Network-Scoped Port Mirroring via Layer 2 Point-to-Point Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional port mirroring techniques require the sink port to be co-located with the mirrored port within the same logical node, necessitating dedicated facilities and mirroring all traffic on a port, which is inefficient and limits diagnostic and monitoring capabilities.
Innovation Solution
The system enables port mirrored data to be sunk to any node in a network using a network-scoped connection-oriented sink, employing provisioned layer two point-to-point connections like SPVCs, Pseudo-Wires, and VLAN cross-connects, allowing specific flow mirroring without the need for dedicated facilities, and supporting egress, ingress, or simultaneous mirroring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional port mirroring is configured to monitor a specific port, then all packets on that port are copied to a sink port, but this requires the sink port to be co-located with the mirrored port within the same logical node and mirrors all traffic including unnecessary flows
Solution Approach 1:
The patent segments the network monitoring function by separating the flow identification logic (at the source node) from the mirroring function (at the sink node). The source node identifies specific flows to monitor and forwards only those flows to the sink node, which then performs the actual mirroring. This segmentation allows precise flow monitoring without requiring complex sink port configurations at every node.
Solution Approach 2:
The patent introduces an intermediary mechanism where the source node acts as a mediator between the network traffic and the sink node. The source node identifies specific flows and forwards them to the sink node, which then mirrors them. This intermediary approach eliminates the need for the sink port to be co-located with the mirrored port and reduces the complexity of configuring mirroring at multiple nodes.
2Loss of information
If port mirroring is configured to monitor all traffic on a port, then comprehensive monitoring is achieved, but bandwidth requirements and network device port utilization are reduced
Solution Approach 1:
The patent extracts only the specific flows that need to be monitored from the overall network traffic. The source node identifies and extracts the relevant flows based on flow identifiers, forwarding only these extracted flows to the sink node for mirroring. This extraction process ensures complete monitoring information for the flows of interest while significantly reducing bandwidth consumption compared to mirroring all traffic.
3Adaptability or versatility
If dedicated facilities are deployed for port mirroring at each node, then local monitoring capability is improved, but capital and operational expenses increase
Solution Approach 1:
The patent makes the sink node universal by allowing it to receive and mirror flows from any source node in the network. The sink node is not restricted to a specific location or dedicated facility but can be positioned anywhere in the network and will receive the flows it needs to monitor. This multi-functionality approach provides monitoring location flexibility without requiring dedicated facilities at each node.
Data Source
AI summary
Systems and methods for sinking port mirrored from one or more identified flows of data to any node in a network are provided. Moreover, the network is configured to convey the mirrored data to the sink, without the need for any facilities expressly dedicated for this purpose. The present invention removes the requirement to co-locate the sink port within the same logical node. The present invention uses a mirrored flow configured as a provisioned layer two point-to-point connection, such as a Switched Permanent Virtual Circuit (SPVC), Pseudo-Wire (PWE3), a Virtual Local Area Network (VLAN) cross-connect, Provider Backbone Bridging-Traffic Engineering (PBB-TE), and the like. The node with the mirrored port is configured to create copies of the appropriate set of packets (i.e., ingress, egress packets, or both based on provisioning and based on the identified flow), and to forward the packets to the sink port through the provisioned point-to-point connection.


