IP Multicast Traffic Measurement Method with IPFIX/PSAMP. Atsushi Kobayashi Yutaka Hirokawa Haruhiko Nishida NTT

Similar documents
IP Multicast Traffic Measurement Method with IPFIX/PSAMP

Packetron. Your path to an Intelligent Visibility Layer

This chapter provides information to configure Cflowd.

Using NetFlow Sampling to Select the Network Traffic to Track

Configuring NetFlow and NetFlow Data Export

Configuring sflow. Information About sflow. sflow Agent. This chapter contains the following sections:

Internet Engineering Task Force (IETF) Request for Comments: TU Muenchen K. Ishibashi NTT. April 2011

Master Course Computer Networks IN2097

Raw Data Formatting: The RDR Formatter and NetFlow Exporting

Using NetFlow Sampling to Select the Network Traffic to Track

NetFlow and NetFlow Data Export.

Using NetFlow Filtering or Sampling to Select the Network Traffic to Track

External Logging. Bulk Port Allocation. Restrictions for Bulk Port Allocation

NetFlow Monitoring. NetFlow Monitoring

Using NetFlow Filtering or Sampling to Select the Network Traffic to Track

Configuring Data Export for Flexible NetFlow with Flow Exporters

Raw Data Formatting: The RDR Formatter and NetFlow Exporting

NAME qof Quality of Flow (yet another yet another flowmeter)

Using Flexible NetFlow Flow Sampling

Using Flexible NetFlow Flow Sampling

Master Course Computer Networks IN2097

Configuring Cisco Performance Monitor

Configuring Data Export for Flexible NetFlow with Flow Exporters

Internet Engineering Task Force (IETF) B. Claise Cisco Systems, Inc. G. Muenz Technische Universitaet Muenchen April 2010

Configuring sflow. About sflow. sflow Agent

Netflow v9 for IPv6. Finding Feature Information. Prerequisites for Netflow v9 for IPv6. Information About Netflow v9 for IPv6

Configuring NetFlow. Feature History for Configuring NetFlow. Release This feature was introduced.

Configuring SNMP and using the NetFlow MIB to Monitor NetFlow Data

From NetFlow to IPFIX the evolution of IP flow information export

Cisco Network Visibility Flow Protocol Specification

Configuring MPLS Egress NetFlow Accounting and Analysis

Traffic Flow Measurements within IP Networks: Requirements, Technologies and Standardization

Internet Engineering Task Force (IETF) Request for Comments: November 2012

YAF(1) Yet Another Flowmeter YAF(1)

Consider these restrictions when configuring NetFlow in Cisco IOS XR software: Do not use the management interface to export the NetFlow packets.

H3C SR6600/SR6600-X Routers

Information Elements for Data Link Layer Traffic Measurement (draft-kashima-ipfix-data-link-layer-monitoring-04)

Flow Sampling for ASR1K

NetFlow Integrator Standard

Contents. Ping, tracert, and system debugging commands 1. debugging 1 display debugging 1 ping 2 ping ipv6 5 tracert 7 tracert ipv6 10

Cisco ASR 9000 Series Aggregation Services Router Netflow Command Reference, Release 4.3.x

The State of Standardization Efforts to support Data Exchange in the Security Domain

Experiences with IPFIX-based Traffic Measurement for IPv6 Networks. Nakjung Choi, Hyeongu Son*, Youngseok Lee* and Yanghee Choi

Packet Sampling for Flow Accounting: Challenges and Limitations

Zone-Based Firewall Logging Export Using NetFlow

Configuring NetFlow Top Talkers using Cisco IOS CLI Commands or SNMP Commands

NetFlow Integrator Standard

Labelcast Protocol.

Configuring NetFlow. NetFlow Overview

Ping, tracert and system debugging commands

Flexible Netflow Configuration Guide, Cisco IOS Release 15S

IPv6 Sampled NetFlow feature was introduced. Destination-based Netflow Accounting feature was introduced.

