SlideShare a Scribd company logo
1 of 59
Download to read offline
Full Speed Ahead
    Packet Capture in High-Speed and Data
              Center Networks

Jay Botelho                         Show us your tweets!
Director of Product Management         Use today’s webinar hashtag:
WildPackets
jbotelho@wildpackets.com                 #wp_highspeed
Follow me @jaybotelho            with any questions, comments, or feedback.
                                           Follow us @wildpackets

                                                     © WildPackets, Inc.   www.wildpackets.com
Administrivia
      • All callers are on mute
           ‒ If you have problems, please let us know via the Chat window
      • There will be Q&A at the end
           ‒ Feel free to type a question at any time
      • Slides and recording will be available:
           ‒ Via a follow-up email




#wp_highspeed                                                © WildPackets, Inc.   2
Agenda
      •   Trends in High-Speed Networking
      •   The New Role of Overlay Networks
      •   Changing Role of Packet-Based Network Analysis
      •   Key Monitoring Points for Network Visibility
      •   About WildPackets




#wp_highspeed                                       © WildPackets, Inc.   3
Trends in High-Speed Networking




                       © WildPackets, Inc.   www.wildpackets.com
                                                                   4
10G – Dispelling the Myth
      • According to The Register
        (http://www.theregister.co.uk/2013/01/03/2013_not_year_of_10gbe/):
           ‒ 2013 will NOT be the year for widespread adoption of 10G
           ‒ Technology is solid – it’s a cost issue
           ‒ Businesses just don't need 10x the bandwidth and aren't willing
             to pay 3x the cost.
      • Server migration to 10G underwhelms during 3Q12
        (http://www.delloro.com/news/server-migration-to-10-gbps-network-connections-underwhelms-during-
        3q12) :

           ‒ The 10G controller and adapter market results were almost flat
             sequentially during the third quarter of 2012
           ‒ “The price premium for 10G is too wide of a gap” - Sameh
             Boujelbene, Senior Analyst, Dell’Oro Group


#wp_highspeed                                                                         © WildPackets, Inc.   5
Optimistic Predictions from Vendors




                http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-696667.html

#wp_highspeed                                                                                       © WildPackets, Inc.   6
How is 10G Being Utilized?
Example 1: Heavy Mfg              Example 2: Network OEM
• Major traffic driver: backup    • Focus now on large, flat 10G
• Current challenge: 2x and 4x     data center fabrics
  1G EtherChannel on backup       • Fabric Path/TRILL “standard”
  servers is saturating
                                  • Nexus 7000 with 32 ports of
• New architecture spec for 10x    10G
  1G EtherChannel                 • Driving need: constant
• What’s coming: virtualized       demand for 1G aggregation
  server clusters growing – one
  has 360 VMs




#wp_highspeed                                        © WildPackets, Inc.   Slide 7
Migration to 40/100G




                http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-696667.html

#wp_highspeed                                                                                       © WildPackets, Inc.   8
New Architectures - New Traffic Patterns
      • Standalone VM Host
        (Virtual Server)



      • Coordinated VM
        Hosts



      • Cloud



#wp_highspeed                    © WildPackets, Inc.   9
The New Role of Overlay Networks




                       © WildPackets, Inc.   www.wildpackets.com
                                                                   10
Standalone VM Networking
      • Multiple guests, single host
           ‒ One or more vNICs per guest
           ‒ One or more physical NICs on host
      • Switch interfaces
           ‒ Guest vNICs
           ‒ Host physical NICs (pNICs)
           ‒ Possible network separation via multiple L2 vSwitches
      • Logically behaves like a TOR or workgroup switch
           ‒ No transit traffic, leaf network
           ‒ Usually no L3 (Routing) between VLANs/vSwitches




#wp_highspeed                                                 © WildPackets, Inc.   11
Standalone VM Networking




#wp_highspeed                         © WildPackets, Inc.   12
North/South vs East/West




#wp_highspeed                          © WildPackets, Inc.   13
Coordinated VM Networking
      • Single switch among multiple VM hosts
           ‒ Each vSwitch per host like a blade switch
           ‒ Physical network like a backplane, but usually no L3
      • Maintains single forwarding table
           ‒ Inter-VM traffic between hosts sent encapsulated to target host
           ‒ No need to “learn” VM MAC addresses
      • Port profiles per guest
           ‒ If VM moves, profile moves too
           ‒ vSwitch forwarding tables automatically updated
           ‒ Physical switches must learn new host for VM




#wp_highspeed                                                  © WildPackets, Inc.   14
Coordinated VM Networking




                    Distributed vSwitch (shared across VM hosts)




#wp_highspeed                                                      © WildPackets, Inc.   15
Overlay vs. Underlay




                 Distributed vSwitch (shared across VM hosts)




#wp_highspeed                                                   © WildPackets, Inc.   16
Cloud
      • Software-allocated networking
           ‒ Network configuration de-coupled from networking hardware
           ‒ A basic form of SDN
      • Focus on connectivity
           ‒ Get servers up and running
           ‒ Keep traffic hidden between customers
      • Self-service paradox
           ‒ Cloud allows customers to provision and monitor VMs
           ‒ Security requires traffic to be hidden between customers
           ‒ Therefore customers can’t monitor the network




#wp_highspeed                                                 © WildPackets, Inc.   17
Cloud Network




#wp_highspeed                   © WildPackets, Inc.   18
Changing Roles of
Packet-based Network Analysis




                      © WildPackets, Inc.   www.wildpackets.com
                                                                  19
Strategy for Monitoring 10G Ethernet
                 Which of the following apply to your strategy for monitoring 10G
                                 segments? (Select all that apply)


                                    Our tools don't support 10G
                                                                                                         41.1%

              Want to keep 1G tools as long as possible                                            32.9%
                         Can't afford upgrading tools to 10G                                 21.9%

                           All set - tools already support 10G                               21.9%
               All set - our mirroring sol'n converts 10G to
                                     1G
                                                                                           14.4%

                                                                       Other        4.1%

                                                                               0%
                                                                                       20%
SOURCE: Benchmarking Network and Security Operations: Tools, Processes, and
Enabling Technologies Study, 2009, Enterprise Management Associates. n=124
                                                                                                   40%
                                                                                                                    60%
 #wp_highspeed                                                                                            © WildPackets, Inc.
10G Compromises
      • 10G to 1G taps
      • Apply pre-capture filters or triggered captures to
        selectively stream to disk
      • 10G NIC upgrades in architectures designed for
        multi-port 1G deployments




#wp_highspeed                                      © WildPackets, Inc.
Typical Network Analysis Workflow

                               Alerts/         User
       Let It Roll!
                               Alarms        Complaints


                  NO
                              Problem?

