Escolar Documentos
Profissional Documentos
Cultura Documentos
Hansang Bae
Senior VP| Citi (f.k.a Citigroup)
hbae@nyc.rr.com
SHARKFEST '09
Stanford University
June 15-18, 2009
SHARKFEST '09 | Stanford University | June 1518, 2009
Challenges:
As it turns out, size does matter!
Citis branch network spans 5,000+ locations in
the US
Citis network infrastructure includes 30,000+
devices
300,000 users located in over 100 countries.
Number of servers in use is mind numbingly
large!
Compliance/Security Quagmire
Doing a full packet capture is difficult.
Tools in use include NetVCR and Opnets ACE.
Wireshark is the only approved protocol
SHARKFEST '09 | Stanford University | June 1518, 2009
analyzer
at Citi. It dislodged past market
Use STATISTICS, IO GRAPH to bring up this graph. Modify the highlighted items
to bring up this view
LBProblemNew.pcap
LBTCPHands hake.pcap
DCMove_Original_LookAt197.pcap
DCMove_OneSideLookAt10-11-12.pcap
DCMove_BothSideLookAt918.pcap
ACT I: ICMP_BHNew*pcap
192.168.1.1 and 192.168.1.254 are servers on the same switch.
ACT II: SlowSSHLoging2.pcap:
192.168.1.1 is the client. 172.16.50.50 is the ssh server. 192.168.75.75 and
192.168.200.200 are NIS+ servers.
ACT III: SlowFtpAnon.pcap
10.10.10.10 is the ftp server. 192.168.1.1 client is pulling the file from the server.
ACT IV: MQSlow.pcap
172.16.50.50 is the MQ server. 192.168.1.1 is the MQ client. The server is pushing the file to
the client.
ACT V: LBProblemNew.pcap
10.2.53.102 and 10.17.97.111 are users in different branches. 172.16.10.10 and 172.16.20.20
belong to the load balancer. 172.16.254.254 is the real web server. 172.16.10.10 is end user
facing IP of the LB and 172.16.20.20 is the IP used by the LB for source NATing when talking
to the real web server.
ACT VI: DCMove_*.pcap
192.168.1.102 and 172.16.1.125 are two servers involved in the transfer. Both send data
independently of one another.