Download Tutorial: A Simple PPL Program

Transcript
DeepSweep™ “Secure Buffered Delivery” Tutorial
IP Fabrics
DeepSweep BIF and MF (CBIS Surveillance Module)
The MF uses a DeepSweep system with two Packet Inspection Accelerators (PIXL) that are
embodied on one Double Espresso (DE) board. This provides dual Gbit Ethernet ports on each
PIXL for a total of four interfaces. This example only uses surveillance ports E0 and E1.
Let’s set up the sample scenario. We want to watch DHCP packet traffic and associated packet
traffic for a particular user ID. We know the MAC address and some other identifying information.
In this sample system, IP addresses are assigned by DHCP for the other. In this example, we
also will assume that the user is currently connected as the time the intercept starts up and that
we know the currently assigned IP address. You will see this as 192.168.43.58 later in the
tutorial.
Figure 2 depicts a greatly simplified network topology for this example. The purpose of this
tutorial is to go though the DeepSweep CBIS concepts rather than how to set up an network. It
shows the use of an in-line tap to provide two simplex Ethernet streams for each tap point but in
actual practice this would likely be done with combinations of mirror ports, span ports, multiple
taps and aggregation equipment. This is highly installation dependent.
“CBIS SM” Tutorial Example
Subject computer
MAC
11-22-33-44-55-66
BIF - DeepSweep “Secure Buffered Delivery”
GB2
DHCP
server
“CMTS-42”
GB1
Browser
I/F
TAP
content
Router
Internet
“outside”
E1
E0
E3
E4..7
E2
MF – DeepSweep
GB2
GB1
cbis_sm
Browser
I/F
LEA
null_sm
Figure 2. Simplified network example for CBIS scenario
DSTC – 1.47-16
Copyright © IP Fabrics, Inc. 2007
Page 4