Transcript
Page 1: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

Emulex Confidential - © 2013 Emulex Corporation

EndaceVision with Packet DecodesAn Introduction to Endace Packets

Jim MacLeod – Senior Product Manager, Emulex

Page 2: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

2 Emulex Confidential - © 2013 Emulex Corporation

Introduction

Jim MacLeod– Senior Product Manager, Emulex– 15 years experience in monitoring– Product Manager for EndaceVision

Endace – Emulex product line – World leader in network recording– 10 years selling network visibility

Page 3: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

3 Emulex Confidential - © 2013 Emulex Corporation

Changing Nature of Networks

Rapid shift to 10GbE – 40 and 100GbE adoption coming

Increasing complexity– Consolidation– Virtualization

Greater reliance on network– Virtual Desktop– Unified Communications

More compliance & regulation– Business and customer data– Scope of data at rest

Lower tolerance to downtime…– Cost measured in millions of dollars

Page 4: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

4 Emulex Confidential - © 2013 Emulex Corporation

Who’d Want To Be An Analyst?

Insane pressure to resolve complex issues fast

More events than time – ‘Triage’ strategy

Lack of immediate data – Still living in ‘HHA’ mode

Tool paralysis– Too many – Too complex– Too slow

#Fail.

Page 5: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

5 Emulex Confidential - © 2013 Emulex Corporation

Sharkbites - the Problem with Wireshark…

Wireshark remains the go-to tool for most analysts and security engineers

Tool fails under 10GbE load– 14,000,000 pps on loaded 10GbE link

Faster network, slower analysis– 5 minutes to open 5GB file on Core i5– 5 minutes for each filter

Troubleshooting requires accurate data– Recording at 10Gbps is challenging– Trace files need to be moved around

Real compliance / security concerns

Page 6: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

6 Emulex Confidential - © 2013 Emulex Corporation

10GbE Troubleshooting Best Practice

Pervasive network recording– 100% accurate capture to disk

Effective traffic search– Trace file consolidation

Event driven trace extraction

High-level trace visualization– Layer 7 awareness is vital

Effective drill-in to precise packets of interest

On-appliance protocol decoder– Filters in seconds, not minutes

Easy trace file export for deep-dive in Wireshark

Page 7: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

7 Emulex Confidential - © 2013 Emulex Corporation

Page 8: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

8 Emulex Confidential - © 2013 Emulex Corporation

Page 9: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

9 Emulex Confidential - © 2013 Emulex Corporation

Page 10: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

10 Emulex Confidential - © 2013 Emulex Corporation

Page 11: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

11 Emulex Confidential - © 2013 Emulex Corporation

Page 12: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

12 Emulex Confidential - © 2013 Emulex Corporation

Page 13: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

13 Emulex Confidential - © 2013 Emulex Corporation

Page 14: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

14 Emulex Confidential - © 2013 Emulex Corporation

Page 15: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

15 Emulex Confidential - © 2013 Emulex Corporation

Page 16: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

16 Emulex Confidential - © 2013 Emulex Corporation

Page 17: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

17 Emulex Confidential - © 2013 Emulex Corporation

Page 18: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

18 Emulex Confidential - © 2013 Emulex Corporation

Page 19: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

19 Emulex Confidential - © 2013 Emulex Corporation

Page 20: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

20 Emulex Confidential - © 2013 Emulex Corporation

Page 21: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

21 Emulex Confidential - © 2013 Emulex Corporation

Page 22: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

22 Emulex Confidential - © 2013 Emulex Corporation

Page 23: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

23 Emulex Confidential - © 2013 Emulex Corporation

Page 24: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

24 Emulex Confidential - © 2013 Emulex Corporation

Page 25: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

25 Emulex Confidential - © 2013 Emulex Corporation

Page 26: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

26 Emulex Confidential - © 2013 Emulex Corporation

Page 27: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

27 Emulex Confidential - © 2013 Emulex Corporation

Page 28: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

28 Emulex Confidential - © 2013 Emulex Corporation

Page 29: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

29 Emulex Confidential - © 2013 Emulex Corporation

Page 30: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

30 Emulex Confidential - © 2013 Emulex Corporation

Page 31: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

31 Emulex Confidential - © 2013 Emulex Corporation

A New Recording Paradigm

EndaceProbe next generation sniffer

100% accurate traffic recording– Real 10 Gbps performance

Up to 64 TB of local storage– Extensible via sledding or SAN

Full flow-based traffic indexing– Including application classification

Open and flexible– Endace Application Dock– Programmable RESTful API

EndaceVision / Endace Packets

Page 32: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

32 Emulex Confidential - © 2013 Emulex Corporation

Total Datacentre Visibility

Page 33: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

33 Emulex Confidential - © 2013 Emulex Corporation

Conclusion

Troubleshooting in a 10GbE world requires 10GbE capable tools

Wireshark needs support to remain relevant in high-speed environment

EndaceVision & Endace Packets solve the scalability challenge

100% accurate recording is mandatory input

– Dedicated purpose built hardware

Long live Wireshark!

Page 34: Introducing Endace Packets - EndaceVision™ with Protocol Decodes

34 Emulex Confidential - © 2013 Emulex Corporation

Thank you.

[email protected]