WO2014046932A1 - Exporting real time network traffic latency and buffer occupancy - Google Patents

Exporting real time network traffic latency and buffer occupancy Download PDF

Info

Publication number
WO2014046932A1
WO2014046932A1 PCT/US2013/059180 US2013059180W WO2014046932A1 WO 2014046932 A1 WO2014046932 A1 WO 2014046932A1 US 2013059180 W US2013059180 W US 2013059180W WO 2014046932 A1 WO2014046932 A1 WO 2014046932A1
Authority
WO
WIPO (PCT)
Prior art keywords
packet
buffer
analytics
network device
packets
Prior art date
Application number
PCT/US2013/059180
Other languages
French (fr)
Inventor
Thomas J. Edsall
Yue J. YANG
Wei-Jen Huang
Chih-Tsung Huang
Original Assignee
Cisco Technology, Inc.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Cisco Technology, Inc. filed Critical Cisco Technology, Inc.
Priority to IN444MUN2015 priority Critical patent/IN2015MN00444A/en
Priority to CN201380048250.6A priority patent/CN104641602B/en
Priority to EP13771660.1A priority patent/EP2898637B1/en
Publication of WO2014046932A1 publication Critical patent/WO2014046932A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/04Processing captured monitoring data, e.g. for logfile generation
    • H04L43/045Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • H04L43/0876Network utilisation, e.g. volume of load or congestion level
    • H04L43/0882Utilisation of link capacity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/10Active monitoring, e.g. heartbeat, ping or trace-route
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/30Flow control; Congestion control in combination with information about buffer occupancy at either end or at transit nodes

