SlideShare a Scribd company logo
A new perspective on NETWORK VISIBILITY
- 10th RiSK Conference, Laško, Slovenia -
Siniša Popović
Regional Sales Manager
11-12th March 2015
Net Optics –
acquired by Ixia
but... NetOptics will still remain as a brand name!
About Net Optics
• Founded in 1996.
• HQ: Silicon Valley, USA
• Offices: Germany, Netherlands, Australia, China
• Manufacured industry 1st TAP ever!
• 7.500+ global deployments
• 20+ patents
• 85% of fortune 100
Awards
Media
Net Optics –
acquired by Ixia
but... NetOptics will still remain as a brand name!
About Net Optics
• Founded in 1996.
• HQ: Silicon Valley, USA
• Offices: Germany, Netherlands, Australia, China
• Manufacured industry 1st TAP ever!
• 7.500+ global deployments
• 20+ patents
• 85% of fortune 100
Awards
Media
Service Providers trust IXIA to:
 Improve and speed service delivery
 Speed roll out of next gen services
 Improve network and application visibility
and performance
Equipment Manufacturers trust IXIA to:
 Develop next generation devices
 Speed time to market
 Improve performance and reliability
Enterprises trust IXIA to:
 Assess vendor equipment and applications
 Improve network security posture
 Improve network and application visibility
and performance
Chip Fabricators trust IXIA to:
 Validate protocol conformance
 Speed time to market
Test
Security
Visibility
The MOST TRUSTED names
in networking trust
Today’s Challenges
Network growing faster than tools!
0% 10% 20% 30% 40% 50%
100M
1G
10G
40G
100G
Current Planned in 12 months
* by EMA research
Maximum networking link speeds within data center / core networks
Threats are growing
Important factor: Network
Performance!
Growing number of tools
Where are the blind spots created?
ESX Stack
Hypervisor
Phantom
Monitor™
V Switch
vm 1 Vm 2 Vm 3
Where are the blind spots created?
ESX Stack
Hypervisor
Phantom
Monitor™
V Switch
vm 1 Vm 2 Vm 3
Where are the blind spots created?
ESX Stack
Hypervisor
Phantom
Monitor™
V Switch
vm 1 Vm 2 Vm 3
Where are the blind spots created?
ESX Stack
Hypervisor
Phantom
Monitor™
V Switch
vm 1 Vm 2 Vm 3
Traditional access methods don‘t
work!
1. Dropping packets
2. High switch CPU and memory load
3. Doesn‘t forward L1/L2 errors
4. Needs to be configured
5. Mixing source/destination information
6. Limited number of SPAN ports
7. Compliance issues!!!
8. Distorts packet arrival times
SPAN port
Step 1: use Network TAP instead of
SPAN
Benefits
• 100% visibility, no dropped packets
• Doesn’t affect switch CPU and memory
• Plug-and-play — no configuration required
• Permanent access: no need to break the link each
time you need to remove tool
• Forwards important L1 and L2 errors
• Dual power supplies: keeps the network link up
and running in case of power failure
• Doesn’t change packet arrival times
SwitchFirewall
Analyzer
Switch
SPAN or TAP?
New challenge: amount of traffic is
growing!
Walmart collects over 1 million transactions every hour. This
data is streamed into massive data stores currently containing
over 2.5 petabytes of data.
Result: Tools are OVERSUBSCRIBED
Where are the blind spots created?
ESX Stack
Hypervisor
Phantom
Monitor™
V Switch
vm 1 Vm 2 Vm 3
Where are the blind spots created?
ESX Stack
Hypervisor
Phantom
Monitor™
V Switch
vm 1 Vm 2 Vm 3
Director
Aggregation
Visibility Architecture
Advanced Packet Distribution
Aggregation and regeneration
Intelligent Filtering
Bypass switching
Packet Slicing & DeDuplication
Total Network Visibility
Ixia – Portfolio
Net Tool Optimizer®
Network
Visibility
Solutions
Network TAPs Copper and fiber TAPs for passive network access
Bypass Switches Copper and fiber switches for secure inline access
Network Packet Brokers
Intelligent data access with aggregation, filtering,
load balancing, de-duplication and more
Virtualization TAPs Get the full visibility into virtual networks
GTP Session Controller
Intelligent distribution and control of
mobile network traffic
Intelligent data access
Network Packet Brokers
Intelligent Traffic Distribution
− Aggregation of traffic from multiple links
− Filtering (by IP, MAC, VLAN, Port, etc.)
− Load-balancing traffic across tools
− Replication of traffic to multiple tools
Network Packet Brokers
Intelligent Packet Processing
− Header stripping (MPLS, VLAN, ...)
