Deploy preprocessing independently
Rather than embedding every decapsulation function inside PacketLens, OPTIME created a separate service/server so normalization and IP analysis can scale, operate, and deploy independently.
Networking and High-Performance Systems
A modular C, Assembly, and DPDK preprocessing service validated at approximately 1 Tbps, decapsulating QinQ, MPLS, VNTag, GRE, and GTP traffic before forwarding normalized IP to PacketLens or other systems.
ProtocolForge handles network traffic whose useful IP payload is wrapped in additional encapsulation or tunnel layers that PacketLens or another analysis tool cannot consume directly. The service identifies supported outer protocols, strips or decapsulates the required layers, recovers the underlying IP traffic, and forwards that normalized output downstream.
Verified protocol support includes QinQ, MPLS, VNTag, GRE, and GTP. The public case describes the supported boundaries without exposing parser implementation, private packet formats, or customer routing policy.
The customer intentionally wanted the preprocessing layer separated from PacketLens. ProtocolForge therefore runs as an independent service on a separate server, can scale independently, can be placed in a different data center, and can feed PacketLens or another customer analysis system.
Across a one-year specialized program, OPTIME engineered the DPDK packet-I/O path, C and selected Assembly processing, protocol identification and decapsulation, normalized raw-IP output, independent deployment model, downstream integration, and approximately 1 Tbps local data-center validation.
ProtocolForge is the generalized encapsulation-normalization layer in a related modular architecture. MobileScope specializes in mobile-core GTP-U/GTP-C processing, while PacketLens consumes raw IP for classification, selected protocol analysis, filtering, and traffic steering.
Monitored QinQ, MPLS, VNTag, GRE, or GTP traffic enters the preprocessing service.
The service runs separately from PacketLens and can scale or deploy in a different data center.
High-throughput packet I/O feeds the native data plane with reduced operating-system overhead.
C implements the processing core, with Assembly reserved for selected performance-critical routines.
The data plane identifies the supported outer protocol layers that must be removed.
QinQ, MPLS, VNTag, GRE, and GTP layers are processed at a public conceptual boundary.
The underlying IP payload is recovered without exposing proprietary parser or customer-rule details.
Normalized traffic can feed PacketLens for deeper IP classification and selective analysis.
The same normalized output can be directed toward another customer analysis system.
Rather than embedding every decapsulation function inside PacketLens, OPTIME created a separate service/server so normalization and IP analysis can scale, operate, and deploy independently.
ProtocolForge removes only the required outer layers and emits underlying IP, allowing PacketLens and other tools to consume a consistent downstream format.
The implementation uses C for the data-plane core and selected Assembly only where performance-critical processing justified lower-level optimization.
PacketLens is the primary verified downstream consumer, but the modular output can feed other customer analysis systems without combining them into one monolithic deployment.
Other encapsulated traffic flows through ProtocolForge for QinQ, MPLS, VNTag, GRE, or GTP processing before normalized raw IP reaches PacketLens or another downstream tool.
MobileScope is the related specialized mobile-core preprocessing layer, separating high-rate GTP-U decapsulation from GTP-C control/session analysis. PacketLens remains the raw-IP analysis and traffic-steering layer.
ProtocolForge provides an independently deployable normalization boundary for high-rate encapsulated traffic. It was validated at approximately 1 Tbps in the customer’s local data-center environment; that figure does not imply every deployment continuously processes 1 Tbps.
The modular data plane recovered normalized IP from the verified encapsulation set at approximately 1 Tbps in customer-local validation while preserving independent deployment and scaling from PacketLens.
Validated in the customer’s local data-center environment; not a universal continuous-throughput claim.
CONTACT US
Austin, Texas
Distributed engineering teams across North America, Europe, the Caucasus, and Latin America.
[email protected]