Liyanage, Ahmad, Okwuibe, Montes de Oca, MAI, Perez, and Itzazelaia
240
the virtual and physical machines. Setting up several observation points is necessary to
better diagnose the problems detected. With SDN, it is possible to create network
monitoring applications that collect information and make decisions based on a network‐wide holistic views. This enables centralized event correlation on the network
controller, and allows new ways of mitigating network faults.
10.7 Expected Challenges in Software Defined Monitoring
The lack of visibility and controls on NFV internal virtual networks and the heterogeneity of devices make many performance assessment applications ineffective. On the one
hand, the impact of virtualization on these technologies needs to be assessed. For
instance, network monitoring applications need to be able to monitor virtual connections. On the other hand, these technologies need to cope with ever‐changing contexts
and trade‐offs between the monitoring costs and the benefits involved.
In order to monitor virtualized telecommunication network, it should be possible to
monitor inter‐VNF communication; however, such monitoring may not be possible.
Current OpenStack specifications [8] provide blueprints for the solution, but are not yet
part of the release.
The OpenStack development version has introduced what is called Tap‐as‐a‐Service.
It is being developed as a plug‐in of Neutron and provides an API [12]. TaaS is a project
developed to provide a network service by mirroring network traffic from the port of
virtual machine to another port. The main idea of TaaS is to copy each packet in/out of
the virtual machine via the port and transfer to another port.
In the scenario depicted in Figure 10.4, a new virtual machine VM Monitor is created.
By using TaaS, one can copy and transfer the traffic in/out of VM1 and VM2 from Port 1
and Port 2 to Port M. Then, the VM Monitor receives every packet coming in/out of
VM1 and VM2. Hence, it can monitor the traffic in the Tenant without access to the
compute hosts. However, TaaS only provides the mirroring service, so in order to monitor, analyze and secure the tenant, we must integrate a Monitoring Service.
TENANT X
VM4
TENANT Z
VM Monitor
TENANT X
VM1
TENANT X
Compute Host
Open vSwitch
Port 4
Port M
Port 1
P ort 2
P ort 3
Compute Host
Open vSwitch
VM2
TENANT X
VM3
TENANT Y
Figure 10.4 OpenStack monitoring based on TaaS.
240
the virtual and physical machines. Setting up several observation points is necessary to
better diagnose the problems detected. With SDN, it is possible to create network
monitoring applications that collect information and make decisions based on a network‐wide holistic views. This enables centralized event correlation on the network
controller, and allows new ways of mitigating network faults.
10.7 Expected Challenges in Software Defined Monitoring
The lack of visibility and controls on NFV internal virtual networks and the heterogeneity of devices make many performance assessment applications ineffective. On the one
hand, the impact of virtualization on these technologies needs to be assessed. For
instance, network monitoring applications need to be able to monitor virtual connections. On the other hand, these technologies need to cope with ever‐changing contexts
and trade‐offs between the monitoring costs and the benefits involved.
In order to monitor virtualized telecommunication network, it should be possible to
monitor inter‐VNF communication; however, such monitoring may not be possible.
Current OpenStack specifications [8] provide blueprints for the solution, but are not yet
part of the release.
The OpenStack development version has introduced what is called Tap‐as‐a‐Service.
It is being developed as a plug‐in of Neutron and provides an API [12]. TaaS is a project
developed to provide a network service by mirroring network traffic from the port of
virtual machine to another port. The main idea of TaaS is to copy each packet in/out of
the virtual machine via the port and transfer to another port.
In the scenario depicted in Figure 10.4, a new virtual machine VM Monitor is created.
By using TaaS, one can copy and transfer the traffic in/out of VM1 and VM2 from Port 1
and Port 2 to Port M. Then, the VM Monitor receives every packet coming in/out of
VM1 and VM2. Hence, it can monitor the traffic in the Tenant without access to the
compute hosts. However, TaaS only provides the mirroring service, so in order to monitor, analyze and secure the tenant, we must integrate a Monitoring Service.
TENANT X
VM4
TENANT Z
VM Monitor
TENANT X
VM1
TENANT X
Compute Host
Open vSwitch
Port 4
Port M
Port 1
P ort 2
P ort 3
Compute Host
Open vSwitch
VM2
TENANT X
VM3
TENANT Y
Figure 10.4 OpenStack monitoring based on TaaS.