− Time-stamping with nano-second precision
− De-duplication for removing duplicated packets
− Packet slicing for removing unnecessary payload
Aggregation
• Problem: too many network links/segments, expensive to
deploy
• Solution: aggregate multiple inputs into few outputs
10 Gbps 1 Gbps 1 Gbps 1 Gbps 1 Gbps 1 Gbps 1 Gbps
1 Gbps1 Gbps
Intelligent Filtering
TCP
Filter
HTTP
Filter
192.0.0.5
Filter
SNMP
Filter
Complex filter
Network Port 1 Monitor Port 5Source IP =
192.168.10.1
Network Port 3
Monitor Port 6
Protocol=
UDP
Monitor Port 8
Network Port 6
Source IP =
192.168.10.1
Protocol =
TCP
Layer 4
Port = 80
Monitor Port 2
Multilayer filtering
Simple filter
IDS DAM
Filtering example
Internet
Web Web App EmailFile File File File
Internet
File Security
Web Security
Email Security
Data Center DMZ
Filter only File
Server traffic Filter only WEB
Server traffic
Filter only
Email traffic
10G 10G
Load Balancing
LB Group 2LB Group 1
Switch
IPS 1
Firewall Router
IPS 2 IPS 3 IPS 4 IPS 5 IPS 6
1G 1G 1G 1G 1G 1G
• Sharing 10G link to many 1G tools
• Link can be tapped with a bypass
switch for additional protection
De-duplication
2 3 4 5 6 7 8 9
input
packets
duplicated
packets
1
21 3 4 5output
packets
= 9 * 1580 bytes = 14220 bytes
= 5 * 1580 bytes = 7900 bytes
55% traffic reduction
Packet Slicing
Problem:
In many cases only the header is needed for analyzing. Forwarding a 1500byte packet to a probe does consume more
memory at the disk than a 64byte packet. If the data content is not needed this would be wasting recourses beside that it
does consume bandwidth on the downlink to the probe.
Solution:
A Network Monitoring Switch does remove the data content of a packet before the packet will be forwarded to the probe.
The user can define by the GUI what header information will retrain after trimming.
MAC IP Data FCS
MAC IP FCS
Port tagging
Network Scenarios
DMZ Segment
Database Farm
Tag 1
Tag 3
Tag 2
Server Array
Problem:
When aggregating packets over multiple TAPs, it’s no more
possible to identify from which TAP they have been
originally taken. Measuring the delay e.g. through a
Firewall would result in the need of an additional probe.
This is costly.
Solution:
By adding a Port TAG to the packet, the Network
Monitoring Switch provides full visibility again and for the
Firewall example one probe would last.
Timestamping for precise
measurements
The first four bytes of the timestamp are a 32-bit binary value in seconds.
The second four bytes are a 32-bit binary value representing tenths of microseconds;
The final four bytes are reserved for use when higher-precision timestamping becomes available,
making the timestamp format capable of supporting a resolution of 0.1 picoseconds.
Tap and optimize virtual traffic
„Phantom Virtual Tap enables 100% visibility
of east-west, inter-VM, and blade server
mid-plane traffic, with ability to do
aggregation, replication and multilayer L2-L4
filtering inside the virtual environment.”Best throughput results
Extensive L2-L4 Filtering
Minimal resources used
Virtual and Physical convergence
ES
X
App
OS
VM1
Hypervisor
App
OS
VM2
App
OS
VM2
V Switch
Phantom™
Manager
KV
M
App
OS
VM1
Hypervisor
App
OS
VM2
App
OS
VM2
V Switch
Phantom™
Manager
XE
N
App
OS
VM1
Hypervisor
App
OS
VM2
App
OS
VM2
V Switch
Phantom™
Manager
Tunnel
IDS
NGFW Protocol
Analyzer
DLP
Net Optics Director™
Net Optics Phantom™ HD
Physical Server
Physical Server
LAN/WAN
Without Visibility Architecture
Performance Security Visibility
Good packets
Duplicated packets
Un-filtered packets
Large packets
With Visibility Architecture
Performance Security Visibility
Good packets
Dupl. packets
Ixia
NetOptics
Filter. packets
Carrier Networks
Wired and Mobile
Data Center
Private Cloud
Virtualization
Core
Remote Office
Branch Office
Campus
Network
Operations
Performance
Management
Security
Admin
Server Admin
Audit &
Privacy
Forensics
Visibility Architecture
App
Aware
Out of
Band
NPB
Network
Taps
Element
Mgmt
Virtual
& Cloud
Access
Policy
Mgmt
Inline
NPBInline
Bypass
Session
Aware
Data Center
Automation
Network
Access
Packet
Brokers
Applications Management
www.ixiacom.com/solutions/network-visibility/
www.netoptics.com | www.network-taps.eu
The End
Thank you!
Siniša Popović
Regional Sales Manager
E: sinisa.popovic@np-channel.com
T: +43 676 793 4000

More Related Content

PDF
Ch 01 --- introduction to sdn-nfv
Yoram Orzach
 
PDF
Silverlight Wireshark Analysis
Yoss Cohen
 
PDF
Haystack + DASH7 Security
Haystack Technologies
 
PDF
Enhancing Network Visibility Based On Open Converged Network Appliance
Open Networking Summit
 
PPT
2015 02 24 lmtv baselining
Tony Fortunato
 
PPTX
Deep Packet Inspection technology evolution
Daniel Vinyar
 
PDF
More on Using Haystack + DASH7 with MQTT
Haystack Technologies
 
PDF
MQTT + DASH7 Integration
Haystack Technologies
 
Ch 01 --- introduction to sdn-nfv
Yoram Orzach
 
Silverlight Wireshark Analysis
Yoss Cohen
 
Haystack + DASH7 Security
Haystack Technologies
 
Enhancing Network Visibility Based On Open Converged Network Appliance
Open Networking Summit
 
2015 02 24 lmtv baselining
Tony Fortunato
 
Deep Packet Inspection technology evolution
Daniel Vinyar
 
More on Using Haystack + DASH7 with MQTT
Haystack Technologies
 
MQTT + DASH7 Integration
Haystack Technologies
 

What's hot (19)

PPTX
Eduroam workshop nic mitev loughborough uni - networkshop44
Jisc
 
PPTX
Managing and monitoring large scale data transfers - Networkshop44
Jisc
 
PDF
An Introduction and Comparison of Dante, AVB and CobraNet Methodologies
rAVe [PUBS]
 
PDF
Open stackdaykorea2016 wedge
Junho Suh
 
PDF
SDN & NFV Introduction - Open Source Data Center Networking
Thomas Graf
 
DOC
Ntc 362 effective communication uopstudy.com
ULLPTT
 
PPTX
Innovation is back in the transport and network layers
Olivier Bonaventure
 
PDF
LF_DPDK17_OpenNetVM: A high-performance NFV platforms to meet future communic...
LF_DPDK
 
ODP
Challenges and experiences with IPTV from a network point of view
brouer
 
PPT
Netflow slides
Jose Manuel Vega Monroy
 
PDF
M2M, IoT, Device management: one protocol to rule them all? - EclipseCon 2014
Julien Vermillard
 
