网络抓包

更新时间:
复制 MD 格式

Kubernetes监控支持对容器网络进行抓包,本文介绍如何创建抓包命令并查看抓包数据。

前提条件

网络抓包需要Kubernetes监控组件ack-arms-cmonitor版本在1.1.4或以上。您可以在容器服务管理控制台目标集群下的运维管理 > 组件管理页面升级组件版本。

背景信息

TCPDump是常用的一种网络诊断和分析工具,当软件发生网络问题的时候,通常使用TCPDump工具对网络进行抓包分析确定根因。在容器环境中抓包可能会遇到以下问题:

  • 抓包需要使用exec命令进入容器,但网络异常时,容器不一定处于运行状态,您可能无法使用exec命令进入容器。

  • 容器环境不支持运行Shell命令,例如Shelless容器。

  • 容器可能没有预装TCPDump工具。

Kubernetes监控的网络抓包功能支持TCPDump抓包功能,支持命令动态下发、用户免登录容器,且不需要预装TCPDump工具。

创建抓包命令

  1. 登录ARMS控制台,在左侧导航栏单击Kubernetes监控

  2. Kubernetes监控页面顶部选择目标地域,然后单击目标集群名称。

  3. 进入网络抓包页面。

    方式一:

    在左侧导航栏单击网络抓包

    方式二:

    1. 在左侧导航栏单击集群拓扑,然后在WorkloadPod视图下展开对应命名空间。

    2. 将鼠标悬浮于目标节点上,然后单击抓包

      在右侧页面弹出抓包面板。

  4. 单击新建抓包命令,设置抓包参数,然后单击确定

    参数

    说明

    命名空间

    需要抓包的应用所在的命名空间。

    应用类型

    需要抓包的应用类型。

    应用名称

    需要抓包的应用名称。

    Pod

    Pod名称。

    Container

    容器名称。

    网卡

    需要抓包的网络设备。

    src host

    来源Host,不填则对所有来源Host进行抓包。

    src port

    来源Port,不填则对所有来源Port进行抓包。

    包长度

    单个包的最大长度。

    dst host

    目标Host,不填则对所有目标Host进行抓包。

    dst port

    目标Port,不填则对所有目标Port进行抓包。

    预览

    显示对应的抓包语句。

    时长

    抓包时长,单位为秒。

    输出形式

    选择抓包完成后数据的输出形式。

    • 流式输出:仅支持在抓包任务执行后立即查看。

    • Pcap文件:抓包完后您可以随时下载抓包数据,方便后续使用Wireshark等工具进行数据分析。

查看抓包数据

网络抓包页面显示了所有抓包任务。抓包任务列表包含开始时间抓包时长(s)目标tcpdump语句类型状态操作列。类型分为pcap文件流式两种。状态包括成功已取消初始化。对于成功的pcap文件类型任务,可执行下载复制操作;对于初始化状态的任务,可执行执行复制取消操作。单击右上角新建抓包命令可创建新的抓包任务。

