PacketShaper Information:
This is a summary of the information on the PacketShaper device implemented on the University of Minnesota TC campus
PacketShaper is a network management device that allows administrators to control bandwidth, as well as monitor application traffic, on their network. Packeteer's website states that PacketShaper has the ability to:
Classify traffic by application, protocol, address, subnet, port number, URL or wildcard, host name, LDAP host lists, Diffserv setting, 802.1p/q, MPLS, ISL, IP precedence bits, IP or Mac address, direction (inbound/outbound), source, destination, host speed range, Mime type, web browser, Oracle database, Citrix Published Application, VLAN
PacketShaper utilizes "layer 7 classification, analysis, control and reporting." A summary of what these four steps are, from the PacketShaper Data Sheet are as follows:
Step 1: PacketShaper automatically classifies network traffic into categories based on application, protocol, subnet, URL, and other criteria -- yielding thousands of potential categories. PacketShaper goes beyond static port-matching and IP address schemes. Its layer-7 classification capabilities pinpoint hundreds of applications, from Oracle and SAP to Gnutella and KaZaA.
Step 2: PacketShaper provides detailed analysis of application performance and network efficiency, describing peak and average bandwidth utilization, response times divided into network and server delays, top users, top web pages, top applications, and more.
Step 3: With policy-based bandwidth allocation and traffic shaping, PacketShaper protects critical applications, paces those that are less urgent, and optimizes performance of a limited WAN-address link. You specify bandwidth minimums and/or maximums on a per-session or per-application basis.
Step 4: PacketShaper has extensive reporting capabilities: reports, graphs, statistics and SNMP MIBs. With service-level agreements, you can define performance standards, compare actual performance with service-level goals, and generate reports on compliance.
For ResNet users, PacketShaper's monitoring abilities can be monitoring anything, from which websites you go to, to how many times you access your email, to how often you use a file-sharing program to download files. This means that if you're running a dedicated ftp server, or game server, etc, you are probably getting tracked in a PacketShaper log.
It is not specific whether PacketShaper is capable of monitoring content (like the FBI's Carnivore system), but if so monitoring content to all traffic would be a violation of our rights to privacy (such as monitoring our instant messages or email), so we shouldn't see that happening. We'll most likey have the traffic (not it's content) on campus monitored and have bandwidth altered to optimize for protocols like web browsing, email, DNS, etc, and find less bandwidth for the file-sharing in the residence halls, which is what apparently caused the rate-limiting.
It's capabilities go way beyond what it will be most-likely used for. Be forwarned, PacketShaper's abilities are akin to those used in George Orwell's 1984.