APCON and Riverbed Technology Solution Brief In today’s fast-paced and continually evolving markets, companies of all sizes absolutely depend on their data networks to maintain their competitive edge in the marketplace. That edge dissolves when network application performance slips, which in turn causes end user dissatisfaction. Applications are the means for businesses to reach customers, build products, automate business processes, and perform almost every other task critical to the business. For IT organizations, fast, reliable application performance is the most visible indicator of their success. Network speed and reliability has grown from a side issue to become the critical path, and resolving problems quickly is simply no longer good enough. Network slowdowns and outages must be prevented rather than repaired. The business-critical nature of application monitoring is why more than 20,000 companies worldwide use Riverbed Technology to manage their application performance. Riverbed SteelCentral™ solutions provide IT with the visibility and actionable insight to help deliver the application performance that users and businesses demand. The SteelCentral solution correlates across the three critical parts of the application delivery chain: end user experience, transaction tracing, and the underlying network and infrastructure to deliver a powerful, predictive, and common toolset for solving today’s application performance management challenges. A comprehensive application performance monitoring strategy that provides a competitive advantage includes the ability to: ■ Monitor any point of the network at will ■ Collect data streams from a variety of sources and merge them into a continuous flow ■ Direct the right flow to SteelCentral AppResponse and/or SteelCentral NetShark appliances at any point in time ■ Filter the flow to provide only the data that your SteelCentral tools need Network architectures are growing to meet business and customer data needs. As a result, there is growing complexity in managing and monitoring a network efficiently. By utilizing an APCON intelligent network monitoring switch, customers can gain greater visibility and scale of their Application Performance Monitoring investment by monitoring across multiple network layers, zones and monitoring points. The APCON Solution The APCON solution enables the aggregation of packets from multiple mission-critical monitoring points. Utilizing APCON’s INTELLAFLEX solution, customers can then manipulate, filter and load-balance this traffic to the appropriate monitoring tool. Solution Brief - Riverbed Technology and APCON Data Center Core SPAN or TAP E-Commerce SPAN/ Mirror Port Extranet / Partner SPAN/ Mirror Port 1 3 5 7 9 11 2 4 6 8 10 12 PPS/IRIG IN OUT 10.1.102.72 / 255.255.0.0 26.7ºc INTELLAFLEX Blade ACI-3032-E36-1 JJ 1 3 5 7 9 19 21 23 18 20 22 24 2 1 4 3 6 5 8 7 10 9 12 11 31 33 35 30 32 34 36 15 17 19 21 23 GPS ANT 25 27 29 31 GPS ANT 28 30 32 34 36 27 29 31 33 35 23 24 8 10 12 14 16 18 20 22 24 26 28 30 32 9 11 13 15 17 19 21 23 25 27 29 31 16 18 20 22 24 C 26 28 30 32 Packet Aggregator 1/10 Gbps B Status Power 36 33 35 23 24 34 36 Latency Measuring 1/10 Gbps Ethernet 1/10 Gbps Ethernet Customer Experience 14 34 1/10 Gbps Ethernet 26 25 1/10 Gbps Ethernet 24 23 7 12 WAN Multi Function 1/10 Gbps Status 22 21 6 10 D Figure 1: The APCON INTELLAFLEX Series 3000 provides a highly available, fault tolerant and scalable architecture suitable for use in a production data center running real-time application performance analytics. Power 20 19 5 8 35 18 17 3 6 33 16 15 4 4 SPAN/ Mirror Port Multi Function 1/10 Gbps Status 1 2 SPAN/ Mirror Port Power 14 1/10 Gbps Ethernet Network Management INTELLAFLEX™ Blade ACI-3030-E36-6 29 28 2 I NTELLA F LEX ™ ACI–3144–XR 27 13 1/10 Gbps Ethernet INTELLAFLEX™ Blade ACI-3030-E36-6 25 26 1/10 Gbps Ethernet DOWN ENTER INTELLAFLEX Blade ACI-3032-E36-1 17 16 13 11 PPS/IRIG IN OUT Hit [Enter] for configuration UP 15 1/10 Gbps Ethernet 3144-XR S/N: 72020004 Ver: 1 CANCEL 13 14 1/10 Gbps Ethernet Port SPAN/ Mirror Port 1/10 Gbps Ethernet Distribution SPAN/ Mirror DMZ Packet Aggregator 1/10 Gbps Status A Power Security Troubleshooting Enterprise-grade data center monitoring switches must have the ability to bond several disparate data streams from external-facing, DMZ, and internal switches, and route all this data to SteelCentral tools with packet tags that indicate the source of the data. Further, the switch must be able to filter both individual and aggregated data streams using both pass and drop filtering. Figure 1 shows example of topology that enables multiple monitoring points to be wired to various types of monitoring tools. Production Network – DMZ APCON Monitoring Platform Manage DMZ Traffic to Tools Internet External Aggregation Zone 1 Zone 2 More Zones AT AT AT AT AT AT AT AT APCON TAPs External Firewalls 1 3 5 7 9 2 1 4 3 6 5 8 7 10 9 12 13 16 15 17 18 17 19 20 19 21 22 21 23 4 3 6 