                       YES


       Connect the                            Reproduce
                             Start a Trace
        Analyzer                             if Necessary

#wp_highspeed                                      © WildPackets, Inc.
1Gig Is Easy - Now
      •   Use almost any NIC
      •   Use almost any computer
      •   Capture and analyze all in real-time
      •   Little or no special hardware needed (taps, etc.)
      •   Little to no impact on existing network traffic
      •   “Analysis on the fly” still feasible




#wp_highspeed                                         © WildPackets, Inc.
10Gig Network Analysis Workflow

      Identify Key            Deploy 24x7   Alarms/
      Analysis Pts            Monitoring     Alerts


                   NO
                               Problem?

                        YES


          Rewind                             Tune if
                                Analyze
           Data                             Necessary

#wp_highspeed                                   © WildPackets, Inc.
10G Provides Unique Challenges
      •   Traditional NICs not up to the task
      •   Processing power is a limiting factor
      •   Storage capacity is a limiting factor
      •   I/O bus and disk write speeds are a limiting factor
      •   10G forces clarity in analysis
      •   At 10G, it truly is looking for a needle in a haystack
      •   “Line rate” – be wary of that claim!
           Importance: Packet-based PM tools remain only truly effective
          approach to definitive monitoring and definitive troubleshooting –
            Jim Frey, Enterprise Management Associates, Inc., July 2010

#wp_highspeed                                                     © WildPackets, Inc.
10G Network Data Storage
      • 1Gbps steady-state traffic assuming no storage
        overhead:
        7.68 GB/min
        460 GB/hr
        11 TB/day
        2.9 days in a 32TB appliance
      • 10Gbps:
        76.8GB/min
        4.6 TB/hr
        110 TB/day
        7.0 hours in a 32TB appliance

#wp_highspeed                                   © WildPackets, Inc.
10G Network Data Capture




#wp_highspeed                          © WildPackets, Inc.
10G Network Analysis
      •   Analyze the essentials
      •   Be specific when possible
      •   Know your network – baselines are critical
      •   Know your limits
      •   Real-time vs. forensics
      •   Filter and slice (whenever possible)
      •   Anticipate hardware resource needs




#wp_highspeed                                      © WildPackets, Inc.
Key Monitoring Points
for Network Visibility




                   © WildPackets, Inc.   www.wildpackets.com
                                                               29
Where to Capture
      •   On the Network
      •   On the vSwitch
      •   On a Virtual Tap
      •   On the VM Guest




#wp_highspeed                            © WildPackets, Inc.   30
On the Network
      • Classical switch SPAN port or tap
           ‒ View traffic in/out of a Host
      • The Good:
           ‒ Familiar configuration and process
           ‒ “Easy” if you control the network
      • The Bad:
           ‒ Misses intra-host traffic




#wp_highspeed                                     © WildPackets, Inc.   31
On the Network




#wp_highspeed                    © WildPackets, Inc.   32
On the vSwitch
      • Span port from virtual switch / hypervisor
           ‒ Dedicated VM guest to receive packets
           ‒ Potentially external capture
              • Use pNIC as target for SPAN
              • Also RSPAN/ERSPAN
      • The Good:
           ‒ Visibility of intra-host traffic
           ‒ Built-in to infrastructure
      • The Bad:
           ‒ Capturing on local VM increases IO of net & disk
           ‒ Still have to know which host for specific VM guest
           ‒ May violate separation of customer traffic

#wp_highspeed                                                  © WildPackets, Inc.   33
vSwitch Span Port




#wp_highspeed                       © WildPackets, Inc.   34
With a Virtual Tap
      • Tap to manage SPAN on distributed vSwitches
      • Integrates with VM control system
           ‒ Reads orchestration info to find which host for VM guest
           ‒ Auto-configures capture source
      • The Good:
           ‒ Reduced effort, increased visibility
           ‒ Should auto-filter for customer traffic separation
      • The Bad:
           ‒ May be VM vendor specific, e.g. only VMware
      • Examples: NetOptics, Gigamon, BigSwitch

#wp_highspeed                                                     © WildPackets, Inc.   35
Virtual Tap Infrastructure




                                   Virtual Tap
                   Distributed vSwitch (shared across VM hosts)




#wp_highspeed                                                     © WildPackets, Inc.   36
Capturing Packets in Cloud
      • Private Cloud (In-house)
           ‒ Under your control
                • Functionally similar to distributed VM
           ‒ If you control the network, you can sniff “anywhere”
                • Legal concerns for customer-owned guest VMs
      • Public Cloud / Private Cloud (3rd Party)
           ‒ Unlikely that you can negotiate net sniffing rights
           ‒ IaaS VMs can likely sniff their own traffic
               • Non-promiscuous sniffing
               • Restore visibility on per-VM basis
               • You’ll have to re-aggregate traffic among VMs




#wp_highspeed                                                      © WildPackets, Inc.   37
Capturing on VM Guest




#wp_highspeed                           © WildPackets, Inc.   38
Summary
      • 10G technology is ready – needs to make business
        sense
      • Data center architectures are evolving quickly –
        analysis systems need to keep up
      • Plan for 40G, but it’s years away for most
      • Faster networking technology and new virtualization
        and cloud schemes are challenging conventional
        network monitoring and troubleshooting
      • Plan ahead for network infrastructure monitoring and
        troubleshooting as new solutions are deployed

#wp_highspeed                                     © WildPackets, Inc.   39
Q&A

   Show us your tweets!
      Use today’s webinar hashtag:           Follow us on SlideShare!
                                              Check out today’s slides on SlideShare
        #wp_highspeed                            www.slideshare.net/wildpackets
with any questions, comments, or feedback.
          Follow us @wildpackets



                                                           © WildPackets, Inc.   www.wildpackets.com
WildPackets Corporate Overview

Optimizing Network and Application Performance




                                  © WildPackets, Inc.   www.wildpackets.com
Corporate Background
      • Experts in network monitoring, analysis, and troubleshooting
           ‒ Founded: 1990 / Headquarters: Walnut Creek, CA
           ‒ Offices throughout the US, EMEA, and APAC


      • Customers spanning leading edge organizations
           ‒ Mid-market and enterprise lines of business
           ‒ Financial, manufacturing, ISPs, major federal agencies,
             state and local governments, universities
           ‒ Over 7,000 customers / 60+ countries / 80% of Fortune 1,000


      • Award-winning solutions that improve network performance
           ‒ Internet Telephony, Network Magazine, Network Computing awards
           ‒ United States Patent 5,787,253 issued July 28, 1998
                • “Apparatus and Method of Analyzing Internet Activity”

