Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /usr/local/webview/flowage/flowage.cfg
- Fri May 26 15:14:23 2017
- # =====================================
- # Flowage Sample Configuration
- # =====================================
- # ----------------------------------------------------------------------------
- # flowage globals
- # ----------------------------------------------------------------------------
- directory watch /opt/netflow/capture/2055
- directory data /opt/netflow/data
- directory temp /opt/netflow/tmp
- directory cache /opt/netflow/cache
- directory hierarchical
- logging file flowage.log
- logging size 1_000_000
- index file flowage.idx
- # "fork" sets the number of concurrent processes.
- # fork 4
- # log the autoclock
- track all -clockGood
- click strict-other
- period 300
- # ----------------------------------------------------------------------------
- # define one or more SNMP session data structures
- # ----------------------------------------------------------------------------
- snmp-session snmpDefault
- version=2 # snmp version
- community=[removed] # set your own community here
- # ----------------------------------------------------------------------------
- # define all the netflow exporters that we'll see data from.
- # ----------------------------------------------------------------------------
- exporter auto 0.0.0.0/0 snmpDefault
- exporter no-unknown-interfaces
- # ----------------------------------------------------------------------------
- # define a matrix based on interfaces seen in the flows
- # ----------------------------------------------------------------------------
- if-matrix Interfaces auto aliases=simple
- # ----------------------------------------------------------------------------
- # define output files that might be interesting to look at.
- # ----------------------------------------------------------------------------
- ip access-list extended TRAFFICOUTBOUND
- permit ip 192.168.0.0 0.0.0.255 any
- datafile rrd Applications
- Interfaces Applications
- Step=60 AutoClock Timestamp=average
- IPTracking
- out=TRAFFICOUTBOUND
- index description Applications "View traffic by application"
- # ----------------------------------------------------------------------------
- # define a group of services containing ACLs that match applications we're
- # interested in. The ACLs are defined later.
- # ----------------------------------------------------------------------------
- group Applications
- Internet_HTTP
- Intranet_HTTP
- Print
- Network
- Email
- LDAP
- FTP
- Shell
- SQL
- Citrix
- CiscoWAFS
- TSM_Backup
- MS_File
- MS_RPC
- MS_Remote_Desktop
- VPN
- Multicast
- IPT_g711
- IPT_g711_untagged
- IPT_g729
- IPT_g729_untagged
- IPT_Signaling
- # ----------------------------------------------------------------------------
- # subnets considered "internal"
- # ----------------------------------------------------------------------------
- ip host-list @local_subnets
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 224.0.0.0/4
- # ----------------------------------------------------------------------------
- # heuristic analysis of Microsoft RPC traffic
- # ----------------------------------------------------------------------------
- ip access-list extended EPM
- permit tcp any gt 1023 any eq 135
- dynamic EPM flow %MSRPC_Flows timeout 1
- # ----------------------------------------------------------------------------
- # define ACLs
- # ----------------------------------------------------------------------------
- # --- internet protocols
- ip access-list extended Internet_HTTP
- deny ip host @local_subnets host @local_subnets
- permit tcp any any eq 80 reverse # HTTP
- permit tcp any any eq 443 reverse # HTTPS
- ip access-list extended Intranet_HTTP
- permit tcp host @local_subnets host @local_subnets eq 80 reverse # HTTP
- permit tcp host @local_subnets host @local_subnets eq 443 reverse # HTTPS
- ip access-list extended MS_File
- permit tcp any any eq 445 reverse # CIFS
- permit tcp any any range 137 139 reverse # NETBIOS
- permit udp any any range 137 139 reverse # NETBIOS
- ip access-list extended MS_RPC
- permit tcp any any eq 135 reverse # EPM
- permit tcp host $srcip gt 1023 host $dstip gt 1023 flow %MSRPC_Flows reverse
- ip access-list extended MS_Remote_Desktop
- permit tcp any gt 1023 any eq 3389 reverse # RDP
- ip access-list extended FTP
- permit tcp any any range 20 21 reverse # FTP
- permit tcp any any eq 990 reverse # FTP/SSL
- ip access-list extended Citrix
- permit tcp any gt 1023 any eq 1494 reverse # ICA (old)
- permit tcp any gt 1023 any eq 2598 reverse # ICA (new)
- ip access-list extended CiscoWAFS
- permit tcp any gt 1023 any eq 4050 reverse # Cisco WAFS
- ip access-list extended TSM_Backup
- permit tcp any gt 1023 any eq 1500 reverse # TSM
- ip access-list extended Print
- permit tcp any any eq 515 reverse # LPR
- permit tcp any gt 1023 any eq 9100 reverse # HP
- ip access-list extended VPN
- permit udp any any eq 500 reverse # ISAKMP
- permit udp any any eq 4500 reverse # NAT-T
- permit esp any any # ESP
- permit ah any any # AH
- ip access-list extended Network
- permit udp any any eq 53 reverse # DNS
- permit udp any any eq 123 reverse # NTP
- permit udp any any range 161 162 reverse # SNMP
- permit udp any any range 67 68 reverse # DHCP
- permit udp any any eq 427 reverse # SLP
- permit icmp any any # ICMP
- permit eigrp any any # EIGRP
- permit ospf any any # OSPF
- permit tcp any any eq 179 reverse # BGP
- permit udp any any eq 520 reverse # RIP
- permit udp any any range 1645 1646 reverse # RADIUS
- permit udp any any range 1812 1813 reverse # RADIUS
- permit udp any any eq 514 reverse # SYSLOG
- permit udp any any eq 2055 reverse # NETFLOW EXPORT
- ip access-list extended Email
- permit tcp any any eq 25 reverse # SMTP
- permit tcp any any eq 143 reverse # IMAP
- permit tcp any any eq 110 reverse # POP3
- permit tcp any any eq 465 reverse # SMTP / SSL
- permit tcp any any eq 993 reverse # IMAP / SSL
- permit tcp any any eq 995 reverse # POP3 / SSL
- ip access-list extended Shell
- permit tcp any any eq 22 reverse # SSH
- permit tcp any any eq 23 reverse # Telnet
- permit tcp any any eq 514 reverse # RSH
- ip access-list extended LDAP
- permit tcp any any range 389 390 reverse # LDAP
- permit udp any any range 389 390 reverse # LDAP
- permit tcp any any eq 636 reverse # LDAP/SSL
- permit tcp any any eq 379 reverse # LDAP Site replication
- permit tcp any gt 1023 any range 3268 3269 reverse # LDAP Global Catalog
- ip access-list extended SQL
- permit tcp any gt 1023 any eq 1521 reverse # Oracle TNS Listener
- permit tcp any gt 1023 any eq 1523 reverse # Oracle SQLnet2
- permit tcp any gt 1023 any eq 1433 reverse # Microsoft SQL
- permit udp any gt 1023 any eq 1434 reverse # Microsoft SQL
- ip access-list extended Multicast
- permit ip any 224.0.0.0 15.255.255.255
- # --- IPT protocols
- ip access-list extended IPT_g711_untagged
- permit udp any gt 1023 any gt 1023 kbps range 76 84 seconds ge 5
- ip access-list extended IPT_g711
- permit udp any any dscp ef kbps range 76 84
- ip access-list extended IPT_g729_untagged
- permit udp any gt 1023 any gt 1023 kbps range 20 28 seconds ge 5
- ip access-list extended IPT_g729
- permit udp any any dscp ef kbps range 20 28
- ip access-list extended IPT_Signaling
- permit tcp any gt 1023 any eq 2000 reverse # SCCP
- permit udp any range 2427 2428 any range 2427 2428 # MGCP
- permit tcp any gt 1023 any range 1719 1720 reverse # H.323
- permit tcp any gt 1023 any eq 5060 reverse # SIP
- permit udp any gt 1023 any eq 5060 reverse # SIP
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement