Fabric availability and synchronization

The FAS agent in network devices autonomously manages and synchronizes configurations, addressing network disruptions by ensuring consistent updates and redundancy, thereby reducing downtime and inconsistencies in large distributed networks.

JP2026035774APending Publication Date: 2026-03-04ORACLE INT CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-12-02
Publication Date
2026-03-04

AI Technical Summary

Technical Problem

Large networks with distributed devices across wide geographic areas face disruptions due to network device failures, requiring manual configuration updates that can lead to inconsistent configurations and downtime.

Method used

Implementing a Fabric Availability and Synchronization (FAS) agent in network devices to autonomously manage and synchronize configurations, determining a primary FAS agent based on device characteristics, and using virtual local area networks for communication to propagate configuration changes and ensure fault tolerance.

Benefits of technology

This approach reduces downtime and inconsistencies by automatically synchronizing configuration changes across the network, ensuring seamless communication and redundancy, thus enhancing network availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026035774000001_ABST
    Figure 2026035774000001_ABST
Patent Text Reader

Abstract

To provide a method and system for implementing Fabric Availability and Synchronization (FAS) agents in a fabric network.SOLUTION: A first FAS agent executing on a first network device receives a command from a second network device to modify a configuration of the second network device and updates a configuration of the first network device from a current configuration to a new configuration based on the command. The first FAS agent increments the state identifier associated with the configuration of the first network device to a new state identifier associated with the new configuration. The first FAS agent then sends a control packet including the new state identifier. A second FAS agent executing on the second network device receives the control packet and executes the command to update the configuration of the second network device to the new configuration.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] REFERENCE TO RELATED APPLICATIONS This application claims the benefit of and priority under 35 U.S.C. §119(e) of U.S. Nonprovisional Application Serial No. 17 / 147,327, filed January 12, 2021. The entire contents of the foregoing application are incorporated herein by reference in their entirety for all purposes.

[0002] Technical Field The present disclosure relates generally to distributed network management. More particularly, but not by way of limitation, the present disclosure relates to a fabric availability and synchronization agent for management of fabric networks. [Background technology]

[0003] background Modern networks are often managed by multiple interconnected devices. For example, a business network may include a large number of workstations. The network may be managed by a network administrator who employs a series of routers and / or switches to manage communications for the workstations. Some networks, such as those operated across a university campus or very large enterprise, may operate over a large geographic area. To maintain connectivity, these networks may employ layers of network devices that relay communications to a central server or trunk across the network. A micro layer may maintain connectivity at a particular micro-location (e.g., a building), and a macro layer may maintain connectivity across multiple micro-locations (e.g., a network of multiple buildings). If a network device at the micro or macro layer stops operating (e.g., due to server maintenance, software failure, network intrusion, etc.), communications across the network may be disrupted to the point of being ineffective. Summary of the Invention

[0004] overview Various methods and systems may relate to updating a configuration of a network device in a fabric network. One method includes, at a first network device in the fabric network, receiving, from a second network device in the fabric network, an identification of a command to modify a current configuration of the second network device, the first network device being configured according to the current configuration, the method further including a first Fabric Availability and Synchronization (FAS) agent executing on the first network device authenticating the command, and in response to authenticating the command, the first network device modifying the current configuration of the first network device based on the command, wherein modifying the current configuration of the first network device defines a new configuration. the method further includes storing an identification of the command; and in response to modifying the current configuration of the first network device, updating a state identifier associated with the current configuration of the first network device to correspond to a new state identifier associated with the new configuration; and the first FAS agent sending a control packet including the new state identifier to a second FAS agent executing on a second network device of the fabric network, wherein upon receiving the control packet, the second FAS agent retrieves the identification of the command and implements the command on the second network device to upgrade the current configuration of the second network device to the new configuration.

[0005] Another aspect of the present disclosure includes a system comprising one or more processors and a non-transitory computer-readable medium comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform some or all of the methods described herein.

[0006] Another aspect of the present disclosure includes a non-transitory computer-readable medium containing instructions that, when executed by one or more processors, cause the one or more processors to perform some or all of one or more of the methods described herein.

