NetFlow-Based Approach to Compare the Load Balancing Algorithms



Similar documents
Using UDP Packets to Detect P2P File Sharing

How To Balance A Web Server With Remaining Capacity

Single Pass Load Balancing with Session Persistence in IPv6 Network. C. J. (Charlie) Liu Network Operations Charter Communications

LOAD BALANCING AS A STRATEGY LEARNING TASK

MULTI WAN TECHNICAL OVERVIEW

Understanding Slow Start

AN EFFICIENT LOAD BALANCING ALGORITHM FOR A DISTRIBUTED COMPUTER SYSTEM. Dr. T.Ravichandran, B.E (ECE), M.E(CSE), Ph.D., MISTE.,

ExamPDF. Higher Quality,Better service!

Application Latency Monitoring using nprobe

Emerald. Network Collector Version 4.0. Emerald Management Suite IEA Software, Inc.

Snapt Balancer Manual

HyLARD: A Hybrid Locality-Aware Request Distribution Policy in Cluster-based Web Servers

5 Performance Management for Web Services. Rolf Stadler School of Electrical Engineering KTH Royal Institute of Technology.

Server Traffic Management. Jeff Chase Duke University, Department of Computer Science CPS 212: Distributed Information Systems

FortiOS Handbook - Load Balancing VERSION 5.2.2

ZEN LOAD BALANCER EE v3.04 DATASHEET The Load Balancing made easy

Application and service delivery with the Elfiq idns module

How To Manage Dns On An Elfiq Link Load Balancer (Link Balancer) On A Pcode (Networking) On Ipad Or Ipad (Netware) On Your Ipad On A Ipad At A Pc Or Ipa

Purpose-Built Load Balancing The Advantages of Coyote Point Equalizer over Software-based Solutions

Load Balancing of Web Server System Using Service Queue Length

Quick Start for Network Agent. 5-Step Quick Start. What is Network Agent?

High Performance Cluster Support for NLB on Window

Networking Topology For Your System

TESTING & INTEGRATION GROUP SOLUTION GUIDE

Analysis of SIP Traffic Behavior with NetFlow-based Statistical Information

Building a Systems Infrastructure to Support e- Business

HAProxy. Ryan O'Hara Principal Software Engineer, Red Hat September 17, HAProxy

Load Balancing. FortiOS Handbook v3 for FortiOS 4.0 MR3

ZEN LOAD BALANCER EE v3.02 DATASHEET The Load Balancing made easy

Integration Guide. Zen Load Balancer Ubuntu/Microsoft Windows

Ranch Networks for Hosted Data Centers

Availability Digest. Redundant Load Balancing for High Availability July 2013

Quick Start for Network Agent. 5-Step Quick Start. What is Network Agent?

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

IPv4 and IPv6: Connecting NAT-PT to Network Address Pool

Using The Paessler PRTG Traffic Grapher In a Cisco Wide Area Application Services Proof of Concept

Load balancing MySQL with HaProxy. Peter Boros Percona 4/23/13 Santa Clara, CA

Web Traffic Capture Butler Street, Suite 200 Pittsburgh, PA (412)

Avaya P330 Load Balancing Manager User Guide

Application Delivery Networking

Traffic Analysis With Netflow. The Key to Network Visibility

Network Security Monitoring and Behavior Analysis Pavel Čeleda, Petr Velan, Tomáš Jirsík

Microsoft Office Communications Server 2007 & Coyote Point Equalizer Deployment Guide DEPLOYMENT GUIDE

REDUCING PACKET OVERHEAD IN MOBILE IPV6

Network Agent Quick Start

Avaya P333R-LB. Load Balancing Stackable Switch. Load Balancing Application Guide

Chapter 15: Advanced Networks

How To Understand and Configure Your Network for IntraVUE

How To Manage Outgoing Traffic On Fireware Xtm

A Network Simulation Experiment of WAN Based on OPNET

Link Load Balancing :50:44 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

FortiOS Handbook Load Balancing for FortiOS 5.0

Fault-Tolerant Framework for Load Balancing System

Monitoring of Tunneled IPv6 Traffic Using Packet Decapsulation and IPFIX

ELIXIR LOAD BALANCER 2

Lab VI Capturing and monitoring the network traffic

SonicWALL NAT Load Balancing

msuite5 & mdesign Installation Prerequisites

SonicOS Enhanced 4.0: NAT Load Balancing

How to configure an Advanced Expert Probe as NetFlow Collector

Configuring Citrix NetScaler for IBM WebSphere Application Services

High-Performance IP Service Node with Layer 4 to 7 Packet Processing Features

Abstract. 1. Introduction

Bandwidth Management for Peer-to-Peer Applications

Load Balance Mechanism

UPPER LAYER SWITCHING

Data Analysis Load Balancer

An enhanced TCP mechanism Fast-TCP in IP networks with wireless links

vrealize Automation Load Balancing

Research on Errors of Utilized Bandwidth Measured by NetFlow

Performance Evaluation of AODV, OLSR Routing Protocol in VOIP Over Ad Hoc

Building a Highly Available and Scalable Web Farm

THE BCS PROFESSIONAL EXAMINATIONS BCS Level 6 Professional Graduate Diploma in IT. April 2009 EXAMINERS' REPORT. Network Information Systems

Application Delivery Controller (ADC) Implementation Load Balancing Microsoft SharePoint Servers Solution Guide

S y s t e m A r c h i t e c t u r e

A Load Balancing Algorithm based on the Variation Trend of Entropy in Homogeneous Cluster

Connecting North Carolina s Future Today. Application Monitoring: ClassScape Case Study. NCSU Centennial Networking Lab

How To Configure A Kiwi Ip Address On A Gbk (Networking) To Be A Static Ip Address (Network) On A Ip Address From A Ipad (Netware) On An Ipad Or Ipad 2 (

Configuring Nex-Gen Web Load Balancer

NfSen Plugin Supporting The Virtual Network Monitoring

Direct Web Switch Routing with State Migration, TCP Masquerade, and Cookie Name Rewriting

Performance Evaluation of Linux Bridge

International Research Journal of Interdisciplinary & Multidisciplinary Studies (IRJIMS)

Firewall Load Balancing

Improving Quality of Service

NetFlow Tracker Overview. Mike McGrath x ccie CTO mike@crannog-software.com

NetFlow: What is it, why and how to use it? Miloš Zeković, ICmyNet Chief Customer Officer Soneco d.o.o.

Multicast-based Distributed LVS (MD-LVS) for improving. scalability and availability

Passive Measurement in CSTNET

Signature-aware Traffic Monitoring with IPFIX 1

Coyote Point Systems White Paper

Traffic Analysis with Netflow The Key to Network Visibility

Configuring WAN Failover & Load-Balancing

bbc Adobe LiveCycle Data Services Using the F5 BIG-IP LTM Introduction APPLIES TO CONTENTS

Limitations of Packet Measurement

VoIP Performance Over different service Classes Under Various Scheduling Techniques

Transcription:

6 IJCSNS International Journal of Computer Science and Network Security, VOL.8 No.1, October 8 NetFlow-Based Approach to Compare the Load Balancing Algorithms Chin-Yu Yang 1, and Jian-Bo Chen 3 1 Dept. Computer Sci. & Information Eng., National Central University, Chung-Li, Taiwan, ROC Vanung University, Chung-Li, Taiwan, ROC 3 Ming Chuan University, Taipei, Taiwan, ROC Summary The load balancing architecture is the most popular method to improve the performance of the server. The selection of the load balancing algorithms is one of the most important issues. In this paper, we use NetFlow to collect traffic for six load balancing algorithms, including least connections, round robin, minimum misses, hash, response time, and bandwidth. We compared their flow counts and packet counts separately. Both the WAN link load balancing and server load balancing are implemented. In addition, we also collected the burst traffic for server load balancing. The results for the performance of the algorithms are analyzed and compared. Key words: NetFlow, load balancing, cluster 1. Introduction Clustering technologies enable incremental scaling of Internet server sites at modest cost. It is increasingly common in cluster-based service architectures to distribute incoming request traffic amount servers by using redirect switch. These server switches are called by various names including request distributors, front ends, redirectors, load balancers, network dispatchers, L4-L switches, interception switches, Web switches, content switches, and so on[1]. No matter which server switch we use, the most important issue is which load balancing algorithm are adopted. Different algorithms for load balancing architecture can be used to balance the load on a multi-server system based on the topology of the system[]. The WAN link load balancing is used to balance the Internet connection for enterprise such as proxy server. The server load balancing is used to balance the load of server inside the enterprise such as web server. The purpose of these two systems is to alleviate the load of single server, but their topologies are quite different. In this paper, we use six different algorithms to analyze the behavior of the load balancing system. The six algorithms include least connections, round robin, minimum misses, hash, response time, and bandwidth. In order to avoid the influence of evaluating processes for the load balancing system, we use the port mirror function of the switch to export the traffic. We also use a probe to collect the traffic, then transfer the collected traffic into NetFlow format[3]. At last, we insert these data into SQL server for analyzing. Meanwhile, we also analyze some of the access logs from web servers and proxy servers[4, 5]. The rest of the paper is organized as follows. In section, we present the six load balancing algorithms. In section 3, we describe the system architecture. The experimental result is shown in section 4. The conclusion is described in section 5. Load Balancing Algorithms The load balancing architecture makes decisions regarding which server of a virtual server group to assign the new connection is based on the load balancing algorithms. The different algorithms operations available are as follows[6]..1 Least Connections With the least connections algorithm, the number of connections currently opened on each backend server is measured in real-time. The backend server with least active connections is considered to be the best choice for the next client connection request. This algorithm is the most self-regulating, with the fastest servers typically getting the most connections over time.. Round Robin With the Round-Robin algorithm, new connections are issued to each backend server in turn. That is, the first backend server in the group gets the first connection, the second backend server gets the next connection, followed by the third backend server, and so on. When all the backend servers in this group have received at least one connection, the process starts over with the first backend server. Manuscript received October 5, 8 Manuscript revised October, 8

IJCSNS International Journal of Computer Science and Network Security, VOL.8 No.1, October 8.3 Minimum Misses The minimum misses algorithm is optimized for WAN link load balancing. It uses IP address information in the client request to select a server. The specific IP address information used depends on the application. For WAN link load balancing, the client destination IP address is used. All requests for a specific IP destination address are sent to the same server. This algorithm is particularly useful in caching applications, helping to maximize successful cache hits. Best statistical load balancing is achieved when the client IP addresses are spread across a broad range of IP subnets. For server load balancing, the client source IP address and backend server IP address are used. All requests from a specific client are sent to the same backend server. This algorithm is useful for applications where client information must be retained on the server between sessions. With this algorithm, backend server loading becomes most evenly balanced as the number of active clients with different source or destination addresses increases..4 The hash algorithm uses IP address information in the client request to select a backend server. The specific IP address information used depends on the application. For WAN link load balancing, the client destination IP address is used. All requests for a specific IP destination address will be sent to the same server. This is particularly useful for maximizing successful cache hits. For server load balancing, the client IP address is used. All requests from a specific client will be sent to the same backend server. This option is useful for applications where client information must be retained between sessions. When selecting a backend server, a mathematical hash of the relevant IP address information is used as an index into the list of currently available servers. Any given IP address information will always have the same hash result, providing natural persistence, as long as the backend server list is stable. However, if a server is added to or leaves the system, then a different backend server might be assigned to a subsequent session with the same IP address information even though the original server is still available. Open connections are not cleared. The hash algorithm provides more distributed load balancing than minimum misses at any given instant. It should be used if the statistical load balancing achieved using minimum misses is not as optimal as desired. If the load balancing statistics with minimum misses indicate that one backend server is processing significantly more requests over time than other servers, consider using the hash algorithm..5 Time The response time algorithm uses backend server response time to assign sessions to servers. The response time between the servers and the load balancer is used as the weighting factor. The load balancer monitors and records the amount of time it takes for each backend server to reply to a health check to adjust the backend server weights. The weights are adjusted so they are inversely proportional to a moving average of response time. In such a scenario, a server with half the response time as another server will receive a weight twice as large..6 The bandwidth algorithm uses backend server octet counts to assign sessions to a server. The load balancer monitors the number of octets been sent between the server and itself. Then, the weights of backend server are adjusted so they are inversely proportional to the number of octets that the backend server processed during the last interval. Backend servers that process more octets are considered to have less available bandwidth than those that have processed fewer octets. For example, the backend server that processes half the amount of octets over the last interval receives twice the weight of the other backend servers. The higher the bandwidth used, the smaller the weight assigned to the server. Based on this weighting, the subsequent requests go to the backend server with the highest amount of free bandwidth. These weights are automatically assigned. 3 System Architecture 3.1 NetFlow Traffic Collections The architecture of traffic collection is shown in Fig. 3. The server switch[] acts as a virtual front-end processor to clusters of real servers connected via direct attachment to switch ports or indirectly through hubs and switches. In network environments, NetFlow is probably the most useful standard for network traffic accounting. In our experiment, we use both a NetFlow v5 probe (nprobe) [8] and collector to monitor the flows within the server switch.

8 IJCSNS International Journal of Computer Science and Network Security, VOL.8 No.1 October 8 When the nprobe activated, nprobe will collect traffic data and emit NetFlow v9 flows towards the specified collector. A set of packets with the same (src ip & port, dst ip & port, protocol #) is called flow. Every flow, even a very longstanding ISO CD image download, has a limited lifetime; this is because the flow collector should periodically receive flow chunks for accounting traffic precisely. Then we use a collector to receive the NetFlow v9 flows, and store all the information into MySQL database. improve the performance, we use eight WWW servers instead of the main WWW server. The IP address of the main WWW server was configured in the Server switch. Every time when a client makes a request to the WWW server, the Server switch will choose one WWW server to serve it by the pre-defined algorithm. The eight WWW servers share the same contents. The architecture is shown in Fig.3. Figure 1. NetFlow traffic collections 3. WAN Link Load Balancing Architecture The WAN link load balancing architecture is to share the load for WAN link, especially for the HTTP traffic. In order to improve the performance, we use four proxy servers instead of the main proxy server. The IP address of the main proxy server was configured in the Server switch. Every time when a client makes a request to the main proxy server, the Server switch will choose one proxy server to process the request by its algorithm. The four proxy servers are all installed with two network interface cards. One NIC binds the local IP address in our environments and the other NIC binds the IP address given by the ADSL ISP provider as shown in Fig.. Figure 3. WWW server architecture 4. Experimental Results In our experiments, we collected the NetFlow data for Proxy servers and WWW servers. The flow counts and packet counts are presented. We also calculated the standard derivation for each load balancing algorithm. The burst traffics for WWW were also collected. 4.1 Proxy server load balancing We used the six different load balancing algorithms to collect the traffic data. Each algorithm collects traffic about 4 hours. The data we collected are shown in Table 1. The standard derivations of the data are shown in Table and Fig. 4 and 5. Collector NetFlow Proxy-adsl1 Proxy-adsl Proxy-adsl3 Proxy-adsl4 nprobe Port Mirror Proxy Server Switch Figure. Proxy server architecture 3.3 Server Load Balancing Architecture The server load balancing architecture is to distribute the client requests to several WWW servers. In order to Algorithms Table 1. Proxy server load balancing traffic data Proxyadsladsl Proxy- Proxyadsl3 Proxyadsl4 Flow 56998 4863 33336 39 Packet 9839 1885 1956 866 RoundR Flow 6164 5149 431 614 obin Packet 3441868 198849 654 514 Least Conns Min Misses Flow 4839 548 41918 61488 Packet 34918 451 5391 1563 Flow 6419 6938 468 6433 Packet 31466 93349 35139 1619

IJCSNS International Journal of Computer Science and Network Security, VOL.8 No.1, October 8 9 Res- Flow 53151 34339 31145 566 ponse Packet 386566 61434 63859 5195 Flow 4435 315 5655 31851 Packet 31933 18146 41468 18831 4. WWW server load balancing For server load balancing, we collected the data and calculated the standard derivations of the data Table 3 and Fig. 6 and Fig.. Table. Proxy server load balancing standard derivations Algorithms Flow Packet 166 48418 Round Robin 919 6998 Least Conns 158 584 Min Misses 989 46159 Table 3. WWW server load balancing standard derivations Algorithms Flow Packet 39 195 454 1653 3656 1418 1516 1946 11 3819 398 449 38 64 1184 6489 Flow count Flow count 5 4 3 1 5 4 3 1 Figure 6. Standard derivations for flow counts Figure 4. Standard derivations for flow counts Packet count Packet count 5 4 3 1 1 8 6 4 Figure. Standard derivations for packet counts Figure 5. Standard derivations for packet counts 4.3 Burst traffic of WWW server load balancing In this experiment, we want to know what happenes when the burst traffic occurs. We collected three period of time with burst traffic, and with each period, we collected ten minutes. But due to the session problems of the WWW

8 IJCSNS International Journal of Computer Science and Network Security, VOL.8 No.1 October 8 servers, we only tested the hash algorithm. The data we collected are shown in Table 4 and Fig. 8 and Fig. 9. Table 4. WWW server load balancing with brust data Time slot 1 Time slot Time slot 3 Servers Flow Pack Flow Pack Flow Pack et et et WWW1 543 361 843 486 6998 61 WWW 9369 51 14 541 1458 811 WWW3 519 4 9 5 53 44 6 9 81 64 3 WWW4 689 4995 5 591 431 6 333 838 WWW5 1695 91 13 548 954 59 9 WWW6 3 8344 4635 6 3 364 45 89 599 8 WWW 459 8 965 5346 4 865 6393 5 WWW8 5954 451 9 15 1 5 1 WWW1 5 WWW1 WWW WWW3 WWW4 9 61 593 Time slot 1 Time slot Time slot 3 WWW5 WWW6 Figure 8. The flow counts statistics WW W 651 5659 WWW Time slot 1 Time slot Time slot 3 WW W3 WW W4 WWW5 WW W6 WW W WWW8 WW W8 derivation of round robin is not approximately zero. The reason is that the NetFlow collector reports the collected data periodically. When a flow, or a connection, transfers a large amount of data, NetFlow will spilt this one flow into several flows, so the statistic data will not be the same for each server. The minimum misses algorithm for the WAN link load balancing, or proxy server, will get the highest performance because of its high hit rate. The standard derivation cannot show this advantage because the high hit rate will reduce the response time, not dispatch the traffic fairly. 5. Conclusion In this paper, we used the NetFlow to collect the traffic data of different load balancing algorithms. We can find out that each algorithm in the different kinds of traffic have different performance. We use the flow counts and packet counts to verify the load balancing of each algorithm. As far as we know, these algorithms cannot 1% balancing the loads because the unexpected network conditions and server loads. References [1] Jeffery S. Chase, Server Switching: Yesterday and Tomorrow, Proc. The Second IEEE Workshop on Internet Applications, 1 [] Hemant B. More & Jie Wu, Throughput Improvement Through Dynamic Load Balance, Proc. IEEE SOUTHEASTCON. Bibliographic Details, 1994 [3] NetFlow Services Export Version 9, RFC 3954 [4] Lili Qiu, Venkata N. Padmanabhan, Geoffery M.Voelker, On the Placement of Web Server Replicas, Proc. Twentieth Annual Joint Conference of the IEEE Computer and Communications Societies, vol. 3, 1 [5] Scot Hull, Content Delivery Networks: Web Switching for Security, Availability, and Speed, McGraw Hill,. [6] Notel Networks, Alteon Link Optimizer Application Guide, Release 1., [] http://www.nortelnetworks.com [8] http://www.ntop.org/nprobe.html Figure 9. The packet counts statistics 4.4 Analysis of Experimental Results It seems that the flow count for each server must be the same when we use round robin as the load balancing algorithm. But the results showed that the standard Chin-Yu Yang received the MS degree in department of electrical engineering in Yuan Ze University, Jhongli, Taiwan, Republic of China, in 199, and he is a PhD student in the department of computer science and information engineering in National Central University, Jhongli,

IJCSNS International Journal of Computer Science and Network Security, VOL.8 No.1, October 8 81 Taiwan, Republic of China. He is currently an instructor in the department of computer science and information engineering in Vanung University, Jhongli, Taiwan, Republic of China. His research interests include wireless network, network security and network management. Jian-Bo Chen received the MS degree in the department of electrical engineering in National Taiwan University, Taipei, Taiwan, Republic of China, in 1995, and PhD degree in the department of computer science and engineering in Tatung University, Taipei, Taiwan, Republic of China, in 8. He is currently an assistant professor in the department of information and telecommunications engineering in Ming Chuan University, Taoyuan, Taiwan, Republic of China. His research interests include network management, network security, and load balance.