查看流式输出数据

  1. 类型流式状态初始化的抓包任务右侧单击执行

  2. 查看流式输出数据。

    说明

    当前页面关闭后对应的数据不支持再次查看。

    connect success...ForwardWebsocket connection established success
    start establish c2c connection
    ForwardWebsocket connection established success
    tcpdump: listening on eth0, link-type EN10MB (Ethernet), snapshot length 10240 bytes
    09:27:25.464879 IP (tos 0x0, ttl 63, id xxx, offset 0, flags [DF], proto TCP (6), length
        xxx.81.3100 > iZ2zef0wd1goj2rf0oqm37Z.60376: Flags [.], cksum 0x55cf (correct),
    09:27:25.464895 IP (tos 0x0, ttl 64, id xxx, offset 0, flags [DF], proto TCP (6), length
        iZ2zef0wd1goj2rf0oqm37Z.60534 > xxx.40.7700: Flags [P.], cksum 0xd25f (incorrect
    09:27:25.464958 IP (tos 0x0, ttl 62, id xxx, offset 0, flags [DF], proto TCP (6), length
        iZ2zef0wd1goj2rf0oqm37Z.60376 > xxx.81.3100: Flags [.], seq 22561:33841, ack 0,
    09:27:25.464971 IP (tos 0x0, ttl 63, id xxx, offset 0, flags [DF], proto TCP (6), length
        xxx.81.3100 > iZ2zef0wd1goj2rf0oqm37Z.60376: Flags [.], cksum 0x1eb5 (correct),
    09:27:25.464981 IP (tos 0x0, ttl 63, id xxx, offset 0, flags [DF], proto TCP (6), length
        xxx.81.3100 > iZ2zef0wd1goj2rf0oqm37Z.60376: Flags [.], cksum 0xfda8 (correct),
    09:27:25.465012 IP (tos 0x0, ttl 62, id xxx, offset 0, flags [DF], proto TCP (6), length
        iZ2zef0wd1goj2rf0oqm37Z.60376 > xxx.81.3100: Flags [P.], seq 33841:54415, ack 0
    09:27:25.465066 IP (tos 0x0, ttl 64, id xxx, offset 0, flags [DF], proto TCP (6), length
        iZ2zef0wd1goj2rf0oqm37Z.60534 > xxx.40.7700: Flags [P.], cksum 0xce61 (incorrect
    09:27:25.465127 IP (tos 0x0, ttl 64, id xxx, offset 0, flags [none], proto UDP (17), len
        iZ2zef0wd1goj2rf0oqm37Z.33362 > xxx.195.8472: [no cksum] OTV, flags [I] (0x08),
    IP (tos 0x0, ttl 64, id xxx, offset 0, flags [DF], proto TCP (6), length 182)
        xxx.174.8080 > xxx.27.32928: Flags [P.], cksum 0x6ef4 (correct), seq 2431811889:
            HTTP/1.1 200
            Content-Type: text/plain;charset=UTF-8
            Content-Length: 16
            Date: Wed, 06 Jul 2022 09:27:24 GMT
            2021-11-30 09:46 [|http]
    09:27:25.465237 IP (tos 0x0, ttl 64, id xxx, offset 0, flags [DF], proto TCP (6), length
        iZ2zef0wd1goj2rf0oqm37Z.60534 > xxx.40.7700: Flags [P.], cksum 0xd264 (incorrect
    09:27:25.465345 IP (tos 0x0, ttl 64, id xxx, offset 0, flags [none], proto UDP (17), len
        iZ2zef0wd1goj2rf0oqm37Z.36512 > xxx.195.8472: [no cksum] OTV, flags [I] (0x08),
    IP (tos 0x0, ttl 64, id xxx, offset 0, flags [DF], proto TCP (6), length 182)
        xxx.48.8080 > xxx.32.36654: Flags [P.], cksum 0xcf9d (correct), seq 64201706:6420
            HTTP/1.1 200

查看Pcap文件

  1. 类型Pcap文件的抓包任务右侧单击下载

  2. 使用Wireshark工具打开Pcap文件并分析抓包数据。

    No.  Time       Source          Destination     Protocol  Length  Info
    24   0.001502   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     33387 → 8472 Len=182
    25   0.001591   xxx.xxx.x.197   xxx.xxx.x.195   UDP       246     49993 → 8472 Len=204
    26   0.001780   xxx.xxx.x.197   xxx.xxx.x.195   UDP       246     41861 → 8472 Len=204
    27   0.001796   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     46063 → 8472 Len=182
    28   0.001835   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     42467 → 8472 Len=182
    29   0.001884   xxx.xxx.x.197   xxx.xxx.x.195   UDP       246     33354 → 8472 Len=204
    30   0.001989   xxx.xxx.x.197   xxx.xxx.x.195   UDP       246     40957 → 8472 Len=204
    31   0.002180   xxx.xxx.x.197   xxx.xxx.x.195   UDP       246     43467 → 8472 Len=204
    32   0.002388   xxx.xxx.x.197   xxx.xxx.x.195   UDP       246     40829 → 8472 Len=204
    33   0.002497   xxx.xxx.x.1.1   xxx.xxx.x.197   TCP       66      50233 → 30421 [RST, ACK] Seq=...
    34   0.002534   xxx.xxx.x.1.1   xxx.xxx.x.197   TCP       66      [TCP Dup ACK 33#1] 50233 → 3...
    35   0.002574   xxx.xxx.x.197   xxx.xxx.x.1.1   TCP       54      30421 → 50233 [RST] Seq=1 Wi...
    36   0.003252   xxx.xxx.x.197   xxx.xxx.x.162   TCP       66      11260 → 54360 [ACK] Seq=1 Ac...
    37   0.003324   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     46402 → 8472 Len=182
    38   0.003402   xxx.xxx.x.162   xxx.xxx.x.197   TCP       66      [TCP ACKed unseen segment] 5...
    39   0.003710   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     39970 → 8472 Len=182
    40   0.003765   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     40750 → 8472 Len=182
    41   0.003940   xxx.xxx.x.197   xxx.xxx.x.195   UDP       246     37876 → 8472 Len=204
    42   0.003967   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     43896 → 8472 Len=182
    43   0.004028   xxx.xxx.x.197   xxx.xxx.x.195   UDP       265     35110 → 8472 Len=223
    44   0.004034   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     35435 → 8472 Len=182
    45   0.004112   xxx.xxx.x.195   xxx.xxx.x.197   UDP       224     55753 → 8472 Len=182
    Frame 1: 224 bytes on wire (1792 bits), 224 bytes captured (1792 bits)
    Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_34:b0:17 (00:16:3e:34:b0:17)
    Internet Protocol Version 4, Src: xxx.xxx.x.195, Dst: xxx.xxx.x.197
    User Datagram Protocol, Src Port: xxxxx, Dst Port: xxxx
    Data (182 bytes)
    0000   00 16 3e 34 b0 17 ee ff   ff ff ff ff 08 00 45 00   ..>4..........E.