Products

Network Topology Visualization in Arcfra AECP: Trace Virtual-to-Physical Network Path in One View

Published on by Arcfra Team
Last edited on

In a physical network, devices are physically connected, and the topology is relatively easy to see. Virtual networks, by contrast, are built with software-defined technologies, making their topology more flexible and dynamic. This increases operational complexity and costs, and can also affect business continuity and security. Thus, in a virtualized environment, network topology visualization becomes especially important.

Arcfra Enterprise Cloud Platform (AECP) addresses this with the Network topology view in Arcfra Operation Center (AOC). It maps end-to-end connections from VMs and VM networks through virtual distributed switches, hosts, and physical NICs to physical switches, while allowing administrators to filter resources and identify abnormal ports. This makes it easier to trace dependencies, troubleshoot issues, and assess the impact of network changes.

Why Does Network Topology Visualization Matter?

Most virtualization platforms provide network topology features. Take VMware vSphere as an example. Traffic from a VM first reaches the Port Group to which its virtual NIC is connected. The virtual switch then forwards the traffic through an uplink to the physical network, enabling data exchange between the VM network and the external physical network. VMware provides a network topology view in the virtual switch settings that shows this data path, as illustrated below:

In real-world adoptions, however, customers may find this feature still presents several limitations, including unclear relationships, unintuitive visualization, and limited operational flexibility:

1. With a vSphere Standard Switch (VSS), Port Groups and VMkernel adapters are displayed at the same level. When there are a large number of Port Groups and virtual switches, their relationships become difficult to follow, and the view does not directly show the physical hosts associated with a specific Port Group.

2. The topology view does not provide filtering, so administrators cannot directly search for all VMs under a specified Port Group or virtual switch.

3. When a VM has multiple virtual NICs connected to multiple Port Groups, administrators must inspect the VM separately under each Port Group to trace its data path. A single view cannot show all Port Groups, virtual switches, physical NICs, and physical hosts associated with that VM.

4. In a cluster configuration, the topology view does not clearly show the relationship between virtual switches and physical hosts across the cluster.

5. The topology view does not directly show the upstream physical switch or switch port connected to a physical NIC (such as vmnic1); the topology view extends only as far as the physical host.

6. When a physical NIC or its upstream physical network fails, administrators cannot quickly view, locate and count the affected virtual switches and Port Groups, making it difficult to accurately assess the scope of impact.

These issues often make troubleshooting, upgrades, and maintenance more difficult for users.

1. Hard to Trace Abnormal Network Access

Multi-NIC, multi-network, and multi-tenant configurations are common in virtualized environments. When the source of an attack, unauthorized access, or abnormal traffic cannot be identified quickly, security and operations teams can face a lengthy investigation.

Customer Story 1

A security team discovers a large volume of abnormal access traffic on a dedicated network that can be reached only by some VMs configured with multiple NICs. The virtualization administrator needs to identify which VMs the traffic originates from.

With traditional network investigation methods, the team can identify the switch port associated with a MAC address and the physical host connected to it, but cannot trace the traffic further to the VM. The administrator must manually identify the multi-NIC VMs on that host and contact the relevant users one by one for further investigation, requiring much time and manual effort.

2. Hard to Diagnose Network Slowdowns

When an application experiences network latency or intermittent slowdowns, the cause may lie at multiple layers, including the virtual NIC, Port Group, virtual switch, physical NIC, or physical switch port. Finding the bottleneck often requires coordination across teams and tools, making troubleshooting time-consuming and inefficient.

Customer Story 2

An end user reports that Application A frequently slows down during peak hours when accessed externally. The user wants to know the maximum physical network bandwidth available to the application and which other applications may be competing for the same bandwidth.

In physical networks, multiple VLANs commonly share a switch port, so Application A may share the bandwidth of a physical port with other workloads. The virtualization administrator therefore needs to provide not only the maximum bandwidth available to the VM network used by Application A, but also the other VMs and VLANs sharing the same underlying physical bandwidth, which requires multiple manual steps.

3. Hard to Assess Upgrade and Maintenance Risks

For network changes such as fiber replacement, port migration, or switch upgrades, the lack of clear mapping between VMs and physical hosts often makes it difficult to assess the scope of impact beforehand.

Customer Story 3

A network administrator plans to replace the fiber cable connected to switch port GE1/0/43. The switch configuration shows that the port is not part of a link aggregation group, so replacing the cable will interrupt network connectivity on that port. However, the physical host using the port has multiple NICs connected to other switch ports, making it unclear whether every VM on the host will be affected.

To assess the risk without notifying unaffected users, the network administrator asks the virtualization administrator to identify all VMs that actually use the port and will be impacted. The VMware virtualization platform does not make this information easy to obtain, delaying the maintenance work.

Customer Story 4

A network administrator plans to upgrade the firmware on a physical switch. The upgrade may interrupt network connectivity for connected physical hosts and VMs. The administrator can collect the IP addresses currently using the switch from the network device’s ARP table, but cannot map all of those IP addresses to the corresponding VMs. The administrator therefore needs help from the virtualization team to quickly identify the affected VMs and notify the relevant users.