Definitions

  • the present disclosure relates generally to analysis of occupancy of a buffer in a network device.
  • data is transmitted from a source to a destination in the form of packets that generally pass through one or more network devices (e.g., switches, routers, firewalls, etc.). During the transmission, certain errors may arise that result in, for example, redundant data being added to the original data, dropped packets, etc.
  • network devices e.g., switches, routers, firewalls, etc.
  • Massively Scalable Data Center and Cloud Computing systems are putting more traffic load on network equipment such that over-provisioned networks are no longer possible. Monitoring of a buffer in a network device is useful to gain knowledge for network administration, analysis, and performance.
  • FIG. 1 is a diagram illustrating a network device configured to generate buffer analytics packets based on occupancy of a buffer in the network device.
  • FIG. 2 is a block diagram illustrating one example implementation of the buffer analytics logic.
  • FIG. 3 is a diagram that generally illustrates a format of a buffer analytics packet.
  • FIG. 4 is a flow chart depicting operations in a network device to generate and output buffer analytics packets.
  • FIG. 5 is a flow chart depicting operations in a device that receives and retrieves information from the buffer analytics packets.
  • FIG. 6 is a diagram illustrating an example of playback of buffer occupancy from buffer analytics packets.
  • Packets are received at a network device.
  • Information is captured describing occupancy of the buffer caused by packet flow through the buffer in the network device.
  • Analytics packets are generated containing the information. The analytics packets from the network device for retrieval of the information contained therein for analysis, replay of buffer occupancy, etc.
  • FIG. 1 a diagram is shown of a network environment 5 in which a network device 10 is provided that is configured to generate buffer analytics packets based on occupancy of a buffer the network device 10.
  • the network device 10 comprises a plurality of ports 12(1)-12(N), any of which can serve as an ingress port or egress port at any time.
  • the network device includes a buffer 14, buffer analytics logic 16, a central processing unit (CPU) 18 and memory 19.
  • CPU central processing unit
  • the buffer 14 may reside the switch fabric.
  • the buffer analytics logic 14 may be implemented in hardware by digital logic gates (and embedded in the switch fabric) or by software stored in memory 19 and executed by CPU 18.
  • Packets 20 arrive at the network device 10 via any of the ports 12(1)-12(N).
  • FIG. 1 shows an example where packets are arriving at ports 12(1), 12(2) and 12(3).
  • the network device 10 is coupled to a network 40, e.g., a local area network or wide area network (the Internet), via ports 12(5)-12(N) to ultimately communicate with any one or more of the network devices 50(1)-50(M).
  • a network 40 e.g., a local area network or wide area network (the Internet) to ultimately communicate with any one or more of the network devices 50(1)-50(M).
  • the buffer analytics logic 16 captures information describing occupancy of the buffer 14 caused by packet flow through the buffer in the network device 10, and generates buffer analytics packets 30 containing the information.
  • buffer analytics packets 30 there are two types of buffer analytics packets: enqueue buffer analytics packets and dequeue buffer analytics packets.
  • the buffer analytics packets 30 are then output from the network device 10 at a programmable time schedule (or based of packet size) in any one of several ways to allow for replay of the occupancy of the buffer.
  • the network device 10 may insert into buffer analytics packets 30 an address for a destination of the buffer analytics packet, e.g., address for any device connected to the network 40, such as collector device 60 having a CPU 62 and memory 64.
  • the network device 10 sends the analytics packet 30 via network 40 to the destination collector device 60, which may be at any location, local or remote from network device 10.
  • the network device 10 may output the analytics packet 30 to a dedicated port, e.g., port 12(4) of the network device 10 to which a collector device 70 is connected.
  • the dedicated analytics port 12(4) can participate in port channel or fixed port distribution to expand bandwidth to a single or multiple monitor ports.
  • the collector device 70 since it is connected directly to port 12(4), is usually local to the network device 10.
  • the collector device 70 includes a CPU 72 and memory 74.
  • the analytics packets 30 may be output to the onboard CPU 18 and memory 19 in the network device 10, such that CPU 18 and memory 19 also serve as a collector device.
  • the CPUs 18, 62 and 72 may replay and analyze the occupancy of the buffer 14 based on software instructions stored in its associated memory 19, 64 and 74, respectively.
  • the analytics packets are stored in the memory 19, 64 and 74 for the associated CPU 18, 62 and 72, respectively.
  • the network device 10 can be any network device now known or hereinafter developed, including a switch, router, gateway, a software stack on a host device, virtual network interface cards (VNICs) virtual switches, physical network interface cards (including those that support virtualization).
  • VNICs virtual network interface cards
  • Memory 19, 64 and 74 may comprise read only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical/tangible memory storage devices.
  • the memory 19, 64 and 74 may comprise one or more tangible (non-transitory) computer readable storage media (e.g., a memory device) encoded with software comprising computer executable instructions and when the software is executed (by the associated CPU) it is operable to perform the operations described herein.
  • FIG. 2 shows that the buffer analytics logic 16 comprises an enqueue analytics packet generator 80 and a dequeue analytics packet generator 82.
  • the buffer analytics logic 16 comprises an enqueue analytics packet generator 80 and a dequeue analytics packet generator 82.
  • the admission control block 84 and departure control block 86 are commonly found in a network device and are hardware (or software) blocks used to make processing decisions, such as a drop, scheduling, rate limiting, policing, shaping, etc.
  • the enqueue analytics packet generator 80 is configured to generate an analytics packet, called an enqueue buffer analytics packet shown at reference numeral 32, that describes/summarizes a packet being enqueued into buffer 14.
  • the dequeue analytics packet generator 82 is configured to generate an analytics packet, called a dequeue buffer analytics packet shown at reference numeral 34, that describes/summarizes a packet being dequeued from buffer 14.
  • the packet assembler 88 assembles a packet 20 ready out from the buffer 14 for output from the network device.
  • the enqueue analytics packet generator 80 captures, for a packet enqueued to buffer 14, information describing one or more of identification of ingress port of arrival of the packet at the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, Layer 4 source address and destination address, class of service, and timestamp of arrival at the ingress port.
  • the dequeue analytics packet generator 82 captures, for a packet dequeued from the buffer 14, information describing one or more of identification of egress port for departure of the packet from the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, and timestamp of departure from the egress port.
