Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

IP net management could get easier

By Denise Dubie , Network World , 10/27/2003
  • Share/Email
  • Tweet This
  • Comment
  • Print

A proposed standard under construction at the Internet Engineering Task Force promises to extract more traffic statistics from corporations' network gear, which proponents say will help them develop usage-based billing and more easily spot security breaches.

IP Flow Information Export (IPFIX), expected to be in final draft by early next year, defines a method for routers and switches to export traffic-flow data to management systems. If adopted, the export standard would be included in network gear from Cisco, Nortel, Riverstone Networks and others. IPFIX-compliant management products then would be able to collect and analyze the traffic-flow data and correlate it with other network and application performance metrics in a management console.

Proponents say IPFIX-compliant gear will capture, store and deliver all traffic-flow data that crosses corporate routers and switches. Commercial products and protocols such as SNMP today can extract part of the traffic-flow data stored on network gear, but IPFIX would automatically package the raw data and send it to a collection point for correlation. In many cases, traffic-flow data can be lost on network gear because routers and switches don't have the memory to save the data. After the data is exported, management software could dissect the data, which today is difficult to gather and maintain.

"IPFIX is the foundation technology by which the raw data is transmitted between the network gear and a collector for subsequent analysis," says Dave Plonka, co-chair of the IPFIX working group for the IETF. "Flow-based measurements are a sweet spot between mere aggregate counters and complete packet traces."

To export data, routers present network traffic flow based on seven fields: source IP address; destination IP address; source port; destination port; Layer 3 protocol type; type-of-service byte; and input logical interface. If all seven fields in two packets match, the packets belong to the same flow.

IPFIX is expected to provide the format by which IP flow data can be transferred from the gear to a management collection point. Because IPFIX implementations will include templates, customers could define multiple templates for how various data should be exported. IPFIX-enabled devices then would package the data as defined and send it to IPFIX-compliant collection devices, either network management probes or a server loaded with network management software.

Mining the traffic flow and understanding more packet data could reveal details about how an application uses network devices, how routers respond to requests and which users make the most demands. That data could let network managers bill for IT services based on usage.

"Collecting raw packet data can reveal to network managers if there are different routes or links being used in ways they didn't realize or if there are better ways to route the traffic," says Paul Kohler, technical marketing engineer in the Internet Technologies Division at Cisco. He says IPFIX also could alert network managers to potential security breaches and help them fill any security holes. "It can go beyond just noticing if a link is down; it can identify flows that are the source of a problem."

  • Share/Email
  • Tweet This
  • Comment
  • Print

Partner Content

Blue Stripe Software

www.bluestripe.com/

Improving Application Performance Troubleshooting

Diagnosing why an application is slow is hard, at times taking days or weeks to isolate and resolve. This paper explains the challenges involved using current management tools, provides a 'wish list' for application management and analysis, and explains the need for an application system-wide approach that monitors entire applications, not components.

Download Whitepaper

Virtual Vigilance: Managing Application Performance in Virtual Environments

This paper highlights the impact of virtualization on application performance.  "Managing Application Performance in Virtual Environments" states: "Best-in-Class organizations are predominately taking actions around improving visibility across both physical and virtual systems, assessing the business impact of application performance and understanding interdependencies of applications in virtualized environments."

Download Whitepaper

Application Service Requests: The Missing Link for Pragmatic ITSM

Forrester Research analyst Glenn O'Donnell and BlueStripe co-founder Vic Nyman discuss a breakthrough approach to application problem management. Learn the new approach for ITSM problem management, which provides: Rapid isolation of application slow-downs to specific components for quick problem resolution, 24/7 monitoring for proactive notification of potential issues before end users are impacted and much more.

Register for Webcast

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed