Connecting North Carolina s Future Today. Application Monitoring: ClassScape Case Study. NCSU Centennial Networking Lab



Similar documents
Traffic monitoring with sflow and ProCurve Manager Plus

Network Monitoring and Management NetFlow Overview

How to configure an Advanced Expert Probe as NetFlow Collector

Introduction to Netflow

NetFlow use cases. ICmyNet / NetVizura. Miloš Zeković, milos.zekovic@soneco.rs. ICmyNet Chief Customer Officer Soneco d.o.o.

PANDORA FMS NETWORK DEVICES MONITORING

Using The Paessler PRTG Traffic Grapher In a Cisco Wide Area Application Services Proof of Concept

Network Instruments white paper

PANDORA FMS NETWORK DEVICE MONITORING

Cisco Catalyst 4948E NetFlow- lite

Flow Publisher v1.0 Getting Started Guide. Get started with WhatsUp Flow Publisher.

Best of Breed of an ITIL based IT Monitoring. The System Management strategy of NetEye

Limitations of Packet Measurement

Analyzing Full-Duplex Networks

Recommendations for Network Traffic Analysis Using the NetFlow Protocol Best Practice Document

Quick Start for Network Agent. 5-Step Quick Start. What is Network Agent?

An overview of traffic analysis using NetFlow

Gaining Operational Efficiencies with the Enterasys S-Series

Flow Analysis Versus Packet Analysis. What Should You Choose?

NfSen Plugin Supporting The Virtual Network Monitoring

Watch your Flows with NfSen and NFDUMP 50th RIPE Meeting May 3, 2005 Stockholm Peter Haag

and reporting Slavko Gajin

16-PORT POWER OVER ETHERNET WEB SMART SWITCH

How To Set Up Foglight Nms For A Proof Of Concept

Quick Start for Network Agent. 5-Step Quick Start. What is Network Agent?

Network Agent Quick Start

[Optional] Network Visibility with NetFlow

Network Security Monitoring and Behavior Analysis Pavel Čeleda, Petr Velan, Tomáš Jirsík

Observer Probe Family

NetFlow: What is it, why and how to use it? Miloš Zeković, ICmyNet Chief Customer Officer Soneco d.o.o.

Infrastructure for active and passive measurements at 10Gbps and beyond

Network Monitoring Comparison

From traditional to alternative approach to storage and analysis of flow data. Petr Velan, Martin Zadnik

Monitoring Network Traffic using ntopng

HP Intelligent Management Center v7.1 Network Traffic Analyzer Administrator Guide

UltraFlow -Cisco Netflow tools-

Lab Diagramming Intranet Traffic Flows

NetFlow Tracker Overview. Mike McGrath x ccie CTO mike@crannog-software.com

High-Speed Network Traffic Monitoring Using ntopng. Luca

nfdump and NfSen 18 th Annual FIRST Conference June 25-30, 2006 Baltimore Peter Haag 2006 SWITCH

RECORDING VoIP TRAFFIC via PORT MIRRORING

The Value of Flow Data for Peering Decisions

ON THE IMPLEMENTATION OF ADAPTIVE FLOW MEASUREMENT IN THE SDN-ENABLED NETWORK: A PROTOTYPE

Cisco Performance Visibility Manager 1.0.1

Secure Networks for Process Control

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

Network Management & Monitoring

Scalable Extraction, Aggregation, and Response to Network Intelligence

Lab Characterizing Network Applications

Case Study: Instrumenting a Network for NetFlow Security Visualization Tools

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

Application Note Gigabit Ethernet Port Modes

Cisco IOS Flexible NetFlow Technology

NAS 307 Link Aggregation

We are able to increase application response time thus increasing productivity

Table of Contents. Cisco Mapping Outbound VoIP Calls to Specific Digital Voice Ports

VM-Series Firewall Deployment Tech Note PAN-OS 5.0

CISCO INFORMATION TECHNOLOGY AT WORK CASE STUDY: CISCO IOS NETFLOW TECHNOLOGY

Wireshark Developer and User Conference

Applied Detection and Analysis Using Network Flow Data

Network forensics 101 Network monitoring with Netflow, nfsen + nfdump

Redefine Network Visibility in the Data Center with the Cisco NetFlow Generation Appliance

Multi Stage Filtering

NETFORT LANGUARDIAN INSTALLING LANGUARDIAN ON MICROSOFT HYPER V

Network Monitoring and Traffic CSTNET, CNIC

Smart Network Access System SmartNA 10 Gigabit Aggregating Filtering TAP

Router Throughput Tests

Observer Analysis Advantages

VLAN for DekTec Network Adapters

TELCO challenge: Learning and managing the network behavior

ICS 351: Today's plan. IP addresses Network Address Translation Dynamic Host Configuration Protocol Small Office / Home Office configuration

SolarWinds Technical Reference

NetFlow-Lite offers network administrators and engineers the following capabilities:

NetStream (Integrated) Technology White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date

Experimentation driven traffic monitoring and engineering research

Flow Based Traffic Analysis

Missing the Obvious: Network Security Monitoring for ICS

Observer Probe Family

HTGR- Netflow. or, how to know what your network really did without going broke

Network Security Topologies. Chapter 11

Figure 1. perfsonar architecture. 1 This work was supported by the EC IST-EMANICS Network of Excellence (#26854).

Traffic Analysis With Netflow. The Key to Network Visibility

Detecting Botnets with NetFlow

Programmable Networking with Open vswitch

Architecture Overview

ALCATEL-LUCENT VITALSUITE Application & Network Performance Management Software

Traffic Analysis with Netflow The Key to Network Visibility

How To Create A Network Monitoring System (Flowmon) In Avea-Tech (For Free)

Application Discovery Manager User s Guide vcenter Application Discovery Manager 6.2.1

Chapter 4 Rate Limiting

Overview of Network Traffic Analysis

Deploying Network Taps for improved security

Tue Apr 19 11:03:19 PDT 2005 by Andrew Gristina thanks to Luca Deri and the ntop team

6.0. Getting Started Guide

Transcription:

Connecting North Carolina s Future Today Application Monitoring: ClassScape Case Study John Bass NCSU Centennial Networking Lab Carla S. Hunt MCNC 1

Overview About MCNC and the School Connectivity Initiative K12 School Connectivity Projects Application Characterization: The Challenge Application Monitoring: Approach and Architectural Considerations ClassScape Case Study Topology and Netflow Implementation Results and Data Verification Limitations and Extending the Model 2

About MCNC We own and operate the North Carolina Research and Education Network (NCREN) Our customers include public and private universities, community colleges, K12 school systems, state government and other nonprofit institutions Our mission is to provide K20 connectivity to North Carolina s educational systems as requested by the state 3

NC School Connectivity Program Managed by the Friday Institute at North Carolina State University $6M one-time funding by the NC legislature A partnership between key institutions in NC; including MCNC and NC Department of Public Instruction (DPI) 4

Purpose of Program 5

NC School Connectivity Projects (K12) Connectivity Keep Local Traffic Local Increase Capacity Network Health Assessment NC End to End Performance Initiative Network Documentation Application Characterization Address configuration problems on a School System s local network Capacity planning E2E Performance Issues and Visibility Storage/Access to Network and Technology-related information Application Monitoring and Readiness

Application Characterization: What is the problem we are trying to solve? From the School System s perspective: 1. Existing Applications Poor application performance Or, Inability to run applications 2. New Applications Do we have enough bandwidth? How much bandwidth do we need? 7

Application Monitoring Approach: Ability to answer questions like, Do we have the capacity to run an application? And, How much bandwidth does an application need? Start to answer questions like, Can we run this application plus another one? Architectural Considerations: Scalability of Solution Data Management 8

Case Study Implementation Web-based application called ClassScape Online formative assessment program Examine traffic at the application hosting site Open Source Netflow (Softflowd and Nfsen) 9

ClassScape Netflow Topology port mirror is tx & rx of public port on load balancer ncsu net load balancer Nfdump (netflow collector) Nfsen (netflow sensor) switch db server web server n web server 2 web server 1 Softflowd (netflow probe) 10

Netflow Components 1. A netflow probe sorts traffic streams into flows in memory (Src/Dst IP and TCP/UDP port tuples) 2. When the probe determines a flow has terminated, it sends a netflow packet to a netflow collector 3. A netflow sensor analyzes and displays data from the collector Note: The netflow collector can receive netflow streams from multiple probes and write the netflow data to disk.

Nfsen Case Study Results Aggregate traffic for all School Systems Top Talkers Traffic for individual School System 12

Aggregate Traffic

Top Talkers

Traffic for an Individual School System Clicking on a destination IP Address in the list of Top Talkers returns the DNS name and owner information

Data Verification Nfsen and Softflowd appear to be a useful tool set for monitoring an application s incoming and outgoing traffic. To be sure, we need to verify our data. A couple of ways we could do this: Ask a School System for output from a packeteer (or some other method for evaluating the same traffic with a different monitoring infrastructure) Or, generate a known set of traffic monitored by nfsen and softflowd and compare results

Test Plan Two Main Objectives: Explore the limits of softflowd capabilities Determine softflowd/nfsen accuracy in the range of softflowd s operational limits Spirent Avalanche traffic analysis tool will be used to generate flows 17

Limitations Mirroring has to be implemented correctly Packets will be dropped if the total transmit and receive exceeds the transmit capacity of the mirror port No performance guidelines as to how many flows softflowd and the associated hardware can support 18

Extending the Model This was a proof of concept with: A single probe A single contiguous address space Theoretically, the architecture can be expanded to: Multiple probes Multiple address spaces 19

Next Steps Move the front end to MCNC s data center Consider alternative architecture for the probe Low cost Linux in a box Work with the NC Department of Public Instruction to identify applications to monitor 20

To Learn More ClassScape http://classscape.ncsu.edu Softflowd (a netflow probe for linux) http://www.mindrot.org/projects/softflowd/ Nfsen http://nfsen.sourceforge.net/ NCSU Centennial Networking Lab http://www.cnl.ncsu.edu Email John Bass (jbass@cnl.ncsu.edu) or Carla Hunt (carla@mcnc.org) for the accompanying paper and any additional information 21

Special Thanks John Bass Technical Director Centennial Networking Labs North Carolina State University 22