Professional Documents
Culture Documents
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1
Application Visibility in Data Center
Why Application Visibility in Data
Center
Efficient Operation
•What applications are consuming Si Si
bandwidth
•Who is using them
•When they are being used
•What activities are prevalent Si Si
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 2
Introducing NetFlow-lite
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 3
NetFlow-lite:
Building upon the flexibility of Flexible NetFlow
Permanent cache
Flow
Normal cache Immediate cache
Cache
Immediate cache
•NetFlow-lite exports new keys such as raw packet section & sampling rate
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 4
NetFlow-lite: Metering Process
Packet forwarding
Configurable sampling rate up to 1-in-32 on all 48 downlinks (1G) ad 4 uplinks (10G), AND 1-in-1
sampling on up to 2 ports (1G only)
Configurable packet sample length (export truncated packet section to conserve bandwidth)
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 5
NetFlow-lite: Export Format
Example: NetFlow-lite in NetFlow version 9 export Format
Version 9 is based on template and separate flow records
Templates composed of type and length Template 1
Flow records composed of template ID and value
output
Template Record
packet observed
Input interface
Packet length
packet section
Template ID #1
Sequence #
Total
Sampled
D
interface
(Specific Field
E Types and Lengths)
R # of
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 6
NetFlow-lite: Flow Cache
Additional Reference:
Cisco IOS Flexible NetFlow Technology White Paper
(http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6555/p
s6601/ps6965/prod_white_paper0900aecd804be1cc.html)
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 7
NetFlow-lite vs. NetFlow
Catalyst 4500/4900 Switches NetFlow-lite vs NetFlow Support:
NetFlow-lite NetFlow (SupIV/V,
(4948E, 4948E-F) SupV-10GE, Sup7-E)
Technology Packet-based Flow-based
Hardware FPGA-assist NetFlow ASIC
Metering Method Sampling (configurable, Every packet accounted
up to 1-in-32*) for
Export format v5, v9, IPFIX** v5, v8, v9, IPFIX
Flow Cache Immediate Cache Norman cache/immediate
cache/permanent cache
Ecosystem Easily integrate with any NetFlow collector
NetFlow collector with
NetFlow-lite Aggregator
Platform Support 4948E, 4948E-F SupIV/V (with daughter
card)
SupV-10GE
Sup7-E (Flexible NetFlow)
* Supports 1-in-1 sampling for up to 2 ports for troubleshooting
**Catalyst 4948E/4948E-F is the first Cisco products supporting IPFIX 8
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential
Data Center-wide Monitoring
Integrating NetFlow-lite into Your Network
Integrating NetFlow-lite into existing NetFlow architecture is easy:
Work with existing collectors & back-end tools through NetFlow-lite Aggregators
NetFlow-lite Aggregators and collectors can sit anywhere in the network, as long as L3
reachable
NetFlow-lite Aggregators are transparent to NetFlow collector (NetFlow collectors receive
aggregated flow data as if it’s coming directly from the switch)
NetFlow collector analyzes & correlates both NetFow and aggregated NetFlow-lite data
NetFlow v9 or
IPFIX export
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 9
Why do I Need a NetFlow-lite Aggregator?
NetFlow-lite Aggregator serves the following purposes:
Parse NetFlow-lite data to extract information such as src/dst IP
address, TCP/UDP port, packet length, etc.
Construct temporary flow cache
Extrapolate flow statistics by correlating sampling rate w/ sampled
packets
Export aggregated and extrapolated data to NetFlow collectors in
standard IPFIX or NetFlow v5/v9 format
Conserve valuable forwarding bandwidth by aggregating NetFlow-
lite data to more bandwidth efficient NetFlow export
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 10
NetFlow-lite Aggregator – Using nProbe
What is it?
NetFlow-lite
nProbe is an open source NetFlow aggregator
(nProbe)
collector/probe/NetFlow-lite Aggregator
Any NetFlow
and can be obtained from ntop.org Collector
5.5.5.10:5000
How Si Si
command:
# ./nprobe -i eth2 -b 1 -s 5 -t 60 -w
1000000 --nflite 2055:16 -n
5.5.5.10:2055 -O 2 -e 0
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 12
Use Case Example:
Network Visibility with NetFlow-lite
Screenshot taken from Plixer Scrutinizer
Link utilization
over time
Top
talkers
packet-section size 64
packet-offset 0
!
interface GigabitEthernet1/1
no switchport
ip address 40.40.40.1 255.255.255.0
netflow-lite monitor 1
sampler check
exporter check
NetFlow v9 or
Apply sampler and exporter to IPFIX export
Netflow-lite monitor on the
interface
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 14
Other Resources
Ntop.org
http://www.ntop.org/nProbe.html
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 15
Using nProbe as
NetFlow-Lite Aggregator
© 2011 - ntop.org
Problem Statement
• NetFlow-Lite brings visibility to switched
networks.
• NetFlow-Lite are exports in v9/IPFIX
format and contain packets sections.
• Legacy NetFlow collectors need additional
support to understand and analyze
NetFlow-lite flows.
© 2011 - ntop.org 17
What is nProbe ?
Flow Collection
NetFlow-Lite Flows
“Classic” NetFlow
Flows (v5/v9/IPFIX)
© 2011 - ntop.org 18
Typical nProbe Deployment
NetFlow
Collector • Place nProbe as
close as possible
to the NetFlow-Lite
NetFlow v9 or Switch.
IPFIX exports
• Each nProbe
instance can
Deployed nProbes
collect flows from
multiple switches.
© 2011 - ntop.org 19
Converting NFLite to NetFlow
• nProbe implements a “real” flow cache
without converting each NFLite flow into a
single NetFlow “classic” flow.
• Interface Identifiers are preserved, as well
sampling rate is taken into account as
packets/bytes are scaled.
• Collectors are unaware of the
NFLite-to- NetFlow conversion that is
totally transparent for them.
© 2011 - ntop.org 20
NetFlow-Lite Support in nProbe
[1/2]
• nProbe collects NetFlow-Lite Flows over
IPv4/IPv6 UDP.
• 4948E balances flows on multiple UDP
destination ports
© 2011 - ntop.org 21
NetFlow-Lite Support in nProbe
[2/2]
• For collecting large number of NetFlow-Lite
Flows a kernel plugin (Linux only) has
been developed.
© 2011 - ntop.org 22
Final Remarks
• nProbe 6.5.x natively supports NetFlow-
Lite.
• It is available for both Windows and Unix.
• Typical NetFlow lite conversion speed
range from 250k to 1M flows/sec (Linux
only using the kernel plugin).
• nProbe supports transparent IP address
spoofing for impersonating the 4948E
switch.
© 2011 - ntop.org 23