440 likes | 638 Views
OAUNETMON: A Network Traffic Monitoring Tool. Olatunde Abiona Lecturer/Computer Engineer Department of Computer Science & Engineering Obafemi Awolowo University, Ile-Ife, NIGERIA. World Map. ©1996 MAGELLAN Geographix Santa Barbara, CA (800) 929-4MAP . Africa.
E N D
OAUNETMON: A Network Traffic Monitoring Tool Olatunde Abiona Lecturer/Computer Engineer Department of Computer Science & Engineering Obafemi Awolowo University, Ile-Ife, NIGERIA
World Map ©1996 MAGELLAN Geographix Santa Barbara, CA (800) 929-4MAP
Nigeria Ile-Ife
Obafemi Awolowo University, Ile-Ife Oduduwa Hall
Obafemi Awolowo University, Ile-Ife College of Health Sciences building
Obafemi Awolowo University, Ile-IfeComputer Science & Engineering Dept.
Outline of the Presentation • Introduction • The Obafemi Awolowo University Network (OAUNet). • Design/Architecture of OAUNETMON. • Some screen shots of OAUNETMON. • Conclusions
The Obafemi Awolowo University Ile-Ife, Nigeria • 250km North-East of Lagos • 20,000 students, 13 faculties and 2 colleges • Campus network: TCP/IP protocol and LINUX operating system. • Wireless spread spectrum radio technique for linking buildings • Over 600 individual account users, within a year of operation. • Capacity building component provided critical mass of competent Technical Staff
The Obafemi Awolowo University. Network (OAUNet). • Was born out of a collaboration between International Centre for Theoretical Physics (ICTP), Trieste Italy and Obafemi Awolowo University (OAU) Ile-Ife Nigeria (1996). • Started with 3 subnets now over 14 subnets and 9 cyber cafes. • Full Internet connectivity ie 256 Kbps Uplink and 512 Kbps Downlink bustable to 1Mbps.
OAUNET - Main Network Diagram VSAT Earth Station 64 Kbps AP 2Mbps Main HUB Dial up MODEM 33 Kbps Key sc - sciences tech - Technology cs - Computer Science usb - Secretariat chs - Health Science Agric- Agriculture NC - NACTEM OA - OAU Teaching hospital First Generation sc tech cs Second Generation usb chs agric Third Generation NC OS OS OS Fourth Generation OS OS OS OS C C Fifth Generation OS OS C C C
Main HUB or network WLAN Antenna Inter Subnet Router Mail Server WEB Server Terminal Equipment Backup Server Modem Server Proxy Firewall CISCO router Pentium IV PCs 100 base Tx Ethernet Backbone
Architecture of Most Subnets SA 2 Mbps link to Main network Antenna Subnet Server (UNIF II) INTEL Pentium CPU Powered by Linux Local DHCP Server Local NIS Server Local DNS Server Local Telnet Server Campus Wide NFS Static Router Masquerading and IP forwarding WaveLan cards SWITCH One or more client computers Running Windows or Linux + KDE Provide Print services, and telnet clients Auto- configured through DHCP Ethernet
Features of OAUNETMON • Non-Intrusive Network Monitoring system. • Web-based network monitor and analysis system • Capable of Handling Large log files • Capable of monitoring Fast Ethernet or switched network. • Capable of analyzing Proxy logs (squid access log flies)
Design Consideration • Powerful user interface – web interface • Guaranteed packet capturing – uses gigabit interface for data capture • Classification of all protocol information – ability to classify and display all possible protocol in each layer • Security – Access are restricted only to those with valid username and password. • Viewing of real-time and historical data – shows online real-time status data and accumulated historical status data easily
Equipment required for the setting up OAUNETMON • Pentium iv 2.0Ghz CPU • 1.0GB Ram, 80.0GB HDD • FDD, CD Writer 40X • 1Gigabit Ethernet Switch (D-link DES-3226L) • 1Gigabit Network interface card • 700VA UPS • Linux Operating System ( Mandrake 10.1)
Proxy Log Analysis • OAUNETMON also carryout proxy log analysis on squid access log
Some Bandwidth optimization Technique • CBQ • HTB • Mirroring • Firewall • Filtering • Deny, Reject, Redirect …based on firewall rules • SQUID • Web caching • Access control list • Authentication • Delay pools • it is possible to limit internet traffic in a reasonable way depending on so-called 'magic words', existing in any given URL For example, a magic word could be '.mp3', '.exe' or '.avi', etc.
OAUNETMON Installation • Install linux • /tmon • /logf • Install Mrtg • Install Webalizer • Iptraf • Install Apache • Replace your back bone switch with a Gigabit Switch that can support Port mirroring • Download all files from • http://www.ictp.it/~abionao/tunde To appropriate directories • Restart your computer!
OAUNETMON DEMO • http://82.206.239.38/oaunetmon/
Conclusion • Experimental design goals such as extracting highly detailed information without adversely affecting network performance (speed) is archived through a process of extracting the required information from IP packet without considering the contents. The scripts are available at http://www.ictp.it/~abionao .
Acknowledgement • We wish to acknowledge the support of the Abdus Salam International Centre for Theoretical Physics (ICTP) for the donation of the equipment used for this study.