  • the enqueue buffer analytics packet 32 generated by the enqueue analytics packet generator 80, dequeue buffer analytics packet 34 generated by the dequeue analytics packet generator 82, and packet 20 output by the packet assembler 88, are all supplied to a corresponding input of the multiplexer 90.
  • the multiplexer 90 selectively outputs, at any given time, either a packet 20, an enqueue buffer analytics packet 32 or a dequeue buffer analytics packet 34. Priority is given to output of a packet 20 in order to maintain proper flow of network traffic through the network device 10.
  • Trigger for output of an analytics packet may be based on time (according to a schedule) or size of a packet enqueued to the buffer or dequeued from the buffer.
  • FIG. 3 shows an example format of an enqueue buffer analytics packet 32 or dequeue buffer analytics packet 34.
  • an enqueue buffer analytics packet 32 summarizes a packet that is being enqueued to a buffer
  • a dequeue buffer analytics packet 34 summarizes a packet that is being dequeued from the buffer.
  • an enqueue buffer analytics packet 32 and a dequeue buffer analytics packet 34 includes an Ethernet Header field 100, a Common Header field 110, one or more Records fields 120(1)-120(N) and a cyclic redundancy check (CRC) field 130.
  • the Ethernet header field 110 is field that is used to encapsulate the destination address of the analytics packet, e.g., to direct the analytics packet to a destination, i.e., a local or remote collector device (as indicated in FIG. 1), including to the CPU of the network device itself.
  • the Ethernet header field 110 includes information, such as media access control (MAC) destination address/source address (DA/SA), optional IEEE 802. lq virtual local area network (VLAN) routing information, an optional Internet Protocol (IP) header including an IP SA and IP DA.
  • MAC media access control
  • DA/SA destination address/source address
  • IP Internet Protocol
  • the Ethernet header field 110 contains information used to route the buffer analytics packet to its desired destination.
  • the common header field 110 contains information captured from the header of a packet that has been enqueued to or dequeued (as the case may be) from the buffer.
  • the common header field summarizes the header of a packet that is enqueued to and dequeued from the buffer in the network device.
  • the common header field includes information for a common header version (to allow for backward/future compatibility), timescale information representing the timescale of the enqueued or dequeued packet, a timestamp of the packet arrival and/or departure to/from the buffer to allow for replay, a record number to allow a collector to determine how many, if any records, have been lost in between the current analytics packet and the last received analytics packet, and one or more user defined fields such as class of service, type of service, etc.
  • the record field 120 contains data for an enqueued or dequeued packet that a user configures the buffer analytics logic to capture. Examples of data that may be include in a record field includes:
  • MAC SA/DA L2 Header Fields
  • IP SA/DA priority L3 Header
  • compressed versions i.e. last 24 bits
  • priority L3 Header IP SA/DA
  • compressed versions i.e. last 16 bits
  • User defined fields including one or more of:
  • Drop an indication of whether the packet was dropped.
  • Queue id identifier of the queue (unicast or multicast) to which the packet is associated.
  • Queue length length of the queue to which the packet is associated.
  • Packet length overall length of size of the packet.
  • Timestamp absolute or relative to common header from protocols such as Precision Time Protocol (PTP) or Network Time Protocol (NTP)
  • PTP Precision Time Protocol
  • NTP Network Time Protocol
  • Programmable bytes any user configurable one or more bytes of the payload of a packet
  • Last record to indicate that this is last record field in the analytics packet.
  • the record field 120 for an analytics packet contains information about an enqueued packet or dequeued packet to describe buffer occupancy characteristics such as overall buffer occupancy, buffer occupancy based on packet priority, unicast queue length, multicast queue length; packet properties such as drop, port mirrored, load balanced, bridged or routed, and packet length; and packet error properties such as Cyclic Redundancy Check (CRC), and various error protocols such as Runt, Giant, and Jabber.
  • buffer occupancy characteristics such as overall buffer occupancy, buffer occupancy based on packet priority, unicast queue length, multicast queue length
  • packet properties such as drop, port mirrored, load balanced, bridged or routed, and packet length
  • packet error properties such as Cyclic Redundancy Check (CRC), and various error protocols such as Runt, Giant, and Jabber.
  • information is included in the record field describing one or more of identification of ingress port of arrival of the packet at the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, Layer 4 source address and destination address, class of service, and timestamp of arrival at the ingress port.
  • information is included in the record field describing one or more of identification of egress port for departure of the packet from the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, and timestamp of departure from the egress port.
  • Other examples of data captured into user defined fields include an indication of a packet being rate limited, shaped, policed as well as any programmable bytes of the packet including payload.
  • the size of the analytics packet may be the Maximum Transmit Unit (MTU), a switch specific analytics MTU, determined using a time-based method (e.g., analytics packet generated and transmitted at predetermined times), determined based on a selected number of packets, or by other techniques.
  • MTU Maximum Transmit Unit
  • time-based method e.g., analytics packet generated and transmitted at predetermined times
  • FIG. 4 provides a flow chart that depicts the high level operations performed in a network device in generating and outputting analytics packets.
  • a network device receives a packet.
  • the network device captures information describing occupancy of a buffer caused by packet flow through the buffer in the network device.
  • an analytics packet is generated for each packet that is enqueued to and/or dequeued from the buffer.
  • a destination address is inserted into the analytics packet.
  • the network device processes the packet in the normal course, and outputs an analytics packet to its destination (local or remote network destination) or to a local CPU of the network device.
  • the capturing, generating, and outputting operations are triggered to be performed based on at least one of time and size of enqueued packet or dequeued packet.
  • FIG. 5 illustrates a high level flow chart depicting the operations performed at a destination of the analytics packets.
  • a collector device receives the analytics packets over time.
  • the collector device parses the analytics packets to retrieve information in the individual records as well as the common header, and uses this information to replay buffer occupancy, perform traffic latency and perform other analysis.
  • FIG. 6 shows an example of how a replay of buffer occupancy, subject to certain filtering criteria, may be made.
  • a "*" represents data that has been stored into buffer and lack of "*" represents absence or removal of data from the buffer.
  • a replay of the buffer may be achieved using specific pieces of information that are of interest to network administrators and application developers. Recording each of these categories would require enormous bandwidth if a complete enqueued or dequeued packet is captured.

Abstract

Techniques are presented herein to facilitate the monitoring of occupancy of a buffer in a network device. Packets are received at a network device. Information is captured describing occupancy of the buffer caused by packet flow through the buffer in the network device. Analytics packets are generated containing the information. The analytics packets from the network device for retrieval of the information contained therein for analysis, replay of buffer occupancy, etc.

Description

EXPORTING REAL TIME NETWORK TRAFFIC LATENCY
AND BUFFER OCCUPANCY
RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Application No. 61/702,320, filed September 18, 2012, entitled "Exporting Real Time Network Traffic Latency and Buffer Occupancy," the entirety of which is incorporated herein by reference.
TECHNICAL FIELD
[0002] The present disclosure relates generally to analysis of occupancy of a buffer in a network device.
BACKGROUND
[0003] In a computer network, data is transmitted from a source to a destination in the form of packets that generally pass through one or more network devices (e.g., switches, routers, firewalls, etc.). During the transmission, certain errors may arise that result in, for example, redundant data being added to the original data, dropped packets, etc. Massively Scalable Data Center and Cloud Computing systems are putting more traffic load on network equipment such that over-provisioned networks are no longer possible. Monitoring of a buffer in a network device is useful to gain knowledge for network administration, analysis, and performance.
BRIEF DESCRIPTION OF THE DRAWINGS
[0004] FIG. 1 is a diagram illustrating a network device configured to generate buffer analytics packets based on occupancy of a buffer in the network device.
[0005] FIG. 2 is a block diagram illustrating one example implementation of the buffer analytics logic.
[0006] FIG. 3 is a diagram that generally illustrates a format of a buffer analytics packet.
[0007] FIG. 4 is a flow chart depicting operations in a network device to generate and output buffer analytics packets.
[0008] FIG. 5 is a flow chart depicting operations in a device that receives and retrieves information from the buffer analytics packets. [0009] FIG. 6 is a diagram illustrating an example of playback of buffer occupancy from buffer analytics packets.
DESCRIPTION OF EXAMPLE EMBODIMENTS
Overview
[0010] Techniques are presented herein to facilitate the monitoring of occupancy of a buffer in a network device. Packets are received at a network device. Information is captured describing occupancy of the buffer caused by packet flow through the buffer in the network device. Analytics packets are generated containing the information. The analytics packets from the network device for retrieval of the information contained therein for analysis, replay of buffer occupancy, etc.
Example Embodiments
[0011] Complete network visibility into buffer occupancy and the ability to replay occupancy via export and post processing is important since network disruptions (e.g., microbursts) can occur at any time. Furthermore, the ability to replay buffer occupancy allows for effective diagnosis of network issues to provide corrective actions. Existing solutions such as port mirroring (i.e., Switched Port Analyzer (SPAN)) do not provide visibility of buffer occupancy. As such, presented herein are techniques for monitoring and replaying buffer occupancy.
[0012] Referring now to FIG. 1, a diagram is shown of a network environment 5 in which a network device 10 is provided that is configured to generate buffer analytics packets based on occupancy of a buffer the network device 10. The network device 10 comprises a plurality of ports 12(1)-12(N), any of which can serve as an ingress port or egress port at any time. The network device includes a buffer 14, buffer analytics logic 16, a central processing unit (CPU) 18 and memory 19. It should be understood that there are other components of the network device 10, such as a switch fabric or application specific integrated circuit (ASIC), and the buffer 14 may reside the switch fabric. There are typically numerous buffers in the network device 10, but for simplicity only one is shown in FIG. 1. It should be understood that the techniques presented herein are useful for each of a plurality of buffers in a network device. The buffer analytics logic 14 may be implemented in hardware by digital logic gates (and embedded in the switch fabric) or by software stored in memory 19 and executed by CPU 18.
[0013] Packets 20 arrive at the network device 10 via any of the ports 12(1)-12(N). FIG. 1 shows an example where packets are arriving at ports 12(1), 12(2) and 12(3). The network device 10 is coupled to a network 40, e.g., a local area network or wide area network (the Internet), via ports 12(5)-12(N) to ultimately communicate with any one or more of the network devices 50(1)-50(M).
[0014] Generally, the buffer analytics logic 16 captures information describing occupancy of the buffer 14 caused by packet flow through the buffer in the network device 10, and generates buffer analytics packets 30 containing the information. As will become apparent from the description below in connection with FIG. 2, there are two types of buffer analytics packets: enqueue buffer analytics packets and dequeue buffer analytics packets. The buffer analytics packets 30 are then output from the network device 10 at a programmable time schedule (or based of packet size) in any one of several ways to allow for replay of the occupancy of the buffer.
[0015] First, the network device 10 may insert into buffer analytics packets 30 an address for a destination of the buffer analytics packet, e.g., address for any device connected to the network 40, such as collector device 60 having a CPU 62 and memory 64. The network device 10 sends the analytics packet 30 via network 40 to the destination collector device 60, which may be at any location, local or remote from network device 10.
[0016] Second, the network device 10 may output the analytics packet 30 to a dedicated port, e.g., port 12(4) of the network device 10 to which a collector device 70 is connected. The dedicated analytics port 12(4) can participate in port channel or fixed port distribution to expand bandwidth to a single or multiple monitor ports. The collector device 70, since it is connected directly to port 12(4), is usually local to the network device 10. The collector device 70 includes a CPU 72 and memory 74. [0017] Third, the analytics packets 30 may be output to the onboard CPU 18 and memory 19 in the network device 10, such that CPU 18 and memory 19 also serve as a collector device. In any of these scenarios, the CPUs 18, 62 and 72 may replay and analyze the occupancy of the buffer 14 based on software instructions stored in its associated memory 19, 64 and 74, respectively. Moreover, the analytics packets are stored in the memory 19, 64 and 74 for the associated CPU 18, 62 and 72, respectively.
[0018] The network device 10 can be any network device now known or hereinafter developed, including a switch, router, gateway, a software stack on a host device, virtual network interface cards (VNICs) virtual switches, physical network interface cards (including those that support virtualization).
[0019] Memory 19, 64 and 74 may comprise read only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical/tangible memory storage devices. Thus, in general, the memory 19, 64 and 74 may comprise one or more tangible (non-transitory) computer readable storage media (e.g., a memory device) encoded with software comprising computer executable instructions and when the software is executed (by the associated CPU) it is operable to perform the operations described herein.
[0020] Reference is now made to FIG. 2 for a more detailed description of the buffer analytics logic 16. FIG. 2 shows that the buffer analytics logic 16 comprises an enqueue analytics packet generator 80 and a dequeue analytics packet generator 82. In addition, there are an admission control block 84, a departure control block 86, a packet assembler 88 and a multiplexer 90. The admission control block 84 and departure control block 86 are commonly found in a network device and are hardware (or software) blocks used to make processing decisions, such as a drop, scheduling, rate limiting, policing, shaping, etc.
[0021] The enqueue analytics packet generator 80 is configured to generate an analytics packet, called an enqueue buffer analytics packet shown at reference numeral 32, that describes/summarizes a packet being enqueued into buffer 14. Similarly, the dequeue analytics packet generator 82 is configured to generate an analytics packet, called a dequeue buffer analytics packet shown at reference numeral 34, that describes/summarizes a packet being dequeued from buffer 14. The packet assembler 88 assembles a packet 20 ready out from the buffer 14 for output from the network device.
[0022] The enqueue analytics packet generator 80 captures, for a packet enqueued to buffer 14, information describing one or more of identification of ingress port of arrival of the packet at the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, Layer 4 source address and destination address, class of service, and timestamp of arrival at the ingress port. Similarly, the dequeue analytics packet generator 82 captures, for a packet dequeued from the buffer 14, information describing one or more of identification of egress port for departure of the packet from the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, and timestamp of departure from the egress port.
[0023] The enqueue buffer analytics packet 32 generated by the enqueue analytics packet generator 80, dequeue buffer analytics packet 34 generated by the dequeue analytics packet generator 82, and packet 20 output by the packet assembler 88, are all supplied to a corresponding input of the multiplexer 90. The multiplexer 90 selectively outputs, at any given time, either a packet 20, an enqueue buffer analytics packet 32 or a dequeue buffer analytics packet 34. Priority is given to output of a packet 20 in order to maintain proper flow of network traffic through the network device 10. Trigger for output of an analytics packet may be based on time (according to a schedule) or size of a packet enqueued to the buffer or dequeued from the buffer.
[0024] Reference is now made to FIG. 3. FIG. 3 shows an example format of an enqueue buffer analytics packet 32 or dequeue buffer analytics packet 34. As explained above, an enqueue buffer analytics packet 32 summarizes a packet that is being enqueued to a buffer and a dequeue buffer analytics packet 34 summarizes a packet that is being dequeued from the buffer. These analytics packets, when accumulated over time for packets that pass through the buffer, allow for playback of occupancy characteristics of the buffer and traffic flow of packets through the buffer. As shown in FIG. 3, an enqueue buffer analytics packet 32 and a dequeue buffer analytics packet 34 includes an Ethernet Header field 100, a Common Header field 110, one or more Records fields 120(1)-120(N) and a cyclic redundancy check (CRC) field 130. [0025] The Ethernet header field 110 is field that is used to encapsulate the destination address of the analytics packet, e.g., to direct the analytics packet to a destination, i.e., a local or remote collector device (as indicated in FIG. 1), including to the CPU of the network device itself. To this end, the Ethernet header field 110 includes information, such as media access control (MAC) destination address/source address (DA/SA), optional IEEE 802. lq virtual local area network (VLAN) routing information, an optional Internet Protocol (IP) header including an IP SA and IP DA. Again, the Ethernet header field 110 contains information used to route the buffer analytics packet to its desired destination.
[0026] The common header field 110 contains information captured from the header of a packet that has been enqueued to or dequeued (as the case may be) from the buffer. Thus, the common header field summarizes the header of a packet that is enqueued to and dequeued from the buffer in the network device. For example, the common header field includes information for a common header version (to allow for backward/future compatibility), timescale information representing the timescale of the enqueued or dequeued packet, a timestamp of the packet arrival and/or departure to/from the buffer to allow for replay, a record number to allow a collector to determine how many, if any records, have been lost in between the current analytics packet and the last received analytics packet, and one or more user defined fields such as class of service, type of service, etc.
[0027] The record field 120 contains data for an enqueued or dequeued packet that a user configures the buffer analytics logic to capture. Examples of data that may be include in a record field includes:
Format version to indicate a format version of the record field for backward/future compatibility.
L2 Header Fields (MAC SA/DA) or compressed versions (i.e. last 24 bits) and priority L3 Header (IP SA/DA) or compressed versions (i.e. last 16 bits) and priority and protocol type
L4 Header (TCP/UDP SA/DA)
User defined fields, including one or more of:
Input/output port
Drop— an indication of whether the packet was dropped. Queue id— identifier of the queue (unicast or multicast) to which the packet is associated.
Queue length— length of the queue to which the packet is associated. Packet length— overall length of size of the packet.
Timestamp (absolute or relative to common header from protocols such as Precision Time Protocol (PTP) or Network Time Protocol (NTP)) Programmable bytes— any user configurable one or more bytes of the payload of a packet
Internally specific fields such as logical interface mapped from table with keys such as {ingress/egress port, vlan}
Last record— to indicate that this is last record field in the analytics packet.
[0028] Thus, to summarize, the record field 120 for an analytics packet contains information about an enqueued packet or dequeued packet to describe buffer occupancy characteristics such as overall buffer occupancy, buffer occupancy based on packet priority, unicast queue length, multicast queue length; packet properties such as drop, port mirrored, load balanced, bridged or routed, and packet length; and packet error properties such as Cyclic Redundancy Check (CRC), and various error protocols such as Runt, Giant, and Jabber. More specifically, for a packet enqueued to the buffer, information is included in the record field describing one or more of identification of ingress port of arrival of the packet at the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, Layer 4 source address and destination address, class of service, and timestamp of arrival at the ingress port. Similarly, for a packet dequeued from the buffer, information is included in the record field describing one or more of identification of egress port for departure of the packet from the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, and timestamp of departure from the egress port. Other examples of data captured into user defined fields include an indication of a packet being rate limited, shaped, policed as well as any programmable bytes of the packet including payload.
[0029] The size of the analytics packet (Ethernet header field, common header field and records) may be the Maximum Transmit Unit (MTU), a switch specific analytics MTU, determined using a time-based method (e.g., analytics packet generated and transmitted at predetermined times), determined based on a selected number of packets, or by other techniques.
[0030] Reference is now made to FIG. 4. FIG. 4 provides a flow chart that depicts the high level operations performed in a network device in generating and outputting analytics packets. At 200, a network device receives a packet. At 210, the network device captures information describing occupancy of a buffer caused by packet flow through the buffer in the network device. At 220, an analytics packet is generated for each packet that is enqueued to and/or dequeued from the buffer. At 230, a destination address is inserted into the analytics packet. At 240, the network device processes the packet in the normal course, and outputs an analytics packet to its destination (local or remote network destination) or to a local CPU of the network device. The capturing, generating, and outputting operations are triggered to be performed based on at least one of time and size of enqueued packet or dequeued packet.
[0031] FIG. 5 illustrates a high level flow chart depicting the operations performed at a destination of the analytics packets. At 300, a collector device receives the analytics packets over time. At 310, the collector device parses the analytics packets to retrieve information in the individual records as well as the common header, and uses this information to replay buffer occupancy, perform traffic latency and perform other analysis.
[0032] FIG. 6 shows an example of how a replay of buffer occupancy, subject to certain filtering criteria, may be made. In FIG. 6, a "*" represents data that has been stored into buffer and lack of "*" represents absence or removal of data from the buffer.
[0033] By generating and exporting analytics packets that summarize properties of packets enqueued to and dequeued from a buffer in a network device, a replay of the buffer may be achieved using specific pieces of information that are of interest to network administrators and application developers. Recording each of these categories would require enormous bandwidth if a complete enqueued or dequeued packet is captured.
[0034] In summary, presented herein are techniques that enable a time-based complete replay of the buffer occupancy with resolution determined by a sampling period. These techniques provide visibility of traffic flows received by network devices. The information provided can be used by network administrators to gain insight into their specific network traffic, such as per- packet latency, buffer occupancy, and possible congestion sources. This information can lead to better allocation and provisioning of network resources, reduced congestion, and higher overall throughput. By parsing and aggregating relevant characteristics from each packet according to the techniques presented herein, bandwidth requirements associated with network monitoring are greatly reduced. As such, these techniques assist in reducing the amount of data exported for analysis.
[0035] The above description is intended by way of example only.

Claims

What is claimed is:
1. A method comprising:
receiving packets at a network device;
capturing information describing occupancy of a buffer caused by packet flow through the buffer in the network device;
generating analytics packets containing the information; and
outputting the analytics packets from the network device.
2. The method of claim 1, wherein outputting comprises:
inserting into the analytics packets an address for a destination of the analytics packet; and
sending the analytics packets into a network to the destination.
3. The method of claim 1, wherein outputting comprises outputting the analytics packet to a dedicated port of the network device to which a collector device is connected.
4. The method of claim 1 , wherein capturing comprises capturing, for a packet enqueued to the buffer, information describing one or more of identification of ingress port of arrival of the packet at the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, Layer 4 source address and destination address, class of service, and timestamp of arrival at the ingress port.
5. The method of claim 1, wherein capturing comprises capturing, for a packet dequeued from the buffer, information describing one or more of identification of egress port for departure of the packet from the network device, Layer 2 source address and destination address, Layer 3 source address and destination address, and timestamp of departure from the egress port.
6. The method of claim 1 , wherein generating comprises generating at least one of an enqueue analytics packet and a dequeue analytics packet, the enqueue analytics packet comprising information describing properties associated with a packet being enqueued to the buffer in the network device and the dequeue analytics packet comprising information describing properties associated with a packet being dequeued from the buffer in the network device, and further comprising inserting an address into the enqueue analytics packet and into the dequeue analytics packet, and sending the enqueue analytics packet and dequeue analytics packet into the network to a destination.
7. The method of claim 1, wherein generating the analytics packets comprises generating packets each comprising a header containing information to be used for directing the analytics packet to a destination, and a records summarizing a packet enqueued in the buffer or a packet dequeued from the buffer.
8. The method of claim 1, wherein capturing comprises capturing information describing buffer occupancy characteristics of the buffer including at least one of: overall buffer occupancy, buffer occupancy for based on packet priority, unicast queue length and multicast queue length.
9. The method of claim 1, wherein capturing comprises capturing information describing packet processing properties for packets processed by the network device including at least one of: drop, port mirrored, load balanced, bridged or routed, and packet length.
10. The method of claim 1, wherein capturing comprises capturing information describing packet processing properties for packets corresponding to user defined parameters for one or more of: rate limited, shaped, policed and any programmable bytes of the packet including payload.
11. The method of claim 1 , wherein capturing, generating, and outputting are triggered to be performed based on at least one of time and size of packet.
12. An apparatus comprising:
a buffer configured to buffer packets that are received at a network device and are to be processed for routing in the network by the network device; and
a processor unit coupled to the buffer and configured to:
capture information describing occupancy of a buffer caused by packet flow through the buffer in the network device;
generate analytics packets containing the information; and
output the analytics packets.
13. The apparatus of claim 12, wherein the processor unit is further configured to insert into the analytics packets an address for a destination of the analytics packet, and to send the analytics packets into a network to the destination.
14. The apparatus of claim 12, wherein the processor unit is configured to generate at least one of an enqueue analytics packet and a dequeue analytics packet, the enqueue analytics packet comprising information describing properties associated with a packet being enqueued to the buffer in the network device and the dequeue analytics packet comprising information describing properties associated with a packet being dequeued from the buffer in the network device.
15. The apparatus of claim 12, wherein the processor unit is configured to generate the analytics packets, each analytics packet comprising an Ethernet header field containing information to be used for directing the analytics packet to a destination, a common header containing information derived from a header of a packet enqueued to the buffer or dequeued from the buffer and one or more record fields containing user defined information summarizing data contained in a packet enqueued in the buffer or a packet dequeued from the buffer.
16. The apparatus of claim 12, wherein the processor unit is configured to capture information describing buffer occupancy characteristics of the buffer including at least one of: overall buffer occupancy, buffer occupancy for based on packet priority, unicast queue length and multicast queue length.
17. The apparatus of claim 12, wherein the processor unit is configured to capture information describing packet processing properties for packets corresponding to user defined parameters for one or more of: rate limited, shaped, policed and any programmable bytes of the packet including payload.
18. A computer readable tangible storage media encoded with instructions that, when executed by a processor, cause the processor to:
capture information describing occupancy of a buffer caused by packet flow through the buffer in the network device;
generate analytics packets containing the information; and
output the analytics packets from the network device.
19. The computer readable tangible storage media of claim 18, wherein the instructions that cause the processor to generate comprise instructions that cause the processor generate at least one of an enqueue analytics packet and a dequeue analytics packet, the enqueue analytics packet comprising information describing properties associated with a packet being enqueued to the buffer in the network device and the dequeue analytics packet comprising information describing properties associated with a packet being dequeued from the buffer in the network device.
20. The computer readable tangible storage media of claim 18, wherein the instructions that cause the processor to generate comprise instructions that cause the processor generate the analytics packets, each analytics packet comprising an Ethernet header field containing information to be used for directing the analytics packet to a destination, a common header containing information derived from a header of a packet enqueued to the buffer or dequeued from the buffer and one or more record fields containing user defined information summarizing data contained in a packet enqueued in the buffer or a packet dequeued from the buffer.
21. The computer readable tangible storage media of claim 18, wherein the instructions that cause the processor to capture comprise instructions that cause the processor to capture information describing buffer occupancy characteristics of the buffer including at least one of: overall buffer occupancy, buffer occupancy for based on packet priority, unicast queue length and multicast queue length.
PCT/US2013/059180 2012-09-18 2013-09-11 Exporting real time network traffic latency and buffer occupancy WO2014046932A1 (en)

Priority Applications (3)

