Packet Tagging for Network Traffic Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Diagnosing network connectivity issues in data centers is challenging due to complex topologies and the difficulty in identifying intermittent packet drops, which can lead to poor network performance and revenue loss, especially in virtualized environments where traditional troubleshooting methods are time-consuming and labor-intensive.
Innovation Solution
A method and system for tagging packets at end hosts and entry points in the network, allowing devices on the data path to automatically capture and report packet counters for tagged traffic, enabling quick identification of packet drops by using reserved header fields like DSCP in IP headers and implementing an API for per-user/VM/flow-level tagging and packet capture.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If packet capture is enabled hop by hop on each switch to diagnose network issues, then packet loss can be identified, but the troubleshooting process becomes time-consuming and labor-intensive
Solution Approach 1:
The patent segments the network troubleshooting process by introducing flow-specific identifiers that divide the complex network traffic into identifiable segments. Each flow is tagged with unique identifiers allowing precise tracking through the network without requiring manual capture at every hop, thus maintaining measurement precision while reducing time loss.
Solution Approach 2:
The patent introduces an intermediary mechanism - flow identifiers and tagging systems - that mediate between the network traffic and the diagnostic process. These tags act as intermediaries that carry flow information through the network, enabling automated tracking and identification of packet loss sources without manual intervention at each switch.
2Measurement precision
If traditional packet capture methods are used in complex data center topologies, then network issues can be diagnosed, but the complexity of multiple paths and devices makes troubleshooting difficult and error-prone
Solution Approach 1:
The patent applies local quality by assigning specific flow identifiers and tags to individual traffic flows at local points in the network. This allows each flow to be uniquely identified and tracked through the complex topology, enabling precise diagnosis without requiring operators to manage the overall network complexity manually.
Solution Approach 2:
The patent changes the parameter space by introducing flow identifier tags as new parameters that accompany packets through the network. These additional parameters enable automated tracking and correlation of packets across multiple paths and devices, transforming the complex diagnostic problem into a manageable parameter-matching task.
3Measurement precision
If packet drop counters are used on routers and switches, then some packet loss can be detected, but the counters are not specific enough to identify the source of issues for particular traffic flows
Solution Approach 1:
The patent extracts flow-specific information from the packet data by introducing flow identifiers and tags that are attached to packets. This extraction of identifying information allows the system to separate and track individual flows, enabling precise identification of packet loss sources for specific traffic without losing flow identification information.
Solution Approach 2:
The patent implements feedback mechanisms where flow identifiers are tracked throughout the network path, and diagnostic information is fed back to identify the specific source of packet loss. This feedback loop provides detailed information about which specific flow is experiencing issues, rather than just aggregate packet loss counts.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques are disclosed for capturing network traffic in a virtualized computing environment. A packet to be captured in the virtualized environment is identified. The packet is tagged using a pattern of one or more bits in a header of the packet. The pattern indicates that the packet is to be traced. The pattern is propagated to an outer layer during encapsulation of the packet. A header of the encapsulated packet includes the pattern of one or more bits. At least one network device is caused to mirror identified packets based on the reserved bit.