#wp_highspeed                                                     © WildPackets, Inc.
Why Our Customers Need Us

      • VoIP, video, cloud, virtualization, and key business
        applications are saturating critical network services

      • Evolving network technologies create discontinuities
           ‒ 1 Gig  10 Gig  40 Gig  100 Gig networks
           ‒ Wireless, BYOD initiatives

      • Users and business can not tolerate network
        problems for mission critical services

          Increasing demand for better real-time network visibility,
               network analytics, network forensics, and DPI

#wp_highspeed                                               © WildPackets, Inc.
How We Create Value
         We provide innovative, industry-leading, real-time
         network performance management solutions
                ‒ Easy-to-use, easy-to-learn user interface
                ‒ Uniquely extensible solutions
                ‒ Wireless network leadership
                ‒ Detailed analytics related to network applications
                ‒ Fastest network traffic capture appliance in its class
                ‒ Technical superiority at competitive price point

  WildPackets has continually advanced its solution to meet the needs of its
                                 customers


#wp_highspeed                                                        © WildPackets, Inc.
Unprecedented Network Visibility

                           NETWORK HEALTH
      GLOBAL               WatchPoint can manage and report on key
                           device performance and availability across
                           the entire network, from anywhere on the network.

                           UNDERSTAND END-USER PERFORMANCE
                           TimeLine and Omnipliance network recorders monitor
          DISTRIBUTED      and analyze performance across critical network
                           segments, virtual environments, and remote sites.

                           PINPOINT NETWORK ISSUES ANYWHERE
                           Omnipliance Portable can rapidly identify and troubleshoot
                PORTABLE   issues before they become major problems—wired or
                           wireless—down the hall or across the globe.

                           ROOT-CAUSE ANALYSIS
                           OmniPeek network analyzer performs deep packet inspection
                 DPI       and can reconstruct all network activity, including e-mail and
                           IM, as well as analyze VoIP and video traffic quality.


#wp_highspeed                                                    © WildPackets, Inc.
A History of Innovation

                 2001                         2005                              2009                                     2011
                 • First 802.11               Combined distributed              Innovative dashboard                     • Total visibility with
                 wireless analyzer            network and VoIP                  with drill-down for VoIP                 zero packet loss
                 • First network              network analysis                  and video                                • First wireless
                 analyzer with                                                                                           network analyzer to
                 automated expert                                                                                        support capture and
                 analysis                                                                                                analysis of 802.11n
                                                                                                                         3-stream wireless




             2003                           2008                             2010                                     2012
 Distributed real-time               Enterprise-wide          First to achieve 11 Gbps              • Capture, record, and
      troubleshooting       Monitoring and Reporting         sustained capture-to-disk                   analyze from 40G
                                                                                                         network segments
                                                                                                   • First wireless network
                                                                                                        analyzer to support
                                                                                                     801.11ac, k, r, u, v, w



#wp_highspeed                                                                                              © WildPackets, Inc.
Product Line Overview




                  © WildPackets, Inc.   www.wildpackets.com
Omni Distributed Analysis Platform
                                       OmniPeek
                Enterprise Packet Capture, Decode and Analysis
                   • Ethernet,1/10 Gigabit, 802.11, and voice and video over IP
                   • Portable capture and OmniEngine console
                   • Aggregate analysis data across multiple capture points


                                Omnipliance / TimeLine
                       Distributed Enterprise Network Forensics
                            • High-performance packet capture and real-time analysis
                            • Stream-to-disk for forensics analysis
                            • Integrated OmniAdapter network analysis cards up to 40G


                                              WatchPoint
                   Centralized Enterprise Network Monitoring Appliance
                          • Aggregation and graphical display of network data
                          • WildPackets OmniEngines
                          • NetFlow and sFlow

#wp_highspeed                                                                     © WildPackets, Inc.
Omni Distributed Analysis Platform
                  Software and Turnkey Solutions
      • Enterprise monitoring and reporting
           ‒ WatchPoint Server
           ‒ OmniFlow, NetFlow, and sFlow Collectors
      • Software probes and network recorders
           ‒ Omnipliance network recorders – Edge, Core
           ‒ TimeLine network recorders
           ‒ OmniAdapter analysis cards
      • Distributed analysis software
           ‒ OmniPeek – Enterprise, Professional, Basic, Connect
           ‒ OmniEngine – Enterprise, Desktop, OmniVirtual
      • Portable solutions
           ‒ OmniPeek network analyzer
           ‒ Omnipliance Portable
#wp_highspeed                                                      © WildPackets, Inc.
Key New Features in v7
      • 40G network support
      • Analyze issues from end to end:
        Multi-Segment Analysis (MSA)
      • Collect data from non-technical end users:
        OmniPeek Remote Assistant (ORA)
      • Single, interactive dashboard for
        utilization, top talkers, top protocols,
        latency, Experts, flows, and wireless
        signal strength
      • New wireless specifications
           ‒ 802.11ac         802.11k
           ‒ 802.11r          802.11u
           ‒ 802.11v          802.11w

#wp_highspeed                                        © WildPackets, Inc.
OmniPeek Network Analyzer
      • Distributed analysis manager
           – Connect to and configure distributed OmniEngines, Omnipliances,
             and TimeLines
      • Comprehensive dashboards present network traffic in real-time
           – Vital statistics and graphs display trends on network and application
             performance
           – Visual peer-map shows conversations and protocols
           – Intuitive drill-down for root-cause analysis of performance bottlenecks
      • Visual Expert diagnosis speeds problem resolution
           – Packet and payload visualizers provide business-centric views
      • Automated analytics and problem detection 24/7
           – Easily create filters, triggers, scripting, advanced alarms, and alerts



#wp_highspeed                                                          © WildPackets, Inc.
Omnipliance Network Recorders
      •   Captures and analyzes all network traffic 24x7
           – Runs WildPackets OmniEngine software probe
           – Generates vital statistics on network and application performance
           – Intuitive root-cause analysis of performance bottlenecks
      •   Expert analysis speeds problem resolution
           – Fault analysis, statistical analysis, and independent notification
      •   Multiple issue digital forensics
           – Real-time and post capture data mining for compliance and troubleshooting
      •   Intelligent data transport
           –    Network data analyzed locally
           –    Detailed analysis passed to OmniPeek on demand
           –    Summary statistics sent to WatchPoint for long term trending and reporting
           –    Efficient use of network bandwidth
      •   User-extensible platform
           – Plug-in architecture and SDK

