nagios conference 2014 - gerald combs - a trillion truths

41
A Trillion Truths Gerald Combs [email protected] @geraldcombs

Upload: nagios

Post on 19-Dec-2014

183 views

Category:

Technology


2 download

DESCRIPTION

Gerald Combs's presentation on A Trillion Truths. The presentation was given during the Nagios World Conference North America held Oct 13th - Oct 16th, 2014 in Saint Paul, MN. For more information on the conference (including photos and videos), visit: http://go.nagios.com/conference

TRANSCRIPT

Page 1: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

A Trillion TruthsGerald [email protected]

@geraldcombs

Page 2: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Why Am I Here?

Dunno. Ask Ethan.

Page 3: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Nagios @ wireshark.org

Page 4: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

What's happening on your network?

Page 5: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Nagios Is Paging Me

Is this the cause?

Page 6: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Packet Analysis

Page 7: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Wireshark is a Dissection Engine

Page 8: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Wireshark is a Community

Page 9: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Who uses it?Network engineer: Troubleshooting toolSecurity engineer: Forensics toolDeveloper: Debugging toolEducator: Teaching toolProtocol designer: Validation tool

Page 10: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Open Source Business Models

Small? Use GitHub

Large? Get Google or IBM to give you piles of money

Medium? Uhhhh…

Page 11: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Complementary Products

2006: CACE Technologies

2010:

Page 12: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Finding Network Truths

Page 13: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Your 5 Minute Average Is Full Of Lies

Page 14: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

14

Did the interval look like this…

Page 15: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Copyright Riverbed Technology 15

…or this…

Page 16: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

16

…or this?

Page 17: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

17

Maybe this…

Page 18: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

18

…or this

Page 19: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

The Packets Never Lie

Different truths at different layers

What do you do with a trillion truths?

Page 20: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Capturing At Zero Scale

1. Start tcpdump.2. Say "Try it now."3. Stop tcpudmp. scp the capture & analyze.

Page 21: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

21

Visibility You Want

Flows

Bits

NowDawn of Time

You'll have to make your own surveillance jokes. I have to go through a TSA checkpoint tomorrow.

Page 22: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

22

Visibility You Get

Flows

Bits

NowDawn of Time

Page 23: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Retrospective Analysis

Cheap: Laptop or server running dumpcap or tcpdump

Fancy: Dedicated boxes

Time equals money. And disks. Time equals disks.

Page 24: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Port Mirroring

Pros

Any1 switch does this…Just a config change…

Cons

…often poorly…requiring change control

1. Any switch you'd want to use in production.

Page 25: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Taps

Pros

PassiveTime accuracyFilteringDuplication

Cons

CostExtra hardwareSometimes a switch

Page 26: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

VM Capture

Where do you want to kill performance today?

Jasper Bongertz:http://blog.packet-foo.com/2013/04/capturing-packets-of-vmware-machines/http://blog.packet-foo.com/2013/04/capturing-packets-of-vmware-machines-part-2/

Page 27: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Cloud Capture

Like VM but with less control.

Back to tcpdump. Seriously?

Page 28: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

SDN, or Why Cloud Capture Annoys Me

Microsoft (Rich Groves): DEMonBig Switch: Big Tap

Distributed tap built on SDNScales to thousands of ports

Page 29: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Using Wireshark For The First Time

http://en.wikipedia.org/wiki/File:Airbus_A380_cockpit.jpg

Page 30: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Educational Resources

Wireshark Q&A · https://ask.wireshark.org/Laura Chappell · http://www.wiresharkbook.com/ Mailing lists · https://www.wireshark.org/lists/Sharkfest · http://sharkfest.wireshark.org/Bibliography · https://www.wireshark.org/bibliography.html

Page 31: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

More Educational Resources

Hansang Bae · http://www.riverbed.com/blogs/authors/Hansang-Bae.htmlMore Hansang · https://blog.wireshark.org/Tim O'Neill · http://www.lovemytool.com/Jasper Bongertz · http://blog.packet-foo.com/

Page 32: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Latency – 2012

Page 33: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Latency – 1996

Page 34: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Latency – 1976

http://bitsavers.informatik.uni-stuttgart.de/pdf/xerox/ethernet/XeroxWireDraft_Dec1976.pdf

Page 35: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

…and yet…

Page 36: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Wireshark Today

Large, vibrant ecosystemHundreds of authorsStatistics:

1500 protocols117k filter fields500k 1M downloads / month2M lines of codeRich web presence

Your network is not a black boxhttp://www.hanselman.com/blog/TheInternetIsNotABlackBoxLookInside.aspx

Page 37: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

What's Next?

Page 38: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Challenges

To install on OS X you need a bucket and a screwdriverPacket analysis + tablet = sadness"The cloud" is not in the interface list400GBASE-OUCH-THAT-HURTSYou want process information? Too bad

Page 39: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

We made the news

Page 40: Nagios Conference 2014 - Gerald Combs - A Trillion Truths

Demo Time

Page 41: Nagios Conference 2014 - Gerald Combs - A Trillion Truths