Observe Traffic and Troubleshoot

After the service network is in use, enable traffic collection on the target hosts. Then narrow down issues by reviewing Traffic Overview, Traffic Topology or its table, and Packet Capture. Traffic views use data collected for the selected scope and time range. Packet Capture shows packets visible on a specified VM NIC.

If a view has no data, check the host collection status and the selected compute manager, Cluster, and time range. If necessary, check Agent Status in the host details. An empty view does not mean that the service has no traffic. Traffic Topology shows collected communication relationships, not the complete forwarding path.

Enable Host Traffic Collection

Traffic Overview, Traffic Topology, and Packet Capture depend on host-side collection. When collection is enabled on a host for the first time, ZNS collects traffic from all eligible NICs on that host. When collection is enabled again, existing collection modes are retained.

  1. Go to ZNS Network Center > Compute Managers, open the target compute manager details, and under Related Resources, select Hosts.
  2. Find the host that runs the target VM, and check Collection Status.

    If the status is Unknown, refresh the list first. You can enable collection only on hosts where it is disabled.

  3. Select the target host, click Enable Collection, and confirm.
  4. Refresh and check the collection status, then review the data in a traffic view.

To stop collecting new data, use Disable Collection on a host where collection is enabled. Previously collected data is retained.

View Traffic Overview

Traffic Overview shows traffic trends and rankings for the selected compute platform, Cluster, and time range. Use it first to determine the scope of an issue.

  1. Go to ZNS Network Center > Traffic Visualization & Troubleshooting > Traffic Overview.
  2. Select a compute manager, Cluster, and time range.

    Record the filter criteria. Data from different scopes or time ranges cannot be compared directly.

  3. Review sessions, traffic trends, protocol distribution, and rankings to locate an unusual time, VM, or communication endpoint.
  4. To narrow down the issue further, open Traffic Topology and review communication relationships with the same scope and time range.

If the view has no data, check whether collection is enabled on the target hosts and whether the filter scope contains matching data. An empty view does not mean that the network is healthy or that the service has no traffic.

View Traffic Topology and Table

Traffic Topology shows collected communication relationships. Table View lets you search, filter, and inspect individual flows. Nodes and links in the topology represent observed communication endpoints, not the complete packet path.

  1. Go to ZNS Network Center > Traffic Visualization & Troubleshooting > Traffic Topology.
  2. Select a compute manager, Cluster, and time range, then narrow the scope by VM or communication endpoint.
  3. Review nodes and communication relationships in the topology. Click a node or link to view details.

    When reviewing traffic statistics, consider the collection interface and traffic direction. To confirm whether a security policy is effective, also check its configuration and actual access results.

  4. Switch to Table View, and use search criteria and fields to inspect the corresponding flows.
  5. To inspect packets, locate a VM NIC on which collection is still enabled, then open Packet Capture.

Create and Review a Packet Capture Task

Packet Capture uses a VM NIC with active collection as its capture interface and can capture only packets visible on that NIC. Before creating a task, go to ZNS Network Center > Compute Managers, open the target compute manager details, and confirm that collection is enabled on the target host under Related Resources in the Hosts list. Open the host details and check the connection state under Agent Status.

  1. Go to ZNS Network Center > Traffic Visualization & Troubleshooting > Packet Capture, and click Create Capture Task.
  2. Enter a task name, and select a capture interface and an available VM NIC.

    If no NIC is available, return to the Hosts list associated with the compute manager to check collection status. In the host details, check Agent Status for the connection state and failure reason. The selected NIC determines which packets are visible.

  3. Set the capture duration and NIC capture direction. Add source address, destination address, protocol, or port filters as needed.

    Direction is relative to the selected NIC. Filters determine only which packets are saved; they do not change the capture interface.

  4. Review the capture interface, duration, and filters, then create the task.
  5. Check the running state in the task list. After completion, open the details to review the file overview and packet preview, and download the PCAPNG file as needed.

If no matching packets were captured, check the capture NIC, filters, and whether corresponding traffic occurred during the capture. You can stop a running task if needed.

Network Services | Network Service · ZCF | ZStack Resource Center