Netflow Offload to Network Silicon for High-Speed Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Netflow technologies are limited in collecting fine-grained network traffic data, especially in environments with non-Cisco network switches, leading to performance degradation due to the need for software-based packet inspection in high-speed networks, and inability to monitor individual NIC ports or VM-to-VM traffic effectively.
Innovation Solution
Offloading Netflow data collection and export functions to network silicon, such as chipset, SoC, or NIC levels, enabling detailed flow data collection and export at the Physical Function (PF) and Virtual Function (VF) layers, allowing for monitoring of individual queues and VM-to-VM traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If software-based packet inspection is used to collect Netflow data, then Netflow data can be collected, but system performance degrades significantly in high-speed networks
Solution Approach 1:
The patent extracts the Netflow data collection function from the software layer and implements it in hardware (network silicon/chipset). This separation allows the software to focus on higher-level processing while the hardware handles packet inspection, resolving the performance degradation issue.
Solution Approach 2:
The patent introduces an intermediary hardware component (network silicon with embedded Netflow collection agent) that sits between the physical network interface and the software processing layer. This intermediary performs packet inspection in hardware, preventing software performance degradation while maintaining Netflow collection capability.
2Device complexity
If Netflow data is collected at aggregated platform level, then network traffic monitoring is simplified, but fine-grained traffic data on individual ports and VMs cannot be captured
Solution Approach 1:
The patent segments the monitoring capability by enabling Netflow collection at multiple hierarchical levels: platform level, individual NIC port level, and even virtual function level. This segmentation allows simultaneous aggregation for simplicity and detail for granular analysis where needed.
Solution Approach 2:
The patent adds a new dimension of monitoring granularity by collecting Netflow data not just at the platform level but also at individual virtual function and port levels. This multi-dimensional approach enables both aggregated and fine-grained views of network traffic.
3Measurement precision
If only Cisco network switches are used for Netflow, then Netflow data collection is enabled, but compatibility with non-Cisco network equipment is lost
Solution Approach 1:
The patent implements Netflow collection capability in the network silicon/chipset itself, making it independent of the network switch vendor. This universal implementation allows Netflow data collection on any network equipment regardless of manufacturer, eliminating Cisco-specific limitations.
4Adaptability or versatility
If Netflow collection is performed in software, then implementation flexibility is maintained, but processing overhead increases significantly
Solution Approach 1:
The patent replaces the software-based Netflow collection mechanism with a hardware-based implementation in network silicon. This substitution eliminates the processing overhead and CPU cycles required for software packet inspection while maintaining implementation flexibility through configurable hardware rules.
Data Source
AI summary
Methods and apparatus for collection of Netflow data and export offload using network silicon. In accordance with aspects of the embodiments, the Netflow export and collection functions are offloaded to the network silicon in the chipset, System on a Chip (SoC), backplane switch, disaggregated switch, virtual switch (vSwitch) accelerator, and Network Interface Card/Controller (NIC) level. For apparatus implementing virtualized environments, one or both of the collection and export functions are implemented at the Physical Function (PF) and/or Virtual Function (VF) layers of the apparatus.