[0007] These illustrative examples are mentioned not to limit or define the present disclosure, but to provide examples to aid in its understanding. Further embodiments are discussed in the Detailed Description, where further description is provided. [Brief explanation of the drawings]

[0008] [Figure 1] 1 illustrates an example of a fabric network according to an aspect of the present disclosure. [Figure 2] FIG. 1 illustrates an example block diagram of a FAS-managed network device according to an aspect of the present disclosure. [Figure 3] 1 illustrates an example process for selecting a primary FAS agent according to an aspect of the present disclosure. [Figure 4] 1 illustrates an example process for managing the configuration of a fabric of network devices according to an aspect of the present disclosure. [Figure 5] FIG. 1 illustrates an example process for updating a configuration of a fabric of a network device according to an aspect of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0009] Detailed Description The present disclosure relates to an improved network topology that is semi-autonomously managed by a fabric availability and synchronization (FAS) agent. Networks are often managed using network devices (e.g., devices that facilitate communication with other devices) that connect devices to other devices within the network and to devices outside the network. Large networks with a large number of connected devices and / or devices distributed over a wide geographic area may use a large number of network devices to connect all of the devices in the network. These large networks may operate a fabric network (e.g., sometimes referred to as a switched fabric), where devices in the network are interconnected through multiple network devices (as distinguished from a broadcast network in which one network device exclusively manages communications for several devices).

[0010] Network devices in a fabric network may be provisioned with a fabric availability and synchronization agent to manage the operation of the fabric network and the network devices that comprise the fabric network. In some cases, other devices in the network (e.g., workstations, servers, etc.) may also be provisioned with FAS agents. A FAS agent manages the operation of the network device on which it runs and communicates with other FAS agents to synchronize the operation of the fabric network. FAS agents may provide fabric-level management of network devices, enabling management of network devices in a fabric network from a single network device.

[0011] When a FAS agent runs, it configures the FAS agent based on one or more characteristics of the FAS agent or the characteristics of the network device on which the FAS agent runs. A hierarchy of FAS agents may be automatically defined for each FAS agent. For example, the FAS agent may determine which FAS agent is best suited to act as the primary FAS agent based on the characteristics of each FAS agent or network device. Examples of one or more characteristics may include, but are not limited to, available bandwidth, available processing resources processors and / or memory, the number of devices connected to the network device, the quality of the connection with another network device or server, etc.

[0012] In one example, to determine the primary FAS agent, each FAS agent may derive a priority value indicating the FAS agent's suitability to be the primary FAS agent. The priority value may be derived from characteristics of the FAS agent and / or the network device on which the FAS agent executes. Each FAS agent may then claim the role of primary FAS agent by sending a control packet to other FAS agents that includes a priority value. Upon receipt by a particular FAS agent, the particular FAS agent may compare the priority value from the control packet with the priority value associated with the particular FAS agent. If the priority value of the control packet is greater than the priority value associated with the particular FAS agent, the particular FAS agent may relinquish the primary role to the other FAS agent. Otherwise, if the priority value of the particular FAS agent is higher than the priority value of the other FAS agent, the particular FAS agent becomes the primary FAS agent. The particular FAS agent may then send a control packet to the other FAS agents to confirm to them that the particular FAS agent is the primary FAS agent. In some cases, a particular FAS agent may periodically send primary packets to other FAS agents to maintain its status as the primary FAS agent. If at any time a particular FAS agent receives a priority value from another FAS agent that is greater than the particular FAS agent's priority value, the particular FAS agent may relinquish its status as the primary FAS agent to that FAS agent. If the primary FAS agent fails, the other FAS agents may select a new primary FAS agent, thereby providing fault tolerance and redundancy in the fabric network.

[0013] FAS agents may communicate with other FAS agents using resources of a network device. In some cases, FAS agents may use network channels similar to those used by the network device to connect devices in the network. In other cases, FAS agents may use isolated communication channels of the network device. For example, a network device may include a management channel that allows external devices to send commands to the network device. To facilitate FAS agent communication, a virtual local area network (VLAN) may be established using the management channel. A VLAN may be a private network operating in parallel with connections managed by the network device that may be usable by FAS agents and network administrators. A VLAN may be inaccessible to devices in the fabric network (e.g., devices that rely on the network device for connectivity).

[0014] The primary FAS agent may manage the configuration of the fabric network. The primary FAS agent synchronizes configuration changes for one network device with other network devices in the fabric network. For example, a command to modify the configuration of a particular network device in the fabric network is sent to the primary FAS agent. The modifications to the configuration may be propagated to the FAS agent. The primary FAS agent may authenticate the modifications to the configuration and propagate the modifications to the configuration to other network devices in the fabric network. Similarly, if it is determined that the current configuration causes an error, the FAS agent can propagate a rollback of the current configuration to the previous configuration. Modifications to the configuration of network devices in the fabric network may be achieved without having to modify each network device individually. In some examples, modifications to the configuration may be obtained by other network devices from the primary FAS agent. In other cases, modifications to the configuration may be obtained from a FAS agent running on a network device that operates the modified configuration.

