Netflow cc 20060426

From GEANT2-JRA1 Wiki

JRA1 Flow Monitoring - conference call agenda and minutes

Contents

Info

Date/time: 26th April 2006, 14:00 CET

Expected time of conference call: 90 minutes

Proposed agenda

  1. Review of the action plan from the last meeting
  2. Discussion on overall tool testing report, final decision proposal
  3. Action plan for next period
  4. Y3 planning: lack of manpower? (Nicolas to join conference call at 14:50)
  5. AOB

Minutes

Attendees: Hans Trompert (HT), Jan Van Oorschot (JVO), Alessandro Inzerilli (AI), Jon Kare Hellen (JH), Arne Øslebø (AO), Maurizio Molina (MM), Silvije Milisic (SM), Danijel Matek (DM), Igor Velimirovic (IV)
Joined the conference for topic No. 4: Nicolas Simar (NS)


  1. The minutes from the last meeting in Berlin were reviewed. Action plan from that document also reviewed and confirmed. So far all tasks are going on according to the time plan. HT pointed that task which consists of 3 parts (netflow subscription service + anonymization + encryption) should be splitted in smaller parts, and some more partners should be included. For now, CARNet will take part of anonymization task (testing the LOBSTER anonymization tool) and GARR will join the same task (evaluating CRYPTO-PAn anonymization module). For other two parts we are still missing some man power to support Surfnet.
  2. The draft version of 'Tools evaluation report' was discussed. Several point were decided:
    • support netflow v.9 is strong requirement, and tools that do not support netflow v.9 are eliminated
    • Replaying functionality: there is difference between duplicating netflow streams (possible using UDP samplicator) and replaying (resending) specific extract of netflow data (specific flow, specific period, etc.) which can be provided by some collector tools. Therefore, both methods of replaying netflow data should be investigated.
    • Anonymization functionality is supported in some tools, and there are also some stand alone anonymization tools (LOBSTER anonymization tool). This functionality should not be decisive requirement in tools evaluation.
    • Conclusion of tools evaluation process is that nfdump is a netflow collector tool that fulfills all requirements, and that it is a best tool among tested ones. Therefore, we choose nfdump as a standard collector tool for netflow infrastructure within JRA1.
    • Evaluation of visualisation tools for netflow data should be lounched. Tool candidates: STAGER and nfsen
  3. For the next period action plan is discussed (see 'actions' below). Next conference call will be scheduled for week 20 or 21.
  4. NS joined the conference to discuss Y3 planning for netflow task. There is at the moment a lack of manpower (see e-mail from NS). There is a proposal that missing manpower will be assigned to Uninett (about 1,5 MM) and GARR (about 2 MM). Details will be discussed among those partners and NS.
  5. In general discussion some points have been made about Measurement Archive (MA) implementation. The outcome of the discussion was that some more work is needed in order to specify a specific model that wil be implemented in JRA1. For now, there are several initiatives and ideas:
    • AO plans to build a MA upon STAGER tool (he will send general idea and list of metrics that this MA will provide to the group by e-mail)
    • On Berlin meeting 'netflow subscription service' concept was presented, which will enable the user to subscribe to a specific netflow data export. Also, RRD-based netflow MA become part of the action plan.
    • concept of 'perfSONAR netflow MA' was also mentioned; in this model MA is built upon a collector tool directly, enabling different collector tools to be used as a back-end. This model can be similar to the 'RRD MA' if collector tool can provide RRD data as output, but also can use netflow data from collector in other formats (files, database, ...). Therefore, this model is more general than 'RRD MA', but in implementation can be almost the same.

Actions

  • CARNet to test/evaluate new version of LOBSTER anonymization tool
  • GARR to test/evaluate CRIPTO-PAn anonymization module
  • All partners: use nfdump for further testing/implementation
  • IV to prepare tools evaluation guidelines for visualisation tools; AI will start to evaluate nfsen, other parnes will join.
  • IV to finish tools evaluation report; all partners can send their comments/additions/proposals
  • GARR and Uninett to discuss with NS additional manpower to be asigned for work on JRA1 flow measurement task.
  • AO to send some more details about STAGER development (main idea of MA implementation, list of metrics that MA will provide, etc.) to all partners by e-mail
  • IV and all partners: evaluate all presented ideas of MA design, and start discussion on mailing list

Next conference call will be announced for week 20 or 21.

Conference call details

DFN Gatekeeper - Voice (IP and PSTN) and Video

Gatekeeper: pgk.vc.dfn.de (for non-GDS members)

Voice and Video: The numbers to dial are for H.323: GDS dialstring: 004910091212314***4522

To connect by phone, see: https://www.vc.dfn.de/doku/anleitungen/isdn_gateway.html?lang=en The dialstring here is also 004910091212314***4522.

Note: you can´t use it with NAT, unless you use a NAT proxy.


Back to Flow monitoring

Personal tools