Re: [IPFIX] WG Last Call for draft-ietf-ipfix-information-model-rfc5102bis-05.txt

Brian Trammell <[email protected]>
Newsgroups gmane.ietf.ipfix
Message-ID <[email protected]>
Hi, Paul,

On 1 Nov 2012, at 12:16, Paul Aitken <[email protected]> wrote:

>> If your implementation allows loss between the MP and the EP, there is nothing conceptually different between this situation and loss between the EP and the CP, except you can't use wireshark to debug it. :)
> 
> The MP has no knowledge of what happens to the data it produces, so the infomodel definitions simply can't be expressed in export terms.
> 
> eg, suppose traffic from a first level cache is aggregated into a second level cache. Although traffic isn't "exported" per se, we want the delta counters to begin from zero next time around.
> (Even if this isn't strict IPFIX, the caches are using the IPFIX infomodel, and 5102bis recognises this as valid: "the model is defined in an open way that easily allows using it in other protocols, interfaces, and applications.")
> 
> The point is that the definitions have to work for other potential uses of the infomodel.

Good point. Which means any definition should be even more removed from the cache.

>>> Just the same as when the flow *is* exported. So the definition of deltaCount is independent of export, flow records, etc.
>>> 
>>> So the definitions have to be about the metering time, and particularly that we've started metering again. However, we can't write that, because some implementations may not hold state that tells them this. So all we know is that totalCounters meter from the start of the MP, while delta counters meter a potentially shorter interval, reporting the value metered since the start of that interval.
>> I've stared at this for a while and I can't come up with a way to express it that's unconvoluted enough for my taste. I still don't see why my last attempt at a definition above necessarily invokes export -- it's the MP sending on the information in a proto-Flow Record to the EP and deciding to start the counters over. So I suppose for the corner case that the MP sends something up to the EP and the EP drops it we could complicate the language a bit:
>> 
>> A delta counter counts only observations made since the previous Flow Record for a given Flow, as seen from the point of view of the Metering Process (i.e., discounting any failure or refusal to export the Flow Record on the part of the Exporting Process or failure to receive the Flow Record on the part of the Collecting Process).
>> 
>> although truth be told I think this overly complicated and unreadable for the magnitude of the corner case it addresses. Maybe without the i.e. phrase?
> 
> Agreed; this is just too cumbersome.
> 
> So since MPs generate Flow Records, your earlier definition seems to be best, except that there may not have been any previous Flow Record.
> 
> So, how about "A delta counter only counts observations made since the previous Flow Record (if any) for a given Flow."\


This works for me.

Cheers,

Brian

_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.