EP2058736A2

Systems and methods for flow monitoring and sampling using flow identifiers

Abstract

A network device may include logic configured to receive a packet from a packet forwarding engine, create a flow ID for the packet, determine whether the flow ID matches one of a plurality of flow IDs in a table, determine whether the packet is associated with a flow to be sampled, sample the packet and additional packets associated with the flow that are received from the packet forwarding engine when the flow is to be sampled and transmit the flow ID and the sampled packets via a switch to an interface.

EP2058736A2, drawing sheet 1
Sheet 1 of 9

Term

Projected expiry 5 November 2028.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

20 claims: 8 independent, 12 dependent

  1. 1
    A network device comprising:a plurality of interfaces connected via an interconnect;where each interface includes: a packet forwarding engine (PFE);a switch;and logic configured to: receive a packet from the PFE;create a flow ID for the packet;determine whether the flow ID matches one of a plurality of flow IDs in a table;determine whether the packet is associated with a flow to be sampled;sample the packet and additional packets associated with the flow that are received from the PFE when the flow is to be sampled;and transmit the flow ID and the sampled packets via the switch to another interface.
  2. 10
    A method comprising:creating a flow ID for each packet received from a packet forwarding engine (PFE);updating a table of flow IDs with the created flow IDs for each of the received packets;determining from the table of flow IDs if packets associated with a flow ID are to be sampled;sampling packets associated with the flow ID when it is determined that packets associated with a flow ID are to be sampled;and sending the sampled packets to an interface via an Ethernet switch.
  3. 14
    The method of any one of claims 10 to 13, further comprising:randomly sampling packets associated with one of the flow IDs stored in the table.
  4. 15
    The method of any one of claims 10 to 14, further comprising:counting and storing in the table of flow IDs a number of packets or bytes associated with one of the flow IDs.
  5. 16
    The method of any one of claims 10 to 15, further comprising:determining when the table of flow IDs is full.
  6. 18
    The method of any one of claims 10 to 17, where the table of flow IDs includes:a source address field, a destination address field, a packet or byte count field and a sample field.
  7. 19
    The method of any one of claims 10 to 18, further including:sampling a first N packets of a flow when the created flow ID does not match one of the flow IDs stored in the table.
  8. 20
    A network device comprising:means for receiving packets;means for creating flow IDs based on the received packets;means for storing a table of the created flow IDs;means for determining from the table of created flow IDs whether to sample the received packets;means for sampling the received packets when it is determined when it is determined to sample the received packets;means for determining from the table of created flow IDs when to transmit one of the created flow IDs;and means for transmitting the sampled received packets and the determined flow IDs to a switch.