#wp_highspeed                                                                 © WildPackets, Inc.
TimeLine Network Recorder
      • Continuous network recording and comprehensive
        real-time statistical display — simultaneously
           ‒ 12Gbps sustained capture with zero packet loss
           ‒ Network statistics display in TimeLine visualization format
      • Rapid, intuitive forensics search and retrieval
           ‒ Historical network traffic analysis and quick data rewinding
           ‒ Several pre-defined forensics search templates making
             searches easy and fast
      • A natural extension to the WildPackets product line
      • Turnkey bundled solution
           ‒ Appliance + OmniEngine, OmniAdapter, OmniPeek Connect


#wp_highspeed                                                   © WildPackets, Inc.
WildPackets Network Recorders
                   Price/Performance Solutions for Every Application




        Portable                           Edge                        Core                     TimeLine
        Ruggedized                    Small Networks         Datacenter Workhorse           Enterprise, Highly-
      Troubleshooting                 Remote Offices          Easily Expandable             Utilized Networks
Aluminum chassis / 17” LCD      1U rack mountable chassis    3U rack mountable chassis   3U rack mountable chassis
Dual 2.13 GHz Quad-Core Intel   Quad-Core Intel Xeon X3460   Dual Intel Xeon Quad Core   Dual Intel Xeon Quad Core
Xeon L5630 "Westmere"           2.80Ghz                      E5530 2.4GHz                X5560 2.8GHz
24GB RAM                        4GB RAM                      6GB RAM                     18GB RAM
2 PCI-E Slots                   2 PCI-E Slots                4 PCI-E Slots               4 PCI-E Slots
2 Built-in Ethernet Ports       2 Built-in Ethernet Ports    2 Built-in Ethernet Ports   2 Built-in Ethernet Ports
6TB SATA storage capacity       1TB SATA storage capacity    8/16TB SATA                 8/16/32/48TB SATA
                                                             storage capacity            storage capacity
4.5Gbps CTD                     1.1Gbps CTD                  3Gbps CTD                   12Gbps CTD



#wp_highspeed                                                                              © WildPackets, Inc.
WatchPoint
    Centralized Monitoring for Distributed Enterprise Networks

                                       •   High-level, aggregated
                                           view of all network
                                           segments
                                            – Monitor per campus, per
                                              region, per country
                                       •   Wide range of network
                                           data
                                            – NetFlow, sFlow, OmniFlow
                                       •   Web-based, customizable
                                           network dashboards
                                       •   Flexible detailed reports
                                       •   Direct link to detailed,
                                           packet-based analysis


#wp_highspeed                                          © WildPackets, Inc.
Comprehensive Support and Services
      Standard Support                     Premier Support
         Maintenance and upgrades             24 x 7 x 365
         Telephone and email contacts         Dedicated escalation manager
         Knowledgebase                        2 customer contacts per site
         MyPeek Portal                        Plug-in reconfiguration assistance

      WildPackets Training Academy
       Public, web-based, and on-site classes
       Complete curriculum: technology and product focused
       Practical applications and labs covering network analysis,
        wireless, VoIP monitoring and advanced troubleshooting

      Consulting and Custom Development Services
       Deployment, configuration, and assessment engagement
       Systems integration and testing
       Application integration, driver, decode, interface development

#wp_highspeed                                                        © WildPackets, Inc.
WildPackets Key Differentiators
      • Visual Expert intelligence with intuitive drill-down
           – Let computer do the hard work, and return results, real-time
           – Packet /payload visualization is faster than packet-per-packet diagnostics
           – Experts and analytics can be memorized and automated
      • Automated capture analytics
           – Filters, triggers, scripting, and advanced alarming system combine to provide
             automated network problem detection 24x7
      • Multiple issue network forensics
           – Can be tracked by one or more people simultaneously
           – Real-time or post capture
      • User-extensible platform
           – Plug-in architecture and SDK
      • Aggregated network views and reporting
           – NetFlow, sFlow, and OmniFlow


#wp_highspeed                                                               © WildPackets, Inc.
24x7 Network Monitoring,
                Analysis, and Troubleshooting




#wp_highspeed                             © WildPackets, Inc.
Thank You!


WildPackets, Inc.
1340 Treat Boulevard, Suite 500
Walnut Creek, CA 94597
(925) 937-3200

                                    © WildPackets, Inc.   www.wildpackets.com

More Related Content

More from Savvius, Inc

Are you ready for 802.11ac?
Are you ready for 802.11ac?Are you ready for 802.11ac?
Are you ready for 802.11ac?Savvius, Inc
 
Are You Missing Something?
Are You Missing Something?Are You Missing Something?
Are You Missing Something?Savvius, Inc
 
All Hope is Not Lost Network Forensics Exposes Today's Advanced Security Thr...
All Hope is Not LostNetwork Forensics Exposes Today's Advanced Security Thr...All Hope is Not LostNetwork Forensics Exposes Today's Advanced Security Thr...
All Hope is Not Lost Network Forensics Exposes Today's Advanced Security Thr...Savvius, Inc
 
Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...
Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...
Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...Savvius, Inc
 
Managing a Widely Distributed Network
Managing a Widely Distributed NetworkManaging a Widely Distributed Network
Managing a Widely Distributed Network Savvius, Inc
 
VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...
VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...
VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...Savvius, Inc
 
WildPackets EMA Whitepaper Preview
WildPackets EMA Whitepaper PreviewWildPackets EMA Whitepaper Preview
WildPackets EMA Whitepaper PreviewSavvius, Inc
 
Gigabit WLANs Need Gigabit WLAN Analysis
Gigabit WLANs Need Gigabit WLAN AnalysisGigabit WLANs Need Gigabit WLAN Analysis
Gigabit WLANs Need Gigabit WLAN AnalysisSavvius, Inc
 
Security Attack Analysis for Finding and Stopping Network Attacks
Security Attack Analysis for Finding and Stopping Network AttacksSecurity Attack Analysis for Finding and Stopping Network Attacks
Security Attack Analysis for Finding and Stopping Network AttacksSavvius, Inc
 
Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...
Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...
Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...Savvius, Inc
 
Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)
Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)
Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)Savvius, Inc
 
The Changing Landscape in Network Performance Monitoring
The Changing Landscape in Network Performance Monitoring The Changing Landscape in Network Performance Monitoring
The Changing Landscape in Network Performance Monitoring Savvius, Inc
 
Wired and Wireless Network Forensics
Wired and Wireless Network ForensicsWired and Wireless Network Forensics
Wired and Wireless Network ForensicsSavvius, Inc
 
802.11ac: Technologies and Deployment Strategies with FarPoint Group
802.11ac: Technologies and Deployment Strategies with FarPoint Group802.11ac: Technologies and Deployment Strategies with FarPoint Group
802.11ac: Technologies and Deployment Strategies with FarPoint GroupSavvius, Inc
 
