Re: [IPFIX] clarification questions

Gerhard Muenz <[email protected]>
Newsgroups gmane.ietf.ipfix
Message-ID <[email protected]>
Hi Ramki,

In your own implementation, you can use whatever parameter you want. 
Regarding the standard configuration data model, I do not think that an 
exportInterval parameter should be added to TimeoutCache and 
NaturalCache. This would change the meaning of TimeoutCache and 
NaturalCache as described in RFC 6728.

Regards,
Gerhard


On 28.03.2013 22:06, ramki Krishnan wrote:
>
> Hi Gerhard,
>
> Thanks a lot. More below.
>
> >>- With TimeoutCache and NaturalCache, the Flow is only exported when 
> it is expired. At expiration, the Flow is immediately removed from the 
> Cache. A longlasting flow will result in a new Flow being created in 
> the Cache.
>
> For applications, especially security, it would be worthwhile to 
> periodically export the flow for monitoring purposes. We could add an 
> optional "exportInterval" parameter similar to PermanentCache for 
> this. Your comments/thoughts would be appreciated.
>
> Hi Gerhard/All,
>
> >>It seems that your actual question is how flow selection fits into 
> the IPFIX device architecture which has been taken as a basis for RFC 
> 6728. Concretely, you seem to wonder  whether your flow selection is a 
> kind of Selection Process or a new kind of Cache (or maybe both?).
>
> The new data models I am trying to specify are based on the following 
> draft and presentation at the IETF Orlando meeting.  It seems to me 
> that a good starting point is specifying a new flow selection process. 
> Your comments/thoughts would be appreciated.
>
> http://www.ietf.org/proceedings/86/slides/slides-86-ipfix-1.pptx
>
> http://datatracker.ietf.org/doc/draft-krishnan-ipfix-flow-aware-packet-sampling/
>
> Thanks,
>
> Ramki
>
> *From:*Gerhard Muenz [mailto:[email protected]]
> *Sent:* Wednesday, March 27, 2013 2:22 PM
> *To:* ramki Krishnan
> *Cc:* IPFIX Working Group; Ning So
> *Subject:* Re: [IPFIX] clarification questions
>
>
> Hi Ram,
>
> The configuration model of RFC 6728 does not cover flow selection. If 
> you want to configure something like flow selection, you need to 
> extend the model.
>
> It seems that your actual question is how flow selection fits into the 
> IPFIX device architecture which has been taken as a basis for RFC 
> 6728. Concretely, you seem to wonder  whether your flow selection is a 
> kind of Selection Process or a new kind of Cache (or maybe both?).
>
> I cannot answer this question because I do not know how it would be 
> implemented.
>
> Regarding your question:
> - With TimeoutCache and NaturalCache, the Flow is only exported when 
> it is expired. At expiration, the Flow is immediately removed from the 
> Cache. A longlasting flow will result in a new Flow being created in 
> the Cache.
> - It's different with PermanentCache. Here, the Flow remains in the 
> Cache, and the status is periodically exported.
>
> Regards,
> Gerhard
>
> On 27.03.2013 18:40, ramki Krishnan wrote:
>
>     Dear IPFIX experts,
>
>     From RFC 6728,
>
>     1.Section 4.3.2
>
>     oIs there a way to periodically export the flows if we are using a
>     TimeoutCache or NaturalCache ?
>
>     2.Suppose we want to populate the cache only with long-lived large
>     flows (see Note1  below for data model definitions)
>
>     oOne way to achieve this would be to have a selection process,
>     using a unique observation domain, which filters the long-lived
>     large flows. Are any other better ways ?
>
>     3.Continuing from 3) - suppose we want to sample the other flows
>     (not the long-lived large flows)
>
>     oIs there a way to not include the long-lived large flows in the
>     selection process ?
>
>     Note 1:
>
>     -observationInterval: The minimum time interval to observe a flow
>     for performing further processing of the flow. Unit is in seconds.
>
>     -bandwidthThreshold: The minimum bandwidth of the flow during the
>     observation interval for declaring the flow a long-lived large
>     flow. Unit is in Mbps.
>
>     For example, a flow which is at or above 10 Mbps
>     (bandwidthThreshold )for a time period of at least 30 seconds
>     (observationInterval) could be declared a long-lived large flow.
>
>     --
>
>     Thanks,
>
>     Ram (aka Ramki)
>
>
>
>
>     _______________________________________________
>
>     IPFIX mailing list
>
>     [email protected]  <mailto:[email protected]>
>
>     https://www.ietf.org/mailman/listinfo/ipfix
>

_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.