
ITM Process Integrated Traffic Monitoring
4 Copyright © 2008 ADTRAN, Inc. 61202880L1-29.1E
Traffic Flow Data Collection
Information about traffic flows is captured at observation points. Observation points in the ITM
application are most often network interfaces. On platforms with RapidRoute enabled, RapidRoute
architecture behaves as additional observation points by noticing any IP packets not already classified in a
traffic flow. The following illustration depicts the operation of observation points within the ITM
architecture.
Figure 2. ITM Internal Process
Once traffic flows have been observed by an observation point, the observation point initializes a metering
process on the part of the flow cache.
Traffic Flow Data Sampling and Filtering
Sampling and filtering are two methods which provide a cross-section view of traffic flow while reducing
the amount of data collected and stored via ITM.
Sampling provides a snapshot of traffic flow activity. By reducing the amount of traffic flow data
collected, sampling minimizes memory and CPU usage. Sampling allows an interface to collect only one
of a specified number of IP packets that the interface is receiving or sending. To ensure an accurate
sampling of traffic flow patterns, the sampling method can be either random or fixed.
Filtering occurs by including an access control list (ACL) when ITM is enabled. By including an ACL in
ITM, undesired traffic can be filtered out of the accumulating traffic flow data. For example, all traffic to a
Web server could be filtered out if the monitoring focus is on abnormal traffic activity.
To further reduce the amount of traffic flow data collected, sampling can be used in conjunction with an
ACL. In this case, fewer data packets are inspected because of sampling, and the packets inspected are
filtered through the ACL for further reduction.
Network Interface/
Observation Point:
Collects traffic flow
information
Metering Process: Records
traffic flows and creates traffic
flow entries
Flow Cache: Stores traffic
flow entries until expiration
Export Process:
Exports expired traffic flow
entries to the external data
collector
Traffic flow data sent to
external data collector
IP Packet Traffic
AOS Product
Top Traffic Collector:
Captures a snapshot of
traffic flow statistics
Comentarios a estos manuales