摘要:
An apparatus and method for collecting network traffic information is arranged to receive network traffic elements including one or more key fields having respective key field values. The apparatus and method further classify received network traffic elements into one of a plurality of flows dependent on the key field value of one or more key fields defined by a flow profile. The method and apparatus are further configurable to vary the flow profile, create a flow record and export the flow record to a collecting node.
摘要:
An apparatus and method for collecting network traffic information is arranged to receive network traffic elements including one or more key fields having respective key field values. The apparatus and method further classify received network traffic elements into one of a plurality of flows dependent on the key field value of one or more key fields defined by a flow profile. The method and apparatus are further configurable to vary the flow profile, create a flow record and export the flow record to a collecting node.
摘要:
A method is provided in one example embodiment and includes receiving a plurality of packets and generating a data record that is based on information associated with the packets. The data record includes a synchronized time window field that defines a time boundary at which data aggregation associated with the data record is stopped, where the synchronized time window field remains constant as the data aggregation associated with the data record occurs. In other embodiments, the method includes creating a new cache entry for new packets arriving at a network element, where the new cache entry is created in response to a value of the synchronized time window field changing. The synchronized time window field can include a window size attribute that defines how long the synchronized time window remains unchanged.
摘要:
In one embodiment, a method includes determining a first template defining a data format for one or more first data records and a second template defining a data format for one or more second data records. The template may be needed to decode the information included in an associated data record. The first template is sent on a first stream of a multi-stream protocol in an ordered fashion, such as SCTP. The one or more first data records are also sent on the first stream in an ordered fashion and include first flow information for data sent through a network device. A second template is sent on a second stream using the multi-stream protocol in an ordered fashion. One or more second data records are sent on the second stream including second flow information for data sent through the network device.
摘要:
In one embodiment, a networking device includes logic encoded in one or more tangible media for execution and when executed operable to cause performing receiving a command to collect a unique object identifier that represents a unique management information base (MIB) object; retrieving, in response to receiving the command, a Simple Network Management Protocol (SNMP) MIB variable or table that corresponds to the MIB object; creating an Internet Protocol Flow Information Export (IPFIX) template data structure that includes the object identifier; in which the object identifier is encoded in the IPFIX template data structure as a string that has a variable length; and exporting the encoded object identifier with the variable length string.
摘要:
In one embodiment, a method includes determining a first template defining a data format for one or more first data records and a second template defining a data format for one or more second data records. The template may be needed to decode the information included in an associated data record. The first template is sent on a first stream of a multi-stream protocol in an ordered fashion, such as SCTP. The one or more first data records are also sent on the first stream in an ordered fashion and include first flow information for data sent through a network device. A second template is sent on a second stream using the multi-stream protocol in an ordered fashion. One or more second data records are sent on the second stream including second flow information for data sent through the network device.
摘要:
In one embodiment, a networking device includes logic encoded in one or more tangible media for execution and when executed operable to cause performing receiving a command to collect a unique object identifier that represents a unique management information base (MIB) object; retrieving, in response to receiving the command, a Simple Network Management Protocol (SNMP) MIB variable or table that corresponds to the MIB object; creating an Internet Protocol Flow Information Export (IPFIX) template data structure that includes the object identifier; in which the object identifier is encoded in the IPFIX template data structure as a string that has a variable length; and exporting the encoded object identifier with the variable length string.
摘要:
A method of identifying an egress point to a network location in a data communications network comprising a plurality of nodes and links there between comprises the step, performed at the identifying node, of receiving a notification through the network advertising an adjacency to a network location. The method further comprises the steps, performed at the identifying node, of deriving from the notification adjacency information and identifying, from the adjacency information, the egress point.
摘要:
In one embodiment, a method can include: (i) receiving an incoming probe packet in a network device; (ii) de-encapsulating the incoming probe packet to provide a packet content portion and a drop result portion; (iii) testing the packet content portion against a local access control list (ACL) to determine a local drop result; and (iv) inserting the local drop result and encapsulating an outgoing probe packet.
摘要:
A method for generating a traffic matrix is provided that includes receiving a first set of data from a first provider edge element and a second set of data from a second provider edge element, the first and second sets of data including border gateway protocol (BGP) next hop information. The first and second sets of data may then be aggregated. Information that is associated with one or more customer network elements is then filtered out in order to produce a traffic matrix.