Traffic monitoring systems in VoIP networks. Part one — overview

In this article, we will explore an interesting and useful element of IT infrastructure: the VoIP traffic monitoring system.

Traffic monitoring systems in VoIP networks. Part one — overview
The development of modern telecommunications networks is astonishing: from signaling fires they have stepped far forward, and what seemed unimaginable before is now simple and commonplace. Only professionals know what lies behind the everyday use and wide adoption of innovations in the information technology industry. The variety of transmission media, switching methods, device interaction protocols, and coding algorithms can overwhelm the average person and be a real nightmare for anyone involved in their proper and stable functioning: passing tone signals or voice traffic, inability to register on a softswitch, testing new equipment, and compiling requests for vendor support.

The aforementioned concept of a protocol is the cornerstone of any communication network, affecting its architecture, the composition and complexity of its devices, the range of services it provides, and much more. It is also evident, yet very important, that using a more flexible signaling protocol enhances the scalability of the communication network, which leads to a rapid increase in various network devices within it.

However, even the necessary and justified increase in the number of interconnected network elements under this observed pattern brings a number of challenges related to network maintenance and operation. Many specialists have encountered situations where a captured dump does not allow for clear localization of the problem, as it was obtained in a part of the network that is not involved in its emergence.

This situation is particularly characteristic of VoIP networks, which include more devices than just a single PBX and several IP phones. For instance, when multiple session border controllers, flexible switches, or a softswitch are used in the solution, but the user location function is separated from the others and placed on a separate device. The engineer then has to choose the next segment for analysis based on their empirical experience or chance.

This approach is extremely tedious and unproductive, as it forces one to repeatedly spend time dealing with the same issues: what can be used for packet collection, how to retrieve the results, and so on. On one hand, as is well-known, people get used to anything. One can also get accustomed to this, 'get the hang of it,' and train patience. However, on the other hand, there is still another complication that cannot be ignored – correlating traces taken from different segments. All of the above, as well as many other network analysis tasks, constitute the area of work for many specialists, which traffic monitoring systems are designed to help solve.

On Traffic Monitoring Systems for Communication Networks

And together — we accomplish a common task: you in your way, and I in mine.
Y. Detochkin

Modern media traffic transmission networks are designed and built through the implementation of various concepts, the foundation of which comprises numerous telecommunication protocols: CAS, SS7, INAP, H.323, SIP, etc. A traffic monitoring system (TMS) is a tool that is intended to capture messages from the aforementioned protocols (and others) and possesses a set of convenient, intuitive, and informative interfaces for analysis. The primary purpose of the TMS is to make signaling traces and dumps available to specialists at any time (including in real-time) without using specialized programs (e.g., Wireshark). On the other hand, every qualified specialist pays close attention to issues related to the security of IT infrastructure.

An important aspect directly related to this issue is the specialist's ability to 'keep their finger on the pulse', which can be achieved through timely notifications about certain incidents. When mentioning notification issues, we are talking about network monitoring. Referring back to the definition above, a Traffic Monitoring System (TMS) allows for the monitoring of messages, responses, and activities that may indicate abnormal network behavior (for example, 403 or 408 responses in SIP or a sudden increase in the number of sessions on a trunk), while providing corresponding infographics that visually illustrate what is happening.

However, it should be noted that the VoIP traffic monitoring system is not the classic Fault Monitoring System that creates network maps, controls the availability of its elements, resource utilization, peripherals, and much more (like Zabbix).

Having understood what a traffic monitoring system represents and the tasks it solves, let's move on to how to apply it effectively in practice.

It is evident that the TMS alone cannot gather Call Flow 'by magic'. It is necessary to consolidate the relevant traffic from all used devices into one point – the Capture Server. Thus, the definition emphasizes a characteristic feature of the system that involves the need to centralize the collection of signaling traffic and allows us to answer the previously posed question: what benefits does the use of the system bring to the operational or implemented network.

Typically, it is rare for an engineer to answer on the spot where exactly the specified point of traffic centralization will be or could be located. For a more or less clear answer, specialists need to conduct a series of investigations related to the specific analysis of the VoIP network. For example, rechecking the equipment composition, precisely defining the connection points, as well as understanding the capabilities in the context of sending the corresponding traffic to the collection point. Furthermore, it is clear that the success of addressing this issue directly depends on how the transport IP network is organized.

Therefore, the first benefit of implementing SMT is the long-planned but unexecuted network audit. Of course, a thoughtful reader might immediately ask – what does SMT have to do with this? There is no direct connection, nor can there be, but... The psychology of most people, including those associated with the IT world, tends to link such activities to specific events. The next advantage follows from the previous one: even before SMT is deployed, with Capture Agents installed and configured, and RTCP message sending enabled, any problems requiring immediate intervention may be detected. For instance, a 'bottleneck' might develop somewhere, which is clearly visible even without statistics that SMT can provide using data from sources like RTCP.

Now let's return to the previously described process of collecting the necessary traces and smile as we recall the words of the hero highlighted in the epigraph of this section. An important feature that was not mentioned is that, as a rule, the listed operations can be performed by sufficiently qualified personnel, such as Core Engineers. On the other hand, the issues addressed through traces may also include so-called routine tasks. For example, identifying the reason why a terminal is not registered with the installer or client. In this context, it becomes clear that the exclusive ability to capture dumps by these specialists imposes on them the necessity to handle these production tasks. This is unproductive because it takes time away from resolving other, more important issues.

Moreover, in most companies where the use of a product like SMT is desirable, there is a dedicated department whose tasks include performing routine operations in order to relieve other specialists – service desk, helpdesk, or technical support. It is also not a revelation for the reader if I note that, for security and network stability reasons, access for technical support engineers to the most critical nodes is undesirable (though it is quite possible that it is not prohibited), and these network elements contain the most advantageous perspective for dumps. SMT, being the central point for traffic collection and possessing an intuitive and transparent interface, is quite capable of addressing several mentioned problems. The only condition is to organize access to the interface from the workstations of technical support specialists and possibly write a knowledge base article on its use.

In conclusion, let’s highlight the most well-known and interesting products that perform the functionality described above, among which are: Voipmonitor, HOMER SIP Capture, Oracle Communications Monitor, SPIDERDespite the common approach to organization and deployment, each has its own nuances, subjective pros and cons, and all deserve individual examination. This will be the subject of further materials. Thank you for your attention!

UPD (05.23.2019): In addition to the list provided in the conclusion, there is one more product that the author recently became aware of. SIP3 – a young, developing representative from the world of SIP traffic monitoring systems.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster