본문 바로가기
WIKI 기술 지식 베이스

네트워크 구성 관리 (Network Configuration Management)

원문 보기 위키 갱신

NDM(Network Device Monitoring)을 확장해 장치 구성의 인식과 변경 추적을 제공하는 NCM(Network Configuration Management)을 안내해요. 구성이 시간에 따라 어떻게 바뀌는지 모니터링하고, 버전을 비교하며, 이전 구성으로 롤백할 수 있어요.

출처: 문서

본문

다음 Datadog 사이트 사용자에게 중요한 참고 사항: app.ddog-gov.com, us2.ddog-gov.com

이 제품은 선택한 Datadog site에서는 지원되지 않아요.

개요

네트워크 구성 관리(NCM)는 네트워크 장치 모니터링(NDM)을 확장해 구성 인식과 변경 추적을 포함하게 해요. NCM을 통해 다음을 할 수 있어요.

  • 장치 구성이 시간에 따라 어떻게 변하는지 모니터링
  • 두 구성 버전을 나란히 비교
  • AI 생성 요약을 사용해 장애 발생 중 변경 내용과 잠재적 영향 파악
  • 장치를 이전 구성으로 롤백

사전 요구 사항

설정

  1. Agent의 루트 구성 디렉토리 conf.d/network_config_management.d/에서 conf.yaml 파일을 만들고 다음과 같이 구성해요.

    init_config:
      ## @param namespace - string - optional - default: default
      ## The namespace should match namespaces of devices being monitored
      namespace: default
      ## @param min_collection_interval - integer - optional - default: 900 (15 minutes)
      min_collection_interval: 900
      ## @param ssh - object - optional
      ## Global SSH configuration that applies to all device instances unless
      ## overridden at the device level.
      ssh:
        ## @param timeout - duration - optional - default: 30 (seconds)
        ## Maximum time for the SSH client to establish a TCP connection.
        timeout: 30
        ## @param known_hosts_path - string - required (unless insecure_skip_verify is true)
        ## Path to the known_hosts file containing public keys of servers to
        ## verify the identity of remote hosts. Required for secure connections.
        known_hosts_path: /path/to/known_hosts
        ## @param insecure_skip_verify - boolean - optional - default: false
        ## Skip host key verification. This is INSECURE and should only be used
        ## for development/testing purposes.
        insecure_skip_verify: false
    instances:
      ## ip_address - string - required
      ## The IP address of the network device to collect configurations from.
    - ip_address: <IP_ADDRESS>
      ## @param auth - object - required
      ## Authentication credentials to connect to the network device.
      auth:
        ## @param username - string - required
        ## Username to authenticate to the network device.
        username: <USERNAME>
        ## @param password - string - required (if private_key_file is not provided)
        ## Password to authenticate to the network device.
        ## Used as a fallback after private key authentication if both are provided.
        password: <PASSWORD>
        ## @param private_key_file - string - optional
        ## Path to the SSH private key file for authentication.
        ## At least one of password or private_key_file must be provided.
        private_key_file: /path/to/private_key
    
  2. 선택적으로, 장치가 특정 SSH 알고리즘을 요구한다면 다음 구성을 사용해요.

    init_config:
      ## To confirm a possible value of algorithms, see the constants described in the golang document.
      ## https://pkg.go.dev/golang.org/x/crypto/ssh#pkg-constants
      ##
      ## @param ciphers - list of strings - optional
      ## List of SSH encryption ciphers to use for the connection.
      ## If not specified, the SSH library will use its default ciphers.
      ssh:
        ciphers: [[email protected], aes128-ctr, aes192-ctr]
        key_exchanges: [diffie-hellman-group14-sha256, ecdh-sha2-nistp256]
        host_key_algorithms: [ssh-ed25519]
    
  3. 구성 변경을 적용하려면 Agent를 재시작해요.

구성 보기

네트워크 구성 관리는 네트워크 장치 모니터링의 NDM 장치 보기에서 접근할 수 있어요.

  1. 네트워크 장치 모니터링으로 이동해요.

  2. 장치 목록 또는 Device Geomap이나 Device Topology 맵 같은 NDM 시각화에서 장치를 선택해요.

  3. NDM 장치 보기에서 Configuration 탭을 열어요.

Configuration 탭에서 구성 목록의 표시 범위를 필터링할 수 있어요.

  • All: 실행 중인 구성과 시작 구성을 모두 표시
  • Running: 장치에서 실행 중인 활성 라이브 구성
  • Startup: 장치가 부팅될 때 로드되는 저장된 구성

시간 선택기와 보존 기간

페이지 상단의 시간 컨트롤을 사용해 볼 구성 기록을 선택할 수 있어요. 이 범위를 확장해 보존 한도(1년)까지 이전 버전을 볼 수 있어요.

타임라인과 구성 버전 목록은 선택한 시간 범위에 따라 자동으로 업데이트돼요.

참고: 구성 기록은 계정에서 NCM을 활성화한 시점부터 시작돼요. 활성화 이전의 과거 데이터는 사용할 수 없어요.

특정 시점의 구성 보기

타임라인 또는 목록에서 구성 이벤트를 선택하면 해당 순간의 장치 상태를 보여주는 단일 구성 보기가 열려요.

단일 구성 보기는 다음을 표시해요.

  • 선택한 타임스탬프의 전체 구성
  • 시간과 장치 식별 정보를 포함한 장치 메타데이터

구성을 스크롤해 장애 중 장치 상태를 조사하거나, 시간 범위를 조정해 다른 기간의 구성을 볼 수 있어요.

구성 버전 비교

구성 버전 간의 변경 사항을 보려면:

  1. 체크박스를 사용해 기록 목록 또는 타임라인에서 두 구성을 선택해요.

  2. Compare Two Configs를 클릭해 비교 보기를 열어요.

비교 보기는 변경된 줄을 강조하는 인라인 diff와 함께 두 구성을 나란히 보여줘요. 비교 보기를 닫지 않고도 서로 다른 구성 쌍 사이를 전환할 수 있어요.

이전 구성으로 롤백

구성 변경이 문제를 일으키면 Datadog에서 직접 장치를 이전 구성으로 복원할 수 있어요. 롤백은 Private Action Runner를 사용해 선택한 구성을 장치에 복원해요.

설정 및 사용 지침은 네트워크 구성 관리 롤백을 참고해요.

AI 요약

네트워크 구성 관리에는 구성 변경을 자연어 설명으로 변환하는 AI 기반 요약 패널이 포함돼 있어요.

두 구성 버전을 비교하면 AI 요약이 자동으로 다음을 수행해요.

  • 변경 사항을 사람이 읽을 수 있는 용어로 설명
  • 장애 조사나 위험 분석에 관련될 수 있는 변경 사항을 강조

지원되는 장치 프로필

NCM은 장치 프로필을 사용해 SSH로 네트워크 장치에서 구성을 수집해요. 프로필은 Datadog Agent에 번들로 포함되며, 장치의 운영 체제에 따라 자동으로 매칭되고 Agent 릴리스를 통해 업데이트돼요.

Vendor OS Profile Min. Agent version Running Startup
Arista EOS eos 7.77.0 yes yes
Aruba AOS-CX aoscx 7.76.0 yes yes
Aruba AOS-W aosw 7.75.0 yes
Cisco IOS cisco-ios 7.73.0 yes yes
Cisco NX-OS nxos 7.76.0 yes yes
Dell DellOS10 dellos10 7.77.0 yes yes
F5 TMOS tmos 7.76.0 yes
FortiGate FortiOS fortios 7.77.0 yes
Juniper JunOS junos 7.74.0 yes
Palo Alto PAN-OS pan-os 7.75.0 yes

구성 검색 명령

각 프로필은 SSH를 통해 장치 구성을 수집하기 위해 다음 명령을 사용해요. 전체 명령 정의는 default_profiles.go를 참고해요.

Vendor OS Running config command Startup config command
Arista EOS `show running-config no-more
Aruba AOS-CX show running-config show startup-config
Aruba AOS-W show running-config
Cisco IOS show running-config show startup-config
Cisco NX-OS show running-config show startup-config
Dell DellOS10 show running-configuration show startup-configuration
F5 TMOS cat /config/partitions/*/bigip*.conf
FortiGate FortiOS show full-configuration
Juniper JunOS `show configuration display omit`
Palo Alto PAN-OS show config running

더 알아보기 (Learn more)