ntop / ntop/nProbe

[cento&nprobe] export prev / next AS

Open
#192 1 comment 0 reactions 1 assignee View on GitHub

@lucaderi is already working on this.

Since Jul 17, 2017.

Dominant language
Lua
Stars
1.8k
Forks
51
PR merge metrics
No merged PRs in 30d

Description

To be able to account for traffic from/to BGP peers, cento (and also "normal" nprobe) should be able to export previous AS and next AS fields with IPFIX:
128 bgpNextAdjacentAsNumber (unsigned32 identifier)
129 bgpPrevAdjacentAsNumber (unsigned32 identifier)

As this data is not available from the packet data alone and cento has no bgp information, a mapping from the src/dst mac address has to be done.
Mapping input would be a simple txt file that contains the mac address and the associated AS number. This file has to be filled with data by the user, e.g. by scrapping all mac-addresses used at an internet exchange and mapping the them to the correct AS.
Approximate max number of entries depends on the number of peers with unique mac addresses and is assumed to be around 2500 entries.

Suggested text file structure: AS number - MAC address e.g.:
42-00:12:da:55:e4:1a
42-00:25:90:0a:0a:bd
42-78:ba:f9:49:bf:73
109-f4:cf:e2:6d:be:20
112-a0:36:9f:70:4e:62
251-00:17:cb:db:37:c0
260-00:14:f6:c5:95:fa

Thus, a flow that has packets with src mac address 00:12:da:55:e4:1a and dst mac address 00:14:f6:c5:95:fa would have a bgpPrevAdjacentAsNumber of 42 and a bgpNextAdjacentAsNumber of 260.

Please note that multiple mac addresses can map to the same AS number.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.