introducing endace packets - endacevision™ with protocol decodes

34
Emulex Confidential - © 2013 Emulex Corporation EndaceVision with Packet Decodes An Introduction to Endace Packets Jim MacLeod – Senior Product Manager, Emulex

Upload: emulex-corporation

Post on 17-Jan-2015

578 views

Category:

Technology


1 download

DESCRIPTION

Join Jim MacLeod, Senior Product Manager at Emulex, for an interactive webinar where you'll learn how the combination of Endace Packets and EndaceVision can help troubleshoot your hardest 10GbE network problems.

TRANSCRIPT

Page 1: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

Emulex Confidential - © 2013 Emulex Corporation

EndaceVision with Packet DecodesAn Introduction to Endace Packets

Jim MacLeod – Senior Product Manager, Emulex

Page 2: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

2 Emulex Confidential - © 2013 Emulex Corporation

Introduction

Jim MacLeod– Senior Product Manager, Emulex– 15 years experience in monitoring– Product Manager for EndaceVision

Endace – Emulex product line – World leader in network recording– 10 years selling network visibility

Page 3: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

3 Emulex Confidential - © 2013 Emulex Corporation

Changing Nature of Networks

Rapid shift to 10GbE – 40 and 100GbE adoption coming

Increasing complexity– Consolidation– Virtualization

Greater reliance on network– Virtual Desktop– Unified Communications

More compliance & regulation– Business and customer data– Scope of data at rest

Lower tolerance to downtime…– Cost measured in millions of dollars

Page 4: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

4 Emulex Confidential - © 2013 Emulex Corporation

Who’d Want To Be An Analyst?

Insane pressure to resolve complex issues fast

More events than time – ‘Triage’ strategy

Lack of immediate data – Still living in ‘HHA’ mode

Tool paralysis– Too many – Too complex– Too slow

#Fail.

Page 5: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

5 Emulex Confidential - © 2013 Emulex Corporation

Sharkbites - the Problem with Wireshark…

Wireshark remains the go-to tool for most analysts and security engineers

Tool fails under 10GbE load– 14,000,000 pps on loaded 10GbE link

Faster network, slower analysis– 5 minutes to open 5GB file on Core i5– 5 minutes for each filter

Troubleshooting requires accurate data– Recording at 10Gbps is challenging– Trace files need to be moved around

Real compliance / security concerns

Page 6: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

6 Emulex Confidential - © 2013 Emulex Corporation

10GbE Troubleshooting Best Practice

Pervasive network recording– 100% accurate capture to disk

Effective traffic search– Trace file consolidation

Event driven trace extraction

High-level trace visualization– Layer 7 awareness is vital

Effective drill-in to precise packets of interest

On-appliance protocol decoder– Filters in seconds, not minutes

Easy trace file export for deep-dive in Wireshark

Page 7: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

7 Emulex Confidential - © 2013 Emulex Corporation

Page 8: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

8 Emulex Confidential - © 2013 Emulex Corporation

Page 9: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

9 Emulex Confidential - © 2013 Emulex Corporation

Page 10: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

10 Emulex Confidential - © 2013 Emulex Corporation

Page 11: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

11 Emulex Confidential - © 2013 Emulex Corporation

Page 12: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

12 Emulex Confidential - © 2013 Emulex Corporation

Page 13: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

13 Emulex Confidential - © 2013 Emulex Corporation

Page 14: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

14 Emulex Confidential - © 2013 Emulex Corporation

Page 15: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

15 Emulex Confidential - © 2013 Emulex Corporation

Page 16: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

16 Emulex Confidential - © 2013 Emulex Corporation

Page 17: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

17 Emulex Confidential - © 2013 Emulex Corporation

Page 18: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

18 Emulex Confidential - © 2013 Emulex Corporation

Page 19: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

19 Emulex Confidential - © 2013 Emulex Corporation

Page 20: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

20 Emulex Confidential - © 2013 Emulex Corporation

Page 21: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

21 Emulex Confidential - © 2013 Emulex Corporation

Page 22: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

22 Emulex Confidential - © 2013 Emulex Corporation

Page 23: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

23 Emulex Confidential - © 2013 Emulex Corporation

Page 24: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

24 Emulex Confidential - © 2013 Emulex Corporation

Page 25: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

25 Emulex Confidential - © 2013 Emulex Corporation

Page 26: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

26 Emulex Confidential - © 2013 Emulex Corporation

Page 27: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

27 Emulex Confidential - © 2013 Emulex Corporation

Page 28: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

28 Emulex Confidential - © 2013 Emulex Corporation

Page 29: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

29 Emulex Confidential - © 2013 Emulex Corporation

Page 30: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

30 Emulex Confidential - © 2013 Emulex Corporation

Page 31: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

31 Emulex Confidential - © 2013 Emulex Corporation

A New Recording Paradigm

EndaceProbe next generation sniffer

100% accurate traffic recording– Real 10 Gbps performance

Up to 64 TB of local storage– Extensible via sledding or SAN

Full flow-based traffic indexing– Including application classification

Open and flexible– Endace Application Dock– Programmable RESTful API

EndaceVision / Endace Packets

Page 32: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

32 Emulex Confidential - © 2013 Emulex Corporation

Total Datacentre Visibility

Page 33: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

33 Emulex Confidential - © 2013 Emulex Corporation

Conclusion

Troubleshooting in a 10GbE world requires 10GbE capable tools

Wireshark needs support to remain relevant in high-speed environment

EndaceVision & Endace Packets solve the scalability challenge

100% accurate recording is mandatory input

– Dedicated purpose built hardware

Long live Wireshark!

Page 34: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

34 Emulex Confidential - © 2013 Emulex Corporation

Thank you.

[email protected]