Omnipliance family - Powerful Precise Affordable
Omnipliance family - Powerful Precise AffordableOmnipliance family - Powerful Precise Affordable
Omnipliance family - Powerful Precise AffordableSavvius, Inc
 
Capturing 802.11ac Data
Capturing 802.11ac DataCapturing 802.11ac Data
Capturing 802.11ac DataSavvius, Inc
 
Real-Time Visibility into High Speed Networks
Real-Time Visibility into High Speed NetworksReal-Time Visibility into High Speed Networks
Real-Time Visibility into High Speed NetworksSavvius, Inc
 
Bringing Big Data Analytics to Network Monitoring
Bringing Big Data Analytics to Network MonitoringBringing Big Data Analytics to Network Monitoring
Bringing Big Data Analytics to Network MonitoringSavvius, Inc
 
Network Analysis Tips and Tricks with OmniPeek
Network Analysis Tips and Tricks with OmniPeekNetwork Analysis Tips and Tricks with OmniPeek
Network Analysis Tips and Tricks with OmniPeekSavvius, Inc
 
The blind spot in virtual servers - seeing with network analysis
The blind spot in virtual servers - seeing with network analysisThe blind spot in virtual servers - seeing with network analysis
The blind spot in virtual servers - seeing with network analysisSavvius, Inc
 

More from Savvius, Inc (20)

Are you ready for 802.11ac?
Are you ready for 802.11ac?Are you ready for 802.11ac?
Are you ready for 802.11ac?
 
Are You Missing Something?
Are You Missing Something?Are You Missing Something?
Are You Missing Something?
 
All Hope is Not Lost Network Forensics Exposes Today's Advanced Security Thr...
All Hope is Not LostNetwork Forensics Exposes Today's Advanced Security Thr...All Hope is Not LostNetwork Forensics Exposes Today's Advanced Security Thr...
All Hope is Not Lost Network Forensics Exposes Today's Advanced Security Thr...
 
Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...
Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...
Visibility into 40G/100G Networks for Real-time and Post Capture Analysis and...
 
Managing a Widely Distributed Network
Managing a Widely Distributed NetworkManaging a Widely Distributed Network
Managing a Widely Distributed Network
 
VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...
VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...
VoIP Monitoring and Analysis - Still Top of Mind in Network Performance Monit...
 
WildPackets EMA Whitepaper Preview
WildPackets EMA Whitepaper PreviewWildPackets EMA Whitepaper Preview
WildPackets EMA Whitepaper Preview
 
Gigabit WLANs Need Gigabit WLAN Analysis
Gigabit WLANs Need Gigabit WLAN AnalysisGigabit WLANs Need Gigabit WLAN Analysis
Gigabit WLANs Need Gigabit WLAN Analysis
 
Security Attack Analysis for Finding and Stopping Network Attacks
Security Attack Analysis for Finding and Stopping Network AttacksSecurity Attack Analysis for Finding and Stopping Network Attacks
Security Attack Analysis for Finding and Stopping Network Attacks
 
Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...
Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...
Network Network Visibility - The Key to Rapidly Troubleshooting Network Perfo...
 
Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)
Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)
Wireless Network Analysis 101 VoFi (Voice over Wi-Fi)
 
The Changing Landscape in Network Performance Monitoring
The Changing Landscape in Network Performance Monitoring The Changing Landscape in Network Performance Monitoring
The Changing Landscape in Network Performance Monitoring
 
Wired and Wireless Network Forensics
Wired and Wireless Network ForensicsWired and Wireless Network Forensics
Wired and Wireless Network Forensics
 
802.11ac: Technologies and Deployment Strategies with FarPoint Group
802.11ac: Technologies and Deployment Strategies with FarPoint Group802.11ac: Technologies and Deployment Strategies with FarPoint Group
802.11ac: Technologies and Deployment Strategies with FarPoint Group
 
Omnipliance family - Powerful Precise Affordable
Omnipliance family - Powerful Precise AffordableOmnipliance family - Powerful Precise Affordable
Omnipliance family - Powerful Precise Affordable
 
Capturing 802.11ac Data
Capturing 802.11ac DataCapturing 802.11ac Data
Capturing 802.11ac Data
 
Real-Time Visibility into High Speed Networks
Real-Time Visibility into High Speed NetworksReal-Time Visibility into High Speed Networks
Real-Time Visibility into High Speed Networks
 
Bringing Big Data Analytics to Network Monitoring
Bringing Big Data Analytics to Network MonitoringBringing Big Data Analytics to Network Monitoring
Bringing Big Data Analytics to Network Monitoring
 
Network Analysis Tips and Tricks with OmniPeek
Network Analysis Tips and Tricks with OmniPeekNetwork Analysis Tips and Tricks with OmniPeek
Network Analysis Tips and Tricks with OmniPeek
 
The blind spot in virtual servers - seeing with network analysis
The blind spot in virtual servers - seeing with network analysisThe blind spot in virtual servers - seeing with network analysis
The blind spot in virtual servers - seeing with network analysis
 

Packet capture in high-speed and data center networks

  • 1. Full Speed Ahead Packet Capture in High-Speed and Data Center Networks Jay Botelho Show us your tweets! Director of Product Management Use today’s webinar hashtag: WildPackets jbotelho@wildpackets.com #wp_highspeed Follow me @jaybotelho with any questions, comments, or feedback. Follow us @wildpackets © WildPackets, Inc. www.wildpackets.com
  • 2. Administrivia • All callers are on mute ‒ If you have problems, please let us know via the Chat window • There will be Q&A at the end ‒ Feel free to type a question at any time • Slides and recording will be available: ‒ Via a follow-up email #wp_highspeed © WildPackets, Inc. 2
  • 3. Agenda • Trends in High-Speed Networking • The New Role of Overlay Networks • Changing Role of Packet-Based Network Analysis • Key Monitoring Points for Network Visibility • About WildPackets #wp_highspeed © WildPackets, Inc. 3
  • 4. Trends in High-Speed Networking © WildPackets, Inc. www.wildpackets.com 4
  • 5. 10G – Dispelling the Myth • According to The Register (http://www.theregister.co.uk/2013/01/03/2013_not_year_of_10gbe/): ‒ 2013 will NOT be the year for widespread adoption of 10G ‒ Technology is solid – it’s a cost issue ‒ Businesses just don't need 10x the bandwidth and aren't willing to pay 3x the cost. • Server migration to 10G underwhelms during 3Q12 (http://www.delloro.com/news/server-migration-to-10-gbps-network-connections-underwhelms-during- 3q12) : ‒ The 10G controller and adapter market results were almost flat sequentially during the third quarter of 2012 ‒ “The price premium for 10G is too wide of a gap” - Sameh Boujelbene, Senior Analyst, Dell’Oro Group #wp_highspeed © WildPackets, Inc. 5
  • 6. Optimistic Predictions from Vendors http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-696667.html #wp_highspeed © WildPackets, Inc. 6
  • 7. How is 10G Being Utilized? Example 1: Heavy Mfg Example 2: Network OEM • Major traffic driver: backup • Focus now on large, flat 10G • Current challenge: 2x and 4x data center fabrics 1G EtherChannel on backup • Fabric Path/TRILL “standard” servers is saturating • Nexus 7000 with 32 ports of • New architecture spec for 10x 10G 1G EtherChannel • Driving need: constant • What’s coming: virtualized demand for 1G aggregation server clusters growing – one has 360 VMs #wp_highspeed © WildPackets, Inc. Slide 7
  • 8. Migration to 40/100G http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-696667.html #wp_highspeed © WildPackets, Inc. 8
  • 9. New Architectures - New Traffic Patterns • Standalone VM Host (Virtual Server) • Coordinated VM Hosts • Cloud #wp_highspeed © WildPackets, Inc. 9
  • 10. The New Role of Overlay Networks © WildPackets, Inc. www.wildpackets.com 10
  • 11. Standalone VM Networking • Multiple guests, single host ‒ One or more vNICs per guest ‒ One or more physical NICs on host • Switch interfaces ‒ Guest vNICs ‒ Host physical NICs (pNICs) ‒ Possible network separation via multiple L2 vSwitches • Logically behaves like a TOR or workgroup switch ‒ No transit traffic, leaf network ‒ Usually no L3 (Routing) between VLANs/vSwitches #wp_highspeed © WildPackets, Inc. 11
  • 12. Standalone VM Networking #wp_highspeed © WildPackets, Inc. 12
  • 13. North/South vs East/West #wp_highspeed © WildPackets, Inc. 13
  • 14. Coordinated VM Networking • Single switch among multiple VM hosts ‒ Each vSwitch per host like a blade switch ‒ Physical network like a backplane, but usually no L3 • Maintains single forwarding table ‒ Inter-VM traffic between hosts sent encapsulated to target host ‒ No need to “learn” VM MAC addresses • Port profiles per guest ‒ If VM moves, profile moves too ‒ vSwitch forwarding tables automatically updated ‒ Physical switches must learn new host for VM #wp_highspeed © WildPackets, Inc. 14
  • 15. Coordinated VM Networking Distributed vSwitch (shared across VM hosts) #wp_highspeed © WildPackets, Inc. 15
  • 16. Overlay vs. Underlay Distributed vSwitch (shared across VM hosts) #wp_highspeed © WildPackets, Inc. 16
  • 17. Cloud • Software-allocated networking ‒ Network configuration de-coupled from networking hardware ‒ A basic form of SDN • Focus on connectivity ‒ Get servers up and running ‒ Keep traffic hidden between customers • Self-service paradox ‒ Cloud allows customers to provision and monitor VMs ‒ Security requires traffic to be hidden between customers ‒ Therefore customers can’t monitor the network #wp_highspeed © WildPackets, Inc. 17
  • 18. Cloud Network #wp_highspeed © WildPackets, Inc. 18
  • 19. Changing Roles of Packet-based Network Analysis © WildPackets, Inc. www.wildpackets.com 19
  • 20. Strategy for Monitoring 10G Ethernet Which of the following apply to your strategy for monitoring 10G segments? (Select all that apply) Our tools don't support 10G 41.1% Want to keep 1G tools as long as possible 32.9% Can't afford upgrading tools to 10G 21.9% All set - tools already support 10G 21.9% All set - our mirroring sol'n converts 10G to 1G 14.4% Other 4.1% 0% 20% SOURCE: Benchmarking Network and Security Operations: Tools, Processes, and Enabling Technologies Study, 2009, Enterprise Management Associates. n=124 40% 60% #wp_highspeed © WildPackets, Inc.
  • 21. 10G Compromises • 10G to 1G taps • Apply pre-capture filters or triggered captures to selectively stream to disk • 10G NIC upgrades in architectures designed for multi-port 1G deployments #wp_highspeed © WildPackets, Inc.
  • 22. Typical Network Analysis Workflow Alerts/ User Let It Roll! Alarms Complaints NO Problem? YES Connect the Reproduce Start a Trace Analyzer if Necessary #wp_highspeed © WildPackets, Inc.
  • 23. 1Gig Is Easy - Now • Use almost any NIC • Use almost any computer • Capture and analyze all in real-time • Little or no special hardware needed (taps, etc.) • Little to no impact on existing network traffic • “Analysis on the fly” still feasible #wp_highspeed © WildPackets, Inc.
  • 24. 10Gig Network Analysis Workflow Identify Key Deploy 24x7 Alarms/ Analysis Pts Monitoring Alerts NO Problem? YES Rewind Tune if Analyze Data Necessary #wp_highspeed © WildPackets, Inc.
  • 25. 10G Provides Unique Challenges • Traditional NICs not up to the task • Processing power is a limiting factor • Storage capacity is a limiting factor • I/O bus and disk write speeds are a limiting factor • 10G forces clarity in analysis • At 10G, it truly is looking for a needle in a haystack • “Line rate” – be wary of that claim! Importance: Packet-based PM tools remain only truly effective approach to definitive monitoring and definitive troubleshooting – Jim Frey, Enterprise Management Associates, Inc., July 2010 #wp_highspeed © WildPackets, Inc.
