How to Boost Network Monitoring Tool Efficiency
February 07, 2019

Alastair Hartrup
Network Critical

Share this

Having the right tools and good visibility are critical to understanding what's going on in your network and applications. However, as networks become more complex and hybrid in nature, organizations can no longer afford to be reactive and rely only on portable diagnostic tools. They need real-time, comprehensive visibility.

To accomplish this, more and more organizations are deploying network monitoring platforms and solutions that utilize TAPs (Terminal Access Points) and Packet Brokers to permanently establish network links and gather critical performance data. These technologies provide maximum utilization of connected tools for IT teams looking for comprehensive monitoring and management in, for example, a Network Performance Monitoring and Diagnostics (NPMD) platform.

Why are TAPs so important? Network TAPs are stand-alone devices that make a mirror copy of all of the traffic that flows between two network end-points (or nodes). This can then be output to various network tools, while the live traffic continues to pass through the network. Because they are independent of the network, they're fully configurable. This allows complex packet manipulation to be performed by network performance (or security) solutions.

Packet Brokers take the technology a step further and allow for the combination, integration, separation, manipulation and processing of inputs from many sources (including TAPs), and then deliver that data to a wide variety of appliance, platform and tool destinations. 

Both play a major role in providing the data necessary for real-time, comprehensive network visibility.

Monitoring tools such as sniffers, probes and NPMD solutions can be permanently and safely installed on all network links using TAPs. They connect in-line on a network link, making a mirror copy of all network traffic and then forward that information directly to a monitoring tool (or Packet Broker). TAPs are also extremely safe – if power is lost, the network traffic will continue to flow. For more complex networks with a variety of connected tools, Packet Brokers are used with TAPs.

What are some of the key features that organizations should look for when deploying TAPs and Packet Brokers? Here are three key features to consider:

1. Flexible Port Mapping

Flexible port mapping allows the user to choose which ports the packets will travel through with no preset requirements. Packets may come in from the network, go back out to the network and also be directed to a connected monitoring tool. Some TAPs require certain ports be used for network traffic and others to be used to support monitoring tools. Flexible Port Mapping allows any port to be utilized for any type of traffic. This eliminates the need to buy a bigger system than necessary just because one type of port is maxed out, while other ports are open and unused. It also makes it simpler to add links and tools when any open port can be utilized for a tool or network access at any time. Not all TAPs and Packet Brokers offer this "scale out" flexibility.

2. Easy Aggregation

Aggregation is the combining of traffic from multiple links and sending that traffic to one specific tool. Often, links are underutilized. A 10 Gbps link, for example, may actually be carrying only 4 Gbps of actual traffic.

Understanding the actual traffic on links and aggregating underutilized links to a single TAP or Packet Broker port can provide dramatic savings on monitoring tools. Doing the math, aggregating five links running at 2 Gbps to a single 10 Gbps output port connected to one monitoring tool can reduce the tool budget by a factor of five.

Imagine the savings opportunity in a large complex network. Using this strategy on hundreds of links, organizations can save hundreds of thousands of dollars.

3. Independent Filtering

Independent filtering eliminates traffic that is not relevant to the mission of the connected monitoring tool. It helps tools run faster, more efficiently and allows them to monitor more links.

Hierarchical filtering is the traditional way that filtering is designed. This can be very complicated and prone to network affecting errors. If packets are filtered out at the top of the list, they cannot be re-introduced later.

Independent fast filtering allows filter maps to be created quickly without consequence to other filters further down the list. Independent filtering is faster and more accurate than hierarchical filtering. Look for TAPs or Packet Brokers that allow you to created multiple filters quickly on any stream with no need to distinguish between ingress and egress ports (and be sure you can create filter criteria with ranges and individual criteria).

When independent filtering is combined with aggregation, packets are filtered out of streams, allowing a higher aggregation ratio of links being sent to a monitoring tool. This means that independent filtering not only helps save OPEX by allowing faster, more accurate tool deployment, it also saves CAPEX by enhancing the link to tool aggregation ratio.

When looking to deploy or optimize your network monitoring solutions, consider the impact of strategically deploying network TAPs and Packet Brokers. Be sure you're using the aforementioned features, as they can offer significant tool cost savings and allow for a more efficient network monitoring solution.

Alastair Hartrup is CEO of Network Critical
Share this

The Latest

April 21, 2021

Few tools provide early detection of mission-critical mail outages. On March 15, Microsoft had a service outage worldwide that impacted its services such as Teams AV, Yammer, OneDrive, and Azure Active Directory. Users reported not being able to login into either of these services and were getting timeout messages ...

April 20, 2021

More than half (60%) of IT organizations are investing in improving employee experience to support remote workforce productivity and performance according to The Changing Role of the IT Leader study by Elastic ...

April 19, 2021

Why are CDNs becoming more important to so many businesses? And how will they handle the new applications coming out over the next few years? APMdigest sat down with Mehdi Daoudi, CEO and co-founder of Catchpoint Systems, to find out ...

April 15, 2021

A growing need for process automation as a result of the confluence of digital transformation initiatives with the remote/hybrid work policies brought on by the pandemic was uncovered by an independent survey of over 500 IT Operations, DevOps, and Site Reliability Engineering (SRE) professionals commissioned by Transposit for its inaugural State of DevOps Automation Report ...

April 14, 2021

As the Covid-19 pandemic forces a global reset of how we gather and work, 60% of organizations are looking forward to increased spending in 2021 to deploy new technologies, according to the 14th annual State of the Network global study of enterprise networking and security challenges released by VIAVI Solutions ...

April 13, 2021

Complexity breaks correlation. Intelligence brings cohesion. This simple principle is what makes real-time asset intelligence a must-have for AIOps that is meant to diffuse complexity. To further create a context for the user, it is critical to understand service dependencies and correlate alerts across the stack to resolve incidents ...

April 12, 2021

We're all familiar with the process of QA within the software development cycle. Developers build a product and send it to QA engineers, who test and bless it before pushing it into the world. After release, a different team of SREs with their own toolset then monitor for issues and bugs. Now, a new level of customer expectations for speed and reliability have pushed businesses further toward delivering rapid product iterations and innovations to keep up with customer demands. This leaves little time to run the traditional development process ...

April 08, 2021

On Wednesday January 27, 2021, Microsoft Office 365 experienced an outage affected a number of its services with a prolonged outage affecting Exchange Online. Despite Microsoft indicating that it was just Exchange Online affected during this outage, some monitoring tools detected that Azure Active Directory and dependent services like SharePoint and OneDrive were also affected at the time. The outage information indicated a rollout and rollback but we wouldn't expect to see such a widescale outage and slowdown just affecting some of the schema unless everything had to be taken offline ...

April 07, 2021

Application availability depends on the availability of other elements in a system, for example, network, server, operating system and so on, which support the application. Concentrating solely on the availability of any one block will not produce optimum availability of the application for the end user ...

April 06, 2021

A hybrid work environment will persist after the pandemic recedes, with over 80% stating that they expect over a quarter of workers to remain remote, and over two-thirds desiring flexibility between on-premises and remote deployments according to the 2021 State of the WAN report released by Aryaka ...