Title: TUNDRA The Ultimate Netflow Data Realtime Analysis
1TUNDRAThe Ultimate Netflow Data Realtime
Analysis
- Jeffrey Papen
- Yahoo! Inc.
2TUNDRA Features
- Source and Destination AS bandwidth analysis
- Transit AS bandwidth analysis
- Custom AS macros Bandwidth forecasting, peering
merit analysis - Billing Formulas for cost/ benefit budget
analysis
- Analyze usage for local servers or services
- Charge Back Billing - Symmetric Network Performance Analysis latency
and packet loss - AS path hop count stats
- DOS attack detection
- All in Real Time
3Why should you care about TUNDRA?
- Empirical Data
- Prove that network performance increases
- Prove that network reliability increases as AS
hops decrease - Cost/Savings analysis for new peer or transit
- Know how much bandwidth a peer will use before
(or after) you turn link up determine private
vs. public peering need - Focus and Order peer hit list who should you go
after? - Business case to document support for peers that
say No.
4Why Call It TUNDRA?
5Zebra Server
Router
SNMP Poller
Collector/ Processor
6Flow Data TUNDRA Displays
Inbound Outbound Transit
AS Bandwidth X X X
Port X X
Protocol X X
Server (IP) X X
AS Path X
7Port Out
8Protocol Out
9Bandwidth Out
10Transit Data
All outbound flows have destination IP Each
Destination Subnet learns AS path from Zebra BGP
table - AS padding
removed Zebra BGP table is identical to actual
routes used on local router(s) Local BGP data
reflects immediate policy changes with no
performance impact or security threat to
production routers
11Destination vs. Transit Traffic UUNet
12AS Hop Count Table
AS Path Hop Count Router 1 Router 2
0 (Yahoo!) 0 0
1 (Peering ISP) 0.34715 0.10148
2 15.54806 12.42353
3 46.64506 45.17018
4 27.75107 31.07077
5 7.69483 8.94431
6 1.88979 2.18044
7 0.12290 0.10870
8 0.00004 0.00000
9 0.00109 0.00061
13Performance Analysis
- ICMP Ping vs. TCP packet with bogus SYN/ACK
- Testing is done from your networks perspective
- Route-Maps on collector interface
- Simultaneous testing of multiple paths to same
target AS - No continuous IBGP flapping from /32 updates
- No adding and removing /32 static routes
- No 3rd party remote applications logging onto
routers - Looking Glass server (www) for troubleshooting
14TUNDRA Next Steps
- White Paper No, I really mean it!
- Im looking for help this is a hobby, not my
job - Maintainers to finish baking code and
configuration - Release to Internet community
- Licensing is GPL please peer with Yahoo! ?
15Questions?
Jeffrey Papen jpapen_at_yahoo-inc.com
jeffrey_at_papen.com