Professional Documents
Culture Documents
Abstract
The objective of this white paper is to present the sFlow traffic
sampling technology and Extreme Networks’ sFlow implementa-
tion on the Ethernet switch products. sFlow will provide the great
visibility in the network by its sampling technology to monitor the
network status. By providing complete visibility into the network
usage of today’s high-speed and complex networks, you will be
able to effectively control and manage network usage, helping to
ensure that network services provide a competitive advantage.
- Understanding application mix (e.g. P2P, Web, DNS Wait for Packet
© 2006 Extreme Networks, Inc. All rights reserved. Do not reproduce. Network sFlow — Page
Extreme Networks White Paper
The sFlow Agent is a software process that runs as part of - Detailed—Complete packet header and switching/
the network management software within a device (see routing information permits detailed analysis of Layer
Figure 2). It combines interface counters and flow samples 2-Layer 7 traffic flows.
into sFlow datagrams that are sent across the network to an - Scalable—The sFlow system is scalable in both the
sFlow Collector. The state of the forwarding/routing table size and speed of the network it can monitor. sFlow is
entries associated with each sampled packet is also capable of monitoring networks at 10Gbps, 100Gbps
recorded. and beyond. Thousands of devices can be monitored
by a single sFlow Collector.
The sFlow Agent does very little processing. It simply
packages data into sFlow Datagrams that are immediately - Low Cost—The sFlow Agent is very simple to
sent on the network. Immediate forwarding of data implement and adds negligible cost to a switch or
minimizes memory and CPU requirements associated with router.
the sFlow Agent. - Timely—The sFlow Collector always has an up to the
minute view of traffic throughout the entire network.
Timely information is particularly important if the
traffic data is needed to provide real-time controls,
for example to manage quality of service or to defend
against a denial of service attack.
Traffic Data
Using sFlow
Using sFlow to continuously monitor traffic flows on all
Analysis ports gives network-wide visibility into the use of the
network. This visibility replaces guesswork, fundamen-
tally changing the way that network services are man-
sFlow Agents
sFlow Datagrams aged.
Controlling Congestion
By monitoring traffic flows on all ports continuously,
sFlow can be used to instantly highlight congested links,
identify the source of the traffic, and the associated
Figure 2: sFlow Agents and Collector application level conversations. sFlow provides the
necessary information to determine effective controls,
for example which traffic to rate control or prioritize or
where to provision more bandwidth.
Figure 2 shows the basic elements of the sFlow system. Security and Audit Trail Analysis
sFlow Agents throughout the network continuously send Gartner estimates that 70% of security incidents that
a stream of sFlow Datagrams to a central sFlow Collector actually cause loss to enterprises involve insiders, while
where they are analyzed to produce a rich, real-time, service providers and other organizations are constantly
network-wide view of traffic flows. sFlow monitoring of bombarded with various external attacks. A comprehen-
high-speed, routed and switched networks has the sive security strategy involves protecting the network
following properties: from external and internal misuse and information assets
from theft.
- Accurate—The sFlow system is designed so that the
Since attacks and security threats will come from
accuracy of any measurement can be determined.
unknown sources, effective security monitoring requires
Other traffic flow measurement technologies clip
complete network surveillance, with alerts to suspicious
under heavy loads resulting in errors that are
activity. sFlow provides this blanket audit trail, for the
difficult to quantify.
whole network. The continuous network-wide surveillance
© 2006 Extreme Networks, Inc. All rights reserved. Do not reproduce. sFlow — Page
Extreme Networks White Paper
- A software application that receives and analyzes • Enable sFlow globally on the switch
sFlow data • Enable sFlow on the desired ports
The following platforms support hardware-based Optionally, you may also change the default values of
sampling at a programmed interval: the following items:
© 2006 Extreme Networks, Inc. All rights reserved. Do not reproduce. sFlow — Page
Extreme Networks White Paper