Build Your Own NOC
Geminus writes "Ever wanted to build a cheap NOC but had difficulty explaining tech stuff to bean counting managers? Here's the basics on building one for under two grand. Makes for a pretty good dog-n-pony show, and proves useful too! Damn, I want to be an Armchair Network Operations Center General."
NOC=Nitrous Oxide Computing.
I guess you can build your own NOC, but if you don't have enough bandwidth, you can't teach others how to do it.
There have been 4 comments so far and the story is already slashdotted!
Jory
I was part of a company that wanted to branch into network management for others
problem was, to sell your services as a NOC, you have to already have it built, which we didn't have...we had a bunch of fake looking tools, though...
where was this two years ago when I needed it...LOL
RB
----------
ah honey, we're all resplendent - Bill Mallonee
Just add an LCD projector and I can play a 3d shooter on the big screen while keeping track of network packets.
It must have been a *really* cheap NOC!
Network Operations Center
The NOC advisory "Your first Monitor should be watching CNN or the weather channel"
Change that to Slashdot, Kuro5in, TheRegister, ThtOnion or something else. No CNN please.... if you have any sense of self-esteem, that is.
-
If you keep throwing chairs, one day you'll break windows....
A Website Dedicated to Computer Professional...and some not so Professional
.4a.iso?download
How to build a cheap Security NOC
William M. Nett
The Network Operations Center or NOC is the cornerstone of all computer networks. I've worked at AT&T's NOC, been around Government NOCs and seen small scaled versions. Most look like something out of the movie, "WarGames" and surprisingly, whether you're a Linux or Windows fan you can build one for cheap and be your own armchair NOC General.
What does a NOC do? It monitors connections, network activity, spots problems, conducts threat assessments, and calculates scalability requirements with customer demands... it also puts on a pretty good "dog-n-pony" show for potential investors and customers.
What's required? Again, surprisingly not too much! Depending on the size of your company, this can be achieved with as little as an 8' X 10' room, and 4 computers. Trust me, you more than likely do not need a $15,000 Cisco PIX or Nokia firewall (which runs Linux derivatives).
You'll need at least three big monitors (the bigger the better), two smaller ones (17"), a KVM switch, and OOB dialup. Here's the loadout:
1. Firewall: Get a copy of IPCOP... its Smoothwall on steroids and very easy to configure. It has a built in Intrusion Detection System, Proxy logging, and you can use Coyote Linux as a failover if you think you are being attacked. This package uses a web interface, so there's no need for a
monitor, keyboard, or mouse. These software elements are also free. Minimum requirements are a 333Mhz system with 64MB of RAM and a 2.1GB Hard-Drive.
2. Network Monitoring: Download a copy of F.I.R.E. and run it on a barebones 600 Mhz system. Configure and open Etherape on a monitor for an Air Traffic Controller's view of your network activity... bean counters love this. If you're being attacked or infected, you will quickly see where it's coming from. You should also use a receive only sniffer cable on this box to protect integrity... a receive only box has a zero chance of infection as it's physically impossible.
3. Got wireless? Download and run Airsnare with a semi hyped up Wireless antenna, and you'll quickly spot any war-drivers or unauthorized network connections. If you have an old directional motorized TV antenna system lying around you can go uber-elite and connect a cheap phased array panel antenna or cantenna to locate your wireless intruder with NetStumbler. This can all equally run on a 333Mhz Windows based system.
4. Workstation: Here's the beef... a 1.2Ghz, 512MB, 20GB computer, with dual head Matrox card, with dual booting OS (Linux & Windows), Preferably Linux with a Windows VMWARE guest OS. Trust me, once you go Dual-Head, you won't go back. The best Linux Dual-Head OS is SuSE 8.3. Tie this into the KVM to modify any of your servers.
5. Red Phone... afterall, who doesn't want one? You're batman right?
Your first Monitor should be watching CNN or the weather channel (depending on location), the second should be running Etherape, and the third should be running Airsnare or Windows Services Monitors (CPU, Netload, etc.) All of the software here except Windows is free, and easy to configure... except maybe your General's chair. In the end, aside from having your own
WOPR, you have a NOC for just under $2,000.00
William M. Nett
Links:
http://www.ipcop.org
http://www.coyotel inux.com
http://prdownloads.sourceforge.net/biatc hux/fire-0
http://etherape.sourceforge.net/ images/v0.5.5.png An etherape screenshot
http://www.netstumbler.com
http://hom e.comcast.net/~jay.deboer/airsnare/downl oad.htm
Search Now:
E-mail your comments to dougchick@thenetworkadministrator.com
All rights reserved TheNetworkAdministrator.com
Disclaimer: The Opinions shared on TheNetworkAdministra
For those who are wondering...
A NOC is a Network Operations Center. It is one room, typically filled with many displays of real-time data which display the health/status of a network.
I'd rather be a conservative nutjob than a liberal with no nuts and no job.
what if your boss/manager saw this and decided this is all you needed for your budget?
Hard to justify higher costs when your proof of concept is some webpage discovered by your boss, we've all been there.
Geezus... Everyone who's a true nerd knows that the WOPR is the War Operations box that was in the movie WarGames (Matthew Broderick)....
You know, the movie that made it absolutely *impossible* to get a dial-up into any BBS in the country for about 3 weeks after the movie came out...
Then again, I've been hacking around since about '76, so maybe I'm just showing my age...
>
1. SuSe 8.3 does not exist, it's in fact either 8.2 or 9.0.
2. There is curently no dual head driver from Matrox Parhelia. Olders Matrox's video card has dual head driver, but they don't work anymore with "recent" motherboard since motherboard's voltage is changed from 3.5 to 5 volts. And yes, 1.2 ghz-era computer are affected by this voltage change.
3. Vmware will be too slow with this configuration do to something really useful. Especially with dual heading.
4. This article is either a fake or a troll.
You need:
1. A good network management system (Open-NMS)
2. A good systems monitoring system (MRTG+RRD Tool)
3. A good helpdesk software to follow trouble tickets.
Bashed out a window so a fan can circulate air, installed 4 of the cheap open frame racks, use a OpenBSD firewall and all of our servers run FreeBSD. It costs next to nothing to set up. Idiots down the hall from us spend $1.5 million on their room, $100K just for the air conditioner. The funny thing is they do 1/100th of the traffic we do. Believe me, the "IT" industry is set up to rip you off if you don't know what you're doing. This stuff can be done a lot cheaper than the suits lead you to believe. This is how we survived the bubble while the floor outside our door got marked up from other occupants expensive equipment getting moved in, and then out!
Mirror Here. I'll mirror the rest of the page, as soon as he recovers from the shock and replaces the charred, smoking remains of the server he once had.
I was told that I could listen to the radio at a reasonable volume from nine to eleven...
There is *not* a heck of a lot of content here.
Most of the information is more than obvious to anyone interested in running a NOC (incidently, left out of the Slashdot story is that this is a *Security* NOC).
I've seen random Slashdot posts that would be a lot more useful to someone interested in building a NOC than this thing.
That being said, my own two cents:
If you're using SNMP to manage your network, snmpwalk+scripts is good. If you can stomach not using open source software, Intermapper is really nice. Unfortunately, the two big open source competitors don't quite measure up -- Scotty is kind of old and grotty and rather TCL-oriented, and GxSNMP appears to be dead.
Etherape, as suggested in the article, isn't the greatest choice either...IIRC, it doesn't support satellites, which means it needs to be running on the actual network it's monitoring. Not really acceptable for a NOC tool. Etherape is also, in my experience, rather CPU-hungry. There are a lot of commercial traffic flow visualization tools...not sure what's best, as I haven't played with many.
All in all, while the article's worthy of a post in a random discussion, it really isn't worthy of a Slashdot story.
May we never see th
Or, perhaps someone will come up with the bright idea to let you shoot packets whilst in the 3d game...
Kind of like psDooM (as seen on Slashdot), but at the network level? I'll betcha it could be done.
Carthago delenda est!
With very few exceptions (military, financial, public utilities sectors), it's pretty passe to have a 24/7/365 manned NOC, anymore, given VPN technology, the quality of remote-administration tools, etc.
It just isn't necessary, anymore.
The article calls for:
1) At least three big monitors (the bigger the better), two smaller ones (17"), a KVM switch, and OOB dialup.
2) A 333Mhz system with 64MB of RAM and a 2.1GB Hard-Drive.
3) A barebones 600 Mhz system
4) A 333Mhz Windows based system.
5) A 1.2Ghz, 512MB, 20GB computer, with dual head Matrox card, with dual booting OS (Linux & Windows), Preferably Linux with a Windows VMWARE guest OS
All the above for under $2000.00? Can we also assume that the author works for free, so that setup cost is $0.00? I haven't priced VMWARE in a long time, but if memory serves, that should be near or over the 2K mark by itself. Perhaps the author meant under $20,000.00? What am I missing here folks?
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
I used to host with a fine place, but disagreements over costs and bandwidth usage charges inspired me (along with the purchase of my home) to host in my own basement. I have 3-4 customers, and we'll keep it at that. Bandwidth is a T-1. And I think the place looks pretty sharp. This is also where textfiles.com and bbsdocumentary.com are hosted, so it works for me.
This is the website: http://fire.dmzs.com/
How many other people out there, went over the correct shade of yellow for the alarm lights with a vendor? Funny stories about NOC design. This thread could have some very interesting stuff, if people would let some company secrets slip. ;)
.com ish, but they do feel great.
But onto my point.
Biggest thing about a noc, is you need to see the alarm, other than taking action, missing an alarm is the worst design flaw. Filter, Page, auto-ticket, there are many things a professional NOC can lend some experience on design. Not everything has to cost, in fact many opensource software works great. (Big Brother anyone?)
BTW, windows and vmware? Pfft.. Worst thing you want is a crash in the middle of working, Solaris and xterms. Eye-candy is the worst thing to get in the way of working outages.
Humm, also a good ticketing system is important, if you want to page out someone, you need to have enough detail for the person to do their job.
Oh yea, give me an Aeron Chair also. I know, its
You might want to have a look at Akamai's NOC at http://www.akamai.com//en/html/about/nocc_tour.htm l
Pictures of Akamai's NOC also were in the Wired article about the Slammer Virus a few months ago.
I used to work in a NOC of a major cellphone carrier. Working in shifts, staring at your HP Openview, no coffee/food at your desk, boring calls from the staff "Oh, the connection to server ABC isn't working. Do something!" - and when really something goes wrong you feel you want to be an octopus - you need 8 arms for 8 phones.
Essentially the job is: Stare at network map, wait for thingys to blink, make calls.
Yalla.
You look like a million dollars. All green and wrinkled.
...is indeed the greatest thing since sliced bread. I've had it for about 2.5 years now, and one day when my primary monitor went out, I almost couldn't function. Being able to have Visual studio open in one screen and All sorts of Docs and a web browser in the other, I don't know how I did it before...
In the same vein, nVidia included a really nice feature in their latest drivers (I think it's been around since the 4x.xx series, but it wasn't as refined) that lets you "throw" a window. Pure genius, whoever invented that. With 2048 pixels of desktop space, it actually takes over an entire mousepad to move a window across the desktop. With throwing, I just flick my mouse. If I have a few IM windows open, a few Putty terminals, etc etc, it's great to just get stuff out of the way real fast and put it all into a known area.
Slashdot is proof that Sturgeon's Law applies to mankind.
Although, some companies may have NOC's for no good reason... NOC's do have their places. I am a webhost (a small one) and our servers are in datacenters with thousands (in many cases tens of thousands) of other such machines. There are always at least one or two techs around in the wee hours of the night and a NOC is most certainly necessary to monitor all these machines and the network.
There is NO way a laptop can replace a NOC in such a case. You need a centralized area where everything is monitored. As for remote administration, it's always been pretty decent with Unix (and in our case it's linux mostly) but that just helps the NOC become more useful for us.
Hmmm... Pie...
You can turn in your Geek ID on the way out, as you won't have any further need for it. The geek that has not seen WarGames is not the true geek.
20 January 2017: the End of an Error.
It really is what you hear the Burger King employee whisper into that gooseneck microphone:
"WOPR, large Fries"
-- You are in a maze of little, twisty passages, all different... --
It would really be better if stories like this were not chosen for the front page. Whenever a story is posted with unexplained acronyms, tons more people click the links to see wtf it's talking about. More people who don't care about the actual (obscured) topic needlessly eat up the bandwidth, and the links are slashdotted much sooner. I know this is off-topic, however it does pertain to this story...
How is it there is an article about a homebrew N.O.C. that doesn't mention Nagios?
Everyone's so Anonymous Coward these days! Shame.
Quick explanation for the shot. It's a stitched together panorama shot, using software. It didn't come out like I'd like it to, so I will obviously have to retake it at some point. There are two lisas; there's an artifact of the one lisa looking like two. If you look around it, the shelf blends as well.
Other machines in there that might not be obvious: Vic-20s, C-64s, Apple IIc, Apple IIs (5), Macintosh SE (painted cow colors), Sun Ultra 2, Amiga 500s (3), Commodore PET (my first computer, given to me by dad when I was 9), Atari 800, and a metric ton of PC Compatibles. Oh, and a Microwave.
As for the tree, my home is about 110 years old, and they used actual tree trunks for supporting beams. Multiple inspectors say they're as good or better than other choices for supports, so they stay. I like them, and they're great conversation pieces.
This article was a complete waste of time..
I could just as easily post an article saying 'Get *4* Tires, *2* axells, and engine, and a few other things. Toss them all together, and you just made your own CAR!!'
I mean cripes. It's not talking about ANYTHING besides 'buy cheap puters and put neat graphics up'.
I've had bosses that could have written this article.. Heck, I bet they did. 'Whatcha wantt a fluke for? I mean, we BUILT you a NOC for a grand!!' Bear in mind, the 'NOC' was a closet with two monitors I salvaged..
I dunno, perhaps I'm just getting old but..
I fee like I just wastes a good minute of my life reading that..
-- I'm the root of all that's evil, but you can call me cookie..
There are some vulnerabilities for passive monitoring also. A search of CERT database for snort or tcpdump gives you a following list:
A listen-only box gives you some protection but it cannot be the only protection for your traffic recorder.
What's the point of being Napoleon and BOFH of your own NOC if you don't have lusers to abuse? I think I might have an answer, however.
Tapping the vast pool of cheap out-of-work IT workers, LUSERS'R'US can provide a simulated load of lusers on your network -- Even with an adjustable rate of phone calls with silly-assed questions and problems for home NOC commanders to deal with.
If you want to be a real BOFH, you can't reign in hell without some damned souls to boss around. You need us. You need LUSERS'R'US!
One line blog. I hear that they're called Twitters now.
Unless you suffer from a power outage. Then your 'NOC' is down, your servers down. Everything is useles and out of your control.
Author should mention either hopping on eBay and getting a used rackmount UPS or building a battery backup yourself using car batteries. As crude as it sounds if you have the space (a seperate room) you can build a huge battery back up system for (relatively) next to nothing and be able to simply add more batteries for longer uptime, etc.
-
aphex
I Steal Music!
Can't underestimate the importance of some news channel on at all times. During August of this year, we were in our NOC and we saw our power blip for a second and heard the UPS alarms from the adjacent machine room. Shortly thereafter, we found out we were on diesel power. Our monitoring tools began to show remote devices going down, some coming back, some not. I noticed my SSH session to home died around the same time. I began to worry. I called my house to see if my answering machine would pick up. No dice. It was at this point we realized a big power failure had hit us. A few minutes later, the reports started coming in on CNN that all of New York had gone down, etc. Eventually it all made sense, but it was definitely important to have CNN... even if we knew about the power failure before they did.
"Nature doesn't care how smart you are. You can still be wrong." - Richard Feynman