logoalt Hacker News

ricksunnyyesterday at 4:55 PM5 repliesview on HN

>We were building 40 Gbps packet sniffers at Google (4x 10 Gbps NICs) and needed switches that could do things like mirror traffic across ports at line rate

I'm sure there were good reaasons for this, but man this just sounds bad. Like that's the spec I think NSA must give to their contractors outfitting 611 Folsom Street's Room 641A


Replies

kevin_nisbettoday at 4:16 AM

These tools are very common in non-nefarious ways for troubleshooting networking, and while vendors set up to serve this space solely as troubleshooting tools, I've also built my own that can sit on a network link and monitor for problems.

In my case it was for mobile wireless signaling traffic (all the coordination for creating a mobile internet connection, handing the connection off between towers, etc), and I'd credit it as one of the reasons you're mobile internet connection is so stable. When LTE first came out, myself and many others solved all sorts of bugs in the equipment and protocols by using or building these sorts of tools.

teifereryesterday at 6:19 PM

Port mirroring is the network engineer's equivalent of using breakpoints in a debugger for a programmer. It allows you to inspect what happens on the wire to get a clue for what's wrong.

agilobyesterday at 5:31 PM

It does sound bad the way OP described it, but packet or HTTP mirroring is a standard feature of A/B testing and blue-green deployments of a very critical code. Mirror traffic between version 1 and 2, then compare response body, response time and return response A to the end users.

show 1 reply
wmfyesterday at 5:23 PM

Nah, packet mirroring is a standard networking feature and ideally every feature is line rate.

show 1 reply
unethical_banyesterday at 5:11 PM

There are companies that mirror their traffic to storage for a few days to be able to look back and troubleshoot issues. ALL their traffic, proactively.

show 2 replies