HP A6600 Routers Network Management and Monitoring. Command Reference. Abstract

How the Internet sees you

Configuring IP SLAs ICMP Echo Operations

Contents. Ping, tracert, and system debugging commands 1 debugging 1 display debugging 2 ping 2 ping ipv6 5 tracert 7 tracert ipv6 9

Chapter 6 Addressing the Network- IPv4

Configuring IP SLAs ICMP Echo Operations

Quick Start Guide MU120131A/32A. IP Multicast Measurement MD1230B/MP1590B. Data Quality Analyzer / Network Performance Tester

Configuring NetFlow Top Talkers using Cisco IOS CLI Commands or SNMP Commands

Using Flexible NetFlow Top N Talkers to Analyze Network Traffic

Modular Policy Framework. Class Maps SECTION 4. Advanced Configuration

This document describes the sampled flow (sflow) feature and configuration steps to implement sflow.

Sampling Challenges. Tanja Zseby Competence Center Network Research Fraunhofer Institute FOKUS Berlin. COST TMA September 22, 2008

Configuring NetFlow and NetFlow Data Export

Cisco IOS Flexible NetFlow Command Reference

Covert channel detection using flow-data

Configuring Application Visibility and Control for Cisco Flexible Netflow

Monitoring and Analysis

NetFlow Configuration Guide

Domain Based Metering

Configuring NetFlow. About NetFlow. This chapter describes how to configure the NetFlow feature on Cisco NX-OS devices.

Network Configuration Example

FlowIntegrator. Integrating Flow Technologies with Mainstream Event Management Systems. Sasha Velednitsky

Configuring NetFlow. NetFlow Overview

Recent Advances in MPLS Traffic Engineering

Configuring AVC to Monitor MACE Metrics

Configuring IP SLAs TCP Connect Operations

Network Working Group. Category: Informational Hitachi Europe N. Brownlee CAIDA B. Claise Cisco Systems, Inc. March 2009

Cisco IOS XR Netflow Configuration Guide for the Cisco CRS Router, Release 5.1.x

RTP Profile for TCP Friendly Rate Control draft-ietf-avt-tfrc-profile-03.txt

Cisco ASR 9000 Series Aggregation Services Router Netflow Configuration Guide, Release 5.2.x

On the Scalability of RTCP Based Network Tomography for IPTV Services. Ali C. Begen Colin Perkins Joerg Ott

Configuring IP SLAs LSP Health Monitor Operations

IP SLAs Overview. Finding Feature Information. Information About IP SLAs. IP SLAs Technology Overview

Flexible Flow Aggregation for Adaptive Network Monitoring

NetFlow-based bandwidth estimation in IP networks

MLDP In-Band Signaling/Transit Mode

Establishment of Point-to-Multi-Point path in GMPLS controlled Wide Area

Lightweight enhanced monitoring for high-speed networks

Network Working Group. Category: Informational Fraunhofer FOKUS J. Quittek M. Stiemerling NEC P. Aitken Cisco Systems, Inc.

HP MSR Router Series Network Management and Monitoring

SCRIPT: An Architecture for IPFIX Data Distribution

NetFlow Configuration Guide, Cisco IOS Release 15S

Monitoring and visualization of LLDP information in Zabbix

Problem Max. Points Act. Points Grader

NetFlow Configuration Guide, Cisco IOS Release 15S

Configuring IP SLAs ICMP Path Echo Operations

Configuring IP SLAs TCP Connect Operations

Flow-based Accounting: Applications and Standardisation

Transcription:

IP Multicast Traffic Measurement Method with /PSAMP Atsushi Kobayashi Yutaka Hirokawa Haruhiko Nishida NTT 1

Outline Introduction Motivation Requirements Main requirements for measurement system in largescale network What is /PSAMP? Proposal of Measurement Method Effective measurement method and system architecture using /PSAMP Implementation of prototype Conclusion 2

Motivation Multicast service has started in several provider networks. Large amount of broadband users leads to heavy demand for IP multicast streaming services, such as IPTV. Existing multicast tools work, but not well enough to monitor streaming services in largescale networks. Multicast ping, trace route, and multicast MIB. Easy trouble shooting tools are required. /PSAMP seems helpful. 3

IP Multicast Streaming Traffic The traffic volume of an IPTV channel is 12 Mb/s and 1.2 Kp/s. Indicates maximum volume of H.264 codec. A lot of IP multicast stream traffic includes RTP headers. Easily detects packet loss by keeping track of RTP seq. number. More than 50 channels pass through the ISP networks. Mb/s 16 14 12 10 8 6 4 2 0 bits [Mb/s] 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 Elapsed Time [s] Kp/s 1.4 1.2 1 0.8 0.6 0.4 0.2 0 packets [Kp/s] FEC packet 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 Elapsed Time [s] Media packet 4

