Re: [IPFIX] WG Last Call for draft-ietf-ipfix-information-model-rfc5102bis-05.txt

Paul Aitken <[email protected]>
Newsgroups gmane.ietf.ipfix
Message-ID <[email protected]>
Brian,

>>> What verb does the MP apply to a unit of information when it gives it to the EP?
>>>
>>> A delta counter counts only observations made since the last Flow Record for a given Flow was measured.
>>>
>>> Or maybe we can sidestep the action completely:
>>>
>>> A delta counter counts only observations made since the previous Flow Record for a given Flow.
>> No, that's still involving export.
>>
>> What should the MP do if the flow ends *but isn't exported* ?
> In the idealized architecture, the MP can't know, so it just keeps exporting, clearly.

NB the MP doesn't export. As you say, I don't think we have any verb for 
the MP -> EP handoff.


> If your implementation allows loss between the MP and the EP, there is nothing conceptually different between this situation and loss between the EP and the CP, except you can't use wireshark to debug it. :)

The MP has no knowledge of what happens to the data it produces, so the 
infomodel definitions simply can't be expressed in export terms.

eg, suppose traffic from a first level cache is aggregated into a second 
level cache. Although traffic isn't "exported" per se, we want the delta 
counters to begin from zero next time around.
(Even if this isn't strict IPFIX, the caches are using the IPFIX 
infomodel, and 5102bis recognises this as valid: "the model is defined 
in an open way that easily allows using it in other protocols, 
interfaces, and applications.")

The point is that the definitions have to work for other potential uses 
of the infomodel.


>> Just the same as when the flow *is* exported. So the definition of deltaCount is independent of export, flow records, etc.
>>
>> So the definitions have to be about the metering time, and particularly that we've started metering again. However, we can't write that, because some implementations may not hold state that tells them this. So all we know is that totalCounters meter from the start of the MP, while delta counters meter a potentially shorter interval, reporting the value metered since the start of that interval.
> I've stared at this for a while and I can't come up with a way to express it that's unconvoluted enough for my taste. I still don't see why my last attempt at a definition above necessarily invokes export -- it's the MP sending on the information in a proto-Flow Record to the EP and deciding to start the counters over. So I suppose for the corner case that the MP sends something up to the EP and the EP drops it we could complicate the language a bit:
>
> A delta counter counts only observations made since the previous Flow Record for a given Flow, as seen from the point of view of the Metering Process (i.e., discounting any failure or refusal to export the Flow Record on the part of the Exporting Process or failure to receive the Flow Record on the part of the Collecting Process).
>
> although truth be told I think this overly complicated and unreadable for the magnitude of the corner case it addresses. Maybe without the i.e. phrase?

Agreed; this is just too cumbersome.

So since MPs generate Flow Records, your earlier definition seems to be 
best, except that there may not have been any previous Flow Record.

So, how about "A delta counter only counts observations made since the 
previous Flow Record (if any) for a given Flow."


P.
_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.