主权项 |
1. A method comprising:
receiving, from a virtual network controller, by a network device having a virtual network agent and a virtual network switch of a plurality of interconnected virtual network switches connected to the virtual network controller by an overlay network, information specifying packet characteristics of packets to be analyzed and a time period during which to apply the packet characteristics; in response determining that a time the information is received is later than the time period during which to apply the packet characteristics, ignoring, by the virtual network agent, the received information; and in response to determining that the time period during which to apply the packet characteristics has not passed:
installing, by the virtual network agent and based on the information, a packet classifier to the virtual network switch;responsive to determining that a received packet matches the specified characteristics, by the virtual network agent, determining a hash of an invariant portion of the packet that uniquely identifies the packet to obtain a packet signature; andforwarding, to the virtual network controller, a message that specifies: (1) the packet signature, (2) an identifier of the network device, and (3) a timestamp indicating a time the packet was processed by the network device. |