Issues on Multicast Operation Difficult to see IPv4/6 multicast topology When a problem occurs, operators need topology information for troubleshooting and investigating the impact of the failure. Measure service quality Need to monitor service quality overview 5

Requirements Requirement #1: Visualizing multicast topologies Monitor multicast topology per {S,G} periodically Show traffic volume on each topology Requirement #2: Detecting service quality deterioration Detect packet loss and disorder within 1 minute, while there is continuous packet loss at 1/1000 Requirement #3: Showing failure point on multicast topology Need to gather whole traffic data on network 6

Difficult Requirements for NetFlow Current NetFlow implementation meets the requirement 1. Requirement #2: Detecting the service quality deterioration is impractical for current NetFlow implementation. Flow records in NetFlow cannot include packet loss and disorder. Generally, many operators adopt random sampling to introduce NetFlow. I focus on the /PSAMP. 7

Features Developed as extended NetFlow ver.9 Supports various kinds of packets, such as IPv6 or MPLS, by changing the template data structure. Reliable SCTP/TCP transport Enterprise-specific information elements as vendor-specific extensions Variable length information elements Packet-based data, such as IP headers, can be delivered through the protocol. Packet Exporter Template #400 Template #300 Header Collector 8

PSAMP Features Defines several sampling and filtering techniques to measure the packet-based traffic behavior Sampling: Systematic, Random Sampling Time-based selection interval or packet count-based selection interval Filtering: Property match, Hash-based Filtering Combination of sampling and filtering can be applied. Observation point Selector #1 Filtering Selector #2 Filtering Selector #3 Sampling Output 9

Multicast Flow in requirement RFC mentions: Multiple flow records per different output IF should be maintained to export output IF list IF#1 Packet Exporter IF#3 IF#2 IF#1 Collector IF#2 IF#3 Too many (+burst) multicast flow records When active timeout happens, an access router that has thousands of subscribers will export thousands of flow records at the same time. A more sophisticated way is needed. 10

Proposal of Measurement Method Explore measurement method based on the following requirements Requirement #1: Visualizing multicast path tree Requirement #2: Detecting service quality deterioration Detecting packet loss and disorder Requirement #3: Showing failure point on multicast path tree 11

How to Export Output IF List To visualize the multicast topology, exporting an input and output IF list is required. Use optional template in When specified egress interface is added to the topology or deleted, the optional data is updated. An eventidentifier field indicates added or deleted interfaces. 0 15 16 31 Set Id = 3 Template Id = 256 Scope Field Count = 6 Field length = 16 Field length = 16 Field length = 16 Field length = 16 Field length = 4 Field length = 4 Field length = 4 Enterprise Number 0 0 0 0 0 0 1 Length Field Count = 7 ExporterIPv6Address Id =130 DestinationIPv6Address Id = 27 SourceIPv6Address Id = 130 SourceIPv6PrefixLength Id = 27 ingressinterface Id = 27 egressinterface Id = 27 eventidentifier Id = 1 Enterprise Number Padding 12

Detecting Packet Loss and Disorder Combination of PSAMP techniques on Exporter Observe packets at input interface Select multicast packet by filtering Extract them using systematic time-based sampling All input packets during the interval period are selected. Observed packets IF Exporter Filter Samplers Start End Spacing Start End Spacing Start End Filter selects all multicast packets. Samplers do independent systematic time-based sampling. 13

Exporting Packet-based Data ipheaderpacketsection Includes IP/UDP header and a part of RTP header startmiliseconds and endmiliseconds Indicate the start point and end point of a sampling interval period collector can identify a series of packet data in the same sampling interval period Spacing Spacing 0 15 16 31 Set Id = 2 Length Template Id = 257 Field Count = 5 0 ipheaderpacketsection Id=313 Field Length = 65535 Start End Start End 0 ingressinterface Id = 27 Field Length = 4 0 datetimemiliseconds Id = 323 Field Length = 4 1 startmillisecond Id = 1 Field Length = 4 Enterprise Number 1 EndMillisecond Id = 2 Field Length = 4 Enterprise Number 14