PDF
Software Define Network (SDN) and Openflow
KHNOG
 
PDF
How To Triple The Range of LoRa
Haystack Technologies
 
PPTX
Ipv6 deployment at the university of warwick - networkshop44
Jisc
 
PDF
Next-gen Network Telemetry is Within Your Packets: In-band OAM
Open Networking Summit
 
PPT
OpenFlow tutorial
openflow
 
PDF
Hands on with CoAP and Californium
Julien Vermillard
 
PDF
PLNOG 17 - Marcin Aronowski - Technologie dostępowe dla IoT. Jak się w tym ws...
PROIDEA
 
Eduroam workshop nic mitev loughborough uni - networkshop44
Jisc
 
Managing and monitoring large scale data transfers - Networkshop44
Jisc
 
An Introduction and Comparison of Dante, AVB and CobraNet Methodologies
rAVe [PUBS]
 
Open stackdaykorea2016 wedge
Junho Suh
 
SDN & NFV Introduction - Open Source Data Center Networking
Thomas Graf
 
Ntc 362 effective communication uopstudy.com
ULLPTT
 
Innovation is back in the transport and network layers
Olivier Bonaventure
 
LF_DPDK17_OpenNetVM: A high-performance NFV platforms to meet future communic...
LF_DPDK
 
Challenges and experiences with IPTV from a network point of view
brouer
 
Netflow slides
Jose Manuel Vega Monroy
 
M2M, IoT, Device management: one protocol to rule them all? - EclipseCon 2014
Julien Vermillard
 
Software Define Network (SDN) and Openflow
KHNOG
 
How To Triple The Range of LoRa
Haystack Technologies
 
Ipv6 deployment at the university of warwick - networkshop44
Jisc
 
Next-gen Network Telemetry is Within Your Packets: In-band OAM
Open Networking Summit
 
OpenFlow tutorial
openflow
 
Hands on with CoAP and Californium
Julien Vermillard
 
PLNOG 17 - Marcin Aronowski - Technologie dostępowe dla IoT. Jak się w tym ws...
PROIDEA
 
Ad

Similar to A new perspective on Network Visibility - RISK 2015 (20)

PDF
Command Your Data Center - Net Optics/Ixia
Network Performance Channel GmbH
 
PPTX
Tap Into the Health of Your Network
LiveAction Next Generation Network Management Software
 
PDF
Best Practices for Building Scalable Visibility Architectures
Enterprise Management Associates
 
PDF
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PROIDEA
 
PDF
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
Cisco Russia
 
PDF
Ixia/Net Optics - Visibility Architecture Solution Brief
Network Performance Channel GmbH
 
PDF
Visibility and Automation for Enhanced Security
patmisasi
 
PDF
Automatic topology detection in NAV
Morten Brekkevold
 
PDF
VMware and Net Optics an Ixia company Provide Solutions for Monitoring for Vi...
LiveAction Next Generation Network Management Software
 
PPTX
Vision one-customer
Marie-Agnès PONS
 
PDF
Next-Generation Network Packet Brokers: Defining the Future of Network Visibi...
Enterprise Management Associates
 
PPTX
Is the Network Tap Mightier Than the Sword
LiveAction Next Generation Network Management Software
 
PDF
Andy huckridge
Carl Ford
 
PPTX
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network Traffic
Emulex Corporation
 
PPT
network-management Web base.ppt
AssadLeo1
 
PDF
Network Visibility Architecture for the Hybrid, Multi-Cloud Enterprise
Enterprise Management Associates
 
PPT
Deployment guide1
Programmer
 
PDF
IT Monitoring in the Era of Containers | Luca Deri Founder & Project Lead | ntop
InfluxData
 
PDF
9th SDN Expert Group Seminar - Session1
NAIM Networks, Inc.
 
