Stateful traffic trace synchronization in network devices

CN122824698APending Publication Date: 2026-09-25HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510975276.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-03-24
Filing Date
2025-07-15
Publication Date
2026-09-25

Smart Images

  • Figure CN122824698A_ABST
    Figure CN122824698A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to stateful traffic trace synchronization in network devices. In certain examples, a network switching system can include first switch circuitry and second switch circuitry such that the first switch circuitry is distinct from the second switch circuitry, the second switch circuitry having a state data structure. The network switching system can include a hardware-level link coupling the first switch circuitry and the second switch circuitry. The network switching system can include a first processor associated with the first switch circuitry and configured to detect, at the first switch circuitry, a new communication session, generate a stateful synchronization message including state information about the new communication session, send the stateful synchronization message from the first switch circuitry to the second switch circuitry over the hardware-level link, and update, at the second switch circuitry, the state data structure based on the stateful synchronization message received from the first switch circuitry.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Network devices are used in network infrastructure to provide interconnection and communication between various devices and network segments. These network devices may include one or more network switches that bootstrap data traffic between devices based on network protocols and configurations. As networks continue to grow in size and complexity, scalable and flexible switching solutions that can adapt to changing needs while maintaining effective management and operation may be appropriate. Attached Figure Description

[0002] To gain a more complete understanding of this disclosure and its advantages, the following description is now taken in conjunction with the accompanying drawings, in which:

[0003] Figure 1 An example of a stateful business tracking synchronization system based on some implementations is shown;

[0004] Figure 2A This illustrates a network switching system with stateful service tracking synchronization based on some implementation examples;

[0005] Figure 2B The example shows a switch circuit system for a stateful service tracking synchronization system based on some implementations.

[0006] Figure 3 Example data structures for stateful business tracking synchronization systems are shown based on some implementations;

[0007] Figure 4 Examples of stateful business tracing synchronization methods based on some implementations are shown;

[0008] Figure 5 This illustrates an example of a stateful business tracing synchronization method based on some implementations;

[0009] Figure 6 Examples of stateful business tracing synchronization methods are shown based on some implementations; and

[0010] Figure 7 An example of a stateful business tracing synchronization method is shown based on some implementations. Detailed Implementation

[0011] Switch virtualization technology allows two or more physical switches to act as a single logical device at Layer 2 while maintaining an independent control plane at Layer 3. An example of this technology is Virtual Switch Extensions (VSX). Switch virtualization can improve network performance, availability, and redundancy. For example, it can increase network resilience and load balancing capabilities in enterprise and data center environments.

[0012] When implementing stateful service tracing across virtualized switches, synchronizing stateful information between switches may be appropriate. Inconsistencies in service processing and potential security vulnerabilities can occur without such synchronization of stateful information. Synchronization helps maintain accurate flow state, provides appropriate firewall functionality, and delivers relatively seamless network services across virtualized switches.

[0013] As network security objectives evolve, advanced features such as stateful firewalls and deep packet inspection may become suitable for virtualization deployments. Stateful security features can provide relatively consistent policy enforcement and seamless failover capabilities by using relatively precise synchronization of service flow information between virtualized switches.

[0014] Some implementations of this disclosure provide hardware-level synchronization of state between virtualized switches. By reusing existing network infrastructure such as hardware-level links (e.g., keep-alive links), some implementations of the disclosed systems allow for high-speed, low-latency transmission of hardware-level synchronization messages. In some implementations, the approach utilizes the capabilities of the switch hardware while minimizing changes to existing software architectures.

[0015] Some implementations may involve configuring hardware-level links (e.g., keep-alive links) as stacking links, thereby effectively creating a hidden virtual switch framework beneath the virtualized topology. This configuration can transmit hardware-to-hardware messages, including flow state information, protocol state, and / or other relevant data for maintaining synchronized stateful service traces across virtualized switches.

[0016] In some implementations, achieving stateful service tracing synchronization in a virtualized environment may involve configuring multiple interconnect components. In some implementations, a network switching system may include a logical network device formed by two or more physical switches, where each physical switch includes one or more switch circuit systems operating in a virtualized switch configuration, potentially having one or more switch circuit systems of another physical switch. For example, the first and second physical switches may each include a first switch circuit system and a second switch circuit system. The first and second switch circuit systems may be different from each other, thereby allowing independent operation while serving as a single logical unit.

[0017] For example, the first switch circuitry can be implemented as a first virtualized switch, and the second switch circuitry can be implemented as a second virtualized switch. The first and second virtualized switch circuitry can be physical switches working together to provide improved network performance and redundancy. The first and second virtualized switches can be communicatively coupled through multiple communication links to facilitate data transmission and synchronization.

[0018] In some implementations, the virtualization topology may include a data plane communication link between the first and second virtualized switch circuit systems. As a specific example, this link may be an inter-switch link (ISL). The data plane communication link may couple the first and second virtualized switches, serving as the primary path for data plane traffic between the first and second virtualized switches. The data plane communication link may be a high-bandwidth connection that allows for relatively seamless load balancing and failover capabilities, thereby improving the overall reliability of the network.

[0019] In addition to data plane communication links, network switching systems may include hardware-level links (e.g., so-called keep-alive links) coupling first and second virtualized switches. In some implementations, hardware-level links serve a dual purpose in the virtualization configuration. Hardware-level links can be used to exchange heartbeat messages to monitor the operational status of each switch. In the context of stateful traffic tracing synchronization, additionally or alternatively, hardware-level links can be reused to transmit hardware-level synchronization messages between the first and second virtualized switches.

[0020] By implementing synchronization mechanisms at the hardware level, network switching systems can achieve improved performance and reduced latency compared to software-based solutions. In some implementations, this approach improves the scalability and reliability of virtualized deployments, such as in environments with high throughput requirements or in virtualized deployments implementing relatively advanced security features. Certain implementations of the disclosed network switching systems and methods can allow network administrators to deploy relatively more complex security and service management policies across virtualized switches without potentially compromising performance or introducing inconsistencies in service processing.

[0021] By operating at the hardware level, network switching systems can bypass software limitations and utilize the capabilities of certain processing components. This approach can provide precise, high-speed synchronization; it reduces implementation risk and costs.

[0022] Turn to the attached diagram. Figure 1 An example computing system 100 for stateful service tracing synchronization, according to some implementation, is shown. The computing system 100 may include an external network 102, a network switching system 104, and multiple client network devices 106a-106n. The network switching system 104 may be coupled to the external network 102, which may represent a broader network infrastructure. This arrangement allows the network switching system 104 to manage network services between the client network devices 106a-106n and the external network 102.

[0023] The computing system 100 can be implemented in one or more electronic devices and / or systems. Examples of electronic devices and systems may include a range of devices and / or systems that can be coupled to or interact with network 102. Electronic devices can be broadly classified as network switching system 104, client devices 106, and other suitable devices and / or systems. Although Figure 1 A computing system 100 is shown that includes a single network switching system 104, but the computing system 100 may include any suitable number of network devices 104. This disclosure may also relate to network switching systems 104 in singular or plural form.

[0024] Network switching system 104 can be a processing system that facilitates the transmission of data across network 102. Examples of network switching system 104 may include routers that guide data packets along network 102, switches that couple multiple devices to network 102 and manage data traffic, access points that provide wireless connectivity, firewalls that provide network security, and modems that couple network 102 to the Internet. Additionally, network switching system 104 can be configured to perform a range of functions, including those typically associated with hosts and other devices and / or systems. For example, network switching system 104 may be a multi-functional router that can operate bit servers, hosting applications or services directly on network switching system 104. In some implementations, network switching system 104 may provide data routing, switching capabilities, and host network management software and tools. Network switching system 104 can perform one or more roles, thereby improving the efficiency and flexibility of network resource utilization. Network devices 104 may vary in their data transmission speeds, connectivity ranges, security features, or the specific network protocols they support.

[0025] In some implementations, network switching system 104 includes a first network switch 107 and a second network switch 109. The first network switch 107 and the second network switch 109 may be physical switches. In some implementations, network switching system 104 may include virtual switches (e.g., Virtual Switching Framework (VSF) members) implemented using the first network switch 107 and the second network switch 109. In some implementations, network switch 107 and network switch 109 each include a first switch circuitry 108 and a second switch circuitry 110.

[0026] In some implementations, VSF technology virtualizes two or more physical devices into a single virtual structure, which provides relatively high availability due to reduced recovery time and a relatively simplified network design and management. VSF allows supported switches connected to each other via Ethernet connections (e.g., copper or fiber) to behave as a single chassis switch. VSF technology allows network administrators to manage multiple physical switches as a single logical entity, thereby reducing complexity in network deployments and improving scalability.

