Configuring OPBNOS
Aviz OPBNOS provides a highly scalable, flexible and affordable solution to aggregate, filter and load balance network traffic from hardware or virtual TAPs to connected tools for analysis and visualization.
It provides line rate traffic forwarding using switching ASIC by configuring flow paths between two or multiple ports, By leveraging the OPBNOS solution, enterprises can easily scale up or down to meet the ever-changing demands of network visibility and security tools.
Download the latest build of OPBNOS from here
OPBNOS can be installed by following the installation guide
Login into the switch with default credentials
User: admin
Password: admin
Configure Management IP
configure terminal
interface mgmt
ip address 10.10.10.1/23 gateway 10.4.4.1
end
Configure network ports, these are the ports that connect to network-taps
configure terminal
interface ethernet Ethernet248
forward-error-correction rs
type network
end
Configure tool ports, these are the ports that connect to security tools
configure terminal
interface ethernet Ethernet252
forward-error-correction rs
type tool
end
Configure flow to filter and forward traffic
// Matching on L2 traffic
configure terminal
flow flow01
network-ports Ethernet248
tool-ports Ethernet252
rule 1 permit vlan 100 counters enable
rule 2 permit vlan 512 counters enable
enable
end
// Matching on L3 traffic
configure terminal
flow flow01
rule 1 permit src-ip 10.10.10.1/32 dest-ip 20.20.20.1/32 counters enable
rule 2 permit src-ip 213.22.1.2/32 dest-ip 112.23.42.2/32 protocol udp counters enable
enable
end
Verify configured flow
pbnoscli# show flow summary
Flow-Name Rule-Id Status Counter-Value
=========================================================
flow01 2 Active 52562
flow01 1 Active 56289
pbnoscli#
pbnoscli# show running-config
configure terminal
interface ethernet Ethernet248
forward-error-correction rs
type network
!
interface ethernet Ethernet252
forward-error-correction rs
type tool
!
interface mgmt
ip address 10.10.10.1/23 gateway 10.4.4.1
!
flow flow01
enable
network-ports Ethernet248
tool-ports Ethernet252
rule 1 permit src-ip 10.10.10.1/32 dest-ip 20.20.20.1/32 counters enable
rule 2 permit src-ip 213.22.1.2/32 dest-ip 112.23.42.2/32 protocol udp counters enable
!
pbnoscli#
Last updated
Was this helpful?