IP Library Granted Patent US 7,555,562
Granted Patent B2
US 7,555,562 · App. 11/291,347 · Granted Jun 30, 2009

Method and apparatus for mirroring traffic over a network

Assignee: Alcatel Lucent
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,555,562
App. No.
11/291,347
Granted
Jun 30, 2009
Kind
B2
Abstract

A method and apparatus for mirroring traffic from a first network device to a second network device are disclosed. The method includes the selecting of one or more ingress frames from an ingress stream using mirror classification criteria; duplicating the one or more ingress frames; appending a mirrored flow encapsulation header with a virtual local area network tag; transmitting the duplicate frames with tags from the first network device to the second network device; and removing the mirrored flow encapsulation header at the target network device to regenerate the ingress frames originally received at the first network device. The ingress frames may then be forwarded to an egress port of the second network device and analyzed by a traffic analysis tool, for example. With the invention, the traffic received at the first network device may be analyzed remotely.

Claims (33)

1. A method of mirroring a traffic flow from a source network device to a target network device for allowing analysis of the traffic flow using the target network device, the method comprising the steps of:

receiving one or more ingress frames of the traffic flow at the source network device;

generating at least one duplicate frame for each of the one or more ingress frames at the source network device in response to determining that the one or more ingress frames satisfy prescribed mirror classification criteria corresponding to information intended to influence said analysis of the traffic flow, wherein each of the one or more ingress frames at least comprises an associated address corresponding to an original designation network device;

appending a virtual local area network (VLAN) tag to the at least one duplicate frame, wherein the VLAN designated the target network device which is different than the original designation network device;

transmitting the one or more ingress frames from the source network device based on the associated address;

transmitting the at least one duplicate frame with the VLAN tag from the source network device towards the target network device based on the VLAN tag;

receiving the at least one duplicate frame with the VLAN tag at the target network device;

removing the VLAN tag from the at least one duplicate frame at the target network device after receiving the at least one duplicate frame at the target network device such that the target network device generates a substantially identical copy of at least one of the one or more ingress frames of the traffic flow received at the source network device; and

performing analysis of the at least one duplicate frame received at the target network device using the target network device for accessing the at least one duplicate frame.

2. The method of claim 1 , wherein the one or more ingress frames comprise one or more data link layer frames.

3. The method of claim 1 , wherein the one or more data link layer frames comprise one or more Ethernet frames.

4. The method of claim 1 , wherein the VLAN tag is an 802.1Q tag.

5. The method of claim 1 , wherein the VLAN tag comprises a network monitoring VLAN reserved for transmitting at least one mirrored flow.

6. The method of claim 1 , wherein the source network device is one of a first set of source network devices adapted to concurrently generate a plurality of duplicate frames and append said VLAN tag to said plurality of frames.

7. The method of claim 1 , wherein the target network device is one of a second set comprising a plurality of network devices, wherein the method further comprises the steps of: transmitting the at least one duplicate frame with the VLAN tag from the source network device to each of the plurality of network devices based on the VLAN tag; receiving the at least one duplicate frame with the VLAN tag at each of the plurality of network devices; and removing the VLAN tag from the at least one duplicate frame at each of the plurality of network devices.

8. The method of claim 1 , wherein the method further comprises the step of transmitting said generated copy of one or more ingress frames from the target network device to one or more host devices operatively coupled to the target network device.

9. A system adapted to mirror one or more flows between remote network nodes, the system comprising:

a source network device adapted to:

receive one or more ingress frames of the traffic flow at the source network device;

generate at least one duplicate frame for each of the one or more ingress frames at the source network device in response to determining that the one or more ingress frames satisfy prescribed mirror classification criteria corresponding to information intended to influence said analysis of the traffic flow, wherein each of the one or more ingress frames at least comprises an address corresponding to an original designation network device;

append a virtual local area network (VLAN) tag to the at least one duplicate frame, wherein the VLAN designated the target network device which is different than the original designation network device;

transmit the one or more ingress frames from the source network device based on the address;

transmit the at least one duplicate frame with the VLAN tag from the source network device towards the target network device based on the VLAN tag; and

a source network device adapted to:

receive the at least one duplicate frame with the VLAN tag at the target network device; and

remove the VLAN tag from the at least one duplicate frame at the target network device after receiving the at least one duplicate frame at the target network device such that the target network device generates a substantially identical copy of at least one of the one or more ingress frames of the traffic flow received at the source network device thereby allowing analysis of at least a portion of the traffic flow to be performed using the target network device.

10. The system of claim 9 , wherein the one or more ingress frames comprise one or more data link layer frames.

11. The system of claim 10 , wherein the one or more data link layer frames comprise one or more Ethernet frames.

12. The system of claim 9 , wherein the VLAN tag is an 802.1Q tag.

13. The system of claim 9 , wherein the VLAN tag comprises a network monitoring VLAN reserved for transmitting at least one mirrored flow.

14. The system of claim 9 , wherein the source network device is one of a first set of source network devices adapted to concurrently generate a plurality of duplicate frames and append said VLAN tag to said plurality of frames.

15. The system of claim 9 , wherein the target network device is one of a second set comprising a plurality of network devices, and wherein the source network device is further adapted to transmit the at least one duplicate frame with the VLAN tag to each of the plurality of network devices based on the VLAN tag; and wherein the plurality of network devices are adapted to: receive the at least one duplicate frame with the VLAN tag, and remove the VLAN tag from the at least one duplicate frame.

16. The system of claim 9 , wherein the target network device adapted to transmit said generated copy of one or more ingress frames to one or more host devices operatively coupled to the target network device.

Assignments (13)
PATENT SECURITY AGREEMENT Recorded Aug 6, 2024
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 068328/0674 →
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF AN ASSIGNOR ERRONEOUSLY OMITTED FROM ORIGINAL COVER SHEET PREVIOUSLY RECORDED ON REEL 017234 FRAME 0063. ASSIGNOR(S) HEREBY CONFIRMS THE ADDTIONAL ASSIGNOR SHOULD BE JAGJEET BHATIA. Recorded Sep 23, 2014
From: SEE, MICHAEL; BHATIA, JAGJEET
To: ALCATEL
Reel/Frame 033794/0097 →
CHANGE OF NAME Recorded Mar 5, 2009
From: ALCATEL
To: ALCATEL LUCENT
Reel/Frame 022350/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2006
From: SEE, MICHAEL
To: ALCATEL
Reel/Frame 017234/0063 →
Continuity (3)
Continuation In Part 1046507000 · Jun 18, 2003
Provisional Application 6039211600 · Jun 27, 2002
Related Publication 20060143300A1 · Jun 29, 2006