[0027] Switch circuit systems 108 and 110 can be interconnected via data plane communication link 112. In some implementations, data plane communication link 112 allows communication between the first switch circuit system 108 and the second switch circuit system 110, which can be considered as "internal" communication within the virtual switch implemented by network switching system 104. In some implementations, data plane communication link 112 can transmit data plane services between the first switch circuit system 108 and the second switch circuit system 110.

[0028] Network switching system 104 (e.g., a virtual switch) may include hardware-level link 116. In some implementations, hardware-level link 116 (e.g., a keep-alive link) is a dedicated communication channel between two physical switch circuit systems 108 and 110. Originally designed to exchange heartbeat messages to monitor the operational status of each switch circuit system 108 and 110, hardware-level link 116 can be reused to facilitate hardware-level synchronization of stateful service trace information. When operating at Layer 2 or Layer 3 of the Open Systems Interconnection (OSI) model, hardware-level link 116 can allow high-speed, low-latency transmission of dedicated synchronization messages that may not be transmitted over standard data plane communication link 112 due to the unique metadata and protocol characteristics of the synchronization messages. Hardware-level link 116 can be implemented as a single connection or as part of a Link Aggregation Group (LAG) for increased bandwidth and redundancy. By leveraging hardware-level link 116 to provide state synchronization capabilities (and, if necessary, heartbeat functionality), computing system 100 can potentially achieve effective state consistency across physical switch circuit systems 108 and 110 without requiring significant modifications to existing network infrastructure or software architecture.

[0029] According to some implementations, computing system 100 can be used to transmit network communication via virtual ports (such as one of a set of virtual ports). In some implementations, the two switch circuit systems 108 and 110 can be hidden and include software components that represent the two switch circuit systems 108 and 110 as a single virtual switch (e.g., a VSF member). In some implementations, the two switch circuit systems 108 and 110 can each include application-specific integrated circuits (ASICs) or other processing components, which can be interconnected via data plane communication link 112 (e.g., a hidden stacked link).

[0030] In addition to or instead of ASICs, the network switching system 104 can use a variety of other processing components to manage network traffic and implement virtualization functions. These processing components may include network processing units (NPUs), field-programmable gate arrays (FPGAs), general-purpose central processing units (CPUs), system-on-a-chip (SoC) solutions, multi-core processors, graphics processing units (GPUs), custom-designed chips, hybrid solutions combining different types of processors, and / or intelligent network interface cards (intelligent NICs). These processing components can be used individually or in combination (including with one or more ASICs), distributed across chassis units to provide performance, flexibility, and functionality suitable for implementing virtualization and other networking features.

[0031] In some implementations, each processing unit may include 24 ports associated with each switch circuit system 108 and 110. In some implementations, the customer sees 48 ports, all belonging to a single virtual switch. In some implementations, the architecture described herein allows network switching system 104 to be presented to the customer as a single virtual switch with 48 ports (e.g., using client device 106), while internally managing two separate 24-port processing components. It should be understood that the specific number of ports is provided only as an example, and this disclosure contemplates that each ASIC (or other processing component) includes any suitable number of ports.

[0032] In some implementations, network switching system 104 may employ software-defined networking (SDN) protocols to manage the routing of network services for client network devices 106a-106n. This can provide finer-grained control over service flow and quality of service, potentially improving the performance and user experience of client network devices 106a-106n.

[0033] The scalability of the network switching system 104 allows for relatively seamless expansion to accommodate an increase in the number of client network devices 106a-106n. When additional switches (which may include additional processing components) are added to the computing system 100, the network switching system 104 can automatically incorporate these new elements, thereby maintaining a relatively consistent interface and service level for the client network devices 106a-106n.

[0034] Examples of client devices 106 include servers hosting websites or applications, personal computers used by individuals or organizations, mobile devices such as smartphones and tablets, and Internet of Things (IoT) devices such as smart home appliances, wearable devices, and connected vehicles. Additional examples of client devices 106 include storage devices such as network-attached storage devices or cloud storage servers, peripheral devices such as printers or scanners accessible via network 102, and dedicated devices such as security cameras or environmental sensors that transmit data via network 102. In some implementations, client devices 106 may vary in their processing power, storage capacity, operating system, the specific applications they run, the types of data they manage, or the specific network interfaces they use.

[0035] Multiple client devices 106 can be interconnected via a network switching system 104 that can be coupled to network 102. A first client device 106a, a second client device 106b, a third client device 106c, and a fourth client device 106d can be shown as coupled to network switching system 104. Additionally, an Nth client device 106n is shown, indicating a network capability communicatively coupled to an unspecified number of client devices 106, thus representing a scalable network system. Network switching system 104 can be communicatively coupled to network 102, through which data exchange and communication between network devices (e.g., network switching system 104) can be performed. Computing system 100 can facilitate a dynamic communication network that can adapt to changing needs of the coupled network switching system 104 and the data transmitted by network switching system 104 to and from client devices 106 and network 102.

[0036] Computing system 100 can be used in any data processing scenario, including standalone hardware, mobile applications, or combinations thereof. Computing system 100 can be used in computing networks, such as public cloud networks, private cloud networks, hybrid cloud networks, other forms of networks, or combinations thereof. As an example, the methods provided by computing system 100 can be provided as services on the network by, for example, a third party. Computing system 100 can be implemented on one or more hardware platforms, wherein modules within the system can be executed on one or more platforms. Such modules can run on various forms of cloud technologies and hybrid cloud technologies, or be provided as software-as-a-service that can be implemented on or outside of cloud networks. In some aspects, network switching system 104 can be configured to manage network services in various network environments, including but not limited to local area networks (LANs), wide area networks (WANs), and cloud-based networks.

[0037] Each physical switch 107 and 109 in the virtualization pair (e.g., network switching system 104) may include main processors 122 and 132 and memories 126 and 136, respectively, which manage the overall switching operation. As an example, the first switch 107 may include processor 122, interface 124, and memory 126. Processor 122 and interface 124 may be coupled to connector 130 (which may be a communication path or a common bus). In some implementations, memory 126 may also be coupled to connector 130.

[0038] The first switch circuit system 108 may include a first set of physical ports. In some implementations, the second switch circuit system 110 may include a second set of physical ports. These physical ports can be used to couple to other network devices or systems to facilitate the transmission of network services. In some implementations, the physical ports of the first switch circuit system 108 and the second switch circuit system 110 can be communicatively coupled to a virtual port group, such that the physical ports are mapped to the virtual port group.

[0039] The processor 122 can be configured to control the operation of the first switch circuit system 108 and the second switch circuit system 110, manage the routing of network services, and perform other network management tasks.

[0040] In some implementations, memory 126 may be considered as a first and second storage device in various configurations of physical memory (i.e., within one or more memory devices). In some implementations, the second memory may store programs for execution by one or more processors (e.g., processor 122). The program may include instructions for managing the network switching system 104. The instructions may include instructions for mapping a first set of physical ports and a second set of physical ports of the network switching system 104 to a single virtual port group. The instructions may also include instructions for presenting the mapping of the first and second sets of ports as a single virtual port group.

[0041] In some respects, the network switching system 104 can be configured to handle various network service types, including unicast, multicast, broadcast, and other suitable service types. The network switching system 104 can also support various network protocols, such as Internet Protocol (IP), Transmission Control Protocol (TCP), and User Datagram Protocol (UDP).

[0042] In some implementations, the network switching system 104, which may be logical network devices (e.g., virtual switches implemented using physical switches 107 and 109), can be implemented through various configurations of physical switches 107 and 109. For example, the first network switch 107 and the second network switch 109 may be independent physical switches, integrated switches within a larger chassis, or physical switches configured to operate as a virtualized switch pair. In some implementations, the two physical switches 107 and 109 may together form the logical network switching system 104. The specific implementation of the network switching system 104 may depend on the specific requirements of the network environment in which it can be deployed.

[0043] In some implementations, connector 130 can be any suitable combination of bus and / or other types of wired or wireless connectors. In some implementations, connector 130 may include one or more buses, such as one or more PCI-Express buses.

[0044] In some implementations, processor 122 can coordinate the operation of various parts of network switching system 104. As an example, processor 122 can use SDN protocols to manage the routing of network services between first switch circuit system 108 and second switch circuit system 110. Network switching system 104 can utilize SDN protocols to manage the routing of network services between first switch circuit system 108 and second switch circuit system 110.

[0045] In some aspects, the controller (e.g., processor 122) may include programming instructions stored in memory 126. These instructions can be executed by processor 122 to perform various operations of network switching system 104. For example, the programming instructions may include instructions for receiving transmissions on a first physical port of a combined group of physical ports of network switching system 104. The instructions may include instructions for accessing a mapping to determine a first virtual port in a single group of virtual ports corresponding to the first physical port. The instructions may include instructions for generating an indication of the first virtual port as a communication port for transmission, wherein the indication of the first virtual port hides the identification of the first physical port.

[0046] In some implementations, the first and second storage devices can be the same storage device (e.g., memory 126). This configuration can simplify the storage architecture of the network switching system 104, potentially reducing system complexity and improving efficiency. Using a single storage cell for the first and second memories can also facilitate faster data access and retrieval, potentially improving the performance of the network switching system 104.

[0047] In some implementations, the second physical switch 109 may include one or more processors 132, memory 136, and one or more interfaces 134, all of which can communicate using one or more communication links 140.

[0048] Processor 132 may be any component or collection of components suitable for performing computational and / or other processing-related tasks. Processor 132 may be, for example, a microprocessor, microcontroller, control circuitry, digital signal processor, FPGA, ASIC, SoC, or a combination thereof. Processor 132 may include one or more processing cores. Processor 132 may include any suitable number of processors, or multiple processors may collectively form a single processor 132.

[0049] Memory 136 may include any suitable combination of volatile memory, non-volatile memory, and / or virtualization thereof. For example, memory 136 may include any suitable combination of magnetic media, optical media, RAM, ROM, removable media, and / or any other suitable memory device. Memory 136 may include data structures for organizing and storing all or part of the stored data. Memory 136 may include non-transitory computer-readable media for storing programs to be executed by one or more processors of one or more processors 132.

[0050] Interface 134 represents any suitable computer element, or both, that can receive and transmit information from communication link 150. Interface 134 represents any real or virtual port or connection, including any suitable combination of hardware, firmware, and software, including protocol conversion and data processing capabilities, for communication via a LAN, WAN, or other communication system that allows the exchange of information. Interface 134 can facilitate wireless and / or wired communication. In some implementations, at least one interface of interface 134 is configured to communicate with a second physical switch 110 via wired communication link 150.

[0051] Communication link 140 may include any suitable wired or wireless communication medium for the components of the second physical switch 110 to communicate with each other. For example, communication link 140 may include any suitable combination of bus or communication network.

[0052] As described below, the separate first and second switch circuit systems 108 and 110 (e.g., Figure 2A The first and second line cards 260 and 270 shown in each of the switches 107 and 109 can have their own processing components (e.g., processors 284 and 294) and memories (e.g., 286 and 296), as shown. Figure 2B As shown, this allows for distributed processing capabilities across virtualized switch pairs.

[0053] Figure 2A An example network switching system 104 is shown according to some implementations of an example stateful service tracing synchronization system. Network switching system 104 may include two chassis units, each chassis unit including a node (where each node corresponds to, for example, line card 260 or 270). In some implementations, a node may refer to processing and / or switching components within each physical chassis. As an example, each line card 260 and 270 may correspond to one of the physical switch circuit systems 108 or 110 forming a virtualized switch pair.

[0054] The chassis can be a physical enclosure or frame that includes switch components such as switching structures, line cards 260 and 270, and control modules. Each of these chassis units can represent a different physical entity within the network switching system 104. For example, a first chassis unit can correspond to a first physical switch 107. A second chassis unit can correspond to a second physical switch 109. In some implementations, each chassis (the first physical switch 107 and the second physical switch 109, respectively) can include its own nodes, such as line cards 260 and 270, which can have switching and processing capabilities.

[0055] In a virtualized switch architecture, each node can represent a functional unit within a physical chassis. A node may include the switching structure, control plane processing, and interface management capabilities of its corresponding physical switch 107 or 109. A first network switch 107 may correspond to a node in a first chassis, and a second network switch 109 may correspond to a node in a second chassis. These nodes can together form a logical network switching system 104, allowing the network switching system 104 to function as a unified virtual switch while maintaining separate physical hardware.

[0056] The first physical switch 107 and the second physical switch 109 forming a virtualization pair can be implemented in the same chassis or in separate chassis, depending on specific network requirements and hardware configuration. For example, one or more physical switches 107 and 109 can be housed in a single chassis. In some implementations, each chassis may contain one or more line cards (e.g., 260 and 270, respectively), each line card 260 or 270 contributing to the overall switching and processing capacity of the physical switches 107 or 109.

[0057] Figure 2B Examples of stateful service tracing and synchronization systems 108 and 110 are shown according to some implementations. In some implementations, the first switch circuit system 108 may include a first interface 282 (e.g., a port of the first switch circuit system 108), a first processor 284, and a first memory 286. In some implementations, the second switch circuit system 110 may include a second interface 292 (e.g., a port of the second switch circuit system 110), a second processor 294, and a second memory 296.

[0058] In some implementations, each physical switch circuit system 108 and 110 may include stateful instructions for monitoring, analyzing, and maintaining information about network traffic flows through the switch. The processor 284 or 294 and memory 286 or 296 in each physical switch circuit system 108 and 110 may execute these stateful instructions.

[0059] When executed by processor 284 or 294, stateful instructions allow physical switch circuit systems 108 and 110 to detect and track new communication sessions, maintain state information of active flows, analyze packet content to determine flow characteristics, update flow state based on observed service patterns, and / or generate synchronization messages for state updates.

[0060] In some implementations, the processor 284 or 294 in each physical switch circuit system 108 and 110 can execute stateful instructions to manage the synchronization of state information between the two physical switch circuit systems 108 and 110. When executed by the processor 284 or 294, these stateful instructions can allow physical switch circuit systems 108 and 110 to generate hardware-level synchronization messages, transmit synchronization data on hardware-level synchronization link 112, process incoming synchronization messages from peer switches, update local state information based on received synchronization data, manage the priority of synchronization services, and / or handle failover scenarios and ensure state consistency.

[0061] While state tracking and synchronization functions can be implemented using hardware capabilities, they can also be implemented using software instructions executed by switch processors 122 and 132 and / or switch circuit system processors 284 and 294. This software-based approach allows for greater flexibility and relatively streamlined updates compared to dedicated hardware components. When executed by switch processors 122 and 132 and / or switch circuit system processors 284 and 294, state tracking instructions (e.g., Figure 4 As shown in 454 and 464, the first switch 107 and the second switch 109 can detect and track new communication sessions, maintain status information and / or generate synchronization messages as needed.

[0062] For example, in the event of a failure in one of the physical switches (e.g., the first physical switch 107), the virtualized switch architecture allows for a relatively seamless failover process. Figure 1 As shown by the dashed lines, data transmission between the second physical switch 110 and the network 102 can be handled during a failover of the first physical switch 107. In some implementations, hardware-level link 116 allows for relatively rapid state synchronization between the first switch circuitry 108 and the second switch circuitry 110. This state synchronization allows important state information to be maintained and replicated across the first physical switch 107 and the second physical switch 109. During a failover event, the operating switch (e.g., the second physical switch 109) can use the synchronized state information to continue network operation with relatively minimal disruption to maintain consistent service processing and policy enforcement.

[0063] In some implementations, the first interface 282 and the second interface 292 can be used as and operated as Figure 1 Interfaces 124 and 134 are shown. In some implementations, the first memory 286 and the second memory 296 can be used and operated as memories 126 and 136.

[0064] In some implementations, processors 284 and 294 can be used and operate as processor 122. By operating similarly to processor 122, processors 284 and 294 enable distributed processing capabilities across virtualized switch pairs, allowing for efficient management of network operations and state synchronization.

[0065] The hardware synchronization module may be or is included in the processor 122 ( Figure 1 As shown), in the first processor 284 and / or the second processor 294. The hardware synchronization module can assign a unique chassis identifier (ID) to each of the first physical switch circuit system 108 and the second physical switch circuit system 110. This assignment enables the creation of a hidden virtual switch frame (VSF) topology under a virtualization configuration. The unique chassis ID allows the hardware synchronization module to create logical separation between the two switch circuit systems 108 and 110 while maintaining their operation as a single virtual switch.

[0066] For example, the chassis unit can be chassis 0 and chassis 1. Nodes within each chassis, specifically the nodes in chassis 0 (corresponding to the first line card 260, corresponding to the first switch circuitry 108) and the nodes in chassis 1 (corresponding to the second line card 270, corresponding to the second switch circuitry 110), can be coupled via data plane communication link 112 and hardware-level link 116. These connections allow the nodes to function as virtualized switch pairs while maintaining their respective processing capabilities.

[0067] Data plane communication link 112 and hardware-level link 116 can serve different purposes in a virtualized configuration. While data plane communication link 112 can handle data plane traffic, hardware-level link 116 can be dedicated to hardware-level synchronization messages. This separation allows for efficient management of different types of network traffic and control information.

[0068] In some implementations, sending synchronization messages on data plane communication link 112 (e.g., ISL) may be problematic for one or more reasons. For example, synchronization messages may include specific metadata that may be incompatible with standard network services. This metadata may be configured for direct ASIC-to-ASIC (or other processing unit-to-processing unit) communication, and data plane communication link 112 may not be configured to handle these communications. As another example, in some implementations, data plane communication link 112 may be primarily configured for regular client data services and standard control plane communication.

[0069] As another example, in some implementations, metadata in synchronization messages can alter the packet structure in ways that data plane communication link 112 cannot handle correctly. In some implementations, proprietary metadata uses hardware-level identification that data plane communication link 112, operating as a typical network link, may not provide. In some implementations, sending synchronization messages via data plane communication link 112 may lead to data corruption or misreading of synchronization information.

[0070] As another example, in some implementations, attempting to send dedicated services via data plane communication link 112 may negatively impact the performance of regular network services. In some implementations, the metadata of synchronization messages may include sensitive state information that may not be suitable for mixing with regular services on data plane communication link 112.

[0071] As another example, in some implementations, synchronization messages may use proprietary protocols that are incompatible with the standard network protocols used on data plane communication link 112. Examples of such proprietary protocols may be Virtual Switch Extensions (VSX) synchronization protocol, VSX state synchronization protocol, hardware-accelerated replication protocol, stateful tracking switching protocol, fast consistency protocol, and / or low-latency update protocol. In some implementations, typical virtualization architectures may not support the transmission of proprietary synchronization messages over data plane communication link 112.

[0072] In some implementations, VSX can refer to the virtualization of aggregation switches or core switches, allowing two physical switches 107 and 109 to function as a single logical device at Layer 2 while maintaining independent control planes at Layer 3. VSX can enable improved network performance, availability, and redundancy by allowing the two switches 107 and 109 to work together as a unified network switching system 104. From a data path perspective, each virtualized switch 107 or 109 can perform independent forwarding lookups to handle traffic, while some forwarding databases such as Media Access Control (MAC) and Address Resolution Protocol (ARP) tables can be synchronized between the two devices 107 and 109 using the VSX control plane.

[0073] VSF typically combines the control planes of two or more physical switches 107 and 109 into a single unified control plane, while VSX maintains a separate Layer 3 control plane for each physical switch 107 and 109. In some implementations, VSX technology allows two switches 107 and 109 to act as a single logical device at Layer 2 while maintaining a separate Layer 3 control plane. VSF is more commonly used in access layer deployments, while VSX is typically used in aggregation or core layer implementations.

[0074] In some implementations, hardware-level link 116 serves as a hardware-level link to facilitate the exchange of critical control information between switches. In some cases, hardware-level link 116 can operate at Layer 2 or Layer 3 of the OSI model, thus providing flexibility in the implementation of synchronization mechanisms.

[0075] In some implementations, Layer 2 can be the data link layer. In some implementations, Layer 2 can operate at the local network level. In some implementations, Layer 2 can use Media Access Control (MAC) addresses. In some implementations, Layer 2 can handle node-to-node data transmission within the local network segment. In some implementations, Layer 2 can use Ethernet and / or Wi-Fi protocols. In some implementations, Layer 2 can encapsulate data from higher layers into frames by adding headers and trailers. In some implementations, Layer 2 may not route traffic between different networks.

[0076] In some implementations, Layer 3 can be the network layer. In some implementations, Layer 3 can operate across different networks. In some implementations, Layer 3 can use IP addresses. In some implementations, Layer 3 can be responsible for routing data between different networks. In some implementations, Layer 3 can use the IP and ICMP protocols. In some implementations, Layer 3 can encapsulate data from higher layers into packets by adding headers containing routing information. In some implementations, Layer 3 can route traffic between different networks.

[0077] In some implementations, switch virtualization allows two physical switch circuit systems 108 and 110 to function as a single logical device at Layer 2. In other implementations, switch circuit systems 108 and 110 behave as a single switch for local network services. While unified at Layer 2, switch virtualization can maintain independent control planes at Layer 3, allowing each switch circuit system 108 and 110 to make its own routing decisions.

[0078] In some cases, hardware-level link 116 can be configured for redundant LAGs. This configuration can provide multiple physical connections between the first switch circuit system 108 and switch circuit system 110, thereby enhancing the reliability of the synchronization channel. The use of LAGs can allow relatively continuous communication between the first and second switch circuit systems 108 and 110, even if one of the physical links experiences a failure.

[0079] The bandwidth of hardware-level link 116 can be increased from the standard 1Gbps to support more connections per second. This bandwidth increase allows for higher throughput of synchronization messages between the first physical switch circuit system 108 and the second physical switch circuit system 110, thereby allowing the network switching system 104 to handle more network traffic and maintain consistent state information across the first physical switch circuit system 108 and the second physical switch circuit system 110.

[0080] In some implementations, data plane communication link 112 can be used as a data plane communication link between a first switch circuit system 108 and a second switch circuit system 110 (which may include processing component 0 and processing component 1, respectively). Data plane communication link 112 can be directly coupled to processing component 0 and processing component 1 within network switching system 104 in a user-invisible manner. In some implementations, link 112 can be encapsulated within the hardware configuration of network switching system 104. Data plane communication link 112 can provide sufficient bandwidth to move incoming traffic from switch circuit systems 108 and 110 to each other without loss or with minimal loss of packet information.

[0081] In some respects, the data plane communication link 112 can be used as a high-speed, relatively lossless communication channel between nodes within each chassis. This capability allows the network switching system 104 to efficiently handle large volumes of network traffic, potentially reducing latency and improving overall system performance.

[0082] Using data plane communication link 112 for internal communication can also improve the security of network switching system 104 because internal communication between nodes can be hidden from external devices and systems. This hiding can provide an additional layer of protection against potential security threats.

[0083] In some implementations, data plane communication link 112 allows network switching system 104 to present itself as a single virtual switch while internally managing multiple switch circuit systems 108 and 110 that may include processing component circuit systems. When a virtualization table for service routing is configured, network switching system 104 can use data plane communication link 112 as a destination port for internal services between different chassis or nodes.

[0084] For example, in a multicast configuration, the virtualization table of one chassis can route all services to another chassis via data plane communication link 112, while the other chassis can use a combination of data plane communication link 112 and physical ports depending on the destination. This flexible routing capability allows the network switching system 104 to efficiently manage complex network topologies while maintaining a single, uniform switch appearance to external systems and users.

[0085] Data plane communication link 112 also allows for the scalability of network switching system 104. Because additional switches or processing components can be added to the system, data plane communication link 112 provides a consistent and high-performance method for inter-switch communication, allowing the system to grow without significantly increasing complexity or compromising performance. By utilizing data plane communication link 112, network switching system 104 can strike a balance between the benefits of a distributed multi-switch architecture and the relative directness of managing a single logical entity.

[0086] In some implementations, the network switching system 104 may include a first memory (which may be...) Figure 1 A portion of the memory 126 shown stores mappings of virtual ports to at least one of a first group of ports in the first switch circuitry 108 or a second group of ports in the second switch circuitry 110. The mapping presents at least one of the first or second group of ports as a set of virtual ports. This mapping can be used to switch between virtual and physical ports, allowing the network switching system 104 to manage network services in a flexible and efficient manner.

[0087] In some aspects, the network switching system 104 may include software components (e.g., software) and APIs. In some implementations, the software components interact with the API directly or indirectly. The software may include core logic for managing virtualization functions.

[0088] In some implementations, network switching system 104 can internally manage two 24-port processing components (e.g., two or more groups of physical ports) while simultaneously presenting 48 ports (e.g., virtual port groups) to clients. This configuration allows for greater flexibility in hardware design and cost optimization. As an example, a first switch circuit system 108 may include one 24-port processing component (e.g., processing component 0), while a second switch circuit system 110 may include another 24-port processing component (e.g., processing component 1). The controller can manage processing component 0 and processing component 1 in a manner that presents them as a single 48-port switch to external systems and users.

[0089] The data plane communication link 112 between the first switch circuit system 108 and the second switch circuit system 110 can facilitate high-speed communication between the two processing units. This internal communication allows the network switching system 104 to efficiently manage traffic across all 48 ports, potentially improving overall performance and reducing latency of the network switching system 104.

[0090] In some implementations, the network switching system 104 can combine virtual port mappings stored in a first storage device to use uniform chassis identifiers and node identifiers. This combination allows the network switching system 104 to accurately route traffic between the virtual ports presented to clients and the physical ports on the two 24-port processing components. The controller can use this information to manage traffic flow, load balancing, and failover scenarios, potentially improving the reliability and performance of the network switching system 104.

[0091] In some implementations, network switching system 104 can be extended to incorporate additional network switches. For example, a third network switch, including a third set of physical ports, can be added to network switching system 104. The mapping stored in the first memory can be updated to incorporate the third set of physical ports into the virtual port group. This extension allows the system to expand its network capacity while maintaining a uniform virtual switch presentation to clients. The addition of the third network switch can be managed by an API that can receive configuration requests to modify the mapping and update the mapping based on the received configuration requests. This method allows for dynamic expansion of network switching system 104, potentially improving its scalability and flexibility. Although only the addition of a third network switch is described, any number of network switches, such as a fourth network switch, a fifth network switch, etc., can be added.

[0092] When scaling to support more than two processing components or switches, it may be necessary to expand the virtualization table accordingly. For each additional switch added to the topology (which may include a processing component), a new entry in the virtualization table of all existing switches may be appropriate to maintain proper routing paths. This expansion of the virtualization table allows the network switching system 104 to manage service routing across a large number of physical switches while still providing a unified interface to external management systems and users.

[0093] Data plane communication link 112 can provide scaling for network switching system 104. Because additional switches or processing components can be added, data plane communication link 112 can provide relatively consistent and high-performance technology for inter-switch communication. This allows network switching system 104 to grow without significantly increasing complexity or impairing performance.

[0094] The virtualization configuration within network switching system 104 allows such networking features to be implemented as stateful service tracking and associated security functions. By maintaining synchronized state information across first switch circuit system 108 and switch circuit system 110, network switching system 104 allows for relatively consistent application of security policies and prevents potential vulnerabilities that may arise from inconsistent state information across network switching system 104.

[0095] A network architecture for achieving hardware-level synchronization between switches may include a LAG interface 204 connecting network switching system 104 to server 210. In some implementations, network switching system 104 is connected to access network 218 via LAG interface 216, and access network 218 is in turn connected to client device 106.

[0096] Hardware-level link 116 can be a dedicated connection, such as a specific link between two switches in a virtualized pair, for example, the first switch circuitry 108 and the second switch circuitry 110. In some implementations, hardware-level link 116 may be primarily configured to exchange heartbeat messages to verify that the partner switch is operational. In some implementations, hardware-level link 116 can be reused to carry hardware synchronization messages. In some implementations, hardware-level link 116 may be different from data plane communication link 112 used for regular data services (which may be data plane communication link 112).

[0097] Typically, for a 1Gbps connection, hardware-level link 116 may be sufficient for control services, but may not be designed for high-capacity data transmission. In some implementations, hardware-level link 116 can allow maintaining awareness of the state of partner switches in a virtualized topology.

[0098] In some implementations, hardware-level link 116 may become mandatory when implementing stateful synchronization features of a single virtual switch. In some implementations, hardware-level link 116 can provide hardware-level communication and be used to transmit processing component-level messages between the first switch circuit system 108 and the second switch circuit system 110. In some implementations, hardware-level link 116 can provide a dedicated path for control and synchronization services, separate from client data.

[0099] In some cases, one or more hardware synchronization modules (e.g., first and second modules or processors 284 and 294) can be configured to reuse hardware-level link 116 as a stacking link. This reuse can allow hardware-level synchronization messages to be transmitted between the first physical switch circuit system 108 and the second physical switch circuit system 110.

[0100] As an example, a stacking link can be a dedicated high-speed link used to connect a first switch circuit system 108 and a second switch circuit system 110 in a stacked configuration. The stacking link can provide direct hardware-level communication between the switch processing components. The stacking link can be configured to rapidly exchange control and status information between the first switch circuit system 108 and the second switch circuit system 110.

[0101] Stacking links allow the transmission of packets with specific metadata headers that can only be interpreted and processed by the processing component. Stacking links can allow the creation of a single control plane across multiple physical switches (e.g., first switch circuitry and second switch circuitry 108 and 110). In some implementations, stacking links can facilitate automatic hardware-level state synchronization between connected switches. Stacking links can use vendor-specific protocols for inter-switch communication.

[0102] Stacked links can provide higher bandwidth for inter-switch services than standard typical network links. In some implementations, when hardware-level link 116 is a stacked link in a virtualized topology, it allows the carrying of hardware synchronization messages. By reusing hardware-level link 116 to operate similarly to a stacked link, physical switch circuit systems 108 and 110 can benefit from hardware-level synchronization capabilities typically found in stacked switch configurations, without actually implementing a fully stacked solution.

[0103] Reusing hardware-level link 116 as a stacking link functionally transforms it from its original purpose into acting as a stacking link. This reuse allows hardware-level link 116 to carry hardware-level synchronization messages, similar to how links function in a virtualized topology.

[0104] By leveraging the front panel stacking features of the processing components and applying them to a virtualization setup, hardware-level link 116 is reused as a stackable link to utilize virtualization capabilities. In some implementations, reusing hardware-level link 116 as a stackable link can allow the processing components of two virtualized switches to communicate directly, bypassing higher software layers.

[0105] In some implementations, reusing hardware-level link 116 as a stacking link allows for high-speed, low-latency exchange of stateful information between the first switch circuitry 108 and the second switch circuitry 110. In some implementations, reusing hardware-level link 116 as a stacking link allows for hardware-level synchronization without significant modifications to the existing virtualization architecture. In some implementations, for example, by adding new synchronization capabilities while maintaining the original keep-alive functionality, reusing hardware-level link 116 as a stacking link can provide a dual-purpose link.

[0106] In some implementations, reusing hardware-level link 116 as a stacked link allows for stack-like functionality to operate below the OS level, which is relatively invisible to normal switching operations. Utilizing existing dedicated links used for synchronization, rather than burdening data plane communication link 112 or requiring new connections, can improve the performance of individual virtual switches. In some implementations, reusing hardware-level link 116 as a stacked link allows for relatively consistent implementation of stateful features such as firewalls across virtualization pairs.

[0107] In some implementations, if the hardware-level link 116 is not redesigned as a stacked link, it can cause software refactoring, such as code refactoring, architecture changes, reductions in complexity to simplify code structure and thus improve readability and maintainability, performance improvements, a relatively large amount of time and effort to implement changes across multiple software components, the introduction of new vulnerabilities or issues (especially in complex systems), increased project scope, increased time to market, and / or OS-level changes.

[0108] In some implementations, reusing hardware-level link 116 as a stacked link allows for hardware-level stateful synchronization in a virtualized topology without significant software refactoring or hardware changes. Hardware-level link 116 enables efficient, high-speed stateful synchronization between physical switch circuit systems 108 and 110, extending its functionality beyond simply checking the state of partner switches.

[0109] By configuring hardware-level link 116 as a stacking link, the system can facilitate the transmission of hardware-level synchronization messages between the first physical switch circuit system 108 and the second physical switch circuit system 110. This reuse of hardware-level link 116 enables efficient synchronization of stateful service tracing instructions across physical switch circuit systems 108 and 110 without requiring significant changes to the underlying network architecture.

[0110] The hardware synchronization module can use a new processing component application programming interface (API), for example called "pv_vsx", to create stacked topologies under virtualization configurations.

[0111] When performing synchronization operations, the hardware can use a unique replication (REP) entry with a hard-coded multicast index (e.g., called "mcast_idx") and a Virtual Local Area Network (VLAN). This dedicated REP entry facilitates the targeted distribution of synchronization messages between the first physical switch circuit system 108 and the second physical switch circuit system 110, thereby ensuring efficient propagation of state information across the network switching system 104.

[0112] Network switching system 104 may include a hidden virtualization topology that facilitates hardware-level synchronization. LAG interfaces 204 and 216 provide load balancing and redundancy for traffic flowing between connector 130 and client device 106 via network switching system 104.

[0113] In some implementations, LAG can be implemented by combining multiple physical network links into a single logical link. In some implementations, LAG increases bandwidth and provides redundancy. In some implementations, LAG can be implemented on a single switch. In some implementations, LAG conforms to the IEEE 802.3ad standard. In some implementations, LAG distributes traffic across multiple links for load balancing.

[0114] In some implementations, if one link fails, traffic can still flow through the other links in the LAG. In some implementations, the LAG combines the bandwidth of multiple links. In some implementations, the LAG acts as an interface to upper-layer protocols. In some implementations, the LAG can be used to connect switches or servers to switches. In some implementations, the LAG can be a compatible configuration at both ends of a link.

[0115] In some implementations, a Multi-Chassis Link Aggregation Group (MC-LAG) can be an extension of a LAG spanning multiple chassis (or switches). In some implementations, MC-LAG 208 and 214 provide redundancy and load balancing across separate physical switches (e.g., switch circuit systems 108 and 110). In some implementations, MC-LAG 208 and 214 can involve two or more switch circuit systems 108 and 110 that act as a single logical switch.

[0116] In some implementations, MC-LAG 208 and 214 offer greater fault tolerance than standard LAGs. In some implementations, MC-LAG 208 and 214 can proactively forward traffic between two switch circuit systems 108 and 110 essentially simultaneously. In some implementations, state synchronization between participating switches (e.g., switch circuit systems 108 and 110) may be appropriate for implementing MC-LAG 208 and 214. In some implementations, MC-LAG 208 and 214 use proprietary protocols for inter-switch communication.

[0117] This architecture allows for stateful service tracking synchronization between the first physical switch circuit system 108 and the second physical switch circuit system 110, while maintaining normal virtualization operation via the data plane communication link 112.

[0118] Stateful synchronization can be the process of keeping stateful tracking instructions in two virtualized switches relatively consistent with the latest information about network flows, thereby allowing security policies and service processing to remain consistent regardless of which switch circuit systems 108 and 110 handle a given packet.

[0119] In some implementations, stateful synchronization can provide state information, for example, by maintaining and sharing information about the current state of network connections or traffic flows. In some implementations, stateful synchronization can provide real-time or near-real-time exchange of state data between the first switch circuit system 108 and the second switch circuit system 110.

[0120] In some implementations, stateful synchronization allows all participating devices to have the same up-to-date information about the network state. In some implementations, stateful synchronization allows the preservation of the context of network traffic across multiple devices. In some implementations, stateful synchronization can track the state information of various protocols such as TCP, UDP, Internet Control Message Protocol (ICMP), and Fast UDP Internet Connection (QUIC).

[0121] In some implementations, stateful synchronization can allow stateful security features to be implemented across multiple devices, such as firewalls. In some implementations, stateful synchronization can allow tracking of established connections, their progress, and their current state. In some implementations, stateful synchronization can allow dynamic updates by continuously updating state information as network conditions and service patterns change. In some implementations, stateful synchronization can allow relatively consistent behavior across distributed network devices, such as the virtualized pairs in this invention.

[0122] Using a unique chassis ID and a dedicated REP entry allows the network switching system 104 to maintain a clear distinction between normal network traffic and synchronization traffic. This separation can be achieved through more efficient routing of synchronization messages via hardware-level link 116, which can be reused as a stacked link, while minimizing interference with regular data plane operations occurring via data plane communication link 112.

[0123] Figure 3 An exemplary data structure 300 for a stateful traffic tracing and synchronization system, according to some implementation, is shown. Data structure 300 can represent state information maintained by switches in a network device. Data structure 300 includes multiple columns and rows configured to store and organize data for stateful traffic tracing and synchronization between switches.

[0124] In some implementations, data structure 300 includes three columns: a flow ID column 302, a status column 304, and a metadata column 306. The flow ID column 302 may include a unique identifier for each network flow being tracked (e.g., flows 1, 2, and 3 in cells 308, 314, and 320, respectively). This allows the switch to efficiently reference and update information for a specific communication session.

[0125] State column 304 can store the current state of each flow 1, 2, and 3 in cells 308, 314, and 320 respectively (e.g., states A, B, and C in cells 310, 316, and 322 respectively). In some cases, this can include protocol-specific states for TCP connections, such as “SYN SENT,” “ESTABLISHED,” or “FIN WAIT.” For example, “SYN SENT” indicates a TCP connection state where the client has sent a SYN (synchronization) packet to initiate a connection with the server but has not yet received a SYN-ACK (synchronization-acknowledgment) response. In some implementations, this state indicates that a connection attempt is in progress.

[0126] In some implementations, the "ESTABLISHED" state represents a TCP connection state where both the client and server have completed the three-way handshake. In this state, the connection is fully open, and data can be exchanged between the two endpoints.

[0127] In some implementations, the "FIN WAIT" state can be a TCP connection state, occurring when one endpoint has sent a FIN (complete) packet to initiate the connection termination process but is still waiting for acknowledgment and a FIN packet from the other endpoint. Depending on whether the initial FIN has been acknowledged, this state can be further divided into FIN-WAIT-1 and FIN-WAIT-2. For other protocols such as UDP, ICMP, or QUIC, appropriate status indicators can be used to reflect the current state of the communication session.

[0128] Metadata column 306 may include additional information associated with each stream 1, 2, and 3 in units 308, 314, and 320, respectively (e.g., metadata 1, 2, and 3 in units 312, 318, and 324, respectively). Metadata 1, 2, and 3 in units 312, 318, and 324, respectively, may include various types of data, such as source and destination IP addresses, source and destination port numbers for TCP or UDP connections, protocol identifiers, and other details about the communication session.

[0129] In some cases, data structure 300 can store flow packet information and protocol status information for status service tracking. This information allows network switching system 104 to maintain a comprehensive record of ongoing network communications and their current status.

[0130] The status information data structure 300 allows for the maintenance of synchronization status information between the first switch circuit system 108 and the second switch circuit system 110 in the network switching system 104. When a new communication session or a change in the status of an existing session is detected, the first switch circuit system 108 can update its local data structure 300 and generate a hardware-level synchronization message to be sent to other switches (e.g., to the second switch circuit system 110).

[0131] In some cases, these hardware-level synchronization messages can include information stored in a state table, such as flow ID, current state, and associated metadata. This allows receiving switches to update their own state tables, ensuring consistent stateful information across network devices.

[0132] Data Structure 300 can support the tracking and analysis of stateful information for various protocols, including TCP, UDP, ICMP, and QUIC. By maintaining detailed records of each of these protocols, network devices can provide relatively comprehensive stateful service tracing capabilities.

[0133] The synchronization process between the first processor 284 and the second processor 294 may involve the exchange of dedicated messages. These messages may include a stacked header that facilitates routing within the virtualized topology, a metadata layer including relevant state information, and a portion of the original packet data.

[0134] In some cases, the status information stored in data structure 300 and transmitted in the synchronization message may include one or more of the following: source IP address, destination IP address, source TCP port, source UDP port, destination TCP port, destination UDP port, identifier of the new communication session, or protocol status. This relatively granular level of detail enables precise tracking and synchronization of network flows across switches.

[0135] To provide context for synchronization, the hardware-level synchronization message generated based on this data structure 300 can include up to 256 bytes of raw packet data. This additional information can help the receiving switch accurately reconstruct network flows and apply appropriate security policies or service management rules.

[0136] By maintaining and synchronizing the state information data structure 300 across switch circuit systems 108 and 110, network switching system 104 can achieve relatively consistent stateful service tracing and allows for various features across the entire virtual switch framework, such as stateful firewalls and deep packet inspection.

[0137] In some implementations, stateful firewalls track the state of network connections passing through them, allowing or blocking traffic based on the context of the connection rather than just a single packet. By synchronizing state information between the first and second switch circuit systems 108 and 110, respectively, the firewall can maintain consistent behavior across the two switches.

[0138] In some implementations, firewalls track the state of each connection, including information such as: source and destination IP addresses, source and destination ports, protocol (TCP, UDP, etc.), connection state (e.g., SYN sent, SYN-ACK received, ESTABLISHED), and / or the sequence number of the TCP connection.

[0139] In some implementations, a stateful synchronization message is generated when a new connection is established or the state of an existing connection changes on the first switch circuit system. This message can be transmitted to the second switch circuit system via a hardware-level link (keep-alive link). The second switch circuit system then uses this information to update its state table.

[0140] In some implementations, by maintaining synchronized state information, two switch circuits can consistently apply the same firewall rules. For example, if the first switch circuit system allows a connection, the second switch circuit system will also allow packets belonging to that connection, even if it did not see the initial connection established.

[0141] In some implementations, where input and output traffic for a single connection may pass through different switches (asymmetric routing), synchronizing state information allows both switches to have the necessary context to properly handle the traffic.

[0142] In some implementations, if one switch fails, the other switch has the latest state information, allowing it to continue enforcing firewall policies without interrupting or losing connection tracking. In some implementations, by utilizing synchronized state information, the firewall can implement the following security features across two switches: TCP sequence number verification, prevention of spoofing and session hijacking attempts, and / or application layer protocol inspection.

[0143] By performing state synchronization at the hardware level, firewalls can maintain high-speed packet processing while still providing state checks across multiple switches.

[0144] Figure 4 An example stateful traffic tracing synchronization method 400 is illustrated according to some implementations. According to some implementations, method 400 can be a synchronization process for stateful traffic tracing. The synchronization process may involve a first physical switch circuit system 108 (e.g., switch circuit system A), a second physical switch circuit system 110 (e.g., switch circuit system B), and a hardware-level link 116.

[0145] The process begins at step 402, where client device 106 initiates a new communication session by sending a packet to first physical switch circuitry 108. In step 404, first physical switch circuitry 108 forwards the packet to server 210.

[0146] In step 406, the state tracking instruction 454 of the first physical switch circuit system 108 can detect a new communication session and trigger a learning event. This detection can be performed by a first processor 284 associated with the first physical switch circuit system 108. The first processor 284 can be configured to detect new communication sessions at the first physical switch circuit system 108.

[0147] Following the detection, in step 408, the first physical switch circuit system 108 can generate a stateful synchronization message that includes state information about the new communication session. This message may include details such as source and destination IP addresses, port numbers, protocol identifiers, and the current state of the communication session.

[0148] The process continues to step 410, where the first physical switch circuit system 108 transmits a synchronization message to the second physical switch circuit system 110 via hardware-level link 116. Hardware-level link 116 can be configured to transmit heartbeat messages and hardware-level synchronization messages. In some cases, the first processor 284 can prioritize the transmission of heartbeat messages over stateful synchronization messages via hardware-level link 116.

[0149] In step 412, the second physical switch circuit system 110 may receive a synchronization message and update its local stateful tracking instruction 464. This update may involve modifying the state data structure within the second physical switch circuit system 110 based on the received stateful synchronization message.

[0150] In some implementations, state tracking and synchronization instructions 454 and 464 can be stored respectively in the main memories 126 and 136 of each physical switch 107 and 109, in the memories of individual line cards, for example, in the first memory 286 and the second memory 296 of the first switch circuit system 108 and the second switch circuit system 110, or distributed across any of these memories. This relatively flexible storage approach allows for efficient execution of these functions at various levels of the switch architecture.

[0151] Stateful tracing instructions 454 and 464 can be executed by the main processors 122 and 132 of each switch 107 and 109, by processors 284 and 294 on each line card (e.g., the first switch circuit system and the second switch circuit system 108 and 110), or by any combination thereof. This distributed processing allows for relatively efficient handling of stateful operations and synchronization tasks across the virtualized switch architecture.

[0152] In step 414, connector 130 responds to the request from client device 106. Step 416 shows a status tracking instruction 454 from the second physical switch circuit system 110, which identifies flows based on synchronization information. In step 418, return packets can be routed through the second physical switch circuit system 110 due to load balancing.

[0153] In step 419, the second physical switch circuit system 110 can process packets and forward them to the client device 106. This processing can be performed by a second processor 294 associated with the second physical switch circuit system 110. The second processor 294 can determine that the packets are associated with a new communication session based on an updated state data structure and process them accordingly.

[0154] In step 420, the second physical switch circuit system 110 can generate a flow state update synchronization message. In steps 422 and 424, the second physical switch circuit system 110 sends this update message to the first physical switch circuit system 108 via hardware-level link 116.

[0155] In step 426, the first physical switch circuit system 108 receives an update and refreshes its local flow state information. Step 426 may involve resolving any conflicts between the state information in the first physical switch circuit system 108 and the second physical switch circuit system 110 by rewriting the state information in the first physical switch circuit system 108 with the update information from the second physical switch circuit system 110.

[0156] In some cases, a backup filter can be implemented to prevent redundant packet transmission between the first physical switch circuit system 108 and the second physical switch circuit system 110. This filter can identify and block duplicate packets before transmission, thereby improving network efficiency.

[0157] In some implementations, hardware-to-hardware message filters can be used to specify which components require state synchronization. The filter can analyze the message content and destination to determine which hardware components need to be updated when a state change occurs.

[0158] The synchronization process can also include methods for handling potential failures. For example, if hardware-level link 116 fails, the hardware synchronization module can be configured to reroute synchronization services via alternative paths such as other hardware-level links between switch circuit systems 108 and 110 or other available connections. For example, multiple hardware-level links can be distributed across different line cards. This configuration allows for improved reliability by providing redundancy and can increase the bandwidth available for synchronization services in a virtualized setup.

[0159] By implementing this synchronization process, network switching system 104 can maintain consistent stateful information across two physical switches, thereby enabling advanced features such as stateful firewalls and ensuring proper handling of network traffic in a virtualized environment.

[0160] Figure 5 An example of a stateful service tracking synchronization method 500, based on some implementations, is shown. Method 500 can detect and synchronize state changes in computing system 100. Method 500 may include message generation, link availability verification, transmission processing, and acknowledgment steps. Method 500 may include alternative paths based on link availability and successful transmission verification, thereby enhancing the reliability of the synchronization mechanism in the virtualized environment described in the previous figures.

[0161] Method 500 begins at step 502, wherein a new communication session or state change is detected in one of the physical switch circuit systems, which may correspond to a new communication session or state change originating from a physical switch circuit system. Figure 1 The first physical switch circuit system 108 or the second physical switch circuit system 110.

[0162] Method 500 continues to step 504, where a stateful synchronization message is generated, similar to... Figure 4 The process described in step 408. In step 506, relevant status information is included in the message, such as the stream ID and protocol status, which can be stored... Figure 4 The state data structure introduced in [the document / process].

[0163] Method 500 then proceeds to step 508, where the priority of the synchronization messages is determined. Step 508 may involve... Figure 1 The processor 122 and / or the first processor 284 and the second processor 294 from Figure 2 make a decision based on the current network conditions. Following this, in step 510, the processor 122 and / or the first processor 284 and the second processor 294 check the availability of the hardware-level link, which can correspond to... Figure 1 And the hardware-level link 116 shown in Figure 2.

[0164] In step 512, if a hardware-level link is available, the message is transmitted through that link, similar to... Figure 4 The method 400 described in step 410. Alternatively, in step 514, if the link is unavailable, then a link from... Figure 1 The memory 126 serves as a temporary storage device, queuing messages for subsequent transmission.

[0165] Method 500 continues in step 516, wherein the first physical switch circuit system 108 or the second physical switch circuit system 110 confirms successful transmission or initiates a retry if necessary. This step may include Figure 4 The communication between the switch circuit systems 108 and 110 is shown. In some implementations, state information is maintained in data structure 300, which can be implemented in memory 126.

[0166] Figure 6 An example of a stateful traffic tracing synchronization method 600 is shown, based on some implementations. Method 600 can monitor and synchronize hardware-level messages between physical switch circuit systems 108 and 110. Method 600 may include a series of operations for processing incoming synchronization messages, including authentication, state updates, conflict resolution, and acknowledgment processing. Method 600 can use components and methods described in the previous figures, such as switches, communication links, and state information storage devices, while introducing new steps dedicated to the monitoring and synchronization process.

[0167] Method 600 begins at step 602, where processor 122 and / or first stateful tracing instruction 454 and second stateful tracing instruction 464 (e.g., by using a hardware synchronization module, such as first and second processors 284 and 294) monitor the hardware-level link for incoming messages between the two chassis, which may correspond to messages from... Figure 1 The first physical switch circuit system 108 and the second physical switch circuit system 110.

[0168] In step 604, similar to Figure 4 In the process described in step 410, the second physical switch circuit system 110 receives a stateful synchronization message from the first physical switch circuit system 108. Method 600 continues to step 606, where the second physical switch circuit system 110 verifies the integrity and authenticity of the message.

[0169] Method 600 then proceeds to step 608, where the second physical switch circuitry 110 parses the incoming message to extract status information. Step 608 may involve... Figure 1 The processor 122 and / or the second processor 294 from Figure 2 analyze the message content.

[0170] In step 610, the second physical switch circuit system 110 is identified in Figure 3The corresponding local stream or session is introduced into the state data structure 300. In step 612, the local state data structure 300 is updated with the received information. In step 613, subsequent streams (e.g., from server 210) pass through the second physical switch circuit system 110. In step 614, the second physical switch circuit system 110 transmits stateful synchronization information to the first physical switch circuit system 108.

[0171] Method 600 then moves to step 615, where the first physical switch circuit system 108 checks for conflicts with existing local state information. If a conflict is detected, the process continues to step 616, where parsing logic is applied to resolve any differences. Step 616 may involve communication between switch circuit systems 108 and 110, similar to... Figure 4 The process between the first physical switch circuit system 108 and the second physical switch circuit system 110 shown.

[0172] In some implementations, method 600 then proceeds to step 618, where a successful update of the local state at the first physical switch circuit system 108 is acknowledged when the first physical switch circuit system 108 sends an acknowledgment message to the second physical switch circuit system 110. Step 618 may utilize information from... Figure 1 A state data structure 300 (e.g., stored in memory 126) is used to store updated state information.

[0173] Method 600 proceeds to step 620, where, if required by the protocol, the second physical switch circuit system 110 prepares an acknowledgment message. Step 620 may involve... Figure 1 The hardware-level link 116 shown in Figure 2 sends back the message.

[0174] Figure 7 An example of a stateful service tracing synchronization method 700, based on some implementations, is shown. Method 700 can process packets within a synchronization session environment. Method 700 begins at step 702, where subsequent packets related to the synchronization session are received. As an example, a network interface or ingress port of a physical switch circuit system 110 can receive subsequent packets. Step 702 may correspond to... Figure 4 The process described in steps 414 to 419, wherein the return packet is routed through the switch circuit system 110.

[0175] Method 700 continues to step 704, where the second physical switch circuit system 110 identifies the session based on packet information. This step can utilize information from... Figure 1 The processor 122 and / or the second processor 294 from Figure 2 analyze the packet content. For example, the status tracking instruction 464 of the switch circuit system 110 that receives subsequent packets identifies the session.

[0176] In step 706, the second physical switch circuit system 110 from Figure 3 The local data structure 300 introduced in the process retrieves updated states. For example, the second processor 294 of the switch circuit system 110 that receives subsequent packets retrieves updated states from the local state data structure 300.

[0177] Method 700 then proceeds to step 708, where a relevant policy is applied based on the synchronization state. Step 708 may involve processor 122 and / or a second processor 294 to apply the relevant policy based on the synchronization state.

[0178] Subsequently, in step 710, the group is processed according to the current session state, similar to... Figure 4 The process described in step 419. In step 712, if necessary, the local session state is updated based on packet processing. Step 712 may utilize data from... Figure 1 The memory 126 is used to store updated status information.

[0179] Then, method 700 proceeds to step 714, where network switching system 104 determines whether the new state requires synchronization. As an example, a second processor 294, cooperating with the first processor 284 and / or processor 122, can determine whether the new state needs synchronization with peer-to-peer switch circuitry system 108. Step 714 can be similar to... Figure 6 The process described in steps 613 to 615.

[0180] If synchronization is required, method 700 moves to step 716, where the sending process is initiated. Step 716 can be similar to... Figure 4 The process described in steps 422 and 424 involves generating an updated synchronization message and sending it via hardware-level link 116. For example, if synchronization is required, the first processor 284 or the second processor 294 and / or processor 122 can each initiate a sending process to prepare the synchronization message.

[0181] The flowchart then continues to step 718, where normal packet processing continues. This step may involve forwarding packets to their destination, similar to... Figure 4 The process described in steps 418-419. As an example, the packet processing pipeline of the second switch circuit system 110 can continue normal packet processing, which may include forwarding packets to their destination.

[0182] Method 700 proceeds to step 720, where any difference between the expected and actual states is recorded or reported. For example, a recording module and / or processor 122 within the first processor 284 or the second processor 294, or the first switch circuit system 108 or the second switch circuit system 110, records or reports any difference between the expected and actual states.

[0183] Although this invention describes or illustrates specific operations as occurring in a particular order, the invention contemplates that these operations may occur in any suitable order. Furthermore, this disclosure contemplates any suitable operation repeated once or multiple times in any suitable order. While this disclosure describes or illustrates specific operations occurring sequentially, it contemplates any suitable operations that may occur substantially simultaneously, where appropriate. Where appropriate, any suitable operation or sequence of operations described or illustrated herein may be interrupted, suspended, or controlled by another process (e.g., an operating system or kernel). These actions may operate within an operating system environment or as independent routines occupying all or most of the system's processing power.

[0184] Although this disclosure has been described with reference to illustrative implementations, this description is not intended to be limiting. Those skilled in the art will appreciate various modifications and combinations of the illustrative implementations, as well as other implementations of this disclosure, upon reference to this specification. Therefore, the appended claims are intended to cover any such modifications or implementations.

Claims

1. A network switching system, comprising: First switch circuit system; The second switch circuit system is different from the first switch circuit system. The second switch circuit system has a state data structure. A hardware-level link couples the first switch circuit system and the second switch circuit system; as well as A first processor, associated with and configured to: Detect new communication sessions at the first switch circuit system; Generate a stateful synchronization message that includes state information about the new communication session; The stateful synchronization message is transmitted from the first switch circuit system to the second switch circuit system via the hardware-level link; and The state data structure at the second switch circuit system is updated based on the stateful synchronization message received from the first switch circuit system.

2. The network switching system according to claim 1, wherein the hardware-level link is a keep-alive link.

3. The network switching system according to claim 1, further comprising an inter-switch link (ISL) coupling the first switch circuit system and the second switch circuit system, wherein the ISL is separate from the hardware-level link and configured to transmit data plane services between the first switch circuit system and the second switch circuit system.

4. The network switching system according to claim 1, wherein the hardware-level link operates at Layer 2 or Layer 3 of the Open Systems Interconnection (OSI) model.

5. The network switching system according to claim 1, wherein the state information of the stateful synchronization message includes at least one of the following: source Internet Protocol IP address, destination IP address, source Transmission Control Protocol TCP port, source User Datagram Protocol UDP port, destination TCP port, destination UDP port, identifier of the new communication session, or protocol status.

6. The network switching system of claim 1, wherein the network switching system further comprises a second processor associated with the second switch circuitry, the second processor being configured to: Receive subsequent packets related to the new communication session at the second switch circuit system; The subsequent packets are determined to be related to the new communication session based on the updated state data structure; as well as The subsequent grouping is processed based on the updated state data structure.

7. The network switching system of claim 1, wherein the first processor is further configured to prioritize the transmission of heartbeat messages over the transmission of stateful synchronization messages via the hardware-level link.

8. The network switching system of claim 1, wherein the first switch circuitry is in a first chassis and the second switch circuitry is in a second chassis, the first chassis and the second chassis being configured as a Virtual Switching Extension (VSX) pair.

9. The network switching system according to claim 1, wherein the first processor is further configured to: Detecting conflicts between the state information in the first switch circuit system and the state information in the second switch circuit system; and The conflict is resolved by rewriting the state information in the second switch circuit system with the state information from the first switch circuit system.

10. The network switching system of claim 1, wherein the network switching system is configured to operate as a stateful firewall using state information synchronized between the first switch circuit system and the second switch circuit system.

11. A network device, comprising: A first switch circuit system is configured to be coupled to a second switch circuit system via a data plane communication link to transmit data plane services between the first switch circuit system and the second switch circuit system. Processor, the processor being configured to: Detect new communication sessions in the first switch circuit system; Generate a stateful synchronization message including state information about the new communication session; and The stateful synchronization message is transmitted from the first switch circuit system to the second switch circuit system via a hardware-level link, wherein the first switch circuit system is configured to be physically coupled to the second switch circuit system via the hardware-level link.

12. The network device according to claim 11, wherein the hardware-level link is a keep-alive link.

13. The network device of claim 11 further includes an inter-switch link (ISL) coupling the first switch circuit system and the second switch circuit system, wherein the ISL is decoupled from the hardware-level link and configured to transmit data plane services between the first switch circuit system and the second switch circuit system.

14. The network device of claim 11, wherein the hardware-level link operates at Layer 2 or Layer 3 of the Open Systems Interconnection (OSI) model.

15. The network device of claim 11, wherein the network device further comprises: A first processor, associated with and configured to: The state data structure at the second switch circuit system is updated based on the state synchronization message received from the first switch circuit system; as well as A second processor, associated with the second switch circuitry, is configured to: Receive subsequent packets related to the new communication session at the second switch circuit system; The subsequent packets are determined to be related to the new communication session based on the updated state data structure; as well as The subsequent grouping is processed based on the updated state data structure.

16. A computer-implemented method, comprising: Detect new communication sessions at the first switch circuit system; Generate a stateful synchronization message that includes state information about the new communication session; The stateful synchronization message is transmitted from the first switch circuit system to the second switch circuit system via a hardware-level link, wherein: The first switch circuit system is different from the second switch circuit system; The second switch circuit system has a state data structure; and The hardware-level link couples the first switch circuit system and the second switch circuit system; and The state data structure is updated at the second switch circuit system based on the stateful synchronization message received from the first switch circuit system.

17. The computer-implemented method according to claim 16, further comprising: The hardware-level link prioritizes the transmission of heartbeat messages over the transmission of stateful synchronization messages.

18. The computer-implemented method of claim 16, wherein the first switch circuitry is in a first chassis and the second switch circuitry is in a second chassis, the first chassis and the second chassis being configured as a Virtual Switch Extension (VSX) pair.

19. The computer-implemented method according to claim 16, further comprising: Detect the conflict between the state information in the first switch circuit system and the state information in the second switch circuit system; as well as The conflict is resolved by rewriting the state information in the second switch circuit system with the state information from the first switch circuit system.

20. The computer-implemented method of claim 16, wherein the first switch circuit system and the second switch circuit system are configured to operate as a stateful firewall using state information synchronized between the first switch circuit system and the second switch circuit system.