5 8 7 10 9 12 11 AT AT AT Internal Aggregation Corp. Intranet 31 33 34 33 35 Multi Function 1/10 Gbps D 36 35 GPS ANT Multi Function 1/10 Gbps Status C Power 26 28 30 32 25 27 29 31 34 36 33 35 23 24 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 23 24 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 1/10 Gbps Ethernet AT Internal Firewalls 32 24 23 1/10 Gbps Ethernet AT 29 22 21 1/10 Gbps Ethernet AT 30 20 19 1/10 Gbps Ethernet AT 27 18 17 1/10 Gbps Ethernet AT INTELLAFLEX™ Blade ACI-3030-E36-6 31 Status 28 16 15 2 I NTELLA F LEX ™ ACI–3144–XR 29 Power 25 14 13 1/10 Gbps Ethernet INTELLAFLEX™ Blade ACI-3030-E36-6 27 GPS ANT 26 23 1/10 Gbps Ethernet 2 1 25 24 1/10 Gbps Ethernet DOWN ENTER INTELLAFLEX Blade ACI-3032-E36-1 14 11 PPS/IRIG IN OUT Hit [Enter] for configuration UP 15 1/10 Gbps Ethernet INTELLAFLEX Blade ACI-3032-E36-1 JJ 3144-XR S/N: 72020004 Ver: 1 13 11 PPS/IRIG IN OUT 10.1.102.72 / 255.255.0.0 26.7ºc CANCEL 1/10 Gbps Ethernet SPAN from switches DMZ Server Switches Packet Aggregator 1/10 Gbps Status B Power Packet Aggregator 1/10 Gbps Status Power A Figure 2: The APCON INTELLAFLEX Series 3000 aggregates packets copied from SPAN and TAP sources throughout the network and aggregates, manipulates, and filters the packet stream before passing the data to the SteelCentral tools. Solution Brief - Riverbed Technology and APCON Finally, application performance monitoring with SteelCentral tools increasingly involves packet latency monitoring as a means of tracking performance issues to particular locations within the data center. Precise and accurate time stamping of packets monitored as they traverse the data center is a requirement for a fully functional application performance monitoring program. Solution: APCON and Riverbed APCON provides an enterprise-grade intelligent network monitoring switch solution with the port density, overall port count and throughput capacity, and high availability to handle the volume of data generated in a modern data center. APCON also provides time stamping capability at the nanosecond level and the ability to eliminate duplicate packets, slice packets at the header, and filter packets on any criteria. This allows network engineers to bring together data inputs from any point on the network, aggregate and manipulate the data at the packet level, and then direct those data flows to any SteelCentral™ AppResponse or SteelCentral™ NetShark tool in inventory for analysis. Production Network WAN WAN Layer-3 DMZ SPAN / TAP Inputs Core Figure 3: Monitoring tools leveraging the APCON intelligent network monitoring switch can be scaled across the data center. Additional sites can also be managed using APCON’s TITAN multiswitch management software. Layer-3 APCONTAP Distribution AT AT AT AT AT AT AT AT A B TAP A B C D TAP C D A B TAP A B C D TAP C D A B TAP A B C D TAP C D A B TAP A B C D TAP C D A B TAP A B C D TAP C D A B TAP A B C D TAP C D A B TAP A B C D TAP C D A B TAP A B C D TAP C D Layer-3 EXPANSION Multiple Distribution Modules Access / ToR Layer-2 EXPANSION Multiple Access Modules SPAN from all Access Switches Packet Aggregator 1/10 Gbps 1/10 Gigabit Fiber Ethernet 1 2 3 4 5 6 7 8 9 10 11 12 15 16 13 14 15 16 25 13 27 14 29 31 17 18 Status Packet Aggregator 1/10 Gbps 1/10 Gigabit Fiber Ethernet 1 2 3 4 5 6 7 8 9 13 15 17 10 11 12 17 18 Status APCON TAPs C Power INTELLAFLEX™ Blade ACI-3030-E18-6 1 ENTER D Power INTELLAFLEX™ Blade ACI-3030-E18-6 CANCEL 3 5 7 9 11 19 21 23 10 12 1 3 5 7 9 11 2 4 6 8 10 12 14 16 13 15 14 16 18 20 22 24 17 19 21 23 18 20 22 24 26 28 30 32 25 27 29 31 26 28 30 32 34 36 33 35 23 24 34 36 1/10 Gbps Ethernet 8 1/10 Gbps Ethernet 6 35 24 1/10 Gbps Ethernet INTELLAFLEX™ Blade ACI-3030-E36-6 4 1/10 Gbps Ethernet 2 1/10 Gbps Ethernet 1/10 Gbps Ethernet INTELLAFLEX™ Blade ACI-3030-E36-6 33 23 Packet Aggregator 1/10 Gbps Status B Power Packet Aggregator 1/10 Gbps Status A Power TITAN Switch Management Packet Analyzer IDS Malware User Detection Experience APCON Monitoring Platform – Manage Production Traffic to Tools With a comprehensive network monitoring system in place, network engineers can proactively monitor application service levels, bottlenecks, and spikes in network activity and accurately allocate resources for maximum network efficiency. Solution Brief - Riverbed Technology and APCON About APCON APCON develops scalable network switching solutions for enterprise data centers worldwide. APCON intelligent network monitoring switches and taps provide complete network visibility, improve network security and optimize monitoring tool efficiency. APCON’s filtering and aggregation technology and multi-switch management software minimizes network downtime and maximizes monitoring tool investments. Learn more about APCON at www.apcon.com. APCON, Inc. 9255 SW Pioneer Court Wilsonville, Oregon 97070 USA Tel: 503–682–4050 © 2014 APCON, Inc. All rights reserved. SteelCentral is a trademark of Riverbed Technology. 13044-R4-0814