  • 26. 10G Network Data Storage • 1Gbps steady-state traffic assuming no storage overhead: 7.68 GB/min 460 GB/hr 11 TB/day 2.9 days in a 32TB appliance • 10Gbps: 76.8GB/min 4.6 TB/hr 110 TB/day 7.0 hours in a 32TB appliance #wp_highspeed © WildPackets, Inc.
  • 27. 10G Network Data Capture #wp_highspeed © WildPackets, Inc.
  • 28. 10G Network Analysis • Analyze the essentials • Be specific when possible • Know your network – baselines are critical • Know your limits • Real-time vs. forensics • Filter and slice (whenever possible) • Anticipate hardware resource needs #wp_highspeed © WildPackets, Inc.
  • 29. Key Monitoring Points for Network Visibility © WildPackets, Inc. www.wildpackets.com 29
  • 30. Where to Capture • On the Network • On the vSwitch • On a Virtual Tap • On the VM Guest #wp_highspeed © WildPackets, Inc. 30
  • 31. On the Network • Classical switch SPAN port or tap ‒ View traffic in/out of a Host • The Good: ‒ Familiar configuration and process ‒ “Easy” if you control the network • The Bad: ‒ Misses intra-host traffic #wp_highspeed © WildPackets, Inc. 31
  • 32. On the Network #wp_highspeed © WildPackets, Inc. 32
  • 33. On the vSwitch • Span port from virtual switch / hypervisor ‒ Dedicated VM guest to receive packets ‒ Potentially external capture • Use pNIC as target for SPAN • Also RSPAN/ERSPAN • The Good: ‒ Visibility of intra-host traffic ‒ Built-in to infrastructure • The Bad: ‒ Capturing on local VM increases IO of net & disk ‒ Still have to know which host for specific VM guest ‒ May violate separation of customer traffic #wp_highspeed © WildPackets, Inc. 33
  • 34. vSwitch Span Port #wp_highspeed © WildPackets, Inc. 34
  • 35. With a Virtual Tap • Tap to manage SPAN on distributed vSwitches • Integrates with VM control system ‒ Reads orchestration info to find which host for VM guest ‒ Auto-configures capture source • The Good: ‒ Reduced effort, increased visibility ‒ Should auto-filter for customer traffic separation • The Bad: ‒ May be VM vendor specific, e.g. only VMware • Examples: NetOptics, Gigamon, BigSwitch #wp_highspeed © WildPackets, Inc. 35
  • 36. Virtual Tap Infrastructure Virtual Tap Distributed vSwitch (shared across VM hosts) #wp_highspeed © WildPackets, Inc. 36
  • 37. Capturing Packets in Cloud • Private Cloud (In-house) ‒ Under your control • Functionally similar to distributed VM ‒ If you control the network, you can sniff “anywhere” • Legal concerns for customer-owned guest VMs • Public Cloud / Private Cloud (3rd Party) ‒ Unlikely that you can negotiate net sniffing rights ‒ IaaS VMs can likely sniff their own traffic • Non-promiscuous sniffing • Restore visibility on per-VM basis • You’ll have to re-aggregate traffic among VMs #wp_highspeed © WildPackets, Inc. 37
  • 38. Capturing on VM Guest #wp_highspeed © WildPackets, Inc. 38
  • 39. Summary • 10G technology is ready – needs to make business sense • Data center architectures are evolving quickly – analysis systems need to keep up • Plan for 40G, but it’s years away for most • Faster networking technology and new virtualization and cloud schemes are challenging conventional network monitoring and troubleshooting • Plan ahead for network infrastructure monitoring and troubleshooting as new solutions are deployed #wp_highspeed © WildPackets, Inc. 39
  • 40. Q&A Show us your tweets! Use today’s webinar hashtag: Follow us on SlideShare! Check out today’s slides on SlideShare #wp_highspeed www.slideshare.net/wildpackets with any questions, comments, or feedback. Follow us @wildpackets © WildPackets, Inc. www.wildpackets.com
  • 41. WildPackets Corporate Overview Optimizing Network and Application Performance © WildPackets, Inc. www.wildpackets.com
  • 42. Corporate Background • Experts in network monitoring, analysis, and troubleshooting ‒ Founded: 1990 / Headquarters: Walnut Creek, CA ‒ Offices throughout the US, EMEA, and APAC • Customers spanning leading edge organizations ‒ Mid-market and enterprise lines of business ‒ Financial, manufacturing, ISPs, major federal agencies, state and local governments, universities ‒ Over 7,000 customers / 60+ countries / 80% of Fortune 1,000 • Award-winning solutions that improve network performance ‒ Internet Telephony, Network Magazine, Network Computing awards ‒ United States Patent 5,787,253 issued July 28, 1998 • “Apparatus and Method of Analyzing Internet Activity” #wp_highspeed © WildPackets, Inc.
  • 43. Why Our Customers Need Us • VoIP, video, cloud, virtualization, and key business applications are saturating critical network services • Evolving network technologies create discontinuities ‒ 1 Gig  10 Gig  40 Gig  100 Gig networks ‒ Wireless, BYOD initiatives • Users and business can not tolerate network problems for mission critical services Increasing demand for better real-time network visibility, network analytics, network forensics, and DPI #wp_highspeed © WildPackets, Inc.
  • 44. How We Create Value We provide innovative, industry-leading, real-time network performance management solutions ‒ Easy-to-use, easy-to-learn user interface ‒ Uniquely extensible solutions ‒ Wireless network leadership ‒ Detailed analytics related to network applications ‒ Fastest network traffic capture appliance in its class ‒ Technical superiority at competitive price point WildPackets has continually advanced its solution to meet the needs of its customers #wp_highspeed © WildPackets, Inc.
  • 45. Unprecedented Network Visibility NETWORK HEALTH GLOBAL WatchPoint can manage and report on key device performance and availability across the entire network, from anywhere on the network. UNDERSTAND END-USER PERFORMANCE TimeLine and Omnipliance network recorders monitor DISTRIBUTED and analyze performance across critical network segments, virtual environments, and remote sites. PINPOINT NETWORK ISSUES ANYWHERE Omnipliance Portable can rapidly identify and troubleshoot PORTABLE issues before they become major problems—wired or wireless—down the hall or across the globe. ROOT-CAUSE ANALYSIS OmniPeek network analyzer performs deep packet inspection DPI and can reconstruct all network activity, including e-mail and IM, as well as analyze VoIP and video traffic quality. #wp_highspeed © WildPackets, Inc.
  • 46. A History of Innovation 2001 2005 2009 2011 • First 802.11 Combined distributed Innovative dashboard • Total visibility with wireless analyzer network and VoIP with drill-down for VoIP zero packet loss • First network network analysis and video • First wireless analyzer with network analyzer to automated expert support capture and analysis analysis of 802.11n 3-stream wireless 2003 2008 2010 2012 Distributed real-time Enterprise-wide First to achieve 11 Gbps • Capture, record, and troubleshooting Monitoring and Reporting sustained capture-to-disk analyze from 40G network segments • First wireless network analyzer to support 801.11ac, k, r, u, v, w #wp_highspeed © WildPackets, Inc.