System Architecture Huge amount of traffic data A collector needs to gather the whole traffic data from all exporters on networks. Collector Utilizes Mediator Exporter exports packet-based data records to mediator. Mediator counts packet-loss and then exports flow-based data records to collector Collector visualizes multicast topologies and shows traffic data 2500~3000 records/sec Exporter Exporter Exporter 15

System Architecture Huge amount of traffic data A collector needs to gather the whole traffic data from all exporters on networks. 50 records/sec Collector Utilizes Mediator Exporter exports packet-based data records to mediator. Mediator counts packet-loss and then exports flow-based data records to collector Collector visualizes multicast topologies and shows traffic data 2500~3000 records/sec Mediator Exporter Mediator Mediator Exporter Exporter 16

Mediator Receives packet-based data from Exporters Extracts RTP sequence number from ippacketsection and then counts packets loss Combines series of packet data of the same interval into one flow Exports flow-based data to a collector 0 15 16 31 Set Id = 2 Length Spacing Spacing Template Id = 258 Field Count = 13 0 Bytes Id = 1 Field Length =4 0 Packets Id = 2 Field Length = 4 0 protocolidentifier Id = 4 Field Length = 4 0 sourcetransportport Id = 1 Field Length = 2 0 ingressinterface Id = 10 Field Length = 4 Spacing Spacing 0 destinationtransportport Id = 11 Field Length = 2 0 sourceipv6address Id = 27 Field Length = 16 0 destinationipv6address Id = 28 Field Length = 16 0 ipversion Id = 60 Field Length = 1 Start End Start End 0 exporteripv4address Id = 130 Field Length = 4 0 droppedpacketdeltacount = 133 Field Length = 4 0 flowstartmilliseconds = 152 Field Length = 4 0 flowendmilliseconds = 153 Field Length = 4 17

Multicast Topology View A router in which packet loss occurs is indicated in red on the multicast topology map. Packet loss Selects {S,G} session, and then shows specified multicast path tree Bits, packets 18

Evaluation of Prototype System Experimental assumptions: The packets of 50 IPTV channels pass through an exporter at the same time. We evaluate the exporter by varying the sampling interval period. The sum of the sampling and spacing interval period is kept at a fixed value of 1,000 ms. 1,000 ms 1,000 ms 1,000 ms Spacing Spacing Spacing 19

Experimental Results of Exporter The volume of exported data obtained by changing the interval period from 10 to 100 ms. The performance limit seems to be 3,000 records/sec at the interval period of 50 ms. 7000 6000 Collector Record/second 5000 4000 3000 2000 1000 100ms 50ms 40ms 20ms 70ms 10ms Mediator Exporter 0 0 20 40 60 80 100 120 ElapsedTime[s] CPU: Quad Core 2.66GHz Memory: 4GB OS: FreeBSD 6.2 20

Evaluation of Accuracy We evaluate the detection probability for packet loss within the given monitoring interval (n) by changing packet loss rate (p) and the sampling interval time (d). On condition that n is 1 min and packet rate (r) is 1.2 kp/s, experimental result is shown. r n d 1000 1 (1 p) Detection probability is 80% if the sampling interval period is 40 ms and packet loss happens at 1/1000 for over 1 min. Loss Detection Rate[%] 100 90 80 70 60 50 40 30 20 10 1/100 1/1000 1/10000 0 1 10 100 1000 Time[ms] 21

Experimental Results of Mediator The performance limit is obtained by changing the received data volume from 100 to 5,000 records. The performance limit of received data volume seems to be 3,000 records/sec. In the current prototype version, a one-to-one assignment of the mediator to an exporter is needed. 6000 5000 1000 records/sec 2500 records/sec 4000 records/sec 5000 records/sec Collector Records/second 4000 3000 2000 1000 2500 3000 records/s 2500 3000 records/s Mediator 0 0 10 20 30 40 50 60 Elapsed Time[s] CPU: Core Duo 2.00 Hz Memory: 4GB OS: FreeBSD 6.2 Exporter 22

Conclusion We presented a new traffic measurement method of IP multicast streaming services, such as IPTV, and the system architecture using /PSAMP. We demonstrated the feasibility of the prototype. Toward introducing the method to actual networks, higher efficiency and accuracy would be required. The exporter components are preferably implemented in commercial routers, switches, or network appliance devices, which can handle the huge volume of traffic. 23