Production Network Recorder Nodes for Scalable Traffic Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The scalability of monitoring fabrics in network traffic monitoring is limited by the need for separate management of production and monitoring networks, which complicates the integration and scaling of recording capabilities.
Innovation Solution
The solution involves adding recorder nodes directly to the production network, which can be centrally managed through a cloud-based platform, eliminating the need for a monitoring fabric by enabling in-network packet recording and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a monitoring fabric is used to monitor network traffic, then network observability is achieved, but device complexity and management overhead increase
Solution Approach 1:
The patent extracts the monitoring function from the separate monitoring fabric and integrates it directly into the production network switches. Recorder nodes are added to the production network to capture packets locally, eliminating the need for traffic to be routed through a dedicated monitoring fabric infrastructure.
Solution Approach 2:
The patent merges the monitoring network and production network into a single integrated network infrastructure. Recorder nodes are deployed within the production network itself, combining data plane and monitoring plane functions into the same physical infrastructure, thereby reducing overall system complexity.
2Quantity of substance
If recorder nodes are added to scale out recording capabilities, then recording capacity increases, but integration complexity with monitoring fabric increases
Solution Approach 1:
The patent makes the production network switches multi-functional by enabling them to perform both data forwarding and packet recording operations. Recorder nodes are integrated directly into the production network infrastructure, allowing switches to serve dual purposes without requiring separate dedicated monitoring hardware.
Solution Approach 2:
The production network switches perform packet recording themselves without requiring external monitoring fabric infrastructure. The switches capture and forward packets to recorder nodes autonomously, eliminating the need for complex integration with separate monitoring systems.
3Reliability
If separate production and monitoring networks are maintained, then network security is preserved, but scalability of monitoring is limited
Solution Approach 1:
The patent adds a new dimension to the network architecture by introducing recorder nodes that operate within the production network's data plane. This allows monitoring capabilities to scale horizontally by adding recorder nodes without requiring a separate monitoring network infrastructure.
Data Source
AI summary
To scale out recording capabilities, recorder nodes and service leaf or Top-of-Rack (TOR) switches are added to a production network and provisioned to a network-wide workload orchestration and workflow automation platform operating in a cloud computing environment or on the premises of an enterprise. Additionally, switches in the production network are configured to, at ingress, capture packets of a traffic flow between workload applications, mirror the captured packets, and add metadata to an encapsulation header of each captured packet. The encapsulation header includes a virtual Internet Protocol (VIP) address of a recorder node cluster as the destination IP Address. The mirrored packets are routed to the VIP address. The service leaf or TOR switches symmetrically hash the mirrored packets and store them on a recorder node in the cluster. Through a centralized dashboard, a user can search, select, view, diagnose, analyze, or manage network components of the production network.


