMS appliance or TMS-VSM (for
example, Boston).
Proprietary and Confidential Information of Arbor Networks Inc.
533
SP and TMS User Guide, Version 8.0
TMS appliance/TMS-VSM SNMP settings (Continued)
534
Setting
Description
SNMP Community String
box
(Versions 1 and 2c only) Type the FRPPXQLW\ VWULQJ.
For community string requirements, see “About SNMP
community strings” on the previous page.
SNMP Security Level list
(Version 3 only) Select the security level for SNMP v3
connections.
SNMP Authentication
Protocol list
(Version 3 only) Select the encryption hash algorithm.
SNMP Authentication
Username box
(Version 3 only) Type the XVHU QDPH for SNMP
authentication.
SNMP Authentication
Password box
(Version 3 only) Type the SDVVZRUG for SNMP
authentication.
SNMP Privacy Key box
(Version 3 only) Type the private SNMP NH\.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring Deployment Settings for a TMS Appliance, TMS-ISA, or
TMS-VSM
Introduction
You can use the Deployment tab to add or edit deployment settings when you configure a
TMS appliance, TMS-ISA, or TMS-VSM. See “Adding, Editing, and Deleting a TMS Model” on
page 528.
Note: With TMS-ISA, the Port for Challenge Packets is the only available setting.
Note: The deployment settings do not apply to TMS-CGSEs.
About hardware bypass for inline deployments
When you enable hardware bypass, SP allows traffic to go through the appliance in case of a
power loss or other critical failure. You can only enable hardware bypass on the TMS 1200,
2500, 3050, and 3110 appliances. To do this, you must obtain a license key from Arbor
Technical Assistance Center. When you enable hardware bypass on a TMS 1200, the tms4
and tms5 ports are available on the patch panel.
About deployment capabilities
You can configure your TMS appliance to perform with one of the following capabilities:
TMS appliance deployment capabilities
Capability
Description
Enable Full
Reporting
Enables all mitigation and reporting capabilities on all interfaces on a TMS
appliance that is deployed in inline or diversion mode. For a TMS appliance
deployed in SPAN port mode, this enables all reporting capabilities on all
interfaces but does not enable mitigation.
Optimize for
Mitigation
Performance
Enables only mitigation on all interfaces on the TMS appliance or
TMS-VSM.
Advanced
Allows you to apply custom capabilities to a TMS appliance on the Patch
Panel tab. For a description of these settings, see “Interface settings for a
TMS appliance or a TMS-VSM” on page 546.
Note: With a TMS-VSM, the deployment capabilities are not configurable and the Optimize
for Mitigation Performance option is selected.
Configuring deployment settings for a TMS appliance, TMS-ISA, or TMS-VSM
To configure deployment settings for a TMS appliance, TMS-ISA, or TMS-VSM:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance,
TMS-ISA, or TMS-VSM.
See “Adding and editing a TMS model” on page 528.
2. Click the Deployment tab, and then configure the deployment settings.
Proprietary and Confidential Information of Arbor Networks Inc.
535
SP and TMS User Guide, Version 8.0
See “Deployment settings for a TMS appliance, TMS-ISA, or TMS-VSM” below.
3. Click Save.
Deployment settings for a TMS appliance, TMS-ISA, or TMS-VSM
Use the following table to configure deployment settings for a TMS appliance, TMS-ISA, or
TMS-VSM:
TMS appliance deployment settings
Setting
Description
Deployment Type
list
Select the mode in which the TMS appliance is deployed. See
“TMS Appliance Deployment Scenarios” on page 50.
Note: With a TMS-VSM, Diversion is selected in the
Deployment Type list and cannot be changed.
10 Gbps Ports list
(TMS 3050 or 3110 appliances only) If you are configuring a TMS
3050 or 3110 appliance, then select whether you plugged into the
10 Gbps ports on the front or on the back of the appliance.
Capabilities list
Select the capability that you want this TMS appliance to have.
See “About deployment capabilities” on the previous page.
Note: With a TMS-VSM, Optimize for Mitigation
Performance is selected in the Capabilities list and cannot be
changed.
Forwarding Mode
list
Select the mode that you want the TMS appliance to use to
forward data. This option is enabled only if you selected Diversion
from the Deployment Type list.
If you select Patch Panel, then you configure how packets are
forwarded on the Patch Panel tab. If you select Layer 3, then the
packet is forwarded using layer 3 forwarding. See “About layer 3
forwarding” on page 539.
Note: With a TMS-VSM, Patch Panel is selected in the
Forwarding Mode list and cannot be changed.
Port for Challenge
Packets option
Click Input Port or Output Port to select the port that the TMS
appliance, TMS-ISA, or TMS-VSM uses to send challenge packets
back to the sender. For more information about challenge packets,
see “About challenge packets” on page 538.
Note: In addition to challenge packets, the TMS appliance,
TMS-ISA, or TMS-VSM sends all other traffic that it generates out
the port you select.
For more information about the Port for Challenge Packets
setting, including when you might want to select Output Port, see
“About selecting the port for challenge packets” on page 538.
536
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
TMS appliance deployment settings (Continued)
Setting
Description
Failure Handling
check box
(Diversion deployment of TMS appliances and TMS-VSMs only)
Select if you want the TMS appliance or TMS-VSM to
independently end mitigations if it loses connectivity with the
leader.
When you peer from the TMS appliance or TMS-VSM, the route is
withdrawn when the mitigation ends on the TMS appliance or
TMS-VSM.
When peering from an SP appliance, the route is not withdrawn,
but the mitigation ends on the TMS appliance or TMS-VSM.
Although the traffic is still diverted to the TMS appliance or
TMS-VSM, the TMS passes the traffic without applying any
countermeasures as long as the following conditions are met:
n
n
n
The TMS appliance or TMS-VSM is up and operational.
The mitigation ports are up.
The GRE reinjection tunnel is up.
If these conditions are not met, the traffic is blackholed unless the
mitigation is ended by another setting. The fate sharing settings on
this tab and the setting on the Deployment tab for the TMS
Groups page (Administration > Mitigation > TMS Groups)
can be used to end the mitigation and prevent this blackholing.
See “Deployment settings for TMS groups” on page 570.
Note: If a TMS appliance or TMS-VSM ends a mitigation because
Failure Handling is selected, the Type column on a mitigation
listings page will still indicate that the mitigation is started and the
Duration column will still indicate that it is ongoing.
Interface check box
Select if you want SP to put mitigations out of service on this TMS
appliance or TMS-VSM if one of the patch panel interfaces used by
the mitigation loses link. This is known as “fate sharing.”
Nexthop check box
Select if you want SP to put mitigations out of service on this TMS
appliance or TMS-VSM if a nexthop used by the mitigation
becomes unreachable. This is known as “fate sharing.”
BGP Peer check box
Select if you want SP to put mitigations out of service on this TMS
appliance or TMS-VSM if the model detects that a BGP peer has
gone down. This is known as “fate sharing.”
GRE Tunnel check
box
Select if you want SP to put mitigations out of service on this TMS
appliance or TMS-VSM if the TMS detects that a GRE tunnel used
for reinjecting mitigated traffic goes down. This is known as “fate
sharing.”
If you configured multiple prefixes in a mitigation or mitigation
template and a GRE tunnel mapped to one of those prefixes goes
down, then SP stops the entire mitigation.
Proprietary and Confidential Information of Arbor Networks Inc.
537
SP and TMS User Guide, Version 8.0
TMS appliance deployment settings (Continued)
Setting
Description
Enable Hardware
Bypass check box
(TMS appliance inline deployments only) Select if you want to
enable hardware bypass functionality on a TMS 1200, 2500,
3050, or 3110 appliance.
See “About hardware bypass for inline deployments” on page 535.
Number of Blades
list
If you are configuring a TMS 4000, TMS 5000, or TMS HD1000
appliance, then select the number of blades in the chassis.
Important: If you enabled auto-mitigation and SP uses fate-sharing settings that put a
mitigation out of service, then an attack might go unmitigated until you manually restart the
TMS mitigation.
About challenge packets
Some TMS countermeasures use challenge packets to authenticate unknown hosts (for
example, the countermeasures TCP SYN Authentication and DNS Authentication). See
“Configuring the TCP SYN Authentication Countermeasure” on page 671 and “Configuring
the DNS Authentication Countermeasure” on page 648.
In general terms, here is how challenge packet authentication works in a TMS
countermeasure:
n When an unknown host sends a request such as an HTTP request or DNS query to a
TMS-protected host, the TMS sends challenge packets to the unknown host.
n
The unknown host must provide a valid response to the challenge packets before the TMS
will allow the unknown host to connect to the protected host.
For example, if the unknown host sends an HTTP request to the protected host, the TMS replies
with a challenge packet containing an HTTP redirect to a real HTTP server. The unknown host
must respond by opening a new connection to the real server. If it does not, the TMS will refuse
the HTTP request and blacklist the unknown host.
About selecting the port for challenge packets
By default, the TMS appliance or TMS-VSM sends challenge packets out the Input Port
(inbound interface). However, some TMS deployments require routing table changes to support
this default. If this is the case for your deployment, rather than changing the routing table, you
can select Output Port to send challenge packets to the sender through the outbound
interface.
For example: suppose you are configuring the Port for Challenge Packets setting on a
TMS-ISA blade. The blade is inside a router that uses VRF (Virtual Routing and Forwarding).
The default route for the (logical) inbound interface on the TMS-ISA blade points to the
TMS-ISA itself. To send challenge packets back to the sender, you can either change the
virtual routing table instance, or select Output Port as the Port for Challenge Packets in
the TMS-ISA configuration.
Important: If you are configuring a cluster of TMS-ISA blades, you must set Port for
Challenge Packets separately for each blade. Each blade in the cluster must have the same
setting; either all Input Port or all Output Port.
538
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
The Port for Challenge Packets setting is available in Patch Panel forwarding mode, but
not in Layer 3 forwarding mode. In Layer 3 mode, the TMS appliance sends challenge packets
based on the configured routing information. See “About layer 3 forwarding” below.
Note: If you select Output Port in Patch Panel mode, and then switch to Layer 3 mode and
click Save, the port setting reverts to Input Port if you switch back to Patch Panel mode.
However, if you do not click Save in Layer 3 mode, Output Port remains set if you switch
back to Patch Panel mode.
About layer 3 forwarding
When you select Layer 3 as the forwarding mode on the Deployment tab, one of the
following methods is used to forward packets:
n Direct forwarding
This method forwards packets directly to the destination address when this address is in the
same subnet as the TMS appliance.
n
Standard forwarding
This method forwards packets to a nexthop using a static route that is configured on the
IPv4 Forwarding or the IPv6 Forwarding tab. It uses the static route that has the longest
matching prefix. If none of the static routes on the IP Forwarding tab match, then it
forwards the packet to the default nexthop that is also configured on the IP Forwarding
tab.
See “Configuring IP Forwarding Settings for a TMS Appliance” on page 549.
n
GRE forwarding
This method uses the GRE tunnels that are configured on the GRE tabs to forward packets.
The GRE tunnel that has the longest matching prefix is used.
See “Configuring GRE Settings for a TMS Appliance or TMS-VSM ” on page 554.
Note: If you select Output Port in Patch Panel forwarding mode, and then switch to Layer 3
forwarding mode and click Save, the port setting reverts to Input Port if you switch back to
Patch Panel mode. However, if you do not click Save in Layer 3 mode, Output Port remains
set if you switch back to Patch Panel mode. For more information, see Port for Challenge
Packets in “Deployment settings for a TMS appliance, TMS-ISA, or TMS-VSM” on page 536.
Proprietary and Confidential Information of Arbor Networks Inc.
539
SP and TMS User Guide, Version 8.0
Configuring ArborFlow Settings for a TMS Appliance
Introduction
You can use the ArborFlow tab when you add or edit a TMS appliance to configure the flow
that the TMS appliance sends to its managing appliance.
Note: These settings do not apply to TMS-CGSEs, TMS-ISAs, or TMS-VSMs.
See “Adding, Editing, and Deleting a TMS Model” on page 528.
About ArborFlow and TMS appliances
TMS appliances can export ArborFlow to a manager appliance. TMS ArborFlow does the
following:
n allows you to match managed objects
n
provides topology information
n
classifies applications with DPI intelligence
n
classifies traffic according to VLANs
n
provides payload data (for example, URLs, DNS, FQDN)
n
integrates with SP’s report and alert capabilities
n
allows you to classify and match traffic on a TMS appliance using BGP routing data
Configuring TMS appliance ArborFlow settings
To configure TMS appliance ArborFlow settings:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance.
See “Adding and editing a TMS model” on page 528.
2. Click the ArborFlow tab, and then configure the ArborFlow settings.
See “TMS appliance ArborFlow settings” below.
3. Click Save.
TMS appliance ArborFlow settings
Use the following table to configure TMS ArborFlow settings:
TMS appliance ArborFlow settings
540
Setting
Description
Export Port box
Type the 8'3 SRUW on which you want ArborFlow to be sent.
Sampling Rate box
Type the UDWH at which you want SP to sample flows.
If you leave this box blank, then SP uses the default setting, which
is 10 for TMS 1200, 2301, 2302, and 2500 appliances
(sampling 1 in 10 packets) and 1000 for all other TMS
appliances (sampling 1 in 1000 packets).
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
TMS appliance ArborFlow settings (Continued)
Setting
Description
Source of BGP table
for flow
classification list
(Optional) Select the BGP router that you want to assign to the
TMS appliance for flow matching.
This feature functions only when the TMS appliance is managed
by an appliance that has the traffic and routing role.
Ignore ArborFlow for
DoS Detection check
box
Select to prohibit the TMS appliance from generating alerts.
If this box is not selected, then the TMS appliance serves as an
input for DDoS detection and can generate alerts.
Proprietary and Confidential Information of Arbor Networks Inc.
541
SP and TMS User Guide, Version 8.0
Configuring Patch Panel Settings for a TMS Appliance or TMS-VSM
Introduction
You can use the Patch Panel tab to add or edit diversion settings and to configure the TMS
interfaces. If you peer from the SP appliance that manages the router, you can configure the
diversion method to use either BGP or flow specification. If you peer from the TMS appliance
or TMS-VSM, you can only use BGP diversion.
See “Adding, Editing, and Deleting a TMS Model” on page 528.
Note: These settings do not apply to TMS-CGSEs or TMS-ISAs. With a TMS-CGSE or a
TMS-ISA, you configure the diversion settings for the TMS cluster.
See “Configuring Diversion Settings for a TMS Cluster” on page 565.
Configuring TMS appliance or TMS-VSM patch panel settings
To configure TMS appliance or TMS-VSM patch panel settings:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance or
TMS-VSM.
See “Adding, Editing, and Deleting a TMS Model” on page 528.
2. Click the Patch Panel tab, and then configure the diversion settings.
See “Diversion settings for a TMS appliance or TMS-VSM” on the facing page.
3. Do one of the following to configure the TMS interfaces:
l
l
For TMS appliances, in the Interfaces section, configure the TMS interfaces.
For TMS-VSMs, in the VSM Backplane Channel Group section, configure the TMS
interfaces.
See “Interface settings for a TMS appliance or a TMS-VSM” on page 546.
4. Click Save.
542
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Diversion settings for a TMS appliance or TMS-VSM
Use the following table to configure the diversion settings for a TMS appliance or a TMS-VSM:
TMS appliance diversion settings
Setting
Peer from System list
Description
Select one of the following options:
SP
Select this option if you want to peer from the SP appliance
that is configured to manage the router. When you select this
option, the Diversion Method options appear.
n TMS
Select this option if you want to peer from the TMS appliance
or TMS-VSM. When you peer from the TMS appliance or
TMS-VSM, the diversion method is BGP diversion.
n
Diversion Method
options (only when
peering from SP)
Click the method of diversion that you want to use. If you click
BGP, the default diversion nexthop lists appear. If you click
Flowspec, the Route Target box appears.
Default IPv4
Diversion Nexthop
and Default IPv6
Diversion Nexthop
lists (BGP diversion
only)
The TMS appliance or TMS-VSM advertises the default diversion
nexthop via BGP as the destination for traffic that will be
mitigated.
Select one of the following options for the default IPv4 and IPv6
diversion nexthop:
n None
Select this option if you do not want to specify a default
diversion nexthop.
n Other
Select this option if you want to enter the IP address for the
default diversion nexthop. After you select this option, type the
IP address in the box that appears.
n ,3 DGGUHVV
Select an IP address of an existing interface. The list contains
the IP addresses for the interfaces that are configured in the
Interfaces section (for TMS appliances) or the VSM
Backplane Channel Group section (for TMS-VSMs).
For information on how the IP address that you select can
change automatically, see “How the selected IP address for
the default diversion nexthop can change” on the next page.
You can override the default nexthops for BGP peering sessions
when you configure a TMS group. See “BGP diversion settings
for TMS groups” on page 568.
Proprietary and Confidential Information of Arbor Networks Inc.
543
SP and TMS User Guide, Version 8.0
TMS appliance diversion settings (Continued)
Setting
Description
Route Target box
(flow specification
diversion only)
Type the route target. This is the route target that the TMS
appliance or TMS-VSM uses in a mitigation to advertise routes to
its BGP peers. You can use a route target to divert traffic into a
VPN that is tied to a TMS infrastructure. For information about the
supported route target formats, see “Supported route target
formats” on the facing page.
You can override this route target and configure BGP
communities for the flow specification when you configure a TMS
group. See “Flow Specification Diversion settings for TMS
groups” on page 569.
When you configure a TMS mitigation, you can also configure
flow specification filters. See “Flow specification filter settings”
on page 627.
Edit Peering
Sessions button
Click Edit Peering Sessions, and then use the selection
wizard to select the primary and secondary peering sessions for
the TMS to use for diversion. See “Additional information about
the Edit Peering Sessions settings” on the facing page and
“Using Selection Wizards” on page 31.
The selection wizard only displays peering sessions that are
configured for the diversion method that is being used. You
configure the diversion methods of a peering session on the
Primary BGP tab when you add or edit a router. See
“Configuring Primary Router BGP Settings” on page 142.
How the selected IP address for the default diversion nexthop can change
After you select an existing IP address in the Default IPv4 Diversion Nexthop or the
Default IPv6 Diversion Nexthop list, the IP address that you selected can change if the
following actions occur:
n The IP address is changed or deleted in the Interfaces section (for TMS appliances) or in the
VSM Backplane Channel Group section (for TMS-VSMs).
n
A subinterface is added to the interface you selected.
n
(For TMS appliances only) A logical port is added to the interface you selected.
Note: You cannot add a logical port to a TMS-VSM.
These actions affect the IP address you selected for the default diversion nexthop as follows:
If the IP address changes, the IP address that you selected changes accordingly.
n
544
n
If the IP address is deleted, the IP address that you selected is replaced with None.
n
If a subinterface or logical port is added to the selected interface, the IP address that you
selected is replaced with Other followed by the IP address that you originally selected.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Supported route target formats
SP supports the following input string formats for route targets:
Supported formats for route targets
Format
Description
Example
<ASN>:<XX>
2 byte ASN:4 byte number
64496:100
<ASN>L:<XX>
4 byte ASNL:2 byte number
65536L:100
<w.x.y.z>:<XX>
4 byte IP :2 byte number
203.0.113.33:100
Important: These formats are the formats that are specified in RFC 5575. However, RFC
5575 is vague enough that there are current incompatibilities with how various vendors have
implemented this standard. Consequently, although SP supports entering the route target in all
three of these formats, only the 2 byte ASN:4 byte number has been verified to work at this
time.
Additional information about the Edit Peering Sessions settings
The Patch Panel tab allows you to specify which IPv4 and IPv6 peering sessions the TMS
appliance or TMS-VSM can use to announce diversions for each address family. These
settings do not specify the IP address family capabilities that are advertised with the peering
session. You can configure the IP address family capabilities for a peering session when you
configure routers.
For more information about configuring router settings, see “Configuring Primary Router BGP
Settings” on page 142 and “Configuring Secondary Router BGP Settings” on page 144.
Blocking BGP announcements to TMS appliances and TMS-VSMs
Because the TMS only peers for the purpose of route injection, Arbor recommends that you
configure your routers to block BGP announcements to the TMS appliances and TMS-VSMs.
Proprietary and Confidential Information of Arbor Networks Inc.
545
SP and TMS User Guide, Version 8.0
Interface settings for a TMS appliance or a TMS-VSM
Use the following table to configure TMS interface settings. For TMS appliances, configure
interface settings in the Interfaces section. For TMS-VSMs, configure interfaces in the VSM
Backplane Channel Group section.
TMS appliance/TMS-VSM interface settings
Setting
Description
IPv4 Address and
IPv6 Address
boxes
Type the ,3Y DGGUHVV and/or ,3Y DGGUHVV of the interface.
This setting is required for diversion deployments but optional for inline
deployments.
In layer 3 forwarding mode, these settings change to IPv4 Address /
Prefix length and IPv6 Address / Prefix length and they require
the SUHIL[ OHQJWK. For more information on layer 3 forwarding
mode, see “Configuring Deployment Settings for a TMS Appliance,
TMS-ISA, or TMS-VSM” on page 535.
IPv4 Nexthop and
IPv6 Nexthop
boxes
(Diversion deployments only) Type the ,3Y DGGUHVV and/or ,3Y
DGGUHVV of the nexthop for the traffic.
This setting does not appear if you selected Layer 3 for the forwarding
mode on the Deployment tab. See “Configuring Deployment
Settings for a TMS Appliance, TMS-ISA, or TMS-VSM” on page 535.
Output Port box
In the Output Port box, select the output port for the TMS interface
from the list of interfaces for the TMS appliance or TMS-VSM. The
TMS appliance or TMS-VSM forwards traffic from the TMS interface
through the output port you select.
The deployment type, inline or diversion, affects how traffic is
forwarded through the output port as follows:
n
n
In an inline deployment, traffic is forwarded through the output port
to the next upstream or downstream device.
In a diversion deployment, traffic is forwarded through the output
port to the nexthop for the TMS interface. See “IPv4 Nexthop and
IPv6 Nexthop boxes” above.
Important: In a diversion deployment, for each TMS interface
configured on the Patch Panel tab, the addresses for the output
port and the nexthop must have the same network prefix.
You can deploy TMS appliances inline, but not TMS-VSMs. If you
deploy certain TMS appliances inline, you can also enable hardware
bypass. If you enable hardware bypass, you must use specific port
mappings. See “Port mappings for TMS appliances for inline
TMS hardware bypass” on page 548.
The Output Port box does not appear if you selected Layer 3 for the
forwarding mode on the Deployment tab. See “Configuring
Deployment Settings for a TMS Appliance, TMS-ISA, or TMS-VSM”
on page 535.
If you select DNS NXDomain Listening (described below), the
Output Port box is disabled.
546
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
TMS appliance/TMS-VSM interface settings (Continued)
Setting
Description
DNS NXDomain
Listening options
(not shown for
TMS-VSMs)
Select Enabled or Disabled. The system default is Disabled.
If you configure a diversion deployment, select Enabled to allow the
appliance to use the DNS NXDomain Rate Limiting countermeasure.
When DNS NXDomain Listening is enabled, TMS uses this port to
listen to the DNS NXDomain responses. This a simple way to enable
DNS NXDomain response listening on a network SPAN port. See
“Configuring the DNS NXDomain Rate Limiting Countermeasure” on
page 690.
When you select Enabled, the interface you are configuring can no
longer be used to forward traffic and consequently it can no longer be
used to mitigate traffic. As a result, the Output Port box is disabled
and set to none, and the Mitigate check box is disabled.
Note: The Mitigate check box is one of the Capabilities check
boxes. The Capabilities check boxes appear only if you selected
Advanced from the Capabilities list on the Deployment tab.
Mitigate check
box (not shown for
TMS-VSMs)
If you selected Advanced from the Capabilities list on the
Deployment tab, then select this check box to configure the
appliance to apply intelligent traffic filtering rules to traffic flowing into
this interface.
This check box is disabled if DNS NXDomain Listening is set to
Enabled.
Note: For TMS-VSMs: The advanced capability Mitigate is enabled
and cannot be disabled. The advanced capabilities Flow, DNS,
HTTP, and VOIP are all disabled and cannot be enabled.
Flow check box
(not shown for
TMS-VSMs)
If you selected Advanced from the Capabilities list on the
Deployment tab, then select this check box to configure the
appliance to generate ArborFlow data from the incoming traffic on this
interface.
Important: Consult your Arbor Networks Support Engineer (SE)
before you select this check box. This feature requires additional
configuration.
DNS check box
(not shown for
TMS-VSMs)
If you selected Advanced from the Capabilities list on the
Deployment tab, then select this check box to configure the
appliance to gather DNS usage statistics by inspecting the packets
flowing through this interface.
Important: Consult your Arbor Networks Support Engineer (SE)
before you select this check box. This feature requires additional
configuration.
Proprietary and Confidential Information of Arbor Networks Inc.
547
SP and TMS User Guide, Version 8.0
TMS appliance/TMS-VSM interface settings (Continued)
Setting
Description
HTTP check box
(not shown for
TMS-VSMs)
If you selected Advanced from the Capabilities list on the
Deployment tab, then select this check box to configure the
appliance to gather HTTP usage statistics (for example, MIME types,
HTTP URLs) by inspecting the packets flowing through this interface.
VOIP check box
(not shown for
TMS-VSMs)
If you selected Advanced from the Capabilities list on the
Deployment tab, then select this check box to configure the
appliance to gather VoIP usage statistics (for example, top callers,
callees, and conversations) by inspecting the packets flowing through
this interface.
Port mappings for TMS appliances for inline TMS hardware bypass
You can enable hardware bypass on certain TMS appliances when they are deployed inline.
When you enable hardware bypass on a TMS appliance, you must use specific port mappings
so that SP can properly direct traffic. See “About hardware bypass for inline deployments” on
page 535.
Note: TMS 2800, TMS 4000, and TMS 5000 appliances do not support hardware bypass on
any of their interfaces. Also, inline deployment and hardware bypass are not available with
TMS-VSMs. You can use TMS-VSMs in diversion deployments only.
The following table displays the necessary port mappings for the TMS appliances that support
hardware bypass:
Port mappings for TMS appliances that support hardware bypass
Appliance
Ports to Map
TMS 3050 and 3110
n
n
n
n
n
TMS 2500
n
n
n
TMS 1200
n
n
tms0.0 <-> tms0.1
tms0.2 <-> tms0.3
tms0.4 <-> tms0.5
tms0.6 <-> tms0.7
tms0.8 <-> tms0.9
tms0 <-> tms1
tms2 <-> tms3
tms4 <-> tms5
tms2 <-> tms3
tms4 <-> tms5
Note: TMS 1200 does not support hardware bypass on port tms0
or port tms1.
548
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring IP Forwarding Settings for a TMS Appliance
Introduction
The IPv4 Forwarding and IPv6 Forwarding tabs allow you to configure multiple nexthops
for forwarding packets instead of the single nexthop that can be configured on the Patch
Panel tab. The TMS appliance can then use different nexthops for different destination
addresses.
The IPv4 Forwarding and IPv6 Forwarding tabs only appear for TMS appliances that are
deployed in diversion mode and that have the forwarding mode configured to Layer 3. You
configure the forwarding mode on the Deployment tab.
For more information about the forwarding mode, see “Deployment settings for a TMS
appliance, TMS-ISA, or TMS-VSM” on page 536.
The settings on the IPv4 Forwarding and IPv6 Forwarding tabs are used for layer 3
forwarding when a packet cannot be forwarded directly to its destination.
See “About layer 3 forwarding” on page 539.
Configuring TMS appliance IP forwarding settings
To configure TMS appliance IP forwarding settings:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance.
See “Adding and editing a TMS model” on page 528.
2. Click the IPv4 Forwarding or IPv6 Forwarding tab, and in the Default Nexthop box,
type the GHIDXOW ,3Y RU ,3Y DGGUHVV.
The default nexthop is used when a match does not exist between the forwarding address
of a packet and the prefixes that are listed on this tab.
Important: If you do not specify a default nexthop, problems might occur with some
mitigations.
3. Use the following settings to configure a static IP route to be used for forwarding the
traffic:
Setting
Description
IP Prefix box
Type the SUHIL[ for the static route.
Nexthop box
Type the ,3 DGGUHVV of the nexthop of the traffic.
4. To configure additional static routes, click Add and use the preceding table to configure
the settings.
You can configure up to 1,000 static routes.
5. To remove a static route, click Remove next to that route.
6. Click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
549
SP and TMS User Guide, Version 8.0
Configuring Subinterfaces for a TMS Appliance or TMS-VSM
Introduction
You can use the Subinterfaces tab to add or edit a subinterface for a TMS appliance that is
configured for a diversion deployment or for a TMS-VSM. See “Adding, Editing, and Deleting a
TMS Model” on page 528.
Note: A TMS-VSM can be configured for a diversion deployment only.
About subinterfaces
Subinterfaces are multiple virtual interfaces divided from a single parent interface. The parent
interface can be a physical or logical interface. For example, the parent interface can be an
Ethernet port on a TMS appliance or the logical port on a TMS-VSM.
You can add one or more subinterfaces to a parent interface. You must assign a VLAN ID to
each subinterface that you add. Within a given parent, all subinterface VLAN IDs must be
unique. See “Adding a subinterface to a TMS appliance or TMS-VSM” on the facing page.
Routers use subinterfaces to route traffic between VLANs. Each subinterface corresponds to
one VLAN on a switch. When you associate a VLAN ID with a TMS interface, it allows SP to
connect to the subinterface. A subinterface introduces the VLAN Tag on its layer 2 frame, but
operates exactly as any other physical interface at the IP layer (layer 3) and above.
How SP uses subinterfaces to map traffic to interfaces
Subinterfaces allow you to map diversion or reinjection layer 2 VLAN encapsulation traffic on
an interface. This allows you to logically separate traffic at layer 2, which provides:
n specific diversion targets for mitigation
n
clear mitigation paths to a TMS appliance or TMS-VSM
n
(For TMS appliances only) a method to separate traffic and provide loop-free reinjection
paths back to the destination at layer 2
Note: The TMS appliance supports GRE tunnels when using subinterfaces to reinject traffic
only with layer 3 forwarding. You configure layer 3 forwarding on the Deployment tab. See
“Configuring Deployment Settings for a TMS Appliance, TMS-ISA, or TMS-VSM” on
page 535.
Task overview
To apply subinterfaces, complete the following tasks:
Subinterface configuration task overview
550
Task
Description
Reference
1
Create the subinterface.
“Adding a subinterface to a TMS appliance or
TMS-VSM” on the facing page
2
Add layer 3 IP address
information.
“Configuring Patch Panel Settings for a TMS
Appliance or TMS-VSM” on page 542
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Subinterface configuration task overview (Continued)
Task
Description
Reference
3
Create a TMS group to
identify the TMS
subinterfaces to be included.
“Configuring TMS Groups” on page 567
4
Save and commit your
changes.
“Committing configuration changes” on page 402
Adding a subinterface to a TMS appliance or TMS-VSM
To add a subinterface to a TMS appliance that is configured for a diversion deployment or to a
TMS-VSM:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance or
TMS-VSM. See “Adding, Editing, and Deleting a TMS Model” on page 528.
2. Click the Subinterfaces tab, and then configure the following subinterface settings:
Setting
Description
Description box
Type a GHVFULSWLRQ RI WKH VXELQWHUIDFH that will help
you to identify it.
VLAN ID box
Type the ,' QXPEHU RI WKH 9/$1 to which the interface
connects.
MTU box
Type the largest ,3 SDFNHW VL]H (in bytes) that you want to
allow into the subinterface.
Parent list (not
shown for
TMS-VSMs)
(For TMS appliances only) Select the interface (physical or
logical) of the TMS appliance that you want to be the parent of
the subinterface.
Note: For TMS-VSMs, the parent interface is always the VSM
Backplane Channel Group interface logical0.
3. Click Add, click Save, and then commit your changes.
Deleting subinterfaces for a TMS appliance or a TMS-VSM
To delete subinterfaces for a TMS appliance or a TMS-VSM:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance or
TMS-VSM.
See “Adding, Editing, and Deleting a TMS Model” on page 528.
2. Click the Subinterfaces tab.
3. Select the check boxes for the subinterfaces that you want to delete.
4. Click Delete, click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
551
SP and TMS User Guide, Version 8.0
Configuring Port Settings for a TMS Appliance or TMS-VSM
Introduction
For TMS appliances, you can use the Ports tab on the Add Appliance page or the Edit
Appliance page to add logical ports and edit physical and logical port settings. For TMS-VSMs,
you can use the Ports tab to edit the settings for the VSM Backplane Channel Group
interface logical0. See “Adding, Editing, and Deleting a TMS Model” on page 528.
Note: These settings do not apply to TMS-CGSEs or TMS-ISAs.
About logical ports on TMS appliances
To load-balance traffic across multiple physical ports, you can combine multiple physical ports
into one logical port.
You can designate whether a logical port should operate in active or passive LACP (Link
Aggregation Control Protocol) mode.
n In active LACP mode, the TMS appliance sends control packets on physical interfaces and
expects to receive packets from an LACP partner device. If the TMS appliance does not
receive control packets, then SP puts the physical interface out of service.
n
In passive LACP mode, the TMS appliance only sends control packets if it first receives
them from an LACP partner device. SP will not put the physical interface out of service due
to the absence of received control packets, regardless of whether the TMS appliance
previously received them.
Note: For TMS-VSMs, the LACP mode for the logical port is automatically set to passive.
About the logical port on TMS-VSMs
On the Appliance tab, when you select a TMS-VSM in the Appliance list, the system
automatically performs the following logical port configuration actions:
n The logical port logical0 is added to the TMS-VSM.
n
All physical ports on the VSM blade are assigned to logical0.
n
The LACP mode for logical0 is set to passive.
On a TMS-VSM, you cannot delete logical0 and you cannot add logical ports. However, you
can add, edit, and delete subinterfaces for logical0. See “Configuring Subinterfaces for a TMS
Appliance or TMS-VSM” on page 550.
Configuring port settings for a TMS appliance or TMS-VSM
To configure port settings:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance or
TMS-VSM. See “Adding, Editing, and Deleting a TMS Model” on page 528.
2. Click the Ports tab.
3. Perform one of the following tasks to configure logical ports:
l
l
552
For a TMS appliance (diversion deployment only), for each logical port that you want to
add, in the Logical Ports section, click Add Logical Port, and then configure the
settings shown in the table.
For a TMS-VSM, in the VSM Backplane Channel Group section, configure the settings
shown in the table.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Setting
Description
Description box
Type a GHVFULSWLRQ RI WKH ORJLFDO SRUW that will help
you to identify it.
LACP Mode list (not
shown for
TMS-VSMs)
From the LACP Mode list, select the LACP mode for the
logical port. For information about the LACP mode, see “About
logical ports on TMS appliances” on the previous page.
Note: For TMS-VSMs, the LACP mode is automatically set to
passive. See “About the logical port on TMS-VSMs” on the
previous page.
MTU box
Type the largest ,3 SDFNHW VL]H (in bytes) that you want to
allow into the logical port.
4. For TMS appliances (only), in the Physical Ports section, configure the following settings
for each physical port:
Setting
Description
Description box
Type a GHVFULSWLRQ RI WKH SK\VLFDO SRUW that will
help you to identify it.
MTU box
Type the largest ,3 SDFNHW VL]H (in bytes) that you want to
allow into the physical port.
This setting is cleared and disabled if the physical port is a
parent of a subinterface or if the physical port is incorporated
into a logical port.
Logical Port list
(Diversion deployment only) For a physical port that you want to
incorporate into a logical port, select the logical port from the
Logical Port list. These logical ports are the interfaces that
were added in the Logical Ports section.
Note: For TMS-VSMs, the Physical Ports section shows the name of the physical ports
on the VSM blade that are bundled into TMS-VSM's logical port logical0.
5. Click Save, and then commit your changes.
Deleting logical ports for TMS appliance diversion deployments
Note: On a TMS-VSM, you cannot delete the logical port logical0.
To delete logical ports for TMS appliance diversion deployments:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance.
See “Adding, Editing, and Deleting a TMS Model” on page 528.
2. Click the Ports tab.
3. In the Logical Ports section, select the check boxes for the ports that you want to delete.
4. Click Delete, click Save, and then commit your changes.
Proprietary and Confidential Information of Arbor Networks Inc.
553
SP and TMS User Guide, Version 8.0
Configuring GRE Settings for a TMS Appliance or TMS-VSM
Introduction
When you configure a TMS appliance or TMS-VSM, you can use the IPv4 GRE and IPv6
GRE tabs to create GRE tunnels to reinject mitigation traffic from the TMS appliance or
TMS-VSM to the router. You can configure GRE settings only on TMS appliances that are
deployed in diversion mode. TMS-VSMs are always in diversion mode.
Note: These settings do not apply to TMS-CGSEs or TMS-ISAs.
See “Adding, Editing, and Deleting a TMS Model” on page 528.
GRE tunnel types
You can configure the following types of GRE tunnels:
static—the TMS appliance or TMS-VSM tunnels traffic without the option to fail over to a
secondary tunnel.
n
n
redundant—the TMS appliance or TMS-VSM uses keepalives on these tunnels and will fail
over to a secondary tunnel if the primary tunnel fails.
See “About using keepalives” below and “How redundant GRE tunneling works” below.
Monitoring GRE tunnels
You can monitor GRE tunnels on the GRE column in the TMS Statistics tab on the
Appliance Status page (System > Status > Appliance Status). You can also click
(expand) in the Alerts column to view the 5 most recent alerts. If there are recent alerts, the list
of alerts includes an Information column. The Information column displays information about
any failed GRE tunnels.
About using keepalives
Keepalives are used by default on redundant GRE tunnels, but they are optional on static GRE
tunnels. When you enable keepalives on a static GRE tunnel, SP creates a system alert when
that tunnel goes down. If you get an alert, you can quickly address the failed static GRE tunnel.
This is helpful because the TMS appliance or TMS-VSM drops all traffic on that failed static
tunnel, including legitimate traffic.
How redundant GRE tunneling works
The following process describes how redundant GRE tunneling works in SP:
1. The TMS appliance or TMS-VSM encapsulates a GRE keepalive packet inside a second
GRE packet. These packets are now known as the inner and outer GRE packets,
respectively.
2. The TMS appliance or TMS-VSM assigns to the outer GRE packet the source and
destination addresses of the SP-configured GRE tunnel source and destination
addresses, respectively.
3. The TMS appliance or TMS-VSM assigns the source address of the outer GRE packet to
the destination address of the inner GRE packet. Conversely, it also assigns the
destination address of the outer packet to the source address of the inner packet.
4. The TMS appliance or TMS-VSM sends the encapsulated GRE packet to the GRE
endpoint, which then unencapsulates the outer GRE header from the packet.
554
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
5. The unencapsulated GRE packet now has the inner GRE header and is sent back to the
TMS mitigation interface.
6. The TMS appliance or TMS-VSM receives the returned packet and declares the GRE
tunnel up.
Configuring GRE tunnel settings for a TMS appliance or TMS-VSM
To configure GRE tunnel settings for a TMS appliance or TMS-VSM:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance or
TMS-VSM.
See “Adding and editing a TMS model” on page 528.
2. Click the IPv4 GRE or IPv6 GRE tab, and then use the following table to configure the
GRE tunnel settings:
Setting
Description
Source IPv4
Address and Source
IPv6 Address boxes
Type the VRXUFH ,3 DGGUHVV for the GRE tunnel.
Interval between
Keepalives box
Type the QXPEHU RI VHFRQGV between keepalive messages
on the GRE tunnels. The default value is 3 seconds.
Maximum
Consecutive
Keepalives Missed
before GRE Tunnel
Down box
Type the QXPEHU RI FRQVHFXWLYH NHHSDOLYHV that the
TMS appliance or TMS-VSM must send without getting a
response before it marks the tunnel as down. The default
value is 6 consecutive keepalives missed.
Enable Keepalives
on Static GRE
Tunnels check box
(Optional) Select to allow keepalives on static tunnels.
The source address must be the IP address of a mitigation
interface and be reachable with protocol 47 from the GRE
tunnel endpoint device. The source address cannot be the IP
address of the management interface.
Important: If you are configuring redundant tunnels, do not
enable keepalives on your router.
Keepalives are enabled by default on redundant tunnels.
3. Click Add GRE Tunnel to add individual tunnels.
Proprietary and Confidential Information of Arbor Networks Inc.
555
SP and TMS User Guide, Version 8.0
4. Configure the settings for a static or redundant GRE tunnel as follows:
Setting
Description
Name box
Type the QDPH of the tunnel that you want to add.
Each GRE tunnel that you configure for a TMS appliance or
TMS-VSM must have a unique name.
MTU box
In the MTU box, type the largest ,3SDFNHW VL]H (in bytes) that
you want to allow into the GRE tunnel (excluding the GRE
header). The valid range for IP packet size is 28-1544.
If a packet exceeds the MTU setting, the TMS appliance or
TMS-VSM fragments the packet and encapsulates each fragment
in a separate GRE packet.
Destination
Prefix box
In the Destination Prefix box, type the SUHIL[ to associate with
the GRE tunnel.
This prefix maps mitigation traffic into a tunnel.
Note: For static and redundant IPv4 GRE tunnels only, you can
use either an IPv4 or an IPv6 destination prefix. For example, use
an IPv6 prefix with an IPv4 tunnel if you need to mitigate IPv6
traffic but the routers in your deployment only support IPv4 tunnels.
Primary
Destination IP
box
In the Primary Destination IP box, type the ,3 DGGUHVV of the
primary tunnel endpoint.
Secondary
Destination IP
box
(Redundant tunnel only) In the Secondary Destination IP box,
type the ,3 DGGUHVV of the secondary tunnel endpoint.
SP always uses the primary destination IP address, if it can
establish and maintain the GRE tunnel with that address, instead
of the secondary destination IP address.
5. Click Save.
Important: You must configure tunnels on your routers. You can do this either before or after
you configure GRE tunnels on the TMS appliance or TMS-VSM.
Deleting GRE tunnels on a TMS appliance or TMS-VSM
To delete a GRE tunnel on a TMS appliance or TMS-VSM:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS appliance or
TMS-VSM.
See “Adding and editing an SP appliance” on page 104.
2. Click the IPv4 GRE or IPv6 GRE tab.
3. Select the check boxes for the GRE tunnels that you want to delete.
4. Click Delete, and then click Save.
556
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring Blacklist Offloading Settings for a TMS-VSM
Introduction
When you configure a TMS-VSM, you can use the Blacklist Offloading tab to enable or
disable OpenFlow blacklist offloading and to edit settings for OpenFlow blacklist offloading.
See “Adding, Editing, and Deleting a TMS Model” on page 528 and “OpenFlow blacklist
offloading settings for a TMS-VSM” on the next page.
Note: On a TMS-VSM, OpenFlow blacklist offloading can affect IPv4 mitigations only.
For more information about blacklisting and blacklist offloading, see “About Blacklisting in TMS
Mitigation Countermeasures” on page 580 and “About Blacklist Offloading for TMS Models”
on page 584.
About OpenFlow blacklist offloading for a TMS-VSM
TMS-VSMs use OpenFlow software to perform blacklist offloading. Like blacklist offloading on
other TMS models, OpenFow blacklist offloading relieves the TMS of the need to mitigate
traffic from blacklisted hosts that are the highest volume offenders in ongoing mitigations. See
“About Blacklist Offloading for TMS Models” on page 584.
OpenFlow blacklist offloading (OpenFlow BLO) is only available for TMS-VSMs. In OpenFlow
BLO, the BLO device that does the blocking is a virtual OpenFlow network device. The
TMS-VSM software is implemented on a Cisco VSM (Virtual Services Module). The Cisco
VSM and the OpenFlow virtual network device are both in the chassis of a Cisco ASR 9000
series router.
You can view information about traffic blocked by OpenFlow blacklist offloading. See “About
viewing information for traffic blocked by blacklist offloading” on page 586.
Note: To learn more about OpenFlow, see the OpenFlow page on the Open Networking
Foundation Web site at https://www.opennetworking.org/sdn-resources/openflow. You can
download OpenFlow network device specifications from the Technical Library page on this
site. (From the OpenFlow page, select SDN Resources > Technical Library.)
About configuring OpenFlow blacklist offloading for a TMS-VSM
You can enable or disable OpenFlow BLO for a TMS-VSM. See “OpenFlow Blacklist
Offloading options” on the next page.
If you enable OpenFlow BLO, you can configure the following:
The blocking method used by the OpenFlow network device. See “About blocking methods
for blacklist offloading” on page 584 and “Block on options” on the next page.
n
n
The name of the OpenFlow network device that does the blocking. See “Name box” on
page 559.
n
The IPv4 Address of the interface used by the TMS-VSM to offload flow entries to the
OpenFlow network device. See “IPv4 Address box” on page 559.
n
The maximum number of entries to offload to the OpenFlow network device (the “flow
entries limit”). See “About the number of hosts that the TMS can offload” on page 586 and
"Flow Entries Limit (optional) box" on page 559.
To configure these settings, see “Configuring OpenFlow blacklist offloading settings for a
TMS-VSM” on the next page and “OpenFlow blacklist offloading settings for a TMS-VSM” on
the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
557
SP and TMS User Guide, Version 8.0
About the optional Flow Entries Limit setting
On the Blacklist Offloading tab, under OpenFlow Network Device, you can type a value for
the optional Flow Entries Limit setting or leave it blank (default). The flow entries limit is the
maximum number of flow entries that the TMS-VSM will attempt to offload. See “About the
number of hosts that the TMS can offload” on page 586.
If you leave the Flow Entries Limit box blank, or if you set it to 5000 or greater, the
TMS-VSM will attempt to offload at most 5000 flow entries. You might want to set the Flow
Entries Limit to a value less than 5000 if the TMS-VSM shares the OpenFlow network
device with other non-TMS deployments. This will help preserve capacity on the OpenFlow
network device for the other non-TMS deployments. See “Flow Entries Limit (optional) box” on
the facing page.
Configuring OpenFlow blacklist offloading settings for a TMS-VSM
To configure OpenFlow BLO settings for a TMS-VSM:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS-VSM.
See “Adding and editing a TMS model” on page 528.
2. Click the Blacklist Offloading tab, and then configure the OpenFlow BLO settings.
See “OpenFlow blacklist offloading settings for a TMS-VSM” below.
3. Click Save, and then commit your changes.
OpenFlow blacklist offloading settings for a TMS-VSM
Important: Configure the OpenFlow network device and interface IPv4 address in the
ASR9K router’s CLI before you attempt to configure OpenFlow BLO settings for a TMS-VSM.
For instructions, see the Arbor Networks TMS-VSM Configuration Guide.
Use the following table to configure OpenFlow BLO settings for a TMS-VSM:
OpenFlow blacklist offloading settings
558
Setting
Description
OpenFlow
Blacklist
Offloading options
Select Enabled to turn on OpenFlow BLO for the TMS-VSM you
are configuring. If you select Enabled, you must configure the
OpenFlow network device Name and IPv4 address before you
can save your settings. See “Name box” on the facing page and
"IPv4 Address box" on the facing page.
Select Disabled to turn off OpenFlow BLO for the TMS-VSM you
are configuring. Selecting Disabled also clears all flow entries that
were offloaded to the OpenFlow network device by the TMS-VSM.
Block on options
Select Source or Source+Mitigation (default). See “About
blocking methods for blacklist offloading” on page 584.
Changing the Block on option clears all flow entries that were
offloaded to the OpenFlow network device.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
OpenFlow blacklist offloading settings (Continued)
Setting
Description
Name box
Type a name for the OpenFlow network device. It must be unique in
your deployment. The OpenFlow network device name appears in
OpenFlow alert messages for the TMS-VSM on the alert listing
pages . See “About the Alert Listing Pages” on page 465.
Tip: For easier alert message interpretation, incorporate the name
of the ASR9K router in the OpenFlow network device name. For
example, ASR9K-OFSW1.
IPv4 Address box
Type the IPv4 address of the interface that the TMS-VSM uses to
offload flow entries to the OpenFlow network device.
The IPv4 Address you enter must match the IPv4 address
configured for the TenGigEX/n/1/5 interface on the ASR9K router.
See the Arbor Networks TMS-VSM Configuration Guide.
Flow Entries Limit
(optional) box
(Optional) Type the number of flow entries that the TMS-VSM will
attempt to offload to the OpenFlow network device. This limit must
be an integer value greater than 0. If you save settings with this box
blank or with a value greater than 5000, the limit is set to 5000
flow entries.
You might need to set this limit lower than 5000 if the OpenFlow
network device is shared by other non-TMS deployments. For more
information, see “About the optional Flow Entries Limit setting” on
the previous page.
Proprietary and Confidential Information of Arbor Networks Inc.
559
SP and TMS User Guide, Version 8.0
Configuring Advanced Settings for a TMS Model
Introduction
When you configure a TMS model, you can use the Advanced tab to perform one of the
following tasks:
n configure advanced asymmetric flow handling for SPAN port deployments of TMS models
n
adjust the maximum number of ongoing mitigations that you want to run on a TMS model
n
(TMS 5000 appliance only) configure the blocking method for blacklist offloading. See
“Hardware Blacklisting Block on options” below.
To configure and delete a TMS model on the Configure Appliances page (Administration >
Appliances), see “Adding, Editing, and Deleting a TMS Model” on page 528.
About adjusting the maximum number of ongoing mitigations
You can adjust the maximum number of ongoing mitigations that you want to run on a TMS
model. This setting affects the amount of state tracked in each mitigation. The fewer the
ongoing mitigations on a TMS model, the greater the amount of state tracked per mitigation.
Configuring advanced settings for a TMS model
To configure advanced settings for a TMS model:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS model.
See “Adding and editing a TMS model” on page 528.
2. Click the Advanced tab, and then use the following table to configure the Advanced
settings:
Setting
Description
Ignore Input
VLAN/MPLS Tags
check box
(SPAN port deployments only) Select if you want the TMS
model to ignore input VLAN/MPLS tags.
Merge Flows
Across Input Ports
check box
(SPAN port deployments only) Select if you want the TMS
model to merge flows across input ports.
Maximum Ongoing
Mitigations box
Type the maximum QXPEHU of ongoing mitigations that you
want to occur on a TMS model.
Hardware Blacklisting
Block on options
Select Source or Source+Mitigation (default). See
“Configuring the blocking method for blacklist offloading on
TMS 5000 appliances” on page 585.
(TMS 5000 appliance
only)
Changing the Block on option clears the blacklist offloading
device of all information that it used to block blacklisted hosts.
3. Click Save.
560
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring TMS-CGSE Clusters
Introduction
On the TMS-CGSE Clusters page (Administration > Mitigation > TMS-CGSE
Clusters), you can create a cluster that contains one or more TMS-CGSEs. Every
TMS-CGSE must belong to a cluster. SP treats a TMS-CGSE cluster as a single TMS
appliance, with a capacity equal to the total capacity of all TMS-CGSEs that are assigned to
the cluster.
When you create or edit a TMS-CGSE cluster, you can also configure the diversion settings
for the TMS-CGSE cluster. You can configure BGP or flow specification diversion settings for
a TMS-CGSE cluster.
For information about TMS-CGSE deployment scenarios, see “TMS-CGSE Deployment
Scenarios” on page 55.
Requirements for adding TMS-CGSEs to a cluster
The following are the requirements for adding TMS-CGSEs to a cluster:
All TMS-CGSEs that you want to add to a cluster must exist on the same router chassis.
n
n
A TMS-CGSE that you want to add to a cluster cannot already belong to an existing cluster.
If you want to add a TMS-CGSE to a new cluster when it already belongs to an existing
cluster, then you must first delete the TMS-CGSE from the existing cluster.
n
A maximum of 12 TMS-CGSEs can be in a single cluster.
Adding and editing a TMS-CGSE cluster
To add or edit a TMS-CGSE cluster:
1. Navigate to the TMS-CGSE Clusters page (Administration > Mitigation >
TMS-CGSE Clusters).
2. Choose one of the following steps:
l
To add a TMS-CGSE cluster, click Add TMS-CGSE Cluster.
l
To edit a TMS-CGSE cluster, click its name link.
3. On the Add TMS-CGSE Cluster page or the Edit TMS-CGSE Cluster page, click the
Description tab, and then configure the following settings:
Setting
Description
Name box
Type the QDPH that you want to assign to a TMS-CGSE cluster.
Description box
Type a GHVFULSWLRQ that can help to easily identify the
TMS-CGSE cluster in a list.
Availability
Requirement box
Type the SHUFHQWDJH of TMS-CGSEs in the cluster that must
be up in order for the cluster to be operational and able to
mitigate. This feature works only in conjunction with the TMS
Group mitigation precondition that requires all group members
to be up before starting a mitigation.
Proprietary and Confidential Information of Arbor Networks Inc.
561
SP and TMS User Guide, Version 8.0
Setting
Description
Select
TMS-CGSEs button
Click to select and add TMS-CGSEs to a cluster.
Manager list
Select the manager appliance of the TMS-CGSE cluster that
you are adding.
See “Searching for TMS-CGSEs to add to a TMS-CGSE
cluster” below.
SP applies the manager setting to all TMS-CGSEs in the
TMS-CGSE cluster.
Important: To enable TMSDNS Baseline alerting, the
TMS-CGSE cluster must be managed by the leader.
Router Chassis list
(Optional) Select the router on which the TMS-CGSEs in this
TMS-CGSE cluster are installed. (The available options show
only the routers on the same manager.)
Important: The router and TMS-CGSE cluster must both be
managed by the same SP appliance that has the traffic and
routing analysis role.
4. Click the Diversion tab, and configure the diversion settings.
See “Configuring Diversion Settings for a TMS Cluster” on page 565.
5. Click Save.
Searching for TMS-CGSEs to add to a TMS-CGSE cluster
When you click the Select TMS-CGSEs button on the Description tab of the Add
TMS-CGSE Cluster page or the Edit TMS-CGSE Cluster page, the Select one or more
TMS-CGSEs window appears. You can use the Search box in this window to find and select
TMS-CGSEs that you want to add to a TMS-CGSE cluster. You can search for TMS-CGSEs
by name, tag, or description.
Deleting TMS-CGSE clusters
To delete a TMS-CGSE cluster:
1. Navigate to the TMS-CGSE Clusters page (Administration > Mitigation >
TMS-CGSE Clusters).
2. Select the TMS-CGSE clusters that you want to delete, click Delete and then commit
your changes.
562
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring TMS-ISA Clusters
Introduction
On the TMS-ISA Clusters page (Administration > Mitigation > TMS-ISA Clusters), you
can create a cluster that contains one or more TMS-ISAs. Every TMS-ISA must belong to one
cluster. SP treats a TMS-ISA cluster as a single TMS appliance, with a capacity equal to the
total capacity of all TMS-ISAs that are assigned to the cluster.
When you create or edit a TMS-ISA cluster, you can also configure the diversion settings for
the TMS-ISA cluster. You can configure BGP or flow specification diversion settings for a
TMS-ISA cluster
For information about TMS-ISA deployment scenarios, see “TMS-ISA Deployment Scenarios”
on page 57.
Requirements for adding TMS-ISAs to a cluster
The following are the requirements for adding TMS-ISAs to a cluster:
All TMS-ISAs that you want to add to a cluster must exist on the same router chassis.
n
n
A TMS-ISA that you want to add to a cluster cannot already belong to an existing cluster. If
you want to add a TMS-ISA to a new cluster when it already belongs to an existing cluster,
then you must first delete the TMS-ISA from the existing cluster.
Adding and editing a TMS-ISA cluster
To add or edit a TMS-ISA cluster:
1. Navigate to the TMS-ISA Clusters page (Administration > Mitigation > TMS-ISA
Clusters).
2. Choose one of the following steps:
l
To add a TMS-ISA cluster, click Add TMS-ISA Cluster.
l
To edit a TMS-ISA cluster, click its name link.
3. On the Add TMS-ISA Cluster page or the Edit TMS-ISA Cluster page, click the
Description tab, and then configure the following settings:
Setting
Description
Name box
Type the QDPH that you want to assign to a TMS-ISA cluster.
Description box
Type a GHVFULSWLRQ that can help to easily identify the
TMS-ISA cluster in a list.
Availability
Requirement box
Type the SHUFHQWDJH of TMS-ISAs in the cluster that must be
up in order for the cluster to be operational and able to mitigate.
This feature works only in conjunction with the TMS Group
mitigation precondition that requires all group members to be up
before starting a mitigation.
Select TMS-ISAs
button
Click to select and add TMS-ISAs to a cluster.
See “Searching for TMS-ISAs to add to a TMS-ISA cluster” on
the next page.
Proprietary and Confidential Information of Arbor Networks Inc.
563
SP and TMS User Guide, Version 8.0
Setting
Description
Manager list
Select the manager appliance of the TMS-ISA cluster that you
are adding.
SP applies the manager setting to all TMS-ISAs in the
TMS-ISA cluster.
Important: To enable TMSDNS Baseline alerting, the
TMS-ISA cluster must be managed by the leader.
Router Chassis list
(Optional) Select the router on which the TMS-ISAs in this
TMS-ISA cluster are installed. (The available options show only
the routers on the same manager.)
Important: The router and TMS-ISA cluster must both be
managed by the same SP appliance that has the traffic and
routing analysis role.
4. Click the Diversion tab, and configure the diversion settings.
See “Configuring Diversion Settings for a TMS Cluster” on the facing page.
5. Click Save.
Searching for TMS-ISAs to add to a TMS-ISA cluster
When you click the Select TMS-ISAs button on the Description tab of the Add TMS-ISA
Cluster page or the Edit TMS-ISA Cluster page, the Select one or more TMS-ISAs window
appears. You can use the Search box in this window to find and select TMS-ISAs that you
want to add to a TMS-ISA cluster. You can search for TMS-ISAs by name, tag, or description.
Deleting TMS-ISA clusters
To delete a TMS-ISA cluster:
1. Navigate to the TMS-ISA Clusters page (Administration > Mitigation > TMS-ISA
Clusters).
2. Select the TMS-ISA clusters that you want to delete, and then click Delete.
564
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring Diversion Settings for a TMS Cluster
Introduction
You can use the Diversion tab to add or edit diversion settings when you configure a TMS
cluster. The TMS cluster can consist of TMS-CGSEs or TMS-ISAs.
For information about a TMS cluster deployment that uses BGP diversion, see “Deployment
scenario: BGP diversion ” on page 55. For information about a TMS cluster deployment that
uses flow specification diversion, see “Deployment scenario: flow specification diversion” on
page 57.
Configuring diversion settings for a TMS cluster
To configure diversion settings for a TMS cluster:
1. Do one of the following:
l
l
With a TMS-CGSE Cluster, navigate to the Add TMS-CGSE Cluster page or the Edit
TMS-CGSE Cluster page. See “Configuring TMS-CGSE Clusters” on page 561.
With a TMS-ISA Cluster, navigate to the Add TMS-ISA Cluster page or the Edit
TMS-ISA Cluster page. See “Configuring TMS-ISA Clusters” on page 563.
2. Click the Diversion tab, and then configure the diversion settings.
See “Diversion settings for a TMS cluster” below.
3. Click Save.
Diversion settings for a TMS cluster
Use the following table to configure the diversion settings for a TMS cluster:
TMS cluster diversion settings
Setting
Description
Diversion Method
options
Click the method of diversion that you want to use. If you click
BGP, the default diversion nexthop boxes appear. If you click
Flowspec, the Route Target box appears.
Note: Flowspec can only be used with routers that support
flow specification.
Default IPv4 Diversion
Nexthop and Default
IPv6 Diversion Nexthop
lists (BGP diversion only)
Type the IPv4 and IPv6 addresses to use as the default
diversion nexthops. These are the default nexthops that the
TMS Cluster uses in a mitigation to advertise routes to its BGP
peers.
The nexthop could be a VIP (Virtual IP) address that you
configured for the TMS cluster. This VIP address could use
BGP multipath internally to load balance across the TMS
cluster.
You can override the default nexthops for BGP peering
sessions when you configure a TMS group.
See “BGP diversion settings for TMS groups” on page 568.
Proprietary and Confidential Information of Arbor Networks Inc.
565
SP and TMS User Guide, Version 8.0
TMS cluster diversion settings (Continued)
Setting
Description
Route Target box (flow
specification diversion
only)
Type the route target. This is the route target that the TMS
cluster uses in a mitigation to advertise routes to its BGP
peers. You can use a route target to divert traffic into a VPN
that is tied to a TMS infrastructure.
You can override this route target and configure BGP
communities for the flow specification when you configure a
TMS group.
See “Flow Specification Diversion settings for TMS groups” on
page 569.
When you configure a TMS mitigation, you can also configure
flow specification filters.
See “Flow specification filter settings” on page 627.
Edit Peering Sessions
button
Click Edit Peering Sessions, and then use the selection
wizard to select the primary and secondary peering sessions
for the TMS cluster to use for diversion.
See “Additional information about the Edit Peering Sessions
settings” below and “Using Selection Wizards” on page 31 for
more information.
The selection wizard only displays peering sessions that are
configured for the diversion method that is being used. You
configure the diversion methods of a peering session on the
Primary BGP tab when you add or edit a router.
See “Configuring Primary Router BGP Settings” on page 142.
Additional information about the Edit Peering Sessions settings
The Diversion tab allows you to specify which IPv4 and IPv6 peering sessions that the TMS
cluster can use to announce diversions for each address family. These settings do not specify
the IP address family capabilities that are advertised with the peering session. You can
configure the IP address family capabilities for a peering session when you configure routers.
See “Configuring Primary Router BGP Settings” on page 142 and “Configuring Secondary
Router BGP Settings” on page 144 for more information about configuring router settings.
566
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Configuring TMS Groups
Introduction
You can use TMS groups to help mitigate anomalous traffic. After you configure TMS groups
with specific mitigation settings, you can associate the groups with mitigations. You can
configure a TMS group on the TMS Groups page (Administration > Mitigation > TMS
Groups).
A TMS group can include one or more TMS appliances or TMS-VSMs, or one or more TMS
clusters.
Example: You might need to divert traffic to a group of TMS appliances in another location,
such as London. You can create a TMS group that includes TMS appliances located in London
and then configure SP to divert traffic to the appliances in that group.
Adding and editing TMS groups
To add or edit a TMS group:
1. Navigate to the TMS Groups page (Administration > Mitigation > TMS Groups).
2. Choose one of the following steps:
l
To add a group, click Add TMS Group.
l
To edit a group, click its name link.
3. Enter or edit the configuration settings on the following TMS group tabs, click Save, and
then commit your changes:
TMS Group Tab
Description
Description
Allows you to configure basic settings that identify the TMS group.
See “Description settings for TMS groups” on the next page.
Diversion
Allows you to redirect traffic to the TMS appliances, TMS-VSMs,
or TMS clusters and to configure BGP communities. You can use
BGP or flow specification to divert traffic. See “BGP diversion
settings for TMS groups” on the next page and “Flow Specification
Diversion settings for TMS groups” on page 569.
Deployment
Allows you to specify group-specific failure handling options. See
“Deployment settings for TMS groups” on page 570.
TMS
Appliances
Allows you to specify the TMS appliances or TMS-VSMs to use to
mitigate specific traffic. See “Adding TMS Appliances or TMSVSMs to a TMS group” on page 571.
TMS Clusters
Allows you to specify the TMS clusters to use to mitigate traffic. A
TMS cluster is one or more TMS-ISAs or TMS-CGSEs. See
“Adding TMS Clusters to a TMS group” on page 571.
Proprietary and Confidential Information of Arbor Networks Inc.
567
SP and TMS User Guide, Version 8.0
TMS Group Tab
Description
Mitigation
Preconditions
Allows you to specify the preconditions that must exist before a
mitigation is started.
See “Mitigation Preconditions settings for TMS groups” on
page 571.
Active DNS
Authentication
Allows you to redirect DNS queries with a specific destination
address to a secondary DNS server for authentication. See “Active
DNS Authentication (secondary server) settings for TMS groups”
on page 572.
Description settings for TMS groups
Use the following table to configure the basic information for a TMS group on the Description
tab:
TMS group Description tab settings
Setting
Description
Name box
Type the QDPH of the group.
Description box
Type a brief GHVFULSWLRQ of the group.
Type list
Select whether the TMS group includes TMS appliances or TMS
clusters. To include TMS-VSMs in a TMS group select Appliance.
A TMS cluster is one or more TMS-ISAs or TMS-CGSEs.
BGP diversion settings for TMS groups
If you use BGP to divert traffic, you can use the Diversion tab to override the default IPv4 and
IPv6 nexthops of the TMS appliances, TMS-VSMs, or TMS clusters in the group. The nexthops
redirect the traffic to TMS appliances, TMS-VSMs, or TMS clusters using BGP. You can also
use the Diversion tab to configure BGP communities to group and filter diversion prefixes for
BGP diversion. The BGP diversion settings are optional. See “Adding and editing TMS groups”
on the previous page.
If you use flow specification to divert traffic, see “Flow Specification Diversion settings for TMS
groups” on the facing page.
568
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Use the following table to configure the BGP Diversion settings for TMS groups:
BGP diversion settings for TMS groups
Setting
Description
Override
Appliance Default
<IP family>
Nexthop boxes
or
Override Cluster
Default <IP
family> Nexthop
boxes
Type the ,3 DGGUHVV for the nexthop in the IPv4 or IPv6 nexthop
boxes. This is the BGP diversion nexthop of a TMS interface in the
TMS group.
If you specify a nexthop, it overrides the default nexthops of the TMS
appliances, TMS-VSMs, or TMS clusters that are in the TMS group.
If you leave the nexthop boxes blank, the default nexthops of the TMS
appliances, TMS-VSMs, or TMS clusters that are in the TMS group
are used.
For more information about configuring the default nexthops, see
“Diversion settings for a TMS appliance or TMS-VSM” on page 543
and “Configuring Diversion Settings for a TMS Cluster” on
page 565.
The nexthop could be a VIP (Virtual IP) address that you configured
for the TMS appliances, TMS-VSMs, or TMS cluster. This VIP
address could use BGP multipath internally to load balance across
the TMS appliances, TMS-VSMs, or TMS cluster.
Community box
Choose one of the following steps:
n
n
Type the QXPEHU of the community group.
Click Select Community Group to select a group from the
Community Groups window and populate the box.
See “Configuring BGP Community Groups” on page 750.
See “Identifiers for BGP Communities” on page 995.
Local AS check box
Select if the community is local and you are running confederations.
No advertise
check box
Select if the community is not advertised to its peers.
No export check
box
Select if the community is not advertised outside of a confederation
boundary.
No peer check box
Select if the community is not advertised past the neighboring AS.
Flow Specification Diversion settings for TMS groups
If you use flow specification to divert traffic, you can use the Diversion tab to override the
route targets of the TMS appliances, TMS-VSMs, or TMS clusters in the group. The route
targets redirect traffic to the TMS appliances, TMS-VSMs, or TMS clusters using flow
specification. You can also use the Diversion tab to configure BGP communities to group and
filter route targets for flow specification diversion. The flow specification diversion settings are
optional. See “Adding and editing TMS groups” on page 567.
If you use BGP to divert traffic, see “BGP diversion settings for TMS groups” on the previous
page.
Proprietary and Confidential Information of Arbor Networks Inc.
569
SP and TMS User Guide, Version 8.0
Use the following table to configure the flow specification diversion settings for TMS groups:
Flow specification diversion settings for TMS groups
Setting
Description
Override Appliance
Route Target box
or
Override Cluster
Route Target box
Type the ,3Y URXWH WDUJHW. You can use a route target to
divert traffic into a VPN that is tied to a TMS infrastructure.
If you configure a route target, it overrides the route targets of the
TMS appliances, TMS-VSMs, or TMS clusters that are in the TMS
group. If you leave the route target box blank, the route targets of
the TMS appliances, TMS-VSMs, or TMS clusters that are in the
TMS group are used.
For more information about configuring the route target, see
“Diversion settings for a TMS appliance or TMS-VSM” on
page 543 and “Configuring Diversion Settings for a TMS Cluster”
on page 565.
Community box
Choose one of the following steps:
n
n
Type the QXPEHU of the community group.
Click Select Community Group to select a group from the
Community Groups window and populate the box.
See “Identifiers for BGP Communities” on page 995.
Local AS check box
Select if the community is local and you are running
confederations.
No advertise check
box
Select if the community is not advertised to its peers.
No export check box
Select if the community is not advertised outside of a confederation
boundary.
No peer check box
Select if the community is not advertised past the neighboring AS.
Deployment settings for TMS groups
You can use the Deployment tab to configure group-specific failure handling options for TMS
groups. See “Adding and editing TMS groups” on page 567.
When you select the check box on the Deployment tab, mitigations for the group are stopped
in the following situations:
n when one or more TMS appliances, TMS-VSMs, or TMS clusters are put out of service,
become unreachable, or fail
n
the group’s leader appliance becomes unreachable
Example: If a large amount of mitigated traffic traverses multiple TMS appliances and one of
the TMS appliances fails, then the other appliances might become overloaded. You can enable
this feature if you decide that it is best to stop the mitigation and avoid passing the diverted
traffic through overloaded TMS appliances.
570
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 19: Configuring TMS Models
Adding TMS Appliances or TMS-VSMs to a TMS group
You can use the TMS Appliances tab to select the TMS appliances or TMS-VSMs to add to
a TMS group.
To add TMS appliances or TMS-VSMs to a TMS group:
1. Navigate to the TMS Appliances tab.
See “Adding and editing TMS groups” on page 567.
2. Click Select TMS Appliances.
3. (Optional) To search for TMS appliances or TMS-VSMs, in the Select TMS Ports window,
follow these steps:
a. In the Search list at the top of the window, select the option to search by.
b. In the Search box, type the QDPH, GHVFULSWLRQ, PRGHO QXPEHU (for example, 1200
or 2500), or JURXS QDPH of the appliance that you are searching for.
c. If the appliance that you are searching for is deployed inline, then select the Inline
check box.
d. If the appliance that you are searching for supports 10 Gbps traffic, then select the
10G check box.
e. Click Search.
4. To view an appliance’s associated ports and subinterfaces, click
TMS appliance.
(expand) next to the
5. To select a TMS appliance group, choose one of the following steps:
l
To include all of the ports in the group, select the check box next to the TMS appliance
or TMS-VSM, and then click OK.
l
Select the check boxes of the individual input (diversion) ports to include, and then click
OK.
Adding TMS Clusters to a TMS group
The TMS Clusters tab allows you to select the TMS clusters that you want to use to mitigate
traffic.
To add TMS clusters to a TMS group:
1. Navigate to the TMS Clusters tab.
See “Adding and editing TMS groups” on page 567.
2. Click Select TMS Cluster.
3. Select the TMS clusters that you want to add to the group, and then click OK.
Tip: You can search for TMS clusters by name, tag, or description in the Search box.
Mitigation Preconditions settings for TMS groups
The Mitigation Preconditions tab allows you to set conditions that must be met by TMS
appliances, TMS-VSMs, or TMS clusters in a TMS group before a mitigation is allowed to start.
The mitigation preconditions are enabled by default. See “Adding and editing TMS groups” on
page 567.
TMS mitigations consume some of the resources of a TMS model. These resources are limited
by the number of GRE tunnels, mitigations, etc., configured on a TMS appliance, TMS-VSM, or
TMS cluster. Therefore, starting a mitigation on a TMS appliance, TMS-VSM, or TMS cluster
that does not have sufficient resources can cause the current mitigation to fail or cause
Proprietary and Confidential Information of Arbor Networks Inc.
571
SP and TMS User Guide, Version 8.0
previous mitigations on the TMS appliance, TMS-VSM, or TMS cluster to fail. To prevent a
failure, you can add mitigation preconditions for TMS groups.
Use the following table to configure the mitigation precondition settings for TMS groups:
Mitigation Preconditions settings for TMS groups
Setting
Description
Require all group
members to be up
before starting a
mitigation check box
Select to ensure that sufficient resources are available
before a mitigation starts.
Require all diversion
peering sessions to be
up before starting a
mitigation check box
(TMS appliance or TMS-VSM groups only) Select to ensure
that the TMS appliances or TMS-VSMs are part of a peering
session. If a TMS appliance or TMS-VSM is not part of a
peering session (for example, if it is rebooting), a mitigation
might not begin successfully.
Require all group
members to have
available bandwidth
before starting a
mitigation check box
Select to ensure that all TMS appliances, TMS-VSMs, or
TMS clusters in a group use less than 90% of the allowed
traffic rate in order for a mitigation to start. You can view the
bandwidth limit on the Appliance Status page.
Active DNS Authentication (secondary server) settings for TMS groups
The Active DNS Authentication tab allows you to redirect DNS queries with a specific
destination address to a secondary DNS server for authentication. If you want to enable the
DNS Authentication countermeasure in active UDP mode, then configure secondary servers.
See “Adding and editing TMS groups” on page 567 and “Configuring the DNS Authentication
Countermeasure” on page 648.
To configure active DNS authentication settings for a TMS group, in the Secondary Servers
box, type the SUHIL[HV for the DNS query traffic that a TMS appliance, TMS-VSM, or TMS
cluster in this group should intercept, followed by the ,3 DGGUHVVHV of the secondary DNS
servers to receive that traffic.
Tip: You can type the IP address of a different authoritative DNS server or the IP address of an
alias for the same DNS server.
Deleting TMS groups
To delete a TMS group:
1. Navigate to the TMS Groups page (Administration > Mitigation > TMS Groups).
2. Select the check boxes for the groups that you want to delete.
3. Click Delete, and then commit your changes.
572
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20:
Introduction to TMS Mitigations
Introduction
This section describes general information about using TMS to protect your network against
attacks.
For general information about mitigating attacks without using TMS appliances, see Chapter
24: “Other Ways to Mitigate Attacks” on page 725.
User access
Administrators and non-administrative users have access to the mitigation views.
In this section
This section contains the following topics:
About TMS Mitigations
574
About TMS Mitigation Countermeasures
575
About Blacklisting in TMS Mitigation Countermeasures
580
About Blacklist Offloading for TMS Models
584
About TMS Mitigation Templates
587
About the TMS Mitigation Status Page
589
Starting and Stopping TMS Mitigations
596
Configuring Global TMS Mitigation Settings
597
About Auto-Mitigation
600
Mitigating Customer Attacks in the Cloud
604
About Sample Packets
608
Using the Long-Term Statistics Page
611
Editing and Monitoring TMS VLANs
612
SP and TMS User Guide, Version 8.0
573
SP and TMS User Guide, Version 8.0
About TMS Mitigations
Introduction
You can create a mitigation to filter malicious traffic and permit expected traffic through
intelligent filtering devices. Because SP provides a robust filtering language and real-time
traffic reports, you can precisely define filters and observe their effect. SP uses the system’s
reporting capabilities to monitor the removal of unwanted traffic. This ability, combined with the
DoS detection functionality of SP, protects your network from attacks.
For a description of all the ways that you can mitigate attacks with SP, see “Mitigating Attacks
Using SP” on page 726.
You can create mitigation templates that allow you to set common configurations for multiple
mitigations. See “About TMS Mitigation Templates” on page 587.
About the TMS Mitigations page
The TMS Mitigations page (Mitigation > Threat Management) allows you to do the
following:
n Configure and delete TMS mitigations.
See “Configuring and Deleting TMS Mitigations” on page 618.
n
Search for TMS mitigations.
See “Searching for Mitigations” on page 728.
n
View information about TMS mitigations.
The TMS Mitigations page displays the same information as the All Mitigations page, but
also includes mitigations that have not started.
See “About the All Mitigations Page” on page 727.
Note: Traffic graphs of hardware mitigations might show some traffic (approximately
100-200 bps) even if diversion routes or filters are not active. This is the result of various
broadcast packets (ARP, STP, etc.) from the routers and the TMS appliance and is not an
issue.
For information about navigating through multiple pages of TMS mitigations, see “Navigating
multiple pages” on page 30.
n
Start or stop TMS mitigations.
See “Starting and Stopping TMS Mitigations” on page 596.
n
Download or email a TMS mitigation report by clicking an icon on the Arbor Smart Bar.
See “About the Arbor Smart Bar ” on page 28.
For more information see the following:
“About the All Mitigations Page” on page 727
n
n
574
“About the TMS Mitigation Status Page” on page 589
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
About TMS Mitigation Countermeasures
Introduction
Countermeasures are defense mechanisms that you can use to target and remove attack
traffic so that your network can continue to operate. Different countermeasures are designed
to stop different types of attack traffic.
Types of countermeasures
TMS uses the following types of countermeasures:
Countermeasure types
Type
Description
Per-packet
This type of countermeasure is applied to every packet that matches the
prefix associated with a mitigation. Per-packet countermeasures are
processed before event-driven countermeasures.
See “Configuring Per-Packet Countermeasures” on page 643.
Event-driven
This type of countermeasure is divided into the following groups:
n
n
Application-specific stream-based — TMS identifies the traffic
stream with an application ID before it applies the countermeasure.
Time-based — Timers detect specific events. For example, the TCP
Connection Reset countermeasure drops traffic when a connection
remains idle for too long.
See “Configuring Event-Driven Countermeasures” on page 681.
Countermeasure processing order
The TMS forwards each packet received on a TMS mitigation interface to one or more ongoing
mitigations. Each mitigation processes the packets it receives against all of the
countermeasures that are enabled (set ON) in that mitigation.
The countermeasures process packets in the order shown in the table below. However, if a
packet was sent from a host that is currently on the TMS blacklist, the TMS blocks the packet.
Packets that are blocked by blacklisting are not processed by countermeasures in any
mitigation. See “About Blacklisting in TMS Mitigation Countermeasures” on page 580.
Note: If the TMS model supports blacklist offloading, packets from hosts that are sending the
highest volumes of attack traffic can be blocked by a network device before they consume
TMS mitigation resources. See “About Blacklist Offloading for TMS Models” on page 584.
Proprietary and Confidential Information of Arbor Networks Inc.
575
SP and TMS User Guide, Version 8.0
Countermeasure processing order for IPv4 and IPv6
Step
Countermeasure
IPv4
IPv6
1
Invalid Packets
This non-configurable countermeasure drops invalid packets. The
criteria used to validate packets are listed under this countermeasure
on the TMS Mitigation Status page.
ݲ
ݲ
2
IPv4/IPv6 Address Filter Lists
See “Configuring the IP Address Filter Lists Countermeasure” on
page 651.
ݲ
ݲ
3
IPv4/IPv6 Black/White Lists
a. Inline Filters
b. IPv4/IPv6 Black/White Filter Lists
c. Blacklist Fingerprints
ݲ
ݲ
See “Configuring the Black/White Lists Countermeasure” on
page 644.
576
4
Packet Header Filtering
See “Configuring the Packet Header Filtering Countermeasure” on
page 653.
ݲ
5
IP Location Filter Lists
See “Configuring the IP Location Filter Lists Countermeasure” on
page 656.
ݲ
6
Zombie Detection
See “Configuring the Zombie Detection Countermeasure ” on
page 676.
ݲ
7
Per Connection Flood Protection
See “Configuring the Per Connection Flood Protection
Countermeasure ” on page 664.
ݲ
8
TCP SYN Authentication (includes HTTP Authentication)
See “Configuring the TCP SYN Authentication Countermeasure” on
page 671.
ݲ
ݲ
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
Countermeasure processing order for IPv4 and IPv6 (Continued)
Step
Countermeasure
IPv4
9
DNS Scoping
DNS Scoping is not a countermeasure. Rather, it is a group of
advanced settings that you can apply to the following
countermeasures:
ݲ
n
n
n
n
IPv6
DNS Authentication
DNS Rate Limiting
DNS NXDomain Rate Limiting
DNS Regular Expression.
DNS Scoping limits the DNS traffic that these DNS countermeasures
will process. It does so by matching the domains queried in DNS
requests against a set of DNS regular expressions.
Note: DNS Scoping does not apply to the DNS Malformed
countermeasure.
See “Configuring Advanced Settings for TMS Mitigations and
Templates” on page 632 and “DNS Regular Expressions” on
page 965.
10
DNS Authentication (except in active mode with DNS Scoping)
See “Configuring the DNS Authentication Countermeasure” on
page 648.
ݲ
11
Payload Regular Expression
See “Configuring the Payload Regular Expression Countermeasure”
on page 661.
ݲ
12
Protocol Baselines
See “Configuring the Protocol Baselines Countermeasure” on
page 667.
ݲ
13
Shaping
See “Configuring the Shaping Countermeasure” on page 669.
ݲ
14
IP Location Policing
See “Configuring the IP Location Policing Countermeasure ” on
page 658.
ݲ
15
TCP Connection Reset (traffic detection only, also happens later)
See “Configuring the TCP Connection Reset Countermeasure” on
page 721.
ݲ
16
TCP Connection Limiting
See “Configuring the TCP Connection Limiting Countermeasure” on
page 717.
ݲ
17
DNS Malformed (missing payload check only)
See “Configuring the DNS Malformed Countermeasure” on
page 688.
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
ݲ
ݲ
577
SP and TMS User Guide, Version 8.0
Countermeasure processing order for IPv4 and IPv6 (Continued)
Step
Countermeasure
IPv4
18
DNS Rate Limiting
See “Configuring the DNS Rate Limiting Countermeasure” on
page 692.
ݲ
19
DNS Regular Expression
See “Configuring the DNS Regular Expression Countermeasure” on
page 696.
ݲ
20
DNS NXDomain Rate Limiting
See “Configuring the DNS NXDomain Rate Limiting
Countermeasure” on page 690.
ݲ
21
HTTP Malformed
See “Configuring the HTTP Malformed Countermeasure” on
page 703.
ݲ
22
HTTP Scoping
HTTP Scoping is not a countermeasure. Rather, it is a group of
advanced settings that you can apply to the following
countermeasures:
ݲ
n
n
IPv6
HTTP Rate Limiting
AIF and HTTP/URL Regular Expression
HTTP Scoping limits the HTTP traffic that these HTTP
countermeasures will process. It does so by matching URL domains in
HTTP requests against a set of HTTP URL regular expressions.
Note: HTTP Scoping does not apply to the HTTP Malformed
countermeasure.
See “Configuring Advanced Settings for TMS Mitigations and
Templates” on page 632 and “HTTP Header Regular Expressions” on
page 962.
See “Configuring Advanced Settings for TMS Mitigations and
Templates” on page 632.
578
23
HTTP Rate Limiting
See “Configuring the HTTP Rate Limiting Countermeasure” on
page 706.
ݲ
24
AIF and HTTP/URL Regular Expression
See “Configuring the AIF and HTTP/URL Regular Expression
Countermeasure” on page 682.
ݲ
25
SIP Malformed (missing payload check only)
See “Configuring the SIP Malformed Countermeasure” on page 709.
ݲ
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
Countermeasure processing order for IPv4 and IPv6 (Continued)
Step
Countermeasure
IPv4
26
SIP Request Limiting
See “Configuring the SIP Request Limiting Countermeasure” on
page 711.
ݲ
27
SSL Negotiation
See “Configuring the SSL Negotiation Countermeasure” on
page 713.
ݲ
IPv6
About configuring countermeasure settings
You can configure the countermeasure settings in the following ways:
When you configure mitigations or mitigation templates
n
See “Configuring and Deleting TMS Mitigations” on page 618 and “Configuring and
Deleting TMS Mitigation Templates” on page 614.
n
When you view a mitigation on the TMS Mitigation Status page
When you configure countermeasure settings on the TMS Mitigation Status page, you can
see the results in real time. This allows you to refine the mitigations to make them more
effective. See “About the TMS Mitigation Status Page” on page 589.
Proprietary and Confidential Information of Arbor Networks Inc.
579
SP and TMS User Guide, Version 8.0
About Blacklisting in TMS Mitigation Countermeasures
Introduction
When mitigations include blacklisting countermeasures, hosts that offend those
countermeasures during active mitigations are temporarily blocked. While a host is blocked,
the TMS drops traffic from the host instead of applying countermeasures to that traffic. See
“About TMS Mitigation Countermeasures” on page 575.
Blacklisting in TMS countermeasures limits the amount of TMS mitigation resources consumed
by known offenders. This allows the TMS to more effectively mitigate traffic from new
offenders.
Note: If the TMS model supports blacklist offloading, the TMS can offload the task of blocking
the top blacklisted hosts to a separate device. This further improves mitigation performance
against new threats. See “About blacklisting with blacklist offloading” on page 582.
How blacklisting works in an ongoing mitigation
When an ongoing mitigation contains blacklisting countermeasures, the TMS continuously
performs the following steps for that mitigation:
1. Monitors the mitigation for violations of the blacklisting countermeasures that it contains.
Note: The TMS only monitors blacklisting countermeasures that have blacklisting
enabled. For some countermeasures, blacklisting is always enabled. For others,
blacklisting is optional. See “Countermeasures that can blacklist hosts” on the facing page
and “Enabling optional blacklisting for a countermeasure” on the facing page.
2. When an offense occurs, the TMS does the following:
l
Adds the offending host’s source IP address to the blacklist.
l
Blocks traffic sent from the offending host to any diversion prefix in the mitigation.
Note: Diversion prefixes specify the destinations that a mitigation protects. See
“Configuring Protect Settings for TMS Mitigations and Templates” on page 626.
Note: If the TMS model supports blacklist offloading, traffic from the top offending
hosts can be blocked for any destination or (on some models) just for the diversion
prefixes in the mitigation. See “About blacklisting with blacklist offloading” on
page 582.
3. While a host is blocked, the TMS periodically checks to see if that host is still sending
traffic that is offending blacklisting countermeasures in the mitigation.
l
If so, the host remains blocked.
l
If not, the TMS waits to see if the host will offend again.
4. If the host does not offend again, the TMS unblocks the host and removes it from the
blacklist for the mitigation.
580
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
Countermeasures that can blacklist hosts
The following table shows which IPv4 and IPv6 countermeasures can blacklist offending hosts.
For each countermeasure, it also shows if blacklisting is always on or optionally enabled.
Blacklisting
Always on
Optional
Countermeasure
IPv4
IPv6
IPv4/IPv6 Address Filter Lists
ݲ
ݲ
ݲ
IPv4/IPv6 Black/White Lists
ݲ
ݲ
ݲ
Zombie Detection
ݲ
ݲ
TCP Connection Limiting
ݲ
ݲ
TCP Connection Reset
ݲ
ݲ
Payload Regular Expression
ݲ
DNS Rate Limiting
ݲ
DNS NXDomain Rate Limiting
ݲ
DNS Regular Expression
ݲ
HTTP Malformed
ݲ
ݲ
HTTP Rate Limiting
ݲ
ݲ
AIF and HTTP/URL Regular Expression
ݲ
SSL Negotiation
ݲ
ݲ
SIP Malformed
ݲ
ݲ
SIP Request Limiting
ݲ
ݲ
ݲ
ݲ
ݲ
ݲ
ݲ
ݲ
ݲ
Enabling optional blacklisting for a countermeasure
To enable optional blacklisting for a countermeasure in a TMS mitigation or mitigation
template:
1. Do one of the following:
l
Navigate to the Countermeasures tab of the mitigation or the mitigation template.
See “Adding and editing a TMS mitigation” on page 618 and “Adding and editing a
TMS mitigation template” on page 614.
l
Navigate to the TMS Mitigation Status page. See “Navigating to the TMS Mitigation
Status page” on page 589.
On the Countermeasures panel, click
its settings.
(expand) beside the countermeasure to show
Note: You can edit only the countermeasure settings that are not locked. You must
also be in an account group that is assigned the capability to edit mitigations.
Proprietary and Confidential Information of Arbor Networks Inc.
581
SP and TMS User Guide, Version 8.0
2. To enable blacklisting for the selected countermeasure, select one of the following
options, depending on the countermeasure:
l
l
l
l
Select the Blacklist Sources check box.
For Action to Apply to Offending Host or Action to Apply, select the Blacklist
option or the Blacklist Hosts option.
(TCP Connection Reset only) For Consecutive Idles Before Blacklisting Host,
enter a number of consecutive idles.
(AIF and HTTP/URL Regular Expression only) Select the Blacklist on Blocked check
box.
3. Click Save. If you made changes to a mitigation template, then commit your changes.
About information and statistics for blocked hosts
The TMS logs the following information and statistics about each host that is blocked by
blacklisting countermeasures in a mitigation:
n Host source IP address and location (country)
n
Number of bytes and packets from the host that were blocked:
l
by each countermeasure
l
by all countermeasures in the mitigation
This information is logged for all blocked hosts. It is also logged separately for the top 20 hosts
that sent the most blocked bytes/packets. You can download text files containing this blocked
host information and use it to refine other countermeasure settings in the mitigation. See
“Downloading blocked hosts for a mitigation or a blacklisting countermeasure” below.
Note: Blocked host information and statistics are available on all TMS models except
TMS-VSMs.
Downloading blocked hosts for a mitigation or a blacklisting countermeasure
To download the text file for blocked hosts or top blocked hosts for all blacklisting
countermeasures in a mitigation, see “Downloading blocked hosts on the Summary pane” on
page 592.
To download the text file for blocked hosts or top blocked hosts for a single blacklisting
countermeasure in a mitigation:
1. Navigate to the TMS Mitigation Status page. See “Navigating to the TMS Mitigation
Status page” on page 589.
2. On the Countermeasures tab, click
countermeasure.
(expand) to show the settings for the blacklisting
3. In the settings for the countermeasure, near the bottom, click Download Blocked Hosts
or Download Top Blocked Hosts.
4. Click Save.
About blacklisting with blacklist offloading
On TMS models that support blacklist offloading, traffic from the top offending hosts can be
blocked by a separate network device before mitigation processing. Blacklisting with blacklist
offloading relieves the TMS of the need to mitigate high volumes of attack traffic from top
offenders. Blacklist offloading improves mitigation performance against attacks from new
offenders more than blacklisting alone.
582
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
Blacklist offloading is always on for some TMS models. For others, it is optional. In addition, on
some TMS models that support blacklist offloading, you can configure the blacklist offloading
device and the blocking method that the device employs. See “About blacklist offloading on
different TMS models” on the next page.
Note: For TMS-VMSs, blacklist offloading is available for IPv4 mitigations only.
Proprietary and Confidential Information of Arbor Networks Inc.
583
SP and TMS User Guide, Version 8.0
About Blacklist Offloading for TMS Models
Introduction
Blacklisting with blacklist offloading provides better mitigation performance than blacklisting
alone. It relieves the TMS of the need to mitigate traffic from the blacklisted hosts that are the
highest volume offenders in ongoing mitigations. See “About Blacklisting in TMS Mitigation
Countermeasures” on page 580.
About blacklist offloading
Blacklist offloading blocks hosts that are sending the highest volumes of traffic that offends
blacklisting countermeasures in ongoing mitigations. See “Countermeasures that can blacklist
hosts” on page 581.
With blacklist offloading, the attack traffic from high-volume senders is blocked preemptively,
before it consumes mitigation resources. A TMS model with blacklist offloading (BLO) uses a
network device, such as a switch, to do the preemptive blocking. The TMS continually offloads
to the BLO device an updated list of hosts to block . Hosts that are currently sending the
highest volume of attack traffic across all mitigations are offloaded and blocked with the
highest priority.
Note: You can download information and statistics about hosts that are currently being
blocked by blacklisting countermeasures in a mitigation. When blacklist offloading is available
and enabled, some of these blacklisted hosts might be blocked by the BLO device if they were
recently sending high volumes of attack traffic. See “Downloading blocked hosts for a
mitigation or a blacklisting countermeasure” on page 582.
About blacklist offloading on different TMS models
The following TMS models support blacklist offloading:
TMS 4000 appliances
n
n
TMS 5000 appliances
n
TMS-VSMs
The implementation and configuration of blacklist offloading is slightly different on each model.
For example, on TMS 4000s and 5000s, the BLO device is a hardware switch in the TMS
chassis. On TMS-VSMs, the BLO device is a virtual OpenFlow network device in a router. See
“About blacklist offloading configuration options for TMS models” on the facing page.
About hardware blacklisting and blacklist offloading
Blacklist offloading is the updated version of hardware blacklisting. Both functions use a
separate device to block blacklisted hosts. However, with blacklist offlloading, the blocking
device can be physical or virtual, depending on the TMS model. You can also configure
settings for blacklist offloading on newer TMS models.
About blocking methods for blacklist offloading
The blocking methods for blacklist offloading are match conditions that a BLO device can use
to block traffic from blacklisted hosts. TMS models that support blacklist offloading use one of
the following blocking methods:
n Source — blocks packets sent from offloaded hosts to any destination. With source
blocking, the BLO device blocks a packet when the packet’s source IP address matches the
584
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
IP address for a blacklisted host that was offloaded to the BLO device. The packet’s
destination address is ignored when matching.
Note: Blocking on Source will block traffic from offloaded hosts to all destinations. This
might not be desirable if traffic to some destinations in your deployment must not be
blocked. Or, for example, if you want a host blacklisted and blocked when it offends one
mitigation but not others.
n
Source+Mitigation — blocks packets sent from offloaded hosts to diversion prefixes only.
With source+mitigation blocking, the BLO device blocks a packet when the packet meets
both of the following conditions:
l
l
The packet’s source address matches the IP address for a blacklisted host that was
offloaded to the BLO device.
The packet’s destination address matches a diversion prefix in the mitigation that the
offloaded host offended.
On some TMS models that support blacklist offloading, you can use the Block on option to
select the Source or Source+Mitigation blocking method. See “About blacklist offloading
configuration options for TMS models” below.
Note: You can use the global TMS mitigation setting, IP Address Filter Pass Lists
Override Hardware Blacklisting to prevent specific hosts from being blocked by blacklist
offloading. See “About preventing hosts from being blocked by blacklist offloading” on
page 597.
About blacklist offloading configuration options for TMS models
The following table summarizes the blacklist offloading configuration options for TMS models
that support blacklist offloading.
Blacklist offloading configuration options for TMS models
Block on options
Always
on
Optional
Source
Source+
(default) Mitigation
Model
IPv4 IPv6
TMS 4000
ݲ
ݲ
ݲ
ݲ
TMS 5000
ݲ
ݲ
ݲ
ݲ
ݲ
TMS-VSM
ݲ
ݲ
ݲ
ݲ
Configure
BLO device
ݲ
For more information about configuring TMS models for blacklist offloading, see “Configuring
the blocking method for blacklist offloading on TMS 5000 appliances” below and “Configuring
Blacklist Offloading Settings for a TMS-VSM” on page 557.
Configuring the blocking method for blacklist offloading on TMS 5000 appliances
To configure the blocking method to use for blacklist offloading on a TMS 5000:
1. Navigate to the Add Appliance page or the Edit Appliance page for the TMS 5000
appliance. See “Adding and editing a TMS model” on page 528.
2. Click the Advanced tab.
3. Under Hardware blacklisting, select a Block on option: Source (default) or
Source+Mitigation. See “About blocking methods for blacklist offloading” on the
Proprietary and Confidential Information of Arbor Networks Inc.
585
SP and TMS User Guide, Version 8.0
previous page.
Changing the Block on option clears all flow entries that were offloaded to the BLO
device.
4. Click Save, and then commit your changes.
About the number of hosts that the TMS can offload
Each host that the TMS offloads to the BLO device consumes one entry in the device. The
maximum number of entries that the TMS can offload to the device (the “entries limit”) depends
on the TMS model.
With source blocking, the number of hosts that the TMS can offload is equal to the entries limit.
Each entry blocks packets from a different host, regardless of the destinations for those
packets.
However, with source+mitigation blocking, the number of hosts blocked can be less than the
entries limit. This occurs when blacklisting mitigations contain multiple diversion prefixes. In this
case, the TMS offloads the same host in multiple entries with a different diversion prefix in each
entry.
Example: offloading multiple entries
If two hosts are blacklisted high-volume attackers in the same mitigation, and if that mitigation
has three diversion prefixes, the TMS will offload six entries for that mitigation; three entries for
one host and three for the other. The three entries for each host will each have one of the three
diversion prefixes.
See “About blocking methods for blacklist offloading” on page 584.
Note: On a TMS-VSM, the OpenFlow device configuration for blacklist offloading includes a
flow entries limit setting. You can use this setting to adjust the maximum number of entries
that the TMS-VSM offloads. See “OpenFlow blacklist offloading settings for a TMS-VSM” on
page 558.
About viewing information for traffic blocked by blacklist offloading
The Blocked Hosts statistics and traffic graphs on the TMS Mitigation Status page include
traffic that is blocked by blacklist offloading and by blacklisting alone.
For example, on the TMS Mitigation Status page, the traffic graphs show troughs and peaks
when the BLO device is blocking packets. The troughs occur when the BLO device starts
blocking traffic from high-volume blacklisted hosts. The peaks occur after the BLO device
stops blocking traffic from these hosts and the traffic from the hosts is once again forwarded to
the TMS for mitigation. See “About the TMS Mitigation Status Page” on page 589.
In addition, if a DoS alert exists for an active TMS mitigation, you can use the traffic volume
differences shown on the DoS alert details page to view the effects of blacklist offloading.
For example, on the DoS Alert details page, compare the traffic volume at the network
boundary upstream with the volume at a managed object boundary downstream. When the
BLO device is actively blocking malicious traffic, the volume at the managed object boundary
will be less than the volume at the network boundary.
Note: To access the DoS Alert details page, from the DoS Alerts page (Alerts > DoS) click
the DoS alert link. See “Introduction to DoS Alerts” on page 492.
586
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
About TMS Mitigation Templates
Introduction
Mitigation templates allow you to set common configurations for multiple mitigations. The
system-defined mitigation templates serve as examples for how you might configure a
mitigation for a particular attack. You can use the system-defined mitigation templates or
create your own templates for attacks against specific infrastructure (for example, VoIP and
DNS servers) or against particular customer types (for example, video hosting).
When a managed object produces an anomalous alert, either you can manually configure a
mitigation or SP can automatically configure a mitigation to protect your network against the
attack. When SP performs a mitigation, it applies the settings from the template you select or
from the default template.
When you apply a mitigation template to an existing mitigation, the settings in the template
override the settings in the mitigation. If the settings in the template are blank, the empty
settings in the template will clear the corresponding settings in the mitigation except for the
diversion prefixes and timeout setting that are configured on the Protect tab of a mitigation. If
the diversion prefixes and timeout setting are blank in the template, they do not clear the
corresponding settings in the mitigation.
See “About TMS Mitigations” on page 574.
Mitigation template configuration
You can configure mitigation templates on the Mitigation Templates page (Administration >
Mitigation > Templates). See “Configuring and Deleting TMS Mitigation Templates” on
page 614.
About the Lock check box
When you add or edit a mitigation template, the Lock check box appears with many of the
settings. When the Lock check box is selected for a setting or set of settings, the setting or set
of settings are locked for each mitigation to which you apply that template. In a mitigation, a
(lock) icon appears beside each locked setting. To change a locked setting, you must first
unlock it. To unlock a setting, either edit and reapply the template, or select a different
template.When you reapply a template, or apply a different template, the settings in the
template override the settings in the mitigation. See “About TMS Mitigation Templates” above.
System-defined templates
SP includes the following system-defined mitigation templates:
System-defined mitigation templates
Template Name
Description
Auto-Mitigation
IPv4
SP uses this as the default template for managed object IPv4 automitigations.
Auto-Mitigation
IPv6
SP uses this as the default template for managed object IPv6 automitigations.
Proprietary and Confidential Information of Arbor Networks Inc.
587
SP and TMS User Guide, Version 8.0
System-defined mitigation templates (Continued)
588
Template Name
Description
Default IPv4
SP uses this as the default template for user-initiated IPv4 mitigations.
It includes optimum countermeasure settings for the most common
types of DDoS attacks.
Default IPv6
SP uses this as the default template for user-initiated IPv6 mitigations.
It includes optimum countermeasure settings for the most common
types of DDoS attacks.
DNS Flood
Protection
Provides countermeasures to support deployments for DNS
infrastructure protection. This includes DNS authentication, malformed
DNS filtering, flood protection, and zombie detection.
VoIP Gateway
Protection
Provides countermeasures to support VoIP gateway flood protection.
Use this template to protect against malformed VoIP traffic and floods.
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
About the TMS Mitigation Status Page
Introduction
The TMS Mitigation Status page displays detailed statistics about a mitigation and allows you
to edit the countermeasures being applied to a mitigation. The name of the mitigation is
appended to the title of the page.
Navigating to the TMS Mitigation Status page
To navigate to the TMS Mitigation Status page:
1. Navigate to one of the following pages:
l
All Mitigations page (Mitigation > All Mitigations)
l
TMS Mitigations page (Mitigation > Threat Management)
2. Click the ID link for a TMS mitigation.
About the Summary pane
The Summary pane displays important information about a mitigation. It includes a Start
button that allows you to start a mitigation and a Stop button that allows you to stop an
ongoing mitigation. You can also download lists of blocked hosts and add or view annotations.
For additional information see:
“Mitigation information displayed on the Summary pane” below
n
n
“Editing mitigation settings on the Summary pane” on the next page
n
“Viewing data on the Summary pane traffic graph” on page 591
n
“Downloading blocked hosts on the Summary pane” on page 592
n
“Adding or viewing comments on the Summary pane” on page 592
Mitigation information displayed on the Summary pane
The Summary pane displays the following information about a TMS mitigation:
Mitigation information on the Summary pane
Information
Description
Status
The start and end time of the mitigation. If the mitigation is currently
active, the end time is replaced with Ongoing.
Alert
The alert associated with a mitigation, if applicable. The alert's link
opens the page that displays information about the alert.
Template
The mitigation template that is used in a mitigation, if applicable. The
template's link opens the page where you can edit the template.
Managed Object
The managed object associated with a mitigation. The managed
object's link opens the page where you can edit the managed object.
Learning Dataset
The learning dataset that is selected for the mitigation.
Proprietary and Confidential Information of Arbor Networks Inc.
589
SP and TMS User Guide, Version 8.0
Mitigation information on the Summary pane (Continued)
Information
Description
TMS Group
The group to which a TMS appliance, TMS-CGSE, TMS-ISA, or
TMS-VSM belongs. The TMS group's link opens the page where you
can edit the TMS group.
Diversion Prefixes
The diversion prefixes that are protected by this mitigation.
Flow Specification
settings
Flow specification settings appear if they were configured for a
mitigation. You can configure flow specification settings only when
you use flow specification to divert traffic. For more information about
the flow specification settings, see “Flow specification filter settings”
on page 627.
Traffic graph
A graph of the traffic that is involved in a mitigation, based on impact
data. See “Viewing data on the Summary pane traffic graph” on the
facing page.
Traffic data table
A table of mitigation traffic data. Dropped traffic is displayed in red,
and passed traffic is displayed in green.
Comment /
Annotation list
A list of the three most recent comments (annotations) that are
applied to a mitigation. You can click the Show All button to view
additional comments (annotations) that are applied to a mitigation.
See “Adding Annotations to a Mitigation” on page 731.
Editing mitigation settings on the Summary pane
To edit mitigation settings on the Summary pane:
1. Navigate to the TMS Mitigation Status page.
See “Navigating to the TMS Mitigation Status page” on the previous page.
2. In the upper-right corner of the Summary pane, click Edit.
3. Use the following table to edit the mitigation settings:
Setting
Description
Learning Dataset
list
Select the learning dataset to apply to a mitigation. SP displays
only the learning datasets for the managed object that is
selected in the mitigation.
Diversion Prefixes
box
Type the SUHIL[HV, in CIDR notation, to specify one or more
address ranges to be diverted.
The match criteria for the managed object that is selected for
the mitigation limit the prefixes whose traffic you can divert.
Auto-mitigation supports one diversion prefix. If you configure
multiple diversion prefixes, then an auto-mitigation selects the
first prefix that is listed in the mitigation.
590
Proprietary and Confidential Information of Arbor Networks Inc.
Chapter 20: Introduction to TMS Mitigations
Setting
Description
Flow Specification
Filters boxes
(IPv4 only) Configure any flow specification filters that you
want to use in a mitigation. You can use flow specification
filters only when you use flow specification to divert traffic. See
“Flow specification filter settings” on page 627.
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )