0% found this document useful (0 votes)
9 views90 pages

Muict Rmon

Remote Monitoring (RMON) allows network information to be gathered at a single workstation. It defines additional MIBs to provide richer data about network usage. RMON consists of probes that gather data on segments and remote sites, and a management station that collects and analyzes the data. RMON probes support both passive monitoring through embedded software, and active monitoring using port mirroring or in-line tapping to copy traffic to the probe without affecting the network.

Uploaded by

Eng Phichayut
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views90 pages

Muict Rmon

Remote Monitoring (RMON) allows network information to be gathered at a single workstation. It defines additional MIBs to provide richer data about network usage. RMON consists of probes that gather data on segments and remote sites, and a management station that collects and analyzes the data. RMON probes support both passive monitoring through embedded software, and active monitoring using port mirroring or in-line tapping to copy traffic to the probe without affecting the network.

Uploaded by

Eng Phichayut
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Lecture 8:

RMON

Chapter 8: RMON
Network Management: Principles and Practice
© Mani Subramanian 2000

1
Outline

▪ I. What is Remote Monitoring?


▪ II. RMON Probes
▪ III. RMON MIB
▪ IV. RMON I
▪ V. RMON II

2
I. What is Remote Monitoring?
RMON Components SNMP Agent
RMON Manager

Data SNMP BACKBONE SNMP RMON


Analyzer Traffic NETWORK Traffic Probe
Router Router

LAN

▪ RMON Probe
❑ Data gatherer - a physical device
▪ Data Analyzer
❑ Processor that analyzes data
▪ RMON Remote Network Monitoring
▪ Standard-based network management protocol
▪ Allows network information to be gathered at a single workstation
▪ Defines additional MIBs to provide a richer set of data about network usage

3
RMON (1)
▪ Remote Monitoring (RMON) is a standard monitoring specification
that enables various network monitors and console systems to
exchange network-monitoring data.
▪ RMON provides network administrators with more freedom in
selecting network-monitoring probes and consoles with features
that meet their particular networking needs.
▪ RMON was originally developed to address the problem of managing
LAN segments and remote sites from a central location.
▪ The RMON specification, which is an extension of the SNMP MIB, is
a standard monitoring specification.
▪ Within an RMON network monitoring data is defined by a set of
statistics and functions and exchanged between various different
monitors and console systems.

4
RMON (2)
▪ Resultant data is used to monitor network utilization for network
planning and performance-tuning, as well as assisting in network
fault diagnosis.
▪ There are 2 versions of RMON: RMON1 (RMONv1) and RMON2
(RMONv2).
▪ RMON1 defined 10 MIB groups for basic network monitoring, which
can now be found on most modern network hardware.
▪ RMON2 (RMONv2) is an extension of RMON that focuses on higher
layers of traffic above the medium access-control (MAC) layer.
▪ RMON2 has an emphasis on IP traffic and application-level traffic.
▪ RMON2 allows network management applications to monitor
packets on all network layers.
▪ This is difference from RMON which only allows network monitoring
at MAC layer or below.

5
RMON (3)
▪ RMON solutions are comprised of two components: a probe (or an
agent or a monitor), and a client, usually a management station.
▪ Agents store network information within their RMON MIB and are
normally found as embedded software on network hardware such as
routers and switches although they can be a program running on a
PC.
▪ Agents can only see the traffic that flows through them so they must
be placed on each LAN segment or WAN link that is to be monitored.

▪ Clients, or management stations, communicate with the RMON


agent or probe, using SNMP to obtain and correlate RMON data.

▪ Now, there are a number of variations to the RMON MIB.


❑ For example, the Token Ring RMON MIB provides objects specific to
managing Token Ring networks.
❑ The SMON MIB extends RMON by providing RMON analysis for
switched networks.

6
Network with RMONs
Management console
with RMON probe
Ethernet
Central
Router Site Router

Local management
console with Router
RMON probe Router
Ethernet

PC with
FDDI backbone Bridge RMON probe

Router with
RMON probe
Ethernet
Token Ring LAN
PC with
RMON probe

▪ Note that RMON is embedded monitoring remote FDDI LAN


▪ Analysis done in NMS

7
Limitations of SNMP
▪ Statistics hardcoded
❑ No local intelligence to:
✓ accumulate relevant information,

✓ alert NMS to pre-specified conditions,

✓ etc.

▪ Highly aggregated traffic information


❑ Aggregate link statistics
❑ Cannot drill down

▪ Protocol: simple=dumb
❑ Cannot express complex queries over MIB information in SNMPv1
✓ “get all or nothing”

✓ More expressibility in SNMPv3: expression MIB

8
RMON Benefits

▪ Monitors and analyzes locally and relays data;


Less load on the network

▪ Needs no direct visibility by NMS

▪ More reliable information

▪ Permits monitoring on a more frequent basis and


hence faster fault diagnosis

▪ Increases productivity for administrators

9
RMON: Commercial Products
▪ Built-in
❑ Passive groups: supported on most modern routers
❑ Active groups: alarm usually supported; filter/capture
are too taxing

▪ Dedicated probes
❑ Typically support all nine RMON MIBs
❑ Vendors: netscout, allied telesyn, 3com, etc.
❑ Combinations are possible: passive supported natively,
filter/capture through external probe

10
II. RMON Probe (1)
▪ The RMON probe also called RMON agent is a dedicated device
including hardware or software or it can be software embedded into
a network device like a router or a switch.
▪ RMON probe can also be software running on a standard operating
system like Windows or Linux.
▪ The application and the agent communicate across the network
using the Simple Network Management Protocol (SNMP).
▪ RMON probes capture or monitor data packets from the network.
▪ A good RMON probe should not impact the network link and the flow.

▪ RMON Probes have 3 methods for acquiring and reading data on


switched enterprise networks:
❑ RMON support in the switch
❑ port mirroring (or spanning). Require a dedicated RMON Probe
❑ in-line network tapping . Require a dedicated RMON Probe (hardware
or software)

[Link] 11
RMON Probe (2)

12
RMON Support in the Switch
▪ The RMON probe functions may be present (embedded) in the
network switches (Ethernet) and provide partial or full support of
some RMON groups.
▪ The switches operate at the physical and link level and therefore
mainly provide statistics at these levels (RMON1) and often for only
a few groups.
▪ Switch / router can provide support for groups RMON2 (case of
Cisco and NAM).

13
Port Mirroring (1)
▪ Port mirroring is used on a network switch to send a copy of all
network packets seen on one switch port (or an entire VLAN) to a
network monitoring connection on another switch port.

▪ Port mirroring capabilities are implemented in nearly all enterprise


class switches.
❑ On typical enterprise switch, a port can be designated as the mirror
port to which the RMON probe can be connected.
❑ The traffic from one or more network ports or from a VLAN can then be
copied to the mirror port.

14
Port Mirroring (2)
▪ Some switches are only able to mirror incoming traffic of a port, while
others are able to mirror both incoming and outgoing traffic of a
mirrored port.
❑ Error packets are not mirrored to avoid the forwarding of corrupted traffic.
▪ The limitation of port mirroring is the bandwidth usage of the mirror port,
multiple ports or VLAN mirrored to one port can cause buffer overflow
and dropped packets.
❑ Since packets go through a buffer and are retimed, accurate time-sensitive
measurements, such as jitter, packet gap analysis or latency are difficult.
❑ In addition, most mirror ports filter anomalies, thus making trouble-
shooting difficult.
▪ Finally, port mirroring puts a load on the switch's CPU/transfer logic,
thus impacting the switch's operational performance.
▪ Port mirroring on a Cisco Systems switch is generally referred to as
Switched Port Analyzer (SPAN); some other vendors have other
names for it, such as Roving Analysis Port (RAP) on 3Com switches.

15
In-line Network Tapping (1)
▪ In-line taps are inserted directly into a network link (copper wire or
fiber).
▪ They split or copy the signals from both channels (full duplex) and
retransmit the data streams hack out to the probe.

16
In-line Network Tapping (2)
▪ Optical taps contain a pair of passive optical beam splitters and no powered
components.
❑ Light entering the tap from each channel is divided and separately channeled out
to the link where the RMON probe can be connected.
❑ Beware that the light is effectively split in half thus an attenuation factor should be
calculated into the optical power budget.
▪ Taps are passive and fault tolerant devices.
❑ They do not require configuration. 10/100 Ethernet taps do not participate in link
negotiation and are not visible to the network.
❑ Taps see 100% of the packets, as well as anomalies and timing values are
accurate thus providing a real support for troubleshooting.
❑ Multiport switching taps can be used where any one of a set of links (servers, inter
switch uplink) have to be remotely monitored in rotation or upon need.
▪ Taps have to be permanently installed in backbone and critical links to avoid
undesirable service outages when a tool is needed on a link.
▪ RMON probe has to be connected to the TAP for traffic analysis and to the
network with another interface for communicating in SNMP with the SNMP
Manager.

17
III. RMON MIB rmon (mib-2 16)
[Link]
windows-and-mac-free-download
SMI: SMIv2 (rfc 1902)

rmonConformance (20)
statistics (1) probeConfig (19)
history (2) usrHistory (18)
alarm (3) a1Matrix (17)
host (4) a1Host (16)
hostTopN (5) n1Matrix (15)
matrix (6) n1Host (14)
filter (7) addressMap (13)
capture (8) protocolDist (12)
event (9) protocolDir (11)

RFC 1757 (2819) RFC 2021


Layer: 2 (Ethernet)
Token Ring (10)
Layers: 3-7
RFC 1513
RMON1

RMON2
RMON1 Extension
18
Protocol Structure - RMON: Remote Monitoring MIBs(RMON1 and
RMON2)
The RMON1 and RMON2 are focused at different network layers:

19
RMON1 MIB
The RMON1 MIB consists of ten groups:

1. Statistics: real-time LAN statistics e.g. utilization, collisions, CRC


errors
2. History: history of selected statistics
3. Alarm: definitions for RMON SNMP traps to be sent when statistics
exceed defined thresholds
4. Hosts: host specific LAN statistics e.g. bytes sent/received, frames
sent/received
5. Hosts top N: record of N most active connections over a given time
period
6. Matrix: the sent-received traffic matrix between systems
7. Filter: defines packet data patterns of interest e.g. MAC address or
TCP port
8. Capture: collect and forward packets matching the Filter
9. Event: send alerts (SNMP traps) for the Alarm group
10. Token Ring: extensions specific to Token Ring

20
RMON2 MIB
The RMON2 MIB adds ten more groups:

1. Protocol Directory: list of protocols the probe can monitor


2. Protocol Distribution: traffic statistics for each protocol
3. Address Map: maps network-layer (IP) to MAC-layer addresses
4. Network-Layer Host: layer 3 traffic statistics, per each host
5. Network-Layer Matrix: layer 3 traffic statistics, per
source/destination pairs of hosts
6. Application-Layer Host: traffic statistics by application protocol, per
host
7. Application-Layer Matrix: traffic statistics by application protocol, per
source/destination pairs of hosts
8. User History: periodic samples of user-specified variables
9. Probe Configuration: remote configure of probes
10. RMON Conformance: requirements for RMON2 MIB conformance

21
RMON1 MIB Groups & Tables (1)
• Tengroups divided into three categories
• Statistics groups (rmon 1, 2, 4, 5, 6, and 10))
• Event reporting groups (rmon 3 and 9)
• Filter and packet capture groups(romon 7 and 8)
• Groups with “2” in the name are enhancements with RMON2

Group OID Function Tables


Statistics rmon 1 Link level statistics -etherStatsTable
-etherStats2Table
History rmon 2 Periodic statistical data -historyControlTable
collection and storage for later -etherHistoryTable
retrieval -historyControl2Table
-etherHistory2Table
Alarm rmon 3 Generates events when the data -alarmTable
sample gathered crosses pre-
established thresholds
Host rmon 4 Gathers statistical data on hosts -hostControlTable
-hostTable
-hostTimeTable
-hostControl2Table
HostTopN rmon 5 Computes the top N hosts on -hostTopNcontrolTable
the respective categories of
statistics gathered 22
Matrix rmon 6 Statistics on traffic between pair -matrixControlTable
Host rmon 4 Gathers statistical data on hosts -hostControlTable
-hostTable
RMON1 MIB Groups & Tables (2) -hostTimeTable
-hostControl2Table
HostTopN rmon 5 Computes the top N hosts on -hostTopNcontrolTable
the respective categories of
statistics gathered
Matrix rmon 6 Statistics on traffic between pair -matrixControlTable
of hosts -matrixSDTable
-matrixDSTable
-matrixControl2Table
Filter rmon 7 Filter function that enables -filterTable
capture of desired parameters -channelTable
-filter2Table
-channel2Table
Packet rmon 8 Packet capture capability to -buffercontrolTable
Capture gather packets after they flow -captureBufferTable
through a channel
Event rmon 9 Controls the generation of -eventTable
events and notifications
Token rmon 10 See Table 8.3 See Table 8.3
Ring

23
RMON1 Standard Overview
▪ RMON1 delivers information in 9 RMON groups of monitoring
elements, each providing specific sets of data to meet common
network-monitoring requirements.
▪ Each group is optional so that vendors do not need to support all the
groups within the Management Information Base (MIB).

Remark: Some RMON groups require support of other RMON


groups to function properly.

24
Table of the nine monitoring groups specified in the RFC 2819
(Obsoletes RFC 1757) Ethernet RMON MIB (1)

Group Description Statistics provided


Packets dropped, packets sent, bytes sent
(octets), broadcast packets, multicast
packets, CRC errors, runts, giants,
Contains statistics measured by the
fragments, jabbers, collisions, and counters
Statistics(1) RMON probe for each monitored
for packets ranging from 64 to 128, 128 to
interface on this device.
256, 256 to 512, 512 to 1024, and 1024 to
1518 bytes.

Records periodic statistical samples


from a network and stores them for Sample period, number of samples, items
History(2)
later retrieval. sampled.

Periodically takes statistical samples


from variables in the probe and Includes the alarm table and requires the
Alarm(3) compares them with previously implementation of the event group. Alarm
configured thresholds. If the monitored type, interval, starting threshold, stop
variable crosses a threshold, an event threshold.
is generated

25
Table of the nine monitoring groups specified in the RFC 2819
(Obsoletes RFC 1757) Ethernet RMON MIB (2)

Group Description Statistics provided


Host address (Ethernet MAC address),
Contains statistics associated with packets, and bytes received and
Host(4) each host (Ethernet Station) transmitted, as well as broadcast, multicast,
discovered on the network. and error packets.

Stores statistics for conversations


between sets of two addresses
Ethernet MAC Source and Ethernet MAC
(Ethernet Station). As the device
Matrix(5) destination address pairs and packets,
detects a new conversation, it creates a
bytes, and errors for each pair.
new entry in its table.

Prepares tables that describe the hosts


(Ethernet Station) that top a list
ordered by one of their base statistics
Statistics, host(s), sample start and stop
Host Top N(6) over an interval specified by the
periods, rate base, duration.
management station. Thus, these
statistics are rate-based.

26
Table of the nine monitoring groups specified in the RFC 2819
(Obsoletes RFC 1757) Ethernet RMON MIB (3)

Group Description Statistics provided


Enables packets to be matched by
a filter equation. These matched
Bit-filter type (mask or not mask), filter
packets form a data stream that
Filters(7) expression (bit level), conditional
might be captured or that might
expression (and, or not) to other filters.
generate events.

Size of buffer for captured packets, full


Packet Enables packets to be captured status (alarm), number of captured
Capture(8) after they flow through a channel. packets.

Controls the generation and


notification of events from this Event type, description, last time event
Events(9)
device. sent.

Token Ring Support of Token Ring


(not used often)
(10)

27
RMON2 MIB (1)
RMON 2 Functions
MIB Group
Protocol The Protocol Directory is a simple and interoperable way for an RMON2
application to establish which protocols a particular RMON2 agent implements.
Directory This is especially important when the application and the agent are from different
vendors

Protocol Mapping the data collected by a probe to the correct protocol name that can then
Distribution be displayed to the network manager.

Address Address translation between MAC-layer addresses and network-layer addresses


mapping which are much easier to read and remember. Address translation not only helps
the network manager, it supports the SNMP management platform and will lead to
improved topology maps.
Network
Layer host Network host (IP layer) statistics

Network layer Stores and retrieves network layer (IP layer) statistics for conversations
matrix between sets of two addresses.

Application
Application host statistic
layer host
Application
Stores and retrieves application layer statistics for conversations between sets
layer matrix of two addresses.
28
RMON2 MIB (2)
RMON 2 Functions
MIB Group
User history This feature enables the network manager to configure history studies of
any counter in the system, such as a specific history on a particular file
server or a router-to-router connection

Probe This RMON2, feature enable one vendor's RMON application to


configuration remotely configure another vendor's RMON probe.

29
Question : Functions of RMON groups

▪ Identify the RMON groups for the following


network traffic analysis functions:
❑ If NMS wants to find out which hosts are transmitting
the most information
✓ ans: HostTopN (gp 2)
❑ If NMS wants to find out which host(s) are talking to
each others
✓ ans: Matrix groups (gp 3)

30
IV. RMON I
RMON I Textual Conventions
State Enume- Description
ration
valid 1 Row exists and is active. It is fully configured and operational
createRequest 2 Create a new row by creating this object
underCreation 3 Row is not fully active
invalid 4 Delete the row by disassociating the mapping of this entry

▪ Row Creation & Deletion


▪ EntryStatus data type introduced in RMON
▪ EntryStatus (similar to RowStatus in SNMPv2) used to create and
delete conceptual row.
▪ Only 4 states in RMON compared to 6 in SNMPv2

31
RMON Groups and Functions
Token Ring Statistics
Token Ring Token Ring History
Statistics History Control

Ethernet Statistics
Ethernet Ethernet History
Statistics History Control

Host and Conversation Statistics


Remotely
Data Host HostTopN Matrix Network
Monitored
Gathering Statistics Statistics Statistics Manager
Network

Filter Group
Packet Channel Packet
Filtering Filtering Capture

Alarm Event
Generation Generation
▪ Probe gathers data
▪ Functions Figure 8.3 RMON1 Groups and Functions

❑ Statistics on Ethernet, token ring, and hosts / conversations


❑ Filter group filters data prior to capture of data
❑ Generation of alarms and events

32
Ethernet Statistic Table
▪ Provides ethernet traffic statistics since the rmon probe was started.
▪ SNMP data are collected from the RMON probe. The probe should be compatible with
the RMON MIB RFC1757.

33
[Link]
Ethernet Packet Size Table
▪ Provides ethernet traffic statistics since the probe was started.

34
Physical Layer Host Table
▪ The "host table" provides ethernet traffic statistics since the probe was started.

35
Physical Layer - Source Destination Matrix Table
▪ The "Source Destination Matrix Table" provides ethernet traffic statistics since the
probe was started.
▪ SNMP data are collected from the RMON probe. The probe should be compatible with
the RMON MIB RFC1757.

36
RMON Physical Layer - Destination Source Matrix Table
▪ The "Destination Source Matrix Table" provides ethernet traffic statistics since the
probe was started.

37
etherStatsTable
statistics etherStatsEntry
etherStatsIndex
ifIndex.1.

etherStatsDataSource
etherStatsDropEvents
etherStatsOctets
etherStatsPkts
rmon 1 etherStatsBroadcastPkts
etherStatsMulticastPkts
etherStatsCRCAlignErrors
etherStatsUndersizePkts
etherStatsOversizePkts
etherStatsFragments
etherStatsJabbers
etherStatsCollisions
etherStatsPkts64Octets
etherStatsPkts65to127Octets
etherStatsPkts128to255Octets
etherStatsPkts256to511Octets
etherStatsPkts512to1023Octets
etherStatsPkts1024to1518Octets
etherStatsOwner
etherStatsStatus

38
etherStatsIndex
etherStatsOwner
ifDesrc.x (etherStatsDataSource) = x
etherStatsStatus

39
etherStatsDropEvents
etherStatsOctets
etherStatsPkts
etherStatsBroadcastPkts
etherStatsMulticastPkts
etherStatsCRCAlignErrors
etherStatsUndersizePkts
etherStatsOversizePkts
etherStatsFragments
etherStatsJabbers
etherStatsCollisions
etherStatsPkts64Octets
etherStatsPkts65to127Octets
etherStatsPkts128to255Octets
etherStatsPkts256to511Octets
etherStatsPkts512to1023Octets
etherStatsPkts1024to1518Octets

40
etherStatsPkts
etherStatsBroadcastPkts
etherStatsMulticastPkts
etherStatsDropEvents

41
etherStatsCRCAlignErrors
etherStatsUndersizePkts
etherStatsOversizePkts
etherStatsFragments
etherStatsJabbers
etherStatsCollisions

42
etherStatsPkts64Octets
etherStatsPkts65to127Octets
etherStatsPkts128to255Octets
etherStatsPkts256to511Octets
etherStatsPkts512to1023Octets
etherStatsPkts1024to1518Octets

43
rmon 2 historyControlTable
history historyControlEntry
historyControlIndex
historyControlDataSource
historyControlBucketsRequested
etherHistoryTable historyControlBucketsGranted
etherHistoryEntry historyControlInterval
etherHistoryIndex → historyControlOwner
etherHistorySampleIndex historyControlStatus
etherHistoryIntervalStart
etherHistoryDropEvents
etherHistoryOctets
etherHistoryPkts
etherHistoryBroadcastPkts
etherHistoryMulticastPkts
etherHistoryCRCAlignErrors
etherHistoryUndersizePkts
etherHistoryOversizePkts
etherHistoryFragments
etherHistoryJabbers
etherHistoryCollisions
etherHistoryUtilization
44
historyControlTable
historyControlEntry
historyControlIndex
historyControlDataSource
historyControlBucketsRequested
historyControlBucketsGranted
historyControlInterval
historyControlOwner
historyControlStatus
45
46
etherHistoryUtilization

▪ 10-Megabit Ethernet utilization:

Pkts * (9.6 + 6.4) + (Octets * .8)


Utilization =
Interval * 10,000

Pkts * (96 + 64) + (Octets * 8)


Utilization =  100%
Interval * 10,000,000
64 bits 96 bits

47
Alarm Group rmon 3

▪ Set thresholds on a variety of items


affecting network performance
▪ When the thresholds are crossed, events
are reported.
▪ In general, the values of thresholds are
determined according to past experience.

48
Thresholds

▪ Threshold Priority
❑ In general, priority: low, medium, high
❑ Multiple threshold values for the same item
❑ Thresholds for multiple items
❑ RMON doesn't support multiple thresholds.
▪ Use rearm mechanism to avoid frequent
threshold events
❑ alarmRisingThreshold, alarmFallingThreshold

49
Alarms

util%
Rising
Threshold
Threshold
Falling
Rearm Threshold
* * * *

123 4 5 6 7
RisingAlarm ➔ time

50
alarm alarmTable
alarmEntry
alarmIndex
alarmInterval
alarmVariable absoluteValue(1),
alarmSampleType deltaValue(2)
risingAlarm(1), alarmValue
fallingAlarm(2), alarmStartupAlarm
risingOrFallingAlarm(3) alarmRisingThreshold
alarmFallingThreshold
alarmRisingEventIndex
alarmFallingEventIndex
alarmOwner
alarmStatus

51
52
rmon 9
event
eventTable logTable
eventEntry logEntry
eventIndex logEventIndex
eventDescription logIndex
eventType logTime
eventCommunity logDescription
eventLastTimeSent
eventOwner
eventStatus

none(1),
log(2),
snmptrap(3),
logandtrap(4)

53
eventTable

logTable

54
55
rmon 4 hostControlTable
hosts hostControlEntry
hostControlIndex
hostControlDataSource
hostControlTableSize
hostControlLastDeleteTime
hostControlOwner
hostControlStatus
hostTable
hostTimeTable
hostEntry
hostTimeEntry
hostAddress hostTimeAddress
hostCreationOrder hostTimeCreationOrder
hostIndex hostTimeIndex →
hostInPkts → hostTimeInPkts
hostOutPkts hostTimeOutPkts
hostInOctets hostTimeInOctets
hostOutOctets hostTimeOutOctets
hostOutErrors hostTimeOutErrors
hostTimeOutBroadcastPkts
hostOutBroadcastPkts
hostTimeOutMulticastPkts
hostOutMulticastPkts
56
hostTopN rmon 5

hostTopNControlTable hostTopNTable
hostTopNControlEntry hostTopNEntry
hostTopNControlIndex hostTopNReport →
hostTopNIndex
hostTopNHostIndex
hostTopNAddress
hostTopNRateBase * hostTopNRate
hostTopNTimeRemaining
hostTopNDuration
hostTopNRequestedSize
hostTopNInPkts(1),
hostTopNGrantedSize
hostTopNOutPkts(2),
hostTopNStartTime
hostTopNInOctets(3),
hostTopNOwner
hostTopNOutOctets(4),
hostTopNStatus
hostTopNOutErrors(5),
hostTopNOutBroadcastPkts(6),
hostTopNOutMulticastPkts(7)

57
Host Top N Group Example
HostTopN

Host 1
Host 2
Host 3
Host 4
Host 5
Host 6
Host 7
Host 8
Host 9
Host 10

0 100 200 300 400


Giga Octets

58
Figure 8.5 HostTop-10 Output Octets
matrix matrixControlTable
matrixControlEntry
matrixControlIndex
rmon 6 matrixControlDataSource
matrixControlTableSize
matrixControlLastDeleteTime
matrixControlOwner
matrixControlStatus

matrixSDTable matrixDSTable
matrixSDEntry matrixDSEntry
matrixSDSourceAddress matrixDSSourceAddress
matrixSDDestAddress matrixDSDestAddress
matrixSDIndex → matrixDSIndex →
matrixSDPkts matrixDSPkts
matrixSDOctets matrixDSOctets
matrixSDErrors matrixDSErrors

59
Matrix Control and SD Tables matrixSDTable

matrixSDEntry
matrixControlTable

matrixSD matrixSD matrix matrix


matrixControlEntry
Source Destination SD SD
Address = Address = Index = Pkts =
[Link] [Link] 1

matrix matrix matrix matrix matrixSD matrixSD matrix matrix


matrix matrix
Control Control Control ControlLast Source Destination SD SD
Control Control
DataSource TableSize = Owner = DeleteTime Address = Address = Index = Pkts =
Index = 1 Status = 1
=ifIndiex.1 10 "Bob" = 1000 [Link] [Link] 1

matrixSD matrixSD matrix matrix


Source Destination SD SD
matrix matrix matrix matrix
matrix matrix Address = Address = Index = Pkts =
Control Control Control ControlLast
Control Control [Link] [Link] 2
DataSource TableSize = Owner = DeleteTime
Index = 2 Status = 1
=ifIndiex.2 10 "Bob" = 100050
matrixSD matrixSD matrix matrix
Note on Indices: Source Destination SD SD
Address = Address = Index = Pkts =
Indices marked in bold letter
[Link] [Link] 2
Value of dataIndex same as value of controlIndex

Figure 8.4 Relationship between Control and Data Tables


▪ matrixSDTable is the source-destination table
▪ controlDataSource identifies the source of the data
▪ controlTableSize identifies entries associated with the data source
▪ controlOwner is creator of the entry

60
Filter Group rmon 7

▪ Filter group used to capture packets defined by logical expressions


▪ Channel is a stream of data captured based on a logical
expression
▪ Filter table allows packets to be filtered with an arbitrary filter
expression
▪ A row in the channel table associated with multiple rows in the filter
table

▪ Filter
❑ A channel is associated with
filter1 OR filter2 OR … filtern
❑ Within a filter, any bits checked in the data and status are AND’ed
with respect to other bits in the same filter.

61
Filter Group filterTable

filterEntry
channelTable

channelEntry filter
filterIndex Filter
ChannelIndex
=1 Parameters
=1

channel channel channel channel Other filter


filterIndex Filter
Index =1 IfIndex = 1 AcceptType DataControl Channel ChannelIndex
=2 Parameters
Parameters =1

filter
filterIndex Filter
ChannelIndex
Other =3 Parameters
channel channel channel channel =2
Channel
Index = 2 IfIndex AcceptType DataControl
Parameters

filter
Note on Indices: filterIndex Filter
ChannelIndex
=4 Parameters
Indices marked in bold letter =2
Value of filterChannelIndex same as value of channelIndex

▪ Filter group used to capture packets defined by logical expressions


▪ Channel is a stream of data captured based on a logical expression
▪ Filter table allows packets to be filtered with an arbitrary filter expression
▪ A row in the channel table associated with multiple rows in the filter table

62
filter
channelTable filterTable
channelEntry filterEntry
channelIndex filterIndex
channelIfIndex On(1)
filterChannelIndex
channelAcceptType Off(2) filterPktDataOffset
channelDataControl filterPktData
channelTurnOnEventIndex filterPktDataMask
channelTurnOffEventIndex filterPktDataNotMask
channelEventIndex filterPktStatus
channelEventStatus filterPktStatusMask
channelMatches filterPktStatusNotMask
channelDescription filterOwner
channelOwner filterStatus
channelStatus

eventReady(1),
acceptMatched(1), eventFired(2),
acceptFailed(2) eventAlwaysReady(3)

63
filterPktDataOffset
Input Packet

filterPktData filterPktDataMask

Bitwise XOR

Bitwise AND filterPktDataNotMask

Bitwise NOT

Bitwise AND Bitwise AND

Pass if all bits are 0 Pass if any bits are 1


64
(pass if match) (pass if mismatch)
Filter Example

filterPktDataOffset = 0
filterPktData = 0x000000000A50000000000BB
filterPktDataMask = 0xFFFFFFFFFFFFFFFFFFFFFFF
filterPktDataNotMask = 0x000000000000FFFFFFFFFFF

Accept all Ethernet packets that have a destination


address of 0xA5 and that do not have a source
address of 0xBB.

65
Packet Capture Group rmon 8

Filter Capture
Table Buffer
Channel (many Table
Table for (One
each entry
channel) per
Channel)

▪ Packet capture group is a post-filter group


▪ Buffer control table used to select channels
▪ Captured data stored in the capture buffer table

66
capture lockWhenFull(1),
wrapWhenFull(2)

bufferControlTable
bufferControlEntry
spaceAvailable(1),
bufferControlIndex
full(2) bufferControlChannelIndex
bufferControlFullStatus
bufferControlFullAction
bufferControlCaptureSliceSize
bufferControlDownloadSliceSize
bufferControlDownloadOffset
bufferControlMaxOctetsRequested
captureBufferTable bufferControlMaxOctetsGranted
captureBufferEntry bufferControlCapturedPackets
captureBufferControlIndex bufferControlTurnOnTime
captureBufferIndex bufferControlOwner
captureBufferPacketID bufferControlStatus
captureBufferPacketData
captureBufferPacketLength
captureBufferPacketTime
captureBufferPacketStatus

67
rmon 10
RMON TR Extension Groups
Token Ring Group Function Tables
Statistics Current utilization tokenRingMLStatsTable
and error statistics tokenRingMLStats2Table
of Mac Layer
Promiscuous Statistics Current utilization tokenRingPStatsTable
and error statistics tokenRingPStats2Table
of promiscuous
data
Mac-Layer History Historical tokenRingMLHistoryTable
utilization and
error statistics of
Mac Layer
Promiscuous History Historical tokenRingPHistoryTable
utilization and
error statistics of
promiscuous data
Ring Station Station statistics ringStationControlTable
ringStationTable
ringStationControl2Table
Ring Station Order Order of the ringStationOrderTable
stations
Ring Station Active ringStationConfigControlTable
Configuration configuration of ringStationConfigTable
ring stations
Source Routing Utilization statistics sourceRoutingStatsTable
of source routing sourceRoutingStats2Table
information
68
V. RMON2
▪ Applicable to Layers 3 and above
▪ Functions similar to RMON1
▪ Enhancement to RMON1
▪ Defined conformance and compliance
▪ RMON2 (RFC 2021) expands on the features of the original RMON
▪ RMON2 drives remote monitoring standards beyond the Media
Access Control (MAC) layer to the network and application layers.
▪ This setup enables administrators to analyse and troubleshoot on
individual networked applications such as Web traffic, e-mail,
database access, Network File System (NFS) and others.
▪ provides information about the actual usage of the network,
▪ provides information about end-to-end traffic flows

69
RMON 2 MIB (1)
Table 8.4 RMON2 MIB Groups and Tables
Group OID Function Tables
Protocol rmon 11 Inventory of protocols protocolDirTable
Directory
Protocol rmon 12 Relative statistics on protocolDistControlTable
Distribution octets and packets protocolDistStatsTable
Address Map rmon 13 Mac address to addressMapControlTable
network address on addressMapTable
the interfaces
Network rmon 14 Traffic data from and n1HostControlTable
Layer Host to each host n1HostTable
Network rmon 15 Traffic data from each n1MatrixControlTable
Layer Matrix pair of hosts n1MatrixSDTable
n1MatrixDSTable
n1MatrixTopNControlTable
n1MatrixTopNTable
Application rmon 16 Traffic data by a1HostTable
Layer Host protocol from and to
each host
Application rmon 17 Traffic data by a1MatrixSDTable 70
Layer Matrix protocol between a1MatrixDSTable
Network rmon 15 Traffic data from each n1MatrixControlTable
Layer Matrix pair of hosts n1MatrixSDTable
RMON 2 MIB (2) n1MatrixDSTable
n1MatrixTopNControlTable
n1MatrixTopNTable
Application rmon 16 Traffic data by a1HostTable
Layer Host protocol from and to
each host
Application rmon 17 Traffic data by a1MatrixSDTable
Layer Matrix protocol between a1MatrixDSTable
pairs of hosts a1MatrixTopNControlTable
a1MatrixTopNTable
User History rmon 18 User-specified usrHistoryControlTable
Collection historical data on usrHistoryObjectTable
alarms and statistics usrHistoryTable
Probe rmon 19 Configuration of probe serialConfigTable
Configuration parameters netConfigTable
trapDestTable
serialConnectionTable
RMON rmon 20 RMON2 MIB See Section 8.4.2
Conformance Compliances and
Compliance Groups

71
Protocol Directory rmon 11

Protocol Identifier
protocolDirLastChange [Link]
protocolDirTable [Link].[Link].[Link].[Link].161
protocolDirEntry
[Link]
protocolDirID [Link].[Link].[Link].17
protocolDirParameters
protocolDirLocalIndex [Link].0 [Link]
protocolDirDescr
(bit 0) countsFragments
protocolDirType (bit 1) tracksSessions
protocolDirAddressMapConfig
BITS {
protocolDirHostConfig extensible(0),
protocolDirMatrixConfig addressRecognitionCapable(1)
protocolDirOwner }

protocolDirStatus
notSupported(1),
supportedOff(2),
[Link].[Link].[Link].[Link].[Link].0.0 supportedOn(3)

72
protocolDirTable Example
protocolDirLocalIndex protocolDirAddressMapConfig protocolDirOwner

protocolDirDescr protocolDirHostConfig protocolDirStatus


protocolDirType protocolDirMatrixConfig

[Link]
.[Link].[Link].[Link].[Link].[Link].2.0.0
.[Link].[Link].[Link].[Link].[Link].[Link].[Link]
.[Link].[Link].[Link].[Link].[Link].[Link].[Link].[Link].0

73
rmon 12
Protocol Distribution
protocolDistControlTable
protocolDistControlEntry
Object Identifier Value protocolDistControlIndex
[Link].[Link].[Link] [Link].[Link].1.1.1 protocolDistControlDataSource
protocolDistControlDroppedFrames
[Link].[Link].[Link] 0
protocolDistControlCreateTime
[Link].[Link].[Link] 0:00:03
protocolDistControlOwner
[Link].[Link].[Link] monitor
protocolDistControlStatus
[Link].[Link].[Link] 1

protocolDistStatsTable
protocolDistStatsEntry Object Identifier Value
protocolDistStatsPkts [Link].[Link].[Link].4 132684185
protocolDistStatsOctets
[Link].[Link].[Link].4 3101564931
INDEX { protocolDistControlIndex,
protocolDirLocalIndex }

74
protocolDistStatsTable

OID(protocolDistStatsPkts) protocolDistStatsPkts protocolDistStatsOctets


ip .[Link].[Link].[Link].4 152226584 2843228331
*.[Link] .[Link].[Link].[Link].5 30243806 1959274214
*.[Link] .[Link].[Link].[Link].41 3847220 1373764210
*.[Link] .[Link].[Link].[Link].6 120905544 790647401
*.[Link] .[Link].[Link].[Link].66 2408006 581005950
*.[Link] .[Link].[Link].[Link].73 989794 516661768
*.arp .[Link].[Link].[Link].7 7996093 511820512
*.[Link]-data .[Link].[Link].[Link].39 487171 492196391
*.[Link] .[Link].[Link].[Link].68 1694817 338336823
protocolDirLocalIndex
protocolDirDescr Sorted by Octets
(protocolDirTable)
75
rmon 13
Address Map Group
addressMapControlTable
addressMapControlEntry
addressMapControlIndex
Object Identifier Value
addressMapControlDataSource
[Link].[Link].[Link] [Link].[Link].1.1.1
addressMapControlDroppedFrames
[Link].[Link].[Link] 43764662
addressMapControlOwner
[Link].[Link].[Link] monitor
addressMapControlStatus
[Link].[Link].[Link] 1
addressMapTable
addressMapEntry
addressMapTimeMark
addressMapNetworkAddress
addressMapSource
addressMapPhysicalAddress
addressMapLastChange

{ addressMapTimeMark, protocolDirLocalIndex, addressMapNetworkAddress,


addressMapSource } 76
addressMapTable

length (11 bytes)


ifIndex
addressMapSource ([Link].[Link].[Link])

addressMapNetworkAddress ([Link].132)
protocolDirLocalIndex (4: ip)
IP address
addressMapTimeMark
length (4 bytes)
addressMapPhysicalAddress

77
Network Layer Host Group rmon 14

hlHostControlTable
hlHostControlTable
hlHostControlEntry
hlHostControlIndex
Object Identifier Value
hlHostControlDataSource
[Link].[Link].[Link] [Link].[Link].1.1.1
hlHostControlNlDroppedFrames
[Link].[Link].[Link] 43862736
hlHostControlNlInserts
[Link].[Link].[Link] 1260049
hlHostControlNlDeletes
[Link].[Link].[Link] 1254088 hlHostControlNlMaxDesiredEntries
[Link].[Link].[Link] -1 hlHostControlAlDroppedFrames
[Link].[Link].[Link] 44537366 hlHostControlAlInserts
[Link].[Link].[Link] 2605477 hlHostControlAlDeletes
[Link].[Link].[Link] 2589365 hlHostControlAlMaxDesiredEntries
[Link].[Link].[Link] -1 hlHostControlOwner
[Link].[Link].[Link] monitor hlHostControlStatus
[Link].[Link].[Link] 1

hl, nl, al means higher layer, network layer, and application layer 78
Network-Layer Host Table rmon 14 2

nlHostTable
nlHostEntry
nlHostTimeMark
nlHostAddress
nlHostInPkts
nlHostOutPkts
nlHostInOctets
nlHostOutOctets
nlHostOutMacNonUnicastPkts
nlHostCreateTime

INDEX { hlHostControlIndex, nlHostTimeMark, protocolDirLocalIndex, nlHostAddress }

nlHostOutPkts.1.783495.[Link].6.6.

79
Network Layer Matrix Group rmon 15

rmon 15 1 hlMatrixControlTable
hlMatrixControlEntry
hlMatrixControlIndex
Object Identifier Value
hlMatrixControlDataSource
[Link].[Link].[Link] [Link].[Link].1.1.1
hlMatrixControlNlDroppedFrames
[Link].[Link].[Link] 44585985
hlMatrixControlNlInserts
[Link].[Link].[Link] 1297186 hlMatrixControlNlDeletes
[Link].[Link].[Link] 1280047 hlMatrixControlNlMaxDesiredEntries
[Link].[Link].[Link] -1 hlMatrixControlAlDroppedFrames
[Link].[Link].[Link] 44636481 hlMatrixControlAlInserts
[Link].[Link].[Link] 2733462 hlMatrixControlAlDeletes
[Link].[Link].[Link] 2689097 hlMatrixControlAlMaxDesiredEntries
[Link].[Link].[Link] -1 hlMatrixControlOwner
[Link].[Link].[Link] monitor hlMatrixControlStatus

[Link].[Link].[Link] 1

80
Network-Layer Source/Destination Statistics
rmon 15 2 rmon 15 3

nlMatrixSDTable nlMatrixDSTable
nlMatrixSDEntry nlMatrixDSEntry
nlMatrixSDTimeMark nlMatrixDSTimeMark
nlMatrixSDSourceAddress nlMatrixDSSourceAddress
nlMatrixSDDestAddress nlMatrixDSDestAddress
nlMatrixSDPkts nlMatrixDSPkts
nlMatrixSDOctets nlMatrixDSOctets
nlMatrixSDCreateTime nlMatrixDSCreateTime

INDEX { hlMatrixControlIndex, nlMatrixSDTimeMark, protocolDirLocalIndex,


nlMatrixSDSourceAddress, nlMatrixSDDestAddress }
INDEX { hlMatrixControlIndex, nlMatrixDSTimeMark, protocolDirLocalIndex,
nlMatrixDSDestAddress, nlMatrixDSSourceAddress }
nlMatrixSDPkts.1.783495.[Link].[Link].2.6.7

81
nlMatrixSDTable

nlMatrixSDPkts nlMatrixSDDestAddress
nlMatrixSDSourceAddress
protocolDirLocalIndex (ip)
nlMatrixSDTimeMark

hlMatrixControlIndex

82
rmon 15 4
Network-Layer Top N Matrix
nlMatrixTopNPkts(1), nlMatrixTopNControlTable
nlMatrixTopNOctets(2) nlMatrixTopNControlEntry
nlMatrixTopNControlIndex
nlMatrixTopNControlMatrixIndex
rmon 15 5
nlMatrixTopNControlRateBase
nlMatrixTopNTable
nlMatrixTopNControlTimeRemaining
nlMatrixTopNEntry
nlMatrixTopNControlGeneratedReports
nlMatrixTopNIndex
nlMatrixTopNControlDuration
nlMatrixTopNProtocolDirLocalIndex
nlMatrixTopNControlRequestedSize
nlMatrixTopNSourceAddress
nlMatrixTopNControlGrantedSize
nlMatrixTopNDestAddress
nlMatrixTopNControlStartTime
nlMatrixTopNPktRate
nlMatrixTopNControlOwner
nlMatrixTopNReversePktRate
nlMatrixTopNControlStatus
nlMatrixTopNOctetRate
nlMatrixTopNReverseOctetRate

nlMatrixTopNControlIndex, nlMatrixTopNIndex 83
Application-Layer Host Group rmon 16

rmon 16 1

alHostTable
alHostEntry
alHostTimeMark
alHostInPkts
alHostOutPkts
alHostInOctets
alHostOutOctets
alHostCreateTime *.ip
INDEX { hlHostControlIndex, alHostTimeMark, protocolDirLocalIndex,
nlHostAddress, protocolDirLocalIndex }

*.[Link]
84
alHostTable
alHost alHost alHost alHost
OID(alHostInPkts) alHostCreateTime
InPkts OutPk InOct OutOct
62 days, 0 hours, 7
.[Link].[Link].[Link].[Link].[Link] 854 1652 66115 137243 minutes, 28 seconds.
62 days, 0 hours, 7
.[Link].[Link].[Link].[Link].[Link] 592 705 46124 56107 minutes, 58 seconds.
62 days, 0 hours, 7
.[Link].[Link].[Link].[Link].[Link] 0 195 0 18720 minutes, 59 seconds.
62 days, 0 hours, 7
.[Link].[Link].[Link].[Link].[Link] 262 752 19991 62416 minutes, 28 seconds.
62 days, 0 hours, 8
.[Link].[Link].[Link].[Link].[Link] 202 315 20396 30367 minutes, 3 seconds.
62 days, 0 hours, 7
.[Link].[Link].[Link].[Link].[Link] 195 195 12864 12870 minutes, 58 seconds.
62 days, 0 hours, 7
.[Link].[Link].[Link].[Link].[Link] 0 195 0 18720 minutes, 59 seconds.

  
: hlHostControlIndex : alHostTimeMark : protocolDirLocalIndex,
: nlHostAddress :protocolDirLocalIndex
85
Application Layer Matrix Group rmon 17

rmon 17 1 rmon 17 2

alMatrixSDTable alMatrixDSTable
alMatrixSDEntry alMatrixDSEntry
alMatrixSDTimeMark alMatrixDSTimeMark
alMatrixSDPkts alMatrixDSPkts
alMatrixSDOctets alMatrixDSOctets
alMatrixSDCreateTime alMatrixDSCreateTime

INDEX { hlMatrixControlIndex, alMatrixSDTimeMark, protocolDirLocalIndex,


nlMatrixSDSourceAddress, nlMatrixSDDestAddress, protocolDirLocalIndex }

INDEX { hlMatrixControlIndex, alMatrixDSTimeMark, protocolDirLocalIndex,


nlMatrixDSDestAddress, nlMatrixDSSourceAddress, protocolDirLocalIndex }

86
Application-Layer Top N Matrix
alMatrixTopNControlTable
rmon 17 3
alMatrixTopNControlEntry
alMatrixTopNControlIndex
alMatrixTopNControlMatrixIndex
alMatrixTopNControlRateBase
alMatrixTopNTerminalsPkts(1), alMatrixTopNControlTimeRemaining
alMatrixTopNTerminalsOctets(2), alMatrixTopNControlGeneratedReports
alMatrixTopNAllPkts(3), alMatrixTopNControlDuration
alMatrixTopNControlRequestedSize
alMatrixTopNAllOctets(4)
alMatrixTopNControlGrantedSize
alMatrixTopNControlStartTime
alMatrixTopNControlOwner
alMatrixTopNControlStatus
collection only from protocols that
have no child protocols that are counted.

87
alMatrixTopNTable
rmon 17 4

alMatrixTopNTable
alMatrixTopNEntry
alMatrixTopNIndex
alMatrixTopNProtocolDirLocalIndex
alMatrixTopNSourceAddress
alMatrixTopNDestAddress
alMatrixTopNAppProtocolDirLocalIndex
alMatrixTopNPktRate
alMatrixTopNReversePktRate
alMatrixTopNOctetRate
alMatrixTopNReverseOctetRate

INDEX { alMatrixTopNControlIndex, alMatrixTopNIndex }

88
User History Collection Group rmon 18

rmon 18 1

usrHistoryControlTable
usrHistoryControlEntry
usrHistoryControlIndex
usrHistoryControlObjects
usrHistoryControlBucketsRequested
rmon 18 2 usrHistoryControlBucketsGranted
usrHistoryControlInterval
usrHistoryObjectTable usrHistoryControlOwner
usrHistoryObjectEntry usrHistoryControlStatus
usrHistoryObjectIndex
usrHistoryObjectVariable absoluteValue(1),
usrHistoryObjectSampleType deltaValue(2)

INDEX { usrHistoryControlIndex, usrHistoryObjectIndex }

89
User History Table
rmon 18 3

usrHistoryTable
usrHistoryEntry
usrHistorySampleIndex
usrHistoryIntervalStart
valueNotAvailable(1),
usrHistoryIntervalEnd
usrHistoryAbsValue valuePositive(2),
usrHistoryValStatus valueNegative(3)

INDEX { usrHistoryControlIndex, usrHistorySampleIndex,


usrHistoryObjectIndex }

90

You might also like