RhSoft Network Tap
1. Defend DDoS attack.
2. Monitor traffic.
3. Mirror. (PROTOCOL, IP, PORT, MAC)
4. Filter (PROTOCOL, IP, PORT, MAC).
5. Support Windows Vista/7/8.
6. Highly Optimized for speed. It is working on 1G/10G.
7. Windows 6 NDIS driver. Low packet processing latency.
RhSoft Network Tap supports L2/L3/L4 network traffic.
Environment :
Intel Pentium G2120 with DDR-1333
Packet generator : Easy NIC Test , 72% , 86%
Traffic : Bi-directional , Packet size is 1514
Bridging only
Bridging with mirroring
L2 management switch
測試方法
port 1 <-> port 2 (wire rate , gigabit , max packet len)
mirror to port 24
switch UBS-5024 , marvell solution
結論
1. 單向 mirror 可達到不掉任何封包 , utilization 約 98%
2. 雙向一定會packet drop, utilization 約 100%
3. 所以這台的port mirror 應該是用 hardware 的方式實作
4. 一台萬元左右的功能就足夠強了,加台電腦, 用台linux做NAT 並 mirror 做 ntop , 對中小企業就是超強穩定的enterprise router,可以馬上抓出誰吃頻寛
5. 現在好像都是fanlesss了
openvswitch
AMD phenom x4 975 3.0G
broadcom gigabit x 3
ubuntu server 12
bridge two adapter 且 mirror TX/RX 到一個網路卡
測試結果幾乎和management switch相同 , 不會掉封包
Linux network driver model 實在相當優良
openvswitch 還支援 sFlow/netflow實在強爆了, 一台低耗電的PC可以取得昂貴的C版switch
|