Command Your Data Center - Net Optics/Ixia
Network Performance Channel GmbH
 
Tap Into the Health of Your Network
LiveAction Next Generation Network Management Software
 
Best Practices for Building Scalable Visibility Architectures
Enterprise Management Associates
 
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PROIDEA
 
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
Cisco Russia
 
Ixia/Net Optics - Visibility Architecture Solution Brief
Network Performance Channel GmbH
 
Visibility and Automation for Enhanced Security
patmisasi
 
Automatic topology detection in NAV
Morten Brekkevold
 
VMware and Net Optics an Ixia company Provide Solutions for Monitoring for Vi...
LiveAction Next Generation Network Management Software
 
Vision one-customer
Marie-Agnès PONS
 
Next-Generation Network Packet Brokers: Defining the Future of Network Visibi...
Enterprise Management Associates
 
Is the Network Tap Mightier Than the Sword
LiveAction Next Generation Network Management Software
 
Andy huckridge
Carl Ford
 
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network Traffic
Emulex Corporation
 
network-management Web base.ppt
AssadLeo1
 
Network Visibility Architecture for the Hybrid, Multi-Cloud Enterprise
Enterprise Management Associates
 
Deployment guide1
Programmer
 
IT Monitoring in the Era of Containers | Luca Deri Founder & Project Lead | ntop
InfluxData
 
9th SDN Expert Group Seminar - Session1
NAIM Networks, Inc.
 
Ad

Recently uploaded (20)

PPTX
Stamford - Community User Group Leaders_ Agentblazer Status, AI Sustainabilit...
Amol Dixit
 
PPTX
Coupa-Overview _Assumptions presentation
annapureddyn
 
PDF
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
PPTX
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PPT
L2 Rules of Netiquette in Empowerment technology
Archibal2
 
PDF
Building High-Performance Oracle Teams: Strategic Staffing for Database Manag...
SMACT Works
 
PDF
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
PDF
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
PDF
DevOps & Developer Experience Summer BBQ
AUGNYC
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PDF
This slide provides an overview Technology
mineshkharadi333
 
PDF
Doc9.....................................
SofiaCollazos
 
PDF
Revolutionize Operations with Intelligent IoT Monitoring and Control
Rejig Digital
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
Stamford - Community User Group Leaders_ Agentblazer Status, AI Sustainabilit...
Amol Dixit
 
Coupa-Overview _Assumptions presentation
annapureddyn
 
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
L2 Rules of Netiquette in Empowerment technology
Archibal2
 
Building High-Performance Oracle Teams: Strategic Staffing for Database Manag...
SMACT Works
 
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
DevOps & Developer Experience Summer BBQ
AUGNYC
 
Software Development Methodologies in 2025
KodekX
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
This slide provides an overview Technology
mineshkharadi333
 
Doc9.....................................
SofiaCollazos
 
Revolutionize Operations with Intelligent IoT Monitoring and Control
Rejig Digital
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 

A new perspective on Network Visibility - RISK 2015

  • 1. A new perspective on NETWORK VISIBILITY - 10th RiSK Conference, Laško, Slovenia - Siniša Popović Regional Sales Manager 11-12th March 2015
  • 2. Net Optics – acquired by Ixia but... NetOptics will still remain as a brand name!
  • 3. About Net Optics • Founded in 1996. • HQ: Silicon Valley, USA • Offices: Germany, Netherlands, Australia, China • Manufacured industry 1st TAP ever! • 7.500+ global deployments • 20+ patents • 85% of fortune 100 Awards Media
  • 4. Net Optics – acquired by Ixia but... NetOptics will still remain as a brand name!
  • 5. About Net Optics • Founded in 1996. • HQ: Silicon Valley, USA • Offices: Germany, Netherlands, Australia, China • Manufacured industry 1st TAP ever! • 7.500+ global deployments • 20+ patents • 85% of fortune 100 Awards Media
  • 6. Service Providers trust IXIA to:  Improve and speed service delivery  Speed roll out of next gen services  Improve network and application visibility and performance Equipment Manufacturers trust IXIA to:  Develop next generation devices  Speed time to market  Improve performance and reliability Enterprises trust IXIA to:  Assess vendor equipment and applications  Improve network security posture  Improve network and application visibility and performance Chip Fabricators trust IXIA to:  Validate protocol conformance  Speed time to market Test Security Visibility The MOST TRUSTED names in networking trust
  • 8. Network growing faster than tools! 0% 10% 20% 30% 40% 50% 100M 1G 10G 40G 100G Current Planned in 12 months * by EMA research Maximum networking link speeds within data center / core networks
  • 12. Where are the blind spots created? ESX Stack Hypervisor Phantom Monitor™ V Switch vm 1 Vm 2 Vm 3
  • 13. Where are the blind spots created? ESX Stack Hypervisor Phantom Monitor™ V Switch vm 1 Vm 2 Vm 3
  • 14. Where are the blind spots created? ESX Stack Hypervisor Phantom Monitor™ V Switch vm 1 Vm 2 Vm 3
  • 15. Where are the blind spots created? ESX Stack Hypervisor Phantom Monitor™ V Switch vm 1 Vm 2 Vm 3
  • 16. Traditional access methods don‘t work! 1. Dropping packets 2. High switch CPU and memory load 3. Doesn‘t forward L1/L2 errors 4. Needs to be configured 5. Mixing source/destination information 6. Limited number of SPAN ports 7. Compliance issues!!! 8. Distorts packet arrival times SPAN port
  • 17. Step 1: use Network TAP instead of SPAN Benefits • 100% visibility, no dropped packets • Doesn’t affect switch CPU and memory • Plug-and-play — no configuration required • Permanent access: no need to break the link each time you need to remove tool • Forwards important L1 and L2 errors • Dual power supplies: keeps the network link up and running in case of power failure • Doesn’t change packet arrival times SwitchFirewall Analyzer Switch
  • 19. New challenge: amount of traffic is growing! Walmart collects over 1 million transactions every hour. This data is streamed into massive data stores currently containing over 2.5 petabytes of data.
  • 20. Result: Tools are OVERSUBSCRIBED
  • 21. Where are the blind spots created? ESX Stack Hypervisor Phantom Monitor™ V Switch vm 1 Vm 2 Vm 3
  • 22. Where are the blind spots created? ESX Stack Hypervisor Phantom Monitor™ V Switch vm 1 Vm 2 Vm 3 Director Aggregation Visibility Architecture Advanced Packet Distribution Aggregation and regeneration Intelligent Filtering Bypass switching Packet Slicing & DeDuplication Total Network Visibility
  • 23. Ixia – Portfolio Net Tool Optimizer® Network Visibility Solutions Network TAPs Copper and fiber TAPs for passive network access Bypass Switches Copper and fiber switches for secure inline access Network Packet Brokers Intelligent data access with aggregation, filtering, load balancing, de-duplication and more Virtualization TAPs Get the full visibility into virtual networks GTP Session Controller Intelligent distribution and control of mobile network traffic
  • 24. Intelligent data access Network Packet Brokers Intelligent Traffic Distribution − Aggregation of traffic from multiple links − Filtering (by IP, MAC, VLAN, Port, etc.) − Load-balancing traffic across tools − Replication of traffic to multiple tools Network Packet Brokers Intelligent Packet Processing − Header stripping (MPLS, VLAN, ...) − Time-stamping with nano-second precision − De-duplication for removing duplicated packets − Packet slicing for removing unnecessary payload
