Production Network Recorder Nodes for Scalable Traffic Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The scalability of monitoring fabrics in network traffic monitoring is limited by the need for separate management of production and monitoring networks, which complicates the integration and scaling of recording capabilities.

Innovation Solution

The solution involves adding recorder nodes directly to the production network, which can be centrally managed through a cloud-based platform, eliminating the need for a monitoring fabric by enabling in-network packet recording and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a monitoring fabric is used to monitor network traffic, then network observability is achieved, but device complexity and management overhead increase

Engineering Contradiction:
Improvenetwork observabilityVSAvoidmonitoring fabric complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts the monitoring function from the separate monitoring fabric and integrates it directly into the production network switches. Recorder nodes are added to the production network to capture packets locally, eliminating the need for traffic to be routed through a dedicated monitoring fabric infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the monitoring network and production network into a single integrated network infrastructure. Recorder nodes are deployed within the production network itself, combining data plane and monitoring plane functions into the same physical infrastructure, thereby reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Quantity of substance

If recorder nodes are added to scale out recording capabilities, then recording capacity increases, but integration complexity with monitoring fabric increases

Engineering Contradiction:
Improverecording capacityVSAvoidintegration complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent makes the production network switches multi-functional by enabling them to perform both data forwarding and packet recording operations. Recorder nodes are integrated directly into the production network infrastructure, allowing switches to serve dual purposes without requiring separate dedicated monitoring hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The production network switches perform packet recording themselves without requiring external monitoring fabric infrastructure. The switches capture and forward packets to recorder nodes autonomously, eliminating the need for complex integration with separate monitoring systems.

Inventive Principle:
Principle #25Self-service

3Reliability

If separate production and monitoring networks are maintained, then network security is preserved, but scalability of monitoring is limited

Engineering Contradiction:
Improvenetwork securityVSAvoidmonitoring scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds a new dimension to the network architecture by introducing recorder nodes that operate within the production network's data plane. This allows monitoring capabilities to scale horizontally by adding recorder nodes without requiring a separate monitoring network infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250193095A1Enabling scale out recording capabilities for production network without monitoring fabric
Publication Date: 2025.06.12 ARISTA NETWORKS INC
  • US20250193095A1 patent drawing
  • US20250193095A1 patent drawing
  • US20250193095A1 patent drawing

AI summary

To scale out recording capabilities, recorder nodes and service leaf or Top-of-Rack (TOR) switches are added to a production network and provisioned to a network-wide workload orchestration and workflow automation platform operating in a cloud computing environment or on the premises of an enterprise. Additionally, switches in the production network are configured to, at ingress, capture packets of a traffic flow between workload applications, mirror the captured packets, and add metadata to an encapsulation header of each captured packet. The encapsulation header includes a virtual Internet Protocol (VIP) address of a recorder node cluster as the destination IP Address. The mirrored packets are routed to the VIP address. The service leaf or TOR switches symmetrically hash the mirrored packets and store them on a recorder node in the cluster. Through a centralized dashboard, a user can search, select, view, diagnose, analyze, or manage network components of the production network.