Header Only - DO NOT REMOVE - Extreme Networks

Oneview/Purview application response times missing

  • 8 February 2015
  • 32 replies
  • 1425 views

Userlevel 3
Hi,

i see no network or applications response times in Purview/Oneview, what to check in my configuration?

32 replies

Userlevel 2
Badge
Hi all.

please not, that if you use L2 GRE Tunnel to transmit the mirrored traffic to purview and if your gre port is tg.2.24 you need to insert an 10GE optic. It will not work with an 1GE optic.

even if tg.2.24 is up and also the tunnel interface is up. no applications are detected and no fingerprints will match.

Save some time in troubleshooting, insert an 10GE optic and reset the tunnel interface. Then you will see some applications.

Hi Matthias.

in the fail state, no traffic is sent through the gre tunnel. No packets were seen with tcpdump.

As soon as I changed the optic from 1GE to 10GE and reset the tun.0.1 interface traffic pass the tunnel.
Userlevel 6
Badge
Hi all.

please not, that if you use L2 GRE Tunnel to transmit the mirrored traffic to purview and if your gre port is tg.2.24 you need to insert an 10GE optic. It will not work with an 1GE optic.

even if tg.2.24 is up and also the tunnel interface is up. no applications are detected and no fingerprints will match.

Save some time in troubleshooting, insert an 10GE optic and reset the tunnel interface. Then you will see some applications.

Hi,
are there (in the fail state) no policy-n mirror packets in the GRE tunnel ?
(test with: tcpdump -i gre1 / tcpdump -i eth0 ip proto 47)

Or is it a problem of the bandwith 1 GB vs. 10GB ?

Regards
Userlevel 2
Badge
Hi all.

please not, that if you use L2 GRE Tunnel to transmit the mirrored traffic to purview and if your gre port is tg.2.24 you need to insert an 10GE optic. It will not work with an 1GE optic.

even if tg.2.24 is up and also the tunnel interface is up. no applications are detected and no fingerprints will match.

Save some time in troubleshooting, insert an 10GE optic and reset the tunnel interface. Then you will see some applications.
Hi all,

We just solved a problem like this.

The problem was that you must use a "real" port to create the GRE tunnel. If you use an empty physical port ( with no gbic Inside) no traffic will be submitted to the tunnel.
Userlevel 3
I tried the promiscuous mode settings in vMWare (vSwitch and Portgroup) with no effect. But the GRE Traffic itself is just directed unicast traffic, how could the vSwitch settings apply to this?
Checked the time - its synced.
no, still have this problem. But I wasnt further investigating it. Maybe I'll get back to it if we setup a test installation with a partner.
I tried the promiscuous mode settings in vMWare (vSwitch and Portgroup) with no effect. But the GRE Traffic itself is just directed unicast traffic, how could the vSwitch settings apply to this?
Checked the time - its synced.
Did you ever find the solution to this? Im having the same issue as well...
Userlevel 3
I tried the promiscuous mode settings in vMWare (vSwitch and Portgroup) with no effect. But the GRE Traffic itself is just directed unicast traffic, how could the vSwitch settings apply to this?
Checked the time - its synced.
Userlevel 5
I have run into this issue a few times, all of the times it has to do with the mirror. The fix that I have seen is in a Virtual environment to make sure that promiscuous mode is selected on the vswitch, otherwise you will NOT get the identification nor response times. Also confirm the time is synced to NTP on the virtual appliance and switch is correct as well.
Userlevel 3
On the purview appliance there is a script for testing if the necessary data is collected. I think it its appstatus or something similar. It checks if netflow and TopN Data is collected.

Regards
Michael
ah nice script :-)

My setup looks ok:
--------------------------------------------------
Process appid is running at pid 1662
Process appidserver is running at pid 1027
--------------------------------------------------
Checking for traffic on interface gre1
Checking for Netflow records on interface eth0..
Checking for IPFIX records on loopback interface..
--------------------------------------------------
Waiting for captures to complete..
Mirror appears to be setup correctly on gre1.
IPFIX appears to be setup correctly.
Netflow appears to be setup correctly on eth0.
--------------------------------------------------
Userlevel 3
On the purview appliance there is a script for testing if the necessary data is collected. I think it its appstatus or something similar. It checks if netflow and TopN Data is collected.

Regards
Michael
Userlevel 3
I also experienced the same issue. After changing the VM port group VLAN ID from 0(default) to 4095, I could see the network and application response time.

ok thanks for sharing, I guess the vlan issue shouldnt apply in my case because the mirrored data leaves the gre tunnel within the VM. Or maybe I need to check vlan id handling within the data leaving the gre tunnel.
I also experienced the same issue. After changing the VM port group VLAN ID from 0(default) to 4095, I could see the network and application response time.

The purview deployment mode was in overlay mode with a purview engine(virtual appliance) of 2 interfaces, i.e. eth0 for management, eth1 for monitoring mirrored netflow traffic from a purview sensor(CoreFlow2 switch). I changed the VM port group(eth1) VLAN ID from 0 to 4095.
Userlevel 3
I also experienced the same issue. After changing the VM port group VLAN ID from 0(default) to 4095, I could see the network and application response time.

what purview deployment mode you run? i use "single interface" for management + the gre tunnel for mirroring. If i change the vlan id management will be affected
I also experienced the same issue. After changing the VM port group VLAN ID from 0(default) to 4095, I could see the network and application response time.
Userlevel 2
Okay, in our case it just take some minutes. Then we saw application and Network Response time.
Userlevel 3
Hi,
its a virtual appliance, the vmware specific configuration options are in place but we didnt set for vlan 0-4096. I'll try this...
Userlevel 2
In VM Ware it´s necessary to configure the Port Group for mirroring specially. The Promiscuous Mode had to be "Accepted" and the VLAN Type had to be "VLAN-Trunking" In the VLAN Area you have to be defined the VLAN "0-4094". So you can mirror tagged and untagged traffic and you will see Network and application Response Time. In our Installation with a virtual purview appliance the missing VLAN type and vlan Definition 0-4094 resolved the Problem.
Userlevel 2
Do you have a Virtual or Hardware Purview Appliance?
Userlevel 3
Hi,

I just checked the onboard netflow collector of netsight. I dont see any response times for these flows neither. Maybe a general problem with my netsight installation?
Should response times get collected for any flow? I double checked documentation and dont see any advise that I have to enable something to get these data...
yes, the gre tunnel is working, and data is collected - just the response times are missing
Userlevel 6
Hi,

I just checked the onboard netflow collector of netsight. I dont see any response times for these flows neither. Maybe a general problem with my netsight installation?
Should response times get collected for any flow? I double checked documentation and dont see any advise that I have to enable something to get these data...
Is the tunneled data making it to the appliance? Run
tcpdump -i eth0 ip proto 47[/code]in the VM to confirm the GRE tunnel is working.
Userlevel 3
Hi,

I just checked the onboard netflow collector of netsight. I dont see any response times for these flows neither. Maybe a general problem with my netsight installation?
Should response times get collected for any flow? I double checked documentation and dont see any advise that I have to enable something to get these data...
Userlevel 3
Can you post your configuration of coreflow2 device and purview? I already enabled Netflow, policy mirror and port mirror, but didn't use GRE tunnel.any idea why I see no network or application response times? All other data is fine...
Userlevel 3
Can you post your configuration of coreflow2 device and purview? I already enabled Netflow, policy mirror and port mirror, but didn't use GRE tunnel.for my case...i still dont see any response times. I doubt its all at 0ms.
Userlevel 6
Can you post your configuration of coreflow2 device and purview? I already enabled Netflow, policy mirror and port mirror, but didn't use GRE tunnel.Good!
Can you post your configuration of coreflow2 device and purview? I already enabled Netflow, policy mirror and port mirror, but didn't use GRE tunnel.Thanks, all. I can see traffic flows with application groups and respone times shown.

Reply