Napatech

Napatech

Flow Analysis

Flow Analysis systems perform network analysis of traffic between different network endpoints. It can be different "physical" endpoints like IP addresses or it can be application endpoints like traffic between a PC web browser and a web server.
Network Flow Analysis, e.g. VoIP flow
Network Flow Analysis, e.g. VoIP flow
Recognition of flows is supported by Napatech Network Adapter functions, such as:
  • Frame Decoder: Recognizes IP, UDP, TCP, payload, flows and encapsulations. Even when frames are ISL-, VLAN- and/or MPLS-encapsulated, they will be recognized by the Frame Decoder.
  • Hash Key Generation: 2-tuple hash keys will identify IP-to-IP flows, 5-tuple hash keys will identify application-to-application flows, GTP hash keys will identify a mobile conversation flow.
  • Coloring/Tagging:  Adds tags to frames depending on the frame type.

Flow analysis will sometimes be limited to analysis of specific types of traffic, e.g. VoIP traffic, IPTV traffic or web traffic. Such analysis of specific traffic types is supported by the Napatech Network Adapter Frame Decoder and Filtering functionality.

Frame timing information (64-bit), flow identification (31-bit hash key) and tagging information can be prepended to the captured frames and be used by the application to accelerate the processing of the network data.

The hash keys can also be used to distribute the captured network data to multiple host buffers where the captured frames can be handled by up to 32 CPU cores. The hash keys ensure that the same flows are always delivered to the same CPU core, whereby the CPU cache performance is greatly improved.

Additional Information

Highlights:
  • Flows recognized by adapter 
  • Captures only relevant frames
  • Multi-CPU core support
  • NUMA support

See Also:
© Napatech A/S, all rights reserved. Terms & Conditions