Fabric Netflow Collector for Scalable ACI Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current netflow data collection methods in Application Centric Infrastructure (ACI) environments face challenges in correlating and managing granular statistics across multiple switches, scalability issues, and difficulty in dynamically managing collectors, especially in cloud deployments where virtual constructs and dynamic VM environments require more efficient and scalable solutions.

Innovation Solution

A distributed virtual netflow collector system is implemented across switches in the ACI fabric, using hash combinations to map packet subflows to IP multicast addresses, allowing for scalable and dynamic distribution of netflow collection, decoupling collectors from monitoring entities, and leveraging fabric compute resources for efficient data aggregation and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If netflow data collection is done on a per node, per interface basis with individual switch collectors, then each switch can independently collect its own flow statistics, but it becomes very difficult to correlate and aggregate granular statistics across the entire network fabric

Engineering Contradiction:
ImproveIndependent configuration and management of individual switch collectorsVSAvoidInability to correlate and aggregate flow statistics across fabric-wide virtual constructs
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent merges individual switch-level netflow collectors into a unified fabric-wide collection system. Multiple switch collectors are combined under a common fabric netflow collector that aggregates flow statistics across the entire ACI fabric, enabling correlation of granular statistics while maintaining individual switch independence through the common interface.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The fabric netflow collector serves multiple functions: it collects flow statistics from individual switches, aggregates data across fabric-wide virtual constructs (Tenants, VRFs, BDs), and provides a unified interface for fabric-level monitoring. This universal collector handles both individual switch data and aggregate fabric statistics simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If netflow collectors are statically mapped to specific switches or interfaces, then the mapping is simple and stable, but the system cannot scale when bandwidth needs vary across different interfaces or switches

Engineering Contradiction:
ImproveSimple static mapping configurationVSAvoidInability to scale and adapt to varying bandwidth needs across different switches
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic collector mapping where the fabric netflow collector can adapt its data collection and aggregation behavior based on varying bandwidth needs and traffic patterns across different switches and interfaces. The system dynamically adjusts resource allocation and data flow routing rather than relying on fixed static mappings.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters such as collection intervals, aggregation levels, and data routing based on detected bandwidth needs and traffic characteristics. When bandwidth requirements vary across interfaces or switches, the fabric collector adjusts its parameters to optimize performance and scalability.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If multiple netflow collectors are deployed to handle fabric-wide statistics, then collection capacity increases, but management of collector configuration becomes too difficult

Engineering Contradiction:
ImproveIncreased collection capacity for fabric-wide statisticsVSAvoidDifficulty in managing and configuring multiple collectors
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines multiple collector functions into a single fabric netflow collector that handles aggregate fabric-wide statistics. This unified approach increases collection capacity while simplifying management by eliminating the need to configure and maintain multiple separate collectors, as all fabric-level data converges at this single point.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If a collector is provisioned across the entire domain to handle VM moves, then the same collector can track mobile VMs, but this creates a single point of failure and reduces scalability

Engineering Contradiction:
ImproveAbility to track and collect statistics for mobile VMs across the fabricVSAvoidCreation of a single point of failure
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the netflow collection function across multiple fabric netflow collectors distributed throughout the ACI fabric. Each collector handles a portion of the fabric-wide statistics, eliminating single points of failure. When VMs move between switches, the segmented collector architecture maintains reliability by distributing the tracking load across multiple collectors rather than concentrating it at a single point.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3855682B1System and method for providing scalable flow monitoring in a data center fabric
Publication Date: 2024.06.26 CISCO TECHNOLOGY INC
  • EP3855682B1 patent drawingFigure 1
  • EP3855682B1 patent drawingFigure 2
  • EP3855682B1 patent drawingFigure 3

AI summary

A system and method, the method comprising: calculating, at a collector receiving a data flow and via a hashing algorithm, all possible hashes associated with at least one virtual attribute associated with the data flow to yield resultant hash values; based on the resultant hash values, computing a multicast address group; multicasting the data flow to n leafs based on the multicast address group; and, at respective other collectors, filtering received sub-flows of the data flow based on the resultant hash values, wherein if a respective collector is owned by a hash, the respective collector accepts and saves a respective sub-flow in a local switch collector database.