  • 25. Aggregation • Problem: too many network links/segments, expensive to deploy • Solution: aggregate multiple inputs into few outputs 10 Gbps 1 Gbps 1 Gbps 1 Gbps 1 Gbps 1 Gbps 1 Gbps 1 Gbps1 Gbps
  • 26. Intelligent Filtering TCP Filter HTTP Filter 192.0.0.5 Filter SNMP Filter Complex filter Network Port 1 Monitor Port 5Source IP = 192.168.10.1 Network Port 3 Monitor Port 6 Protocol= UDP Monitor Port 8 Network Port 6 Source IP = 192.168.10.1 Protocol = TCP Layer 4 Port = 80 Monitor Port 2 Multilayer filtering Simple filter IDS DAM
  • 27. Filtering example Internet Web Web App EmailFile File File File Internet File Security Web Security Email Security Data Center DMZ Filter only File Server traffic Filter only WEB Server traffic Filter only Email traffic 10G 10G
  • 28. Load Balancing LB Group 2LB Group 1 Switch IPS 1 Firewall Router IPS 2 IPS 3 IPS 4 IPS 5 IPS 6 1G 1G 1G 1G 1G 1G • Sharing 10G link to many 1G tools • Link can be tapped with a bypass switch for additional protection
  • 29. De-duplication 2 3 4 5 6 7 8 9 input packets duplicated packets 1 21 3 4 5output packets = 9 * 1580 bytes = 14220 bytes = 5 * 1580 bytes = 7900 bytes 55% traffic reduction
  • 30. Packet Slicing Problem: In many cases only the header is needed for analyzing. Forwarding a 1500byte packet to a probe does consume more memory at the disk than a 64byte packet. If the data content is not needed this would be wasting recourses beside that it does consume bandwidth on the downlink to the probe. Solution: A Network Monitoring Switch does remove the data content of a packet before the packet will be forwarded to the probe. The user can define by the GUI what header information will retrain after trimming. MAC IP Data FCS MAC IP FCS
  • 31. Port tagging Network Scenarios DMZ Segment Database Farm Tag 1 Tag 3 Tag 2 Server Array Problem: When aggregating packets over multiple TAPs, it’s no more possible to identify from which TAP they have been originally taken. Measuring the delay e.g. through a Firewall would result in the need of an additional probe. This is costly. Solution: By adding a Port TAG to the packet, the Network Monitoring Switch provides full visibility again and for the Firewall example one probe would last.
  • 32. Timestamping for precise measurements The first four bytes of the timestamp are a 32-bit binary value in seconds. The second four bytes are a 32-bit binary value representing tenths of microseconds; The final four bytes are reserved for use when higher-precision timestamping becomes available, making the timestamp format capable of supporting a resolution of 0.1 picoseconds.
  • 33. Tap and optimize virtual traffic „Phantom Virtual Tap enables 100% visibility of east-west, inter-VM, and blade server mid-plane traffic, with ability to do aggregation, replication and multilayer L2-L4 filtering inside the virtual environment.”Best throughput results Extensive L2-L4 Filtering Minimal resources used
  • 34. Virtual and Physical convergence ES X App OS VM1 Hypervisor App OS VM2 App OS VM2 V Switch Phantom™ Manager KV M App OS VM1 Hypervisor App OS VM2 App OS VM2 V Switch Phantom™ Manager XE N App OS VM1 Hypervisor App OS VM2 App OS VM2 V Switch Phantom™ Manager Tunnel IDS NGFW Protocol Analyzer DLP Net Optics Director™ Net Optics Phantom™ HD Physical Server Physical Server LAN/WAN
  • 35. Without Visibility Architecture Performance Security Visibility Good packets Duplicated packets Un-filtered packets Large packets
  • 36. With Visibility Architecture Performance Security Visibility Good packets Dupl. packets Ixia NetOptics Filter. packets
  • 37. Carrier Networks Wired and Mobile Data Center Private Cloud Virtualization Core Remote Office Branch Office Campus Network Operations Performance Management Security Admin Server Admin Audit & Privacy Forensics Visibility Architecture App Aware Out of Band NPB Network Taps Element Mgmt Virtual & Cloud Access Policy Mgmt Inline NPBInline Bypass Session Aware Data Center Automation Network Access Packet Brokers Applications Management www.ixiacom.com/solutions/network-visibility/ www.netoptics.com | www.network-taps.eu
  • 38. The End Thank you! Siniša Popović Regional Sales Manager E: [email protected] T: +43 676 793 4000