45
Performance Vision

Performance Vision - What's new in version 2.9

Embed Size (px)

Citation preview

Page 1: Performance Vision - What's new in version 2.9

Performance Vision

Page 2: Performance Vision - What's new in version 2.9

Agenda

What’s new in SecurActive

Performance Vision v2.9?

Page 3: Performance Vision - What's new in version 2.9

Performance Vision

Official Version

v2.3

v2.5

v2.9

Performance Vision (NPS & APS)

Main new features Virtualized Environments

Virtual Collector & Virtual Pollers

Alerting for BCA/BCN through SNMP

New metric: 0-Window Multiple improvements in:

Distributed mode Network sniffing Reporting and GUI

What’s New?

Q4 2011 Q1 2012Q3 2011

Page 4: Performance Vision - What's new in version 2.9

Performance Vision

Performance Vision v2.9?

Virtual Environments (VMWare)1. Virtual Poller2. Virtual Collector

Page 5: Performance Vision - What's new in version 2.9

Performance VisionPerformance Vision

Performance Vision

Local

Central Site

Single NodePerformance Vision

Appliance

Page 6: Performance Vision - What's new in version 2.9

Performance Vision Single NodePerformance Vision

Appliance

Performance Vision

Performance Vision

Applications, Databases, Intranet, Files, Mails... Users Users

Internet

Firewall

Core Switches Monitoring Port(s)

Admin Port

Page 7: Performance Vision - What's new in version 2.9

Performance VisionPerformance Vision Single NodeVirtual Performance

Vision

Virtual Performance Vision

Local

Central Site

Page 8: Performance Vision - What's new in version 2.9

Performance Vision Single NodeVirtual Performance

Vision

Performance Vision

Monitoring Port(s)

Admin Port

Applications, Databases, Intranet, Files, Mails... Users Users

Internet

Firewall

Core Switches

VMWare ESX

VirtualPerformance

Vision

Virt

ual S

witc

h

Virtual NIC

Physical NIC

Page 9: Performance Vision - What's new in version 2.9

Performance VisionPerformance Vision

Network

Appliance Poller

Appliance Collector

Local

Distant SiteDistant Site

Central Site

Appliance Poller

Distant Site

Appliance Poller

Distributed EnvironmentPerformance Vision

Appliances

Page 10: Performance Vision - What's new in version 2.9

Performance Vision Distributed EnvironmentPerformance Vision

Appliances

Performance Vision

Appliance Collector

Applications, Databases, Intranet, Files, Mails... Users Users

Internet

Firewall

Core Switches Monitoring Port(s)

Admin Port

Switches

SPV Pollers

WAN

Distant Site

Page 11: Performance Vision - What's new in version 2.9

Performance VisionVirtual Poller

Performance Vision

Network

Appliance Collector

Local

Distant Site

Central Site

Appliance PollerVirtual Poller

Distant Site Distant Site

Appliance Poller

Page 12: Performance Vision - What's new in version 2.9

Performance Vision Distributed EnvironmentPerformance Vision Mix

Performance Vision

Appliance Collector

Applications, Databases, Intranet, Files, Mails... Users Users

Internet

Firewall

Core Switches Monitoring Port(s)

Admin Port

Switches

SPV Virtual Pollers or Appliances

WAN

Distant Site

Page 13: Performance Vision - What's new in version 2.9

Performance Vision

Network

Appliance Poller

Virtual Collector

Virtual Poller

Local

Distant Site Distant Site

Central Site

Virtual Collector

Virtual Poller

Distant Site

Page 14: Performance Vision - What's new in version 2.9

Performance Vision

Applications, Databases, Intranet, Files, Mails...

Internet

Firewall

0 1

Performance Vision

Users Users

Monitoring Port(s)

AdminPort

VMWare ESX

Virtual Machine

1

Virtual Switch

Virtual Machine

2

Virtual Machine

3

Virtual Machine

n

Performance Vision can see traffic from/to the VMWare, but cannot see the traffic inside it. Core Switches

Page 15: Performance Vision - What's new in version 2.9

Performance Vision

Applications, Databases, Intranet, Files, Mails...

Internet

Firewall

0 1

Performance Vision

Users Users

Monitoring Port(s)

AdminPort

VMWare ESX

Virtual Machine

1

Virtual Switch

Virtual Machine

2

Virtual Machine

3

VirtualPollerSPV

Listening modes: Promiscuous Mode VDS or 3rd Party vSwitch (with SPAN) Virtual TAP

Core Switches

Page 16: Performance Vision - What's new in version 2.9

Performance Vision

Trial Audit Express Performance Vision

Modules APS APS NPS/APS NPS/APP/APS

Max Interfaces 3 10 3 10

History 15 days 30 days 15 days 360 days

Distributed - - -

Max Pollers - - - 1,2,3+

Reporting - -

Support - - Option

Licence Free for 15 days

Expires after 30

daysUnlimited Unlimited

VMWare Versions

Page 17: Performance Vision - What's new in version 2.9

Performance Vision

Performance Vision v2.9?

Information System Integration BCA & BCN values available

through SNMP

Page 18: Performance Vision - What's new in version 2.9

Performance VisionBCA / BCN & SNMP

Business Critical Applications and Business Critical Networks metrics (and sub-components) are available through SNMP.

The values can be queried through SNMP (see Performance Vision MIB)

SNMP

Centralized Monitoring

Custom Alerting System

Proactive Issue Solving

Page 19: Performance Vision - What's new in version 2.9

Performance Vision

Performance Vision v2.9?

Multiple Improvements!

New features Ease of Use

Page 20: Performance Vision - What's new in version 2.9

Performance Vision

Workflow Drill-Down for TCP Conversations & Events

Improved Data Presentation

Tops Reorganization: Easy access to most active elements

Version 2.5 Version 2.9

Page 21: Performance Vision - What's new in version 2.9

Performance Vision

Conversations

Flow Detail

TCP Events

Improved Data Presentation

Workflow Drill-Down for TCP Conversations & Events

Page 22: Performance Vision - What's new in version 2.9

Performance Vision Improved Filtering Options

Advanced Filters, Search Flows

Without Payload Without VLAN tag Identified as Unilateral flows Without transactions IPv6 only With retransmission Non Classified Applications Without Connections

Cleans main menu entries and improves filtering possibilities

Page 23: Performance Vision - What's new in version 2.9

Performance Vision Improved Filtering Options

More details added into top views One-click access to conversation

details

Version 2.5

Version 2.9

Page 24: Performance Vision - What's new in version 2.9

Performance Vision Improved Filtering Options

Easily create a traffic matrix based on custom Source & Destination IP addresses or subnets

Page 25: Performance Vision - What's new in version 2.9

Performance Vision

Time frame selection improved: New time intervals (1 hour

default) Fixed dates Keep last five recently used

intervals

Improved Usability

Online help: One-click access to documentation

Page 26: Performance Vision - What's new in version 2.9

Performance VisionReports

Reports: Page ordering made easy

Simple Drag’n drop

Time interval is now displayed for easier access to information

Page 27: Performance Vision - What's new in version 2.9

Performance VisionReports

As reports are stored on the probe and available through ftp, email recipients are now optional

Page 28: Performance Vision - What's new in version 2.9

Performance VisionExport as PDF

You can now export each view as PDF file in one single click

Page 29: Performance Vision - What's new in version 2.9

Performance VisionImproved Usability

DNS: On demand one-click name resolution (on/off)

Page 30: Performance Vision - What's new in version 2.9

Performance Vision Regular Expression for Web Applications

More flexibility: Use regular expression for Web applications

For validation you can check regular expression detection

Usage of Regular Expressions can be extremely resource consuming

Page 31: Performance Vision - What's new in version 2.9

Performance VisionVendor / MAC Address

Display Vendor name based on MAC address: On demand one-click name resolution (on/off)

Page 32: Performance Vision - What's new in version 2.9

Performance Vision

Performance Vision v2.9?

New Metric

Zero Window Event

Page 33: Performance Vision - What's new in version 2.9

Performance Vision New MetricTCP Zero Window

Count number of events. Tells that the receiver’s buffer is full and that the sender must wait before sending more data.

Page 34: Performance Vision - What's new in version 2.9

Performance Vision

Performance Vision v2.9? Network Sniffer Improvements

De-duplication process takes into account if vlan & interfaces are aggregated or not

Better segregation of ICMP messages Avoid that standard TCP keep-alives impact

metrics calculation New heuristic to find out clients from servers

without SYNs Support for HTTP chunked transfer encoding Conntracking improved for SIP protocol

Page 35: Performance Vision - What's new in version 2.9

Performance VisionAutoPCAP & PCAP

days

AutoPcap files are now kept for 72 hours instead of 48 hours to cover the week-end

Limitation on storage size for manual PCAP files has been removed. User can now freely manage size of captures depending on available storage capacity

Page 36: Performance Vision - What's new in version 2.9

Performance Vision

Performance Vision v2.9?

Improvements in Pulsar

Page 37: Performance Vision - What's new in version 2.9

Performance VisionPulsar

Reset Unified “reset” command

Page 38: Performance Vision - What's new in version 2.9

Performance VisionPulsar

New or Improved Commands

csv_status ethtool ifconfig ip ntpdate

Page 39: Performance Vision - What's new in version 2.9

Performance VisionConsole Port

You can now also use the console port to access to the probe

Page 40: Performance Vision - What's new in version 2.9

Performance Vision

Performance Vision v2.9?

Main Impacts compared to 2.5: Data Transfer Time (DTT & EURT) Retransmission Rate (RR) Reports

Page 41: Performance Vision - What's new in version 2.9

Performance VisionData Transfer Time (DTT)

If there is no data transfer for a transaction after one second, the DTT metric will now timeout. We consider that the last packet received was the one to take into account for the DTT.

DTT metrics may appear with slower values (and so EURT)

Page 42: Performance Vision - What's new in version 2.9

Performance VisionRetransmission Rate (RR)

The Retransmission Rate is now computed regardless of empty packets.

RR metrics may appear with higher values.

Page 43: Performance Vision - What's new in version 2.9

Performance VisionReports Scheduling

For Reports, date of queries are not longer relatives

Existing reports may be impacted (depending on contains)

Page 44: Performance Vision - What's new in version 2.9

Performance VisionSystem Access

Direct System Access

Only for Certified Partners / Resellers

Platform specific (case by case) Support handled by Partner / Resellers Updates are not guaranteed Reinstallation: a new disk is sent

Page 45: Performance Vision - What's new in version 2.9

Performance Vision

THANK YOU!

For any [email protected]

Please Visitwww.securactive.netblog.securactive.net