  • 47. Product Line Overview © WildPackets, Inc. www.wildpackets.com
  • 48. Omni Distributed Analysis Platform OmniPeek Enterprise Packet Capture, Decode and Analysis • Ethernet,1/10 Gigabit, 802.11, and voice and video over IP • Portable capture and OmniEngine console • Aggregate analysis data across multiple capture points Omnipliance / TimeLine Distributed Enterprise Network Forensics • High-performance packet capture and real-time analysis • Stream-to-disk for forensics analysis • Integrated OmniAdapter network analysis cards up to 40G WatchPoint Centralized Enterprise Network Monitoring Appliance • Aggregation and graphical display of network data • WildPackets OmniEngines • NetFlow and sFlow #wp_highspeed © WildPackets, Inc.
  • 49. Omni Distributed Analysis Platform Software and Turnkey Solutions • Enterprise monitoring and reporting ‒ WatchPoint Server ‒ OmniFlow, NetFlow, and sFlow Collectors • Software probes and network recorders ‒ Omnipliance network recorders – Edge, Core ‒ TimeLine network recorders ‒ OmniAdapter analysis cards • Distributed analysis software ‒ OmniPeek – Enterprise, Professional, Basic, Connect ‒ OmniEngine – Enterprise, Desktop, OmniVirtual • Portable solutions ‒ OmniPeek network analyzer ‒ Omnipliance Portable #wp_highspeed © WildPackets, Inc.
  • 50. Key New Features in v7 • 40G network support • Analyze issues from end to end: Multi-Segment Analysis (MSA) • Collect data from non-technical end users: OmniPeek Remote Assistant (ORA) • Single, interactive dashboard for utilization, top talkers, top protocols, latency, Experts, flows, and wireless signal strength • New wireless specifications ‒ 802.11ac 802.11k ‒ 802.11r 802.11u ‒ 802.11v 802.11w #wp_highspeed © WildPackets, Inc.
  • 51. OmniPeek Network Analyzer • Distributed analysis manager – Connect to and configure distributed OmniEngines, Omnipliances, and TimeLines • Comprehensive dashboards present network traffic in real-time – Vital statistics and graphs display trends on network and application performance – Visual peer-map shows conversations and protocols – Intuitive drill-down for root-cause analysis of performance bottlenecks • Visual Expert diagnosis speeds problem resolution – Packet and payload visualizers provide business-centric views • Automated analytics and problem detection 24/7 – Easily create filters, triggers, scripting, advanced alarms, and alerts #wp_highspeed © WildPackets, Inc.
  • 52. Omnipliance Network Recorders • Captures and analyzes all network traffic 24x7 – Runs WildPackets OmniEngine software probe – Generates vital statistics on network and application performance – Intuitive root-cause analysis of performance bottlenecks • Expert analysis speeds problem resolution – Fault analysis, statistical analysis, and independent notification • Multiple issue digital forensics – Real-time and post capture data mining for compliance and troubleshooting • Intelligent data transport – Network data analyzed locally – Detailed analysis passed to OmniPeek on demand – Summary statistics sent to WatchPoint for long term trending and reporting – Efficient use of network bandwidth • User-extensible platform – Plug-in architecture and SDK #wp_highspeed © WildPackets, Inc.
  • 53. TimeLine Network Recorder • Continuous network recording and comprehensive real-time statistical display — simultaneously ‒ 12Gbps sustained capture with zero packet loss ‒ Network statistics display in TimeLine visualization format • Rapid, intuitive forensics search and retrieval ‒ Historical network traffic analysis and quick data rewinding ‒ Several pre-defined forensics search templates making searches easy and fast • A natural extension to the WildPackets product line • Turnkey bundled solution ‒ Appliance + OmniEngine, OmniAdapter, OmniPeek Connect #wp_highspeed © WildPackets, Inc.
  • 54. WildPackets Network Recorders Price/Performance Solutions for Every Application Portable Edge Core TimeLine Ruggedized Small Networks Datacenter Workhorse Enterprise, Highly- Troubleshooting Remote Offices Easily Expandable Utilized Networks Aluminum chassis / 17” LCD 1U rack mountable chassis 3U rack mountable chassis 3U rack mountable chassis Dual 2.13 GHz Quad-Core Intel Quad-Core Intel Xeon X3460 Dual Intel Xeon Quad Core Dual Intel Xeon Quad Core Xeon L5630 "Westmere" 2.80Ghz E5530 2.4GHz X5560 2.8GHz 24GB RAM 4GB RAM 6GB RAM 18GB RAM 2 PCI-E Slots 2 PCI-E Slots 4 PCI-E Slots 4 PCI-E Slots 2 Built-in Ethernet Ports 2 Built-in Ethernet Ports 2 Built-in Ethernet Ports 2 Built-in Ethernet Ports 6TB SATA storage capacity 1TB SATA storage capacity 8/16TB SATA 8/16/32/48TB SATA storage capacity storage capacity 4.5Gbps CTD 1.1Gbps CTD 3Gbps CTD 12Gbps CTD #wp_highspeed © WildPackets, Inc.
  • 55. WatchPoint Centralized Monitoring for Distributed Enterprise Networks • High-level, aggregated view of all network segments – Monitor per campus, per region, per country • Wide range of network data – NetFlow, sFlow, OmniFlow • Web-based, customizable network dashboards • Flexible detailed reports • Direct link to detailed, packet-based analysis #wp_highspeed © WildPackets, Inc.
  • 56. Comprehensive Support and Services Standard Support Premier Support  Maintenance and upgrades  24 x 7 x 365  Telephone and email contacts  Dedicated escalation manager  Knowledgebase  2 customer contacts per site  MyPeek Portal  Plug-in reconfiguration assistance WildPackets Training Academy  Public, web-based, and on-site classes  Complete curriculum: technology and product focused  Practical applications and labs covering network analysis, wireless, VoIP monitoring and advanced troubleshooting Consulting and Custom Development Services  Deployment, configuration, and assessment engagement  Systems integration and testing  Application integration, driver, decode, interface development #wp_highspeed © WildPackets, Inc.
  • 57. WildPackets Key Differentiators • Visual Expert intelligence with intuitive drill-down – Let computer do the hard work, and return results, real-time – Packet /payload visualization is faster than packet-per-packet diagnostics – Experts and analytics can be memorized and automated • Automated capture analytics – Filters, triggers, scripting, and advanced alarming system combine to provide automated network problem detection 24x7 • Multiple issue network forensics – Can be tracked by one or more people simultaneously – Real-time or post capture • User-extensible platform – Plug-in architecture and SDK • Aggregated network views and reporting – NetFlow, sFlow, and OmniFlow #wp_highspeed © WildPackets, Inc.
  • 58. 24x7 Network Monitoring, Analysis, and Troubleshooting #wp_highspeed © WildPackets, Inc.
  • 59. Thank You! WildPackets, Inc. 1340 Treat Boulevard, Suite 500 Walnut Creek, CA 94597 (925) 937-3200 © WildPackets, Inc. www.wildpackets.com