Telemetry ও Protected Scope Configure করুন
অনুমোদিত network ঘোষণা, RouterOS বা external flow telemetry connect, source health verify এবং monitoring activate করুন।
এই পৃষ্ঠায়
নির্ভরযোগ্য DDoS detection-এর শুরু সঠিক network profile, অনুমোদিত protected prefix এবং স্বাধীনভাবে observed flow record দিয়ে। DDoS Protection → Setup ও Telemetry-তে ধাপগুলো সম্পন্ন করুন।
Network profile সম্পন্ন করুন
Organisation name, monitored capacity, baseline learning window এবং NOC notification email দিন। BGP response বা routing-context analysis পরিকল্পনা থাকলে local ASN যোগ করুন। Attack প্রথম দেখা গেলে in-product owner alert তৈরি হয় এবং NOC address-এ summary queue হয়।
Protected scope ঘোষণা করুন
শুধু organisation-এর মালিকানাধীন বা monitor করার অনুমতি থাকা public/private IPv4 বা IPv6 space যোগ করুন। CIDR অথবা একটি host দিন; single host IPv4 /32 বা IPv6 /128 হিসেবে save হয়।
- Subscriber ও service address space
- Infrastructure ও management range
- Point-to-point, transit ও peering segment
- Monitor করা দরকার এমন private service network
Protected scope কোথায় detection এবং approved exact-host response অনুমোদিত তা নির্ধারণ করে। Address যোগ করলে তা announce, block বা scrub হয় না; protected scope mitigation allowlist-ও নয়।
Telemetry source যোগ করুন
Telemetry খুলে প্রযোজ্য type, name, site, exporter address ও listen port দিন। Supported source:
- sFlow
- NetFlow v5 ও NetFlow v9
- IPFIX
- Managed sensor-এ observed SPAN বা mirrored traffic
- AWS VPC Flow Logs
- Google Cloud VPC Flow Logs
Connected RouterOS device configure করুন
- Telemetry থেকে Configure Traffic Flow in one step বেছে নিন।
- Connected router এবং NetFlow v5/v9 বা IPFIX select করুন।
- Read-only managed collector address, reserved port এবং ছয় অক্ষরের service ID review করুন।
- Saved RouterOS API connection দিয়ে configuration apply করুন।
- Source healthy ধরার আগে ISPbills-এর real flow record decode হওয়া পর্যন্ত অপেক্ষা করুন।
RouterOS API 8728 ও API-SSL 8729 supported। Managed collector প্রতিটি exporter-এর template ও baseline state আলাদা রাখে।
Self-managed sensor connect করুন
sFlow, SPAN ও cloud-log source-এর জন্য authenticated sensor contract-এ observation normalise করা deployed sensor বা adapter দরকার। Tenant-operated collector-এর প্রয়োজন হলেই optional sensor token reveal/rotate করুন, সরাসরি secret manager-এ copy করুন এবং মনে রাখুন rotation আগের token সঙ্গে সঙ্গে invalid করে।
Source health সঠিকভাবে পড়ুন
| State | অর্থ ও করণীয় |
|---|---|
| Pending | Definition save হয়েছে, decoded record verify হয়নি। Exporter setting, credential, address, port, NAT ও firewall path পরীক্ষা করুন। |
| Healthy | Decoded record current। Exporter, latest flow rate এবং verification time intended source-এর সঙ্গে মিলিয়ে নিন। |
| Stale | Record আসা বন্ধ। Exporter, sensor process, template, clock এবং reachability পরীক্ষা করুন। |
| Degraded profile | Reliable current source নেই। Detection বা empty attack queue-এর ওপর নির্ভর করার আগে telemetry restore করুন। |
Successful RouterOS API call বা শুধু UDP packet আসা healthy telemetry নয়। ISPbills decoded flow record বা সফল adapter report-এর অপেক্ষা করে।
Monitoring activate করুন
Protected scope, telemetry ও required detection policy প্রস্তুত হলে setup checklist review করে Activate monitoring select করুন। Activation baseline learning ও policy evaluation শুরু করে; response connector চালায় না। Learning window-এ detection absolute threshold-এর ওপর বেশি নির্ভর করতে পারে।
Telemetry checklist
- Displayed exporter ও site intended device-এর সঙ্গে মেলে।
- Last verified record time recent এবং এগোচ্ছে।
- BPS, PPS ও FPS interface counter-এর তুলনায় plausible।
- দুই address family protected হলে IPv4 ও IPv6 source আছে।
- Collector credential ও sensor token ticket/chat-এর বাইরে সংরক্ষিত।
পরবর্তী ধাপ: detection policy ও analytics configure করুন।