Network Topology Visualization In Arcfra AECP: End-to-End Visibility from VMs to Physical Switches

Arcfra Operation Center (AOC), the centralized management platform for AECP, provides end-to-end network topology visualization across virtual and physical infrastructure. Administrators can understand complex network relationships in a single view, speed up routine operations and troubleshooting, and optimize network performance.

Key Features

  • Visualize network structure: Clearly display virtual networks and their connections in a graphical view, helping administrators understand complex network structures and support network planning and design.
  • Real-time monitoring and troubleshooting: Display the status of virtual devices and links in real time, with search and filtering across multiple dimensions. Administrators can quickly identify problematic links, locate faults, and reduce network downtime.
  • Optimize network performance: Visualize the end-to-end topology from virtual to physical networks and analyze network paths to identify potential issues and performance bottlenecks, supporting network optimization and improving overall service quality.

Innovations and Product Comparison

CapabilityArcfra AECPVMware Virtualization
Topology coverage✅ End-to-end, virtual + physicalVirtual layer only
Filtering/search✅ Multi-dimensional filteringNot supported
Fault isolation✅ One-click highlighting of affected nodesManual investigation required
Physical switch details✅ LLDP-based port and device descriptionsNot visible
Dynamic updates✅ Real-time network status synchronizationStatic view

Business Value and Operational Benefits

AOC’s network topology view makes virtual network architecture and its dynamic dependencies visible, improving network operations in several ways:

  • Dynamic topology overview: Graphically display real-time connections among VMs, VM networks, virtual switches, physical hosts, physical NICs, and physical switches, eliminating the “black box” around virtual network connectivity.
  • Intelligent relationship mapping: Automatically visualize the mapping between VM networks and physical hosts, the multiple traffic paths associated with each VM, and the physical network bandwidth available to each VM.
  • Precise issue identification: When a network issue occurs, quickly locate the fault and identify affected resources through the topology view, shortening mean time to recovery (MTTR) and helping teams take the shortest path to troubleshooting.
  • More informed cost and risk assessment: Clearly show how virtual switches map to physical hosts and physical switches within a cluster, helping administrators assess redundancy and resource concentration risks and maintain a highly available network architecture.
  • Earlier risk detection: Expose physical NIC uplink information such as switch ports and link status, helping administrators identify physical network risks earlier and reduce the impact of potential failures.
  • Lower operational complexity: Present complex network relationships in a clear graphical view, helping administrators with less networking experience get started quickly.

Customer Story 1 Follow-up: Quickly Trace Abnormal Access

The network team has already narrowed the abnormal traffic down to host NODE03. With AOC’s network topology view, the virtualization administrator can identify all “suspect” VMs in three steps:

  • Step 1: Search for and filter NODE03 in the Hosts column;
  • Step 2: Select NODE03 to highlight the related network resources;
  • Step 3: Use the connection lines in the topology view to trace the highlighted resources back to the VM column, and identify all highlighted VMs with two or more virtual NICs connected to different networks. The administrator can then collect the VM names and quickly notify the relevant users for further investigation.

Customer Story 2 Follow-up: Identify Bandwidth Contention Precisely

The virtualization administrator first identifies that the VM for Application A is running on host NODE02. The administrator can then determine Application A’s maximum bandwidth and identify the other VMs sharing that bandwidth in three steps:

  • Step 1: In the network topology view, check the status, bonding mode, and bandwidth of the NODE02 physical NIC. This bandwidth is the maximum available to Application A.
  • Step 2: Identify the virtual distributed switch (VDS) and VM networks associated with that NIC, including other VM networks sharing the same physical bandwidth.
  • Step 3: Identify all VMs using these VM networks. These VMs share the same physical bandwidth as Application A.

Customer Stories 3 & 4 Follow-up: Quickly Assess Impact Before Switch Maintenance

With AOC’s network topology view, the administrator can quickly identify every VM that may be affected by replacing a switch fiber connection:

  • Step 1: Select the switch port to be maintained;
  • Step 2: Follow the topology link to the connected physical host NIC;
  • Step 3: Identify the highlighted VMs that are using this port. These are the affected VMs. The administrator can then notify the relevant users. (VMs on the same VM network that are not highlighted are not using the affected port.)

The same approach can be used to assess the impact of a physical switch firmware upgrade:

  • Step 1: Select and highlight the switch to be upgraded;
  • Step 2: Follow the topology links and check the Hosts column for all hosts using that switch;
  • Step 3: Check the highlighted VMs. These are all VMs currently using the physical switch.

References

About Arcfra

Arcfra simplifies enterprise cloud infrastructure with a full-stack, software-defined platform built for the AI era. We deliver computing, storage, networking, security, Kubernetes, and more — all in one streamlined solution. Supporting VMs, containers, and AI workloads, Arcfra offers future-proof infrastructure trusted by enterprises across e-commerce, finance, and manufacturing. Arcfra is recognized by Gartner as a Representative Vendor in full-stack hyperconverged infrastructure. Learn more at www.arcfra.com.