Fabric Netflow Collector for Scalable ACI Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current netflow data collection methods in Application Centric Infrastructure (ACI) environments face challenges in correlating and managing granular statistics across multiple switches, scalability issues, and difficulty in dynamically managing collectors, especially in cloud deployments where virtual constructs and dynamic VM environments require more efficient and scalable solutions.
Innovation Solution
A distributed virtual netflow collector system is implemented across switches in the ACI fabric, using hash combinations to map packet subflows to IP multicast addresses, allowing for scalable and dynamic distribution of netflow collection, decoupling collectors from monitoring entities, and leveraging fabric compute resources for efficient data aggregation and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If netflow data collection is done on a per node, per interface basis with individual switch collectors, then each switch can independently collect its own flow statistics, but it becomes very difficult to correlate and aggregate granular statistics across the entire network fabric
Solution Approach 1:
The patent merges individual switch-level netflow collectors into a unified fabric-wide collection system. Multiple switch collectors are combined under a common fabric netflow collector that aggregates flow statistics across the entire ACI fabric, enabling correlation of granular statistics while maintaining individual switch independence through the common interface.
Solution Approach 2:
The fabric netflow collector serves multiple functions: it collects flow statistics from individual switches, aggregates data across fabric-wide virtual constructs (Tenants, VRFs, BDs), and provides a unified interface for fabric-level monitoring. This universal collector handles both individual switch data and aggregate fabric statistics simultaneously.
2Device complexity
If netflow collectors are statically mapped to specific switches or interfaces, then the mapping is simple and stable, but the system cannot scale when bandwidth needs vary across different interfaces or switches
Solution Approach 1:
The patent implements dynamic collector mapping where the fabric netflow collector can adapt its data collection and aggregation behavior based on varying bandwidth needs and traffic patterns across different switches and interfaces. The system dynamically adjusts resource allocation and data flow routing rather than relying on fixed static mappings.
Solution Approach 2:
The system changes operational parameters such as collection intervals, aggregation levels, and data routing based on detected bandwidth needs and traffic characteristics. When bandwidth requirements vary across interfaces or switches, the fabric collector adjusts its parameters to optimize performance and scalability.
3Productivity
If multiple netflow collectors are deployed to handle fabric-wide statistics, then collection capacity increases, but management of collector configuration becomes too difficult
Solution Approach 1:
The patent combines multiple collector functions into a single fabric netflow collector that handles aggregate fabric-wide statistics. This unified approach increases collection capacity while simplifying management by eliminating the need to configure and maintain multiple separate collectors, as all fabric-level data converges at this single point.
4Adaptability or versatility
If a collector is provisioned across the entire domain to handle VM moves, then the same collector can track mobile VMs, but this creates a single point of failure and reduces scalability
Solution Approach 1:
The patent segments the netflow collection function across multiple fabric netflow collectors distributed throughout the ACI fabric. Each collector handles a portion of the fabric-wide statistics, eliminating single points of failure. When VMs move between switches, the segmented collector architecture maintains reliability by distributing the tracking load across multiple collectors rather than concentrating it at a single point.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method, the method comprising: calculating, at a collector receiving a data flow and via a hashing algorithm, all possible hashes associated with at least one virtual attribute associated with the data flow to yield resultant hash values; based on the resultant hash values, computing a multicast address group; multicasting the data flow to n leafs based on the multicast address group; and, at respective other collectors, filtering received sub-flows of the data flow based on the resultant hash values, wherein if a respective collector is owned by a hash, the respective collector accepts and saves a respective sub-flow in a local switch collector database.