Application Number Priority Date Filing Date Title
IN444MUN2015 IN2015MN00444A (en) 2012-09-18 2013-09-11
CN201380048250.6A CN104641602B (en) 2012-09-18 2013-09-11 Export real-time network traffic delay and buffering area takes
EP13771660.1A EP2898637B1 (en) 2012-09-18 2013-09-11 Exporting real time network traffic latency and buffer occupancy

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US201261702320P 2012-09-18 2012-09-18
US61/702,320 2012-09-18
US13/708,265 2012-12-07
US13/708,265 US9077619B2 (en) 2012-09-18 2012-12-07 Exporting real time network traffic latency and buffer occupancy

Publications (1)

Publication Number Publication Date
WO2014046932A1 true WO2014046932A1 (en) 2014-03-27

Family

ID=50274367

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2013/059180 WO2014046932A1 (en) 2012-09-18 2013-09-11 Exporting real time network traffic latency and buffer occupancy

Country Status (5)

Country Link
US (4) US9077619B2 (en)
EP (1) EP2898637B1 (en)
CN (1) CN104641602B (en)
IN (1) IN2015MN00444A (en)
WO (1) WO2014046932A1 (en)

Families Citing this family (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9077619B2 (en) 2012-09-18 2015-07-07 Cisco Technology, Inc. Exporting real time network traffic latency and buffer occupancy
US10003530B2 (en) * 2014-07-22 2018-06-19 Futurewei Technologies, Inc. Service chain header and metadata transport
JP6402576B2 (en) * 2014-10-15 2018-10-10 富士通株式会社 COMMUNICATION DEVICE, INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING SYSTEM, AND COMMUNICATION DEVICE CONTROL METHOD
JP2017027196A (en) * 2015-07-17 2017-02-02 株式会社リコー Communication device, power control method, and power control program
US9929928B1 (en) * 2015-12-24 2018-03-27 Microsemi Solutions (U.S.), Inc. Packet transmitter and method for timestamping packets
US10015699B2 (en) * 2016-03-28 2018-07-03 Cisco Technology, Inc. Methods and devices for policing traffic flows in a network
US10218625B2 (en) * 2016-03-30 2019-02-26 New York University Methods and apparatus for alleviating congestion at a switch, such as a shallow buffered switch
US11201684B2 (en) * 2016-07-06 2021-12-14 Telefonaktiebolaget Lm Ericsson (Publ) Transmission and reception of timestamp information
US10764209B2 (en) 2017-03-28 2020-09-01 Mellanox Technologies Tlv Ltd. Providing a snapshot of buffer content in a network element using egress mirroring
US10248357B2 (en) * 2017-07-06 2019-04-02 Seagate Technology Llc Data storage system with hardware-based message routing
US10834006B2 (en) 2019-01-24 2020-11-10 Mellanox Technologies, Ltd. Network traffic disruptions
US10999366B2 (en) * 2019-03-10 2021-05-04 Mellanox Technologies Tlv Ltd. Mirroring dropped packets
US10798014B1 (en) * 2019-04-05 2020-10-06 Arista Networks, Inc. Egress maximum transmission unit (MTU) enforcement
CN110365551B (en) * 2019-07-04 2021-05-07 杭州吉讯汇通科技有限公司 Network information acquisition method, device, equipment and medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050240745A1 (en) * 2003-12-18 2005-10-27 Sundar Iyer High speed memory control and I/O processor system
US20100287297A1 (en) * 2009-05-10 2010-11-11 Yves Lefebvre Informative data streaming server
GB2477640A (en) * 2010-02-03 2011-08-10 Orbital Multi Media Holdings Corp Controlling transmission rate dependent upon block ack/nak bitmask signals and receiver buffer fill levels
US20120093505A1 (en) * 2009-06-26 2012-04-19 Tet Hin Yeap Method and system for service-based regulation of traffic flow to customer premises devices

Family Cites Families (37)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6246684B1 (en) 1997-12-24 2001-06-12 Nortel Networks Limited Method and apparatus for re-ordering data packets in a network environment
US6463068B1 (en) 1997-12-31 2002-10-08 Cisco Technologies, Inc. Router with class of service mapping
US6853623B2 (en) 1999-03-05 2005-02-08 Cisco Technology, Inc. Remote monitoring of switch network
DE69927252T2 (en) * 1999-07-13 2006-06-29 International Business Machines Corp. On the monitoring of buffer occupancy based planning of network capacity
US6892237B1 (en) 2000-03-28 2005-05-10 Cisco Technology, Inc. Method and apparatus for high-speed parsing of network messages
US6990202B2 (en) 2001-10-04 2006-01-24 Hewlett-Packard Development Company, L.P. Packetizing devices for secure scalable data streaming
US7193966B2 (en) * 2001-06-25 2007-03-20 Telefonakitebolaget Lm Ericsson (Publ) Triggered packet data rate change in a communication system
KR100411446B1 (en) 2001-12-24 2003-12-18 엘지전자 주식회사 Method of Controlling Type 3 Packet in the AAL2 Signaling
JP4000905B2 (en) * 2002-05-22 2007-10-31 ソニー株式会社 Information processing system and method, information processing apparatus and method, recording medium, and program
US8165114B2 (en) 2002-06-13 2012-04-24 Nice Systems Ltd. Voice over IP capturing
US7899048B1 (en) 2003-01-15 2011-03-01 Cisco Technology, Inc. Method and apparatus for remotely monitoring network traffic through a generic network
US7474666B2 (en) 2003-09-03 2009-01-06 Cisco Technology, Inc. Switch port analyzers
US7805515B2 (en) 2004-09-20 2010-09-28 Camiant, Inc. Method for dynamic rate adaptation based on selective passive network monitoring
US8116307B1 (en) 2004-09-23 2012-02-14 Juniper Networks, Inc. Packet structure for mirrored traffic flow
US7830793B2 (en) 2004-10-22 2010-11-09 Cisco Technology, Inc. Network device architecture for consolidating input/output and reducing latency
US7969971B2 (en) 2004-10-22 2011-06-28 Cisco Technology, Inc. Ethernet extension for the data center
WO2006069315A1 (en) 2004-12-21 2006-06-29 Qualcomm Incorporated Client assisted firewall configuration
US7961621B2 (en) 2005-10-11 2011-06-14 Cisco Technology, Inc. Methods and devices for backward congestion notification
US7656818B1 (en) 2005-10-28 2010-02-02 Cisco Technology, Inc. Customizable network device management methods and systems
US8208389B2 (en) 2006-07-20 2012-06-26 Cisco Technology, Inc. Methods and apparatus for improved determination of network metrics
US8274905B2 (en) 2006-08-22 2012-09-25 Embarq Holdings Company, Llc System and method for displaying a graph representative of network performance over a time period
WO2008097001A1 (en) 2007-02-05 2008-08-14 Samsung Electronics Co., Ltd. Method and apparatus for transmitting/receiving variable-sized packet in a mobile communication system
US20090100040A1 (en) 2007-04-03 2009-04-16 Scott Sheppard Lawful interception of broadband data traffic
US8605588B2 (en) 2007-05-08 2013-12-10 Cisco Technology, Inc. Packet drop analysis for flows of data
US7936695B2 (en) * 2007-05-14 2011-05-03 Cisco Technology, Inc. Tunneling reports for real-time internet protocol media streams
FR2919778A1 (en) 2007-07-30 2009-02-06 Canon Kk METHOD FOR TRANSMITTING DATA PACKETS IN A TUNNEL, COMPUTER PROGRAM PRODUCT, CORRESPONDING STORAGE MEDIUM AND TUNNEL HEAD
EP2028890B1 (en) 2007-08-12 2019-01-02 LG Electronics Inc. Handover method with link failure recovery, wireless device and base station for implementing such method
US8230113B2 (en) 2007-12-29 2012-07-24 Amx Llc System, method, and computer-readable medium for development and deployment of self-describing controlled device modules in a control system
JP5632834B2 (en) 2008-06-23 2014-11-26 コーニンクレッカ フィリップス エヌ ヴェ Method for communicating over a network and associated radio station
US7940658B2 (en) 2008-09-04 2011-05-10 Cisco Technology, Inc. ERSPAN dynamic session negotiation
US20100154033A1 (en) 2008-12-16 2010-06-17 Telefonaktiebolaget Lm Ericsson (Publ) Method and nodes for securing a communication network
US8640036B2 (en) 2010-04-07 2014-01-28 Cisco Techology, Inc. Messaging and presence protocol as a configuration and management bus for embedded devices
IL210897A (en) * 2011-01-27 2017-12-31 Verint Systems Ltd Systems and methods for flow table management
IL210900A (en) * 2011-01-27 2015-08-31 Verint Systems Ltd System and method for efficient classification and processing of network traffic
US9106545B2 (en) * 2011-12-19 2015-08-11 International Business Machines Corporation Hierarchical occupancy-based congestion management
US8995265B2 (en) * 2012-01-28 2015-03-31 Lenovo Enterprise Solutions (Singapore) Pte. Ltd. Monitoring endpoint buffer occupancy to determine congestion in an ethernet network
US9077619B2 (en) 2012-09-18 2015-07-07 Cisco Technology, Inc. Exporting real time network traffic latency and buffer occupancy

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050240745A1 (en) * 2003-12-18 2005-10-27 Sundar Iyer High speed memory control and I/O processor system
US20100287297A1 (en) * 2009-05-10 2010-11-11 Yves Lefebvre Informative data streaming server
US20120093505A1 (en) * 2009-06-26 2012-04-19 Tet Hin Yeap Method and system for service-based regulation of traffic flow to customer premises devices
GB2477640A (en) * 2010-02-03 2011-08-10 Orbital Multi Media Holdings Corp Controlling transmission rate dependent upon block ack/nak bitmask signals and receiver buffer fill levels

Also Published As

Publication number Publication date
EP2898637A1 (en) 2015-07-29
CN104641602B (en) 2018-01-05
US20170026256A1 (en) 2017-01-26
CN104641602A (en) 2015-05-20
US9641407B2 (en) 2017-05-02
USRE48645E1 (en) 2021-07-13
EP2898637B1 (en) 2016-11-09
US9077619B2 (en) 2015-07-07
IN2015MN00444A (en) 2015-09-11
US20150244637A1 (en) 2015-08-27
US9509622B2 (en) 2016-11-29
US20140078915A1 (en) 2014-03-20

Similar Documents

Publication Publication Date Title
USRE48645E1 (en) Exporting real time network traffic latency and buffer occupancy
US11249688B2 (en) High-speed data packet capture and storage with playback capabilities
EP2993837B1 (en) Methods and apparatus for path selection within a network based on flow duration
US9313115B2 (en) Traffic generator with priority flow control
EP2398188B1 (en) Method of Remote Active Testing of a Device or Network
US7787454B1 (en) Creating and/or managing meta-data for data storage devices using a packet switch appliance
US8520529B2 (en) Reordering network traffic
US8229705B1 (en) Performance monitoring in computer networks
US20090122805A1 (en) Instrumenting packet flows
EP2429128A1 (en) Flow statistics aggregation
US10284460B1 (en) Network packet tracing
US11233885B2 (en) Efficient capture and streaming of data packets
US11128740B2 (en) High-speed data packet generator
CN117176486A (en) network information transmission system
US11943128B1 (en) Path telemetry data collection
US9094290B2 (en) Measuring and displaying bandwidth contention
CN109121017B (en) Method and device for evaluating quality of video networking network

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13771660

Country of ref document: EP

Kind code of ref document: A1

REEP Request for entry into the european phase

Ref document number: 2013771660

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2013771660

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE