Download Tutorial: A Simple PPL Program
Transcript
DeepSweep™ “Secure Buffered Delivery” Tutorial IP Fabrics DeepSweep BIF and MF (CBIS Surveillance Module) The MF uses a DeepSweep system with two Packet Inspection Accelerators (PIXL) that are embodied on one Double Espresso (DE) board. This provides dual Gbit Ethernet ports on each PIXL for a total of four interfaces. This example only uses surveillance ports E0 and E1. Let’s set up the sample scenario. We want to watch DHCP packet traffic and associated packet traffic for a particular user ID. We know the MAC address and some other identifying information. In this sample system, IP addresses are assigned by DHCP for the other. In this example, we also will assume that the user is currently connected as the time the intercept starts up and that we know the currently assigned IP address. You will see this as 192.168.43.58 later in the tutorial. Figure 2 depicts a greatly simplified network topology for this example. The purpose of this tutorial is to go though the DeepSweep CBIS concepts rather than how to set up an network. It shows the use of an in-line tap to provide two simplex Ethernet streams for each tap point but in actual practice this would likely be done with combinations of mirror ports, span ports, multiple taps and aggregation equipment. This is highly installation dependent. “CBIS SM” Tutorial Example Subject computer MAC 11-22-33-44-55-66 BIF - DeepSweep “Secure Buffered Delivery” GB2 DHCP server “CMTS-42” GB1 Browser I/F TAP content Router Internet “outside” E1 E0 E3 E4..7 E2 MF – DeepSweep GB2 GB1 cbis_sm Browser I/F LEA null_sm Figure 2. Simplified network example for CBIS scenario DSTC – 1.47-16 Copyright © IP Fabrics, Inc. 2007 Page 4