Distributed Network Flow Exporter for Virtual Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large-scale virtualized data center environments, traditional network flow monitoring using protocols like NetFlow becomes inefficient and prone to single-point failures due to the high number of network flows, overwhelming the virtual supervisor module (VSM) and leading to potential data loss and performance issues.
Innovation Solution
Implementing a distributed network flow export model where each line card in a distributed virtual switch exports NetFlow statistics directly to a collector, using a unique device identifier and modified NetFlow protocol fields to identify distributed exporters, thereby bypassing the VSM and improving scalability and availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network flow monitoring is implemented using a centralized virtual supervisor module (VSM), then network flow tracking capability is provided, but the VSM becomes overwhelmed and creates a single point of failure in large-scale virtualized environments
Solution Approach 1:
The patent divides the centralized VSM into distributed virtual switch components (VEMs) deployed across multiple line cards. Each VEM independently handles network flow monitoring and export for its local segment, eliminating the single point of failure and distributing the processing burden. This segmentation transforms the monolithic VSM architecture into a resilient distributed system where failure of one component does not compromise the entire system.
Solution Approach 2:
The patent extracts the network flow export function from the centralized VSM and relocates it to individual VEMs on each line card. This extraction removes the bottleneck from the control plane (VSM) and places the flow monitoring capability at the data plane (line cards), thereby reducing VSM complexity while maintaining comprehensive flow tracking across the virtualized network.
2Productivity
If the number of network flows is increased to support large-scale virtualized data centers, then network capacity and virtualization capability are improved, but switch resources required to track and manage each flow become excessive
Solution Approach 1:
The patent implements local flow monitoring and export at each line card level rather than centralizing all flow data processing at the VSM. Each VEM on a line card handles flow tracking locally, exporting only relevant flow records to the collector. This local quality approach reduces the aggregate resource consumption across the system by eliminating redundant centralized processing while maintaining the ability to handle large numbers of network flows.
3Ease of operation
If centralized network flow export is used through the VSM, then flow data collection is simplified, but latency increases and scalability is limited due to the VSM bottleneck
Solution Approach 1:
The patent configures each VEM with local flow monitoring and export capabilities in advance, enabling them to independently export flow records to the collector without requiring real-time VSM intervention. This preliminary action of distributing export functionality eliminates the latency associated with centralized VSM processing while maintaining operational simplicity through standardized export protocols and collector configuration.
Data Source
AI summary
A network appliance that is part of a distributed virtual switch collects network flow information for network flows passing through the network appliance. The network flow information is encapsulated into packets as a data record for transport. Network flow exporter type information is added to the network flow records configured to indicate that the packets are from a distributed exporter. An option template is sent to the network flow data collectors that includes a device identifier that is configured to uniquely identify the network appliance. The packets are exported to the network flow data collector. The network flow data collector uses the network flow exporter type information and the device identifier to associate the network flow information with the distributed virtual switch.


