webleads-tracker

SecurActive - How it works

How it works

Principles

Performance Vision's implementation in the network is straight forward:

  • all the usage and performance measurements are based on an analysis of network traffic;
  • a single point of capture is sufficient to produce both usage and performance metrics.
  • in a multi-site environment, several listening points can be installed. The performance vision solution provide you a centralized view of traffic and application performance.

 

Traffic Capture

There are three common ways to collect traffic:

  • Port mirroring / SPAN
  • TAP / Virtual TAP
  • Promiscuous mode
In all cases, implementing Performance Vision:
  • Does not require any change in the network architecture
  • Does not require any deployment of agents
  • Does not induce any traffic overhead

 

Port mirroring / SPAN

Port mirroring / SPAN is a common feature provided by most Enterprise network switches, which enables the administrator to send a copy of the traffic to / from a certain VLAN/interface to a monitoring port, to which the Performance Vision appliance is connected.

 

TAP

A TAP is a hardware device, which copies the signal on a network link to a third interface which is connected to the Performance Vision appliance.

Virtual TAPs are devices which enable the capture and the forwarding of a traffic within a virtual server to a Performance Vision appliance (physical or virtual).

 

Promiscuous mode

In a Virtual environment, a third option called Promiscuous mode enables the forwarding of all packets to all the interfaces (virtual or physical) in a portgroup; this way, a Performance Vision Virtual Appliance deployed in a virtualization server, in a portgroup with the promiscuous mode activated can capture and analyze all the traffic within the portgroup.

 

Learn more on TAP/Port Mirroring-SPAN

Learn more on how to capture virtual traffic

 

Deployment mode

Performance Vision can either be deployed as a standalone unit or in a distributed architecture.

 

Stand-alone appliance

Performance Vision in a stand-alone mode is composed of a single unit which analyze the traffic, store the statistics and present the data through an interface.

 

Distributed architecture

Performance Vision in a distributed mode will capture and analyze traffic in several physical locations through distinct appliances (called "Pollers" or APP for Application Performance Pollers, which can be either physical or virtual appliances), which send their statistics to a central Performance Vision unit, called "Collector". All the data is aggregated into a single database and accesible through a single User Interface. 

 

distributed mode

 

The pollers (APP) listen and analyze the network traffic. The collector fetches data from the pollers (APP), integrate them in the database, and then provides an access to the data through the Web UI.

Note: the collector appliance may also host one sniffer component. A distributed environment can be composed of both physical and virtual appliances.