Automatic health check and performance monitoring for applications and protocols using deep packet inspection in a datacenter
A method of collecting health check metrics for a network is provided. The method, at a deep packet inspector on a physical host in a datacenter, receives a copy of a network packet from a load balancer. The packet includes a plurality of layers. Each layer corresponds to a communication protocol in a plurality of communication protocols. The method identifies an application referenced in the packet. The method analyzes the information in one or more layers of the packet to determine metrics for the source application. The method sends the determined metrics to the load balancer.
1 . A system comprising:
a load balancer configured to receive a set of data message flows;
a deep packet inspection (DPI) engine coupled to the load balancer, the DPI engine being configured to examine the data message flows to extract a set of attributes related to a set of destinations of the data message flows; and
a controller configured to adjust a load balancing operation of the load balancer based on the set of attributes extracted by the DPI engine.
2 . The system of claim 1 , wherein the DPI engine is configured to analyze information carried in headers of the data messages above a transport layer.
3 . The system of claim 1 , wherein the set of attributes comprise a set of health metrics related to a distributed application operating on the set of destinations.
4 . The system of claim 1 , wherein the load balancer comprises a network interface configured to receive the set of data message flows.
5 . The system of claim 1 , further comprising a memory coupled to the controller, the memory being configured to store the set of attributes extracted by the DPI engine.
6 . The system of claim 1 , further comprising a managed forwarding element (MFE) coupled to the load balancer, the MFE being configured to route the data message flows to the DPI engine.
7 . The system of claim 1 , wherein the set of attributes comprise one or more error values extracted from the set of data message flows.
8 . The system of claim 1 , wherein the set of attributes comprise one or more certificate parameters related to connection session certificates associated with the set of data message flows.
9 . A system comprising:
a first data compute node (DCN) hosted on a physical host, the first DCN being configured to execute an application;
a managed forwarding element (MFE) configured to route network traffic between the first DCN and an external network;
a deep packet inspection (DPI) engine coupled to the MFE, wherein the DPI engine is configured to:
receive a network packet routed by the MFE; and
generate an application performance metrics based on an analysis of the network packet;
a shared memory on the physical host accessible by a load balancer and the DPI engine, wherein the load balancer is configured to place a network packet into the shared memory for the DPI engine, and the DPI engine is configured to place the generated application performance metrics into the shared memory for the load balancer.
10 . The system of claim 9 , further comprising a load balancer coupled to the MFE and the DPI engine, the load balancer being configured to distribute network traffic to the first DCN based on the application performance metrics generated by the DPI engine.
11 . The system of claim 10 , wherein the load balancer is configured to adjust network traffic distribution based on the application performance metrics.
12 . The system of claim 9 , further comprising a memory configured to store the application performance metrics.
13 . A system comprising:
a load balancer configured to receive a set of data message flows and a subset of data message flows and detect idle status of one or more destinations;
a deep packet inspection (DPI) engine coupled to the load balancer, the DPI engine being configured to examine the data message flows to extract a set of attributes; and
a controller configured to adjust a load balancing operation of the load balancer based on the set of attributes extracted by the DPI engine.
14 . The system of claim 13 , wherein the set of attributes are related to a set of destinations of the data message flows.
15 . The system of claim 13 , wherein the DPI engine is configured to analyze information carried in headers of the data messages above a transport layer.
16 . The system of claim 13 , wherein the set of attributes comprise a set of health metrics related to a distributed application operating on the set of destinations.
17 . The system of claim 16 , wherein the set of attributes further comprises identity of one or more source applications from which the set of data message flows emanates.
18 . The system of claim 16 , wherein the set of attributes comprises a response time of the distributed application.
19 . The system of claim 16 , wherein the set of attributes further comprise an indication that the distributed application has at least partially failed.
20 . The system of claim 13 , wherein the set of attributes comprise one or more error values extracted from the set of data message flows.