[0015] Integrating FAS agents into a Fabric network may provide several advantages. FAS agents may improve Fabric availability by avoiding incorrect and inconsistent configurations, thereby reducing downtime and grayouts. FAS agents may also synchronize the state of individual network devices in the Fabric network by propagating changes to the network to FAS agents running on each network device. Changes on one network device may be authenticated, and the same changes may be implemented across the Fabric network without the need to modify each network device individually.

[0016] FIG. 1 is a diagram illustrating an example of a network fabric according to aspects of the present disclosure. The fabric environment 100 may include multiple devices connected through one or more network devices. The fabric network 100 may include multiple interconnected network devices. Each network device, such as network devices 104, 108, and 116, may include any type of device that facilitates communication, such as, but not limited to, a router, a gateway, a network switch, a proxy device, etc. The network devices may also maintain connections between one or more other network devices or between all other network devices (e.g., as shown) to provide network security and communication redundancy for the fabric network 100. The one or more other devices may be any type of device to which communications originate or to which communications are addressed. Examples of devices that may be included in the one or more other devices include, but are not limited to, a server, a computing device, a network device, a mobile device, etc.

[0017] Establishing fabric network 100 may include provisioning a fabric availability and synchronization (FAS) agent in each network device. For example, network device 104 may be provisioned with FAS agent 108, network device 112 may be provisioned with FAS agent 116, and network device 120 may be provisioned with FAS agent 124. Each FAS agent may establish a private connection with at least one other network device (and up to all other network devices). For example, each network device may include a management channel through which remote devices may issue commands to the network device. In some cases, each FAS agent may configure a virtual local area network (VLAN) over the management network. For example, FAS agent 108 may establish VLAN 128 on network device 104. FAS agent 116 may establish VLAN 128 on network device 112. FAS agent 108 may establish VLAN 128 on network device 120. The management channel may be a channel isolated from connections managed by the network devices. As a result, the network device is configured to allow devices in the network environment 100 (other than the network devices 104, 108, and / or 112) to use the VLAN 116. The device may be configured to prevent communication via the

[0018] When a FAS agent first runs, it may determine which FAS agent in the fabric network will be the primary FAS agent. For example, network device 104 may be the first network device added to the network. When FAS agent 108 runs, it may identify predetermined characteristics of network device 104 to derive a priority value. The predetermined characteristics may correspond to available bandwidth, available processing resources processors and / or memory, the number of devices connected to the network device, the quality of the connection with another network device or server, a combination thereof, etc. Because FAS agent 120 is the only FAS agent running, the FAS agent may be the primary FAS agent by default.

[0019] Network device 112 and network device 120 may be added to the fabric network. When FAS agent 116 and FAS agent 124 are executed by network device 112 and network device 120, respectively, FAS agent 116 and FAS agent 124 may determine their respective priority values. FAS agent 116 may broadcast its priority value to each of the other FAS agents (e.g., FAS agent 108 and FAS agent 124). Similarly, FAS agent 124 may broadcast its priority value to each of the other FAS agents (e.g., FAS agent 108 and FAS agent 116). In some cases, upon receiving priority values ​​from FAS agent 116 and FAS agent 124, FAS agent 108 may generate a new priority value (to ensure that the priority value reflects the current operating characteristics of network device 104).

[0020] The FAS agent 108 may determine whether its priority value is greater than any of the received priority values. If the FAS agent 108 includes the maximum priority value, the FAS agent 108 may send a control packet over the VLAN 116 to the FAS agent 116 and the FAS agent 124 to declare the FAS agent 104 as the primary FAS agent for the fabric network 100. In some cases, the FAS agent 108 may also send its priority value over the VLAN 116 so that the FAS agent 116 and the FAS agent 124 may independently verify that the FAS agent 108 is the primary FAS agent. If the priority value of the FAS agent 108 is not greater than the priority values ​​of the FAS agent 116 and the FAS agent 124, the FAS agent 108 may send a control packet to the FAS agent with the greater priority value to relinquish its role as the primary FAS agent.

[0021] The FAS agent may derive a priority value for the network device on which it executes at any time. In some cases, the priority value may be determined at regular intervals, by receiving user input, by receiving a command to generate and / or transmit a priority value from another network device, by detecting the occurrence of an event (e.g., a configuration change, a change in network topology, a change in processing resources of a network device, a change in bandwidth or signal quality of a network device, combinations thereof, etc.), or combinations thereof, etc.

[0022] The fabric network 100 may facilitate communication between devices within the fabric network 100 and between devices of the fabric network 100 and external devices. For example, the network device 104 may communicate with one or more servers 132. , computing device 136-1, and computing device 136-2. A computing device may be any type of network-enabled electronic device, such as a computer, a mobile device (e.g., a smartphone, a wearable device, etc.), a server, a smart device (e.g., a network-enabled automation device, etc.), or a network device. In some examples, a computing device may include one or more virtual devices. For example, a computing device may run one or more virtual machines, each emulating a hardware platform. In these cases, network device 104 may facilitate communications for the computing device and each virtual machine (e.g., treated as separately addressable and distinct computing devices). Network device 112 may also include one or more servers 140 and computing devices 144-1 and 144-2. Network device 120 may include one or more servers 148 and computing devices 152-1 and 152-2.

[0023] In some instances, some devices may connect to more than one network device. For example, one or more servers 148 may maintain connections with each of network devices 112 and 120. In these examples, FAS agent 116 and FAS agent 120 may operate a joint subnet mask that defines the addresses of the one or more servers 148. The joint subnet mask may be based on a dynamic routing protocol managed by the FAS agent that enables the FAS agent to route communications to one or more servers 148 through the connected network devices 112 or 120 based on the current status of fabric network 100. The current status of fabric network 100 may be based on, but is not limited to, throughput through fabric network 100, processing resources available to network device 116 and / or network device 120, signal quality, network load of network device 116 and / or network device 120, combinations thereof, etc. When a communication addressed to one or more servers 148 is received by the fabric network 100, the FAS agent may use the joint subnet mask to determine which connection to use to route the communication to the one or more servers 148.

[0024] Network devices of fabric network 100 may include a common configuration. For example, network device 104 may include a common configuration that is also included in network devices 116 and 120. In broadcast and mesh networks, modifying the configuration of a network device such as network device 104 (e.g., causing a configuration inconsistency) may prevent communications addressed to downstream devices (e.g., devices such as devices 140, 144-1, 144-2, 148, 151-1, and 152-2) from propagating through the network to the destination device. A network administrator may then have to connect to each network device individually to modify its configuration to match the configuration of network device 104.

[0025] Fabric network 100 may automatically synchronize configuration changes throughout the network to prevent inconsistent configurations and ensure that communications continue to propagate throughout the network when configurations are updated. For example, a modification to the configuration of network device 112 may be received. If network device 112 includes a primary FAS agent, the primary FAS agent (e.g., FAS agent 116) may authenticate the configuration change. Authentication may involve (e.g., determining which users are authorized to make the modifications). The authentication may include security authentication (ensuring that the modification was generated by a trusted third party) and / or operational authentication (ensures that the modification does not disrupt the operation of fabric network 100 and / or communications transmitted over fabric network 100). If the modification is authenticated, FAS agent 116 increments the configuration version of network device 112's configuration. FAS agent 116 may then send control packets over VLAN 128 to FAS agent 108 and FAS agent 124 providing the incremented configuration version identifier. FAS agent 108 and FAS agent 124 may then retrieve the modifications to network device 112's configuration (and / or network device 112's current configuration) from network device 112 over VLAN 128.

[0026] If the FAS agent 116 is not the primary FAS agent, the FAS agent 116 may send an identification of the modification to the primary FAS agent, which may then authenticate the modification and, if authenticated, send a control packet to the other FAS agents over VLAN 128.

[0027] A similar process may occur if the FAS agent determines that the current configuration contains a fault. The FAS agent first determines whether a rollback is required, for example, by testing the configuration, determining that there have been a predetermined amount of reported faults, testing throughput through the fabric network 100, determining whether a predetermined amount of communications was not delivered, or a combination thereof. For example, if the current configuration of the network device 104 contains a fault, the FAS agent 108 may determine whether a rollback is required. If a rollback is required, the FAS agent 108 may cause the network device 104 to roll back to a previous configuration, which may be known to be a good configuration. If the FAS agent 108 is the primary FAS agent, the FAS agent 108 may cause the network device 104 to revert to a previous known good configuration and decrement the version identifier of the network device 104's configuration to the version identifier of the known good configuration. The FAS agent 108 may then send a control packet to the FAS agent 116 and the FAS agent 124 that includes an identification of the new (decremented) configuration version identifier.

[0028] If the FAS agent 108 is not the primary FAS agent, the FAS agent 108 may send an identification of the rollback to the primary FAS agent. The primary FAS agent may then determine whether a rollback is required (e.g., using a similar process performed by the FAS agent 108). If a rollback is required, the primary FAS agent may perform the rollback on the primary FAS agent's network device and send a control packet containing the new (decremented) configuration identifier to each of the other FAS agents. The other FAS agents may either perform a similar rollback (if their network devices contain instances of the previous configuration) or obtain the previous configuration from the primary FAS agent.

[0029] Although three network devices are illustrated (e.g., network devices 204, 212, and 220), each facilitating communications for three devices (e.g., devices 132, 136-1, 136-2, 140, 144-1, 144-2, 148, 152-1, and 152-2), any number of network devices may be operable within the fabric network. Each network device may facilitate communications for any number of devices.

[0030] FIG. 2 illustrates an example block diagram of a FAS-managed network device according to aspects of the present disclosure. Fabric networks, such as fabric network 100 of FIG. 1, may be used in different types of environments, such as enterprise networks, control centers, residential networks, etc. Some environments, such as control centers, may use a spine-leaf architecture. A spine tier (e.g., spine devices 204-1 through 204-n) may include network devices that interconnect leaf tier devices in a mesh network topology. Each spine device may be provisioned with a respective FAS agent (e.g., FAS agent 208-1 may run on spine 1 204-1, FAS agent 208-n may run on spine n 204-n, etc.).

[0031] The leaf tier (e.g., computing devices 212-1 through 212-n) may include access devices that aggregate traffic from servers, client devices, user devices, etc. Computing devices 212-1 through 212-n may include one or more leaves (e.g., leaves 216, 224, 244, and 248), each including one or more FAS agents (e.g., FAS agents 220, 228, 252, and 256) that manage the network operations of one or more devices embedded within computing devices 212-1 through 212-n. For example, computing device 212-1 may include leaf 216 running FAS agent 220 and leaf 224 running FAS agent 228. FAS agent 220 may be executed to manage the network operations of devices 232-1, 232-2, 232-3, etc. Devices 232-1, 232-2, 232-3, etc. may include computing devices operating within a control center. In some cases, a computing device may incorporate other devices (e.g., physically or virtually). For example, device 232-3 may be a physical computing device that runs virtual machine 236 and virtual machine 240. Virtual machine 236 and virtual machine 240 may be executed to emulate different execution environments for one or more other devices (e.g., client devices, user devices, other computing devices, etc.) or to provide an execution environment configured for the execution of a particular application.

[0032] Leaf device 216 (and FAS agent 220) and leaf tier 224 (and FAS agent 228) may each manage devices 232-1, 232-2, 232-3, etc., over different communication channels (e.g., as shown) or over the same communication channel (not shown). The leaf tier may manage any number of devices in addition to devices 232-1, 232-2, 232-3 as shown. Each device managed by the leaf tier may run any number of virtual environments. For example, computing device 212-n includes leaf 244, which runs FAS agent 252, and leaf 248, which runs FAS agent 256. Leaf 244 and leaf 256 may each manage devices 260-1, 260-2 through 260-n.

[0033] Each leaf may be connected to each spine to enable management redundancy within each computing device in the leaf tier. For example, if leaf 216 fails or becomes unresponsive, leaf 224 may continue to manage devices 232-1, 232-2, and 232-3. Additionally, because leaf 224 maintains independent connections to spines 204-1 through 204-n and FAS agents 208-1 through 208-n, the FAS agents in the fabric network may continue to manage the network operation of each device (physical or virtual) in the fabric network. For example, with leaf 216 disabled, FAS agent 228 in leaf 224 may continue to manage the network operation of the spine tier. The FAS agent 208 may continue to communicate with the other FAS agents 208-1 to 208-n.

[0034] FAS agents may communicate with each other to determine which FAS agent will be the primary FAS agent. In some examples, FAS agents may communicate over a separate management channel. For example, a FAS agent may establish a VLAN over a separate management channel to establish communication with other FAS agents that is separate from the network operations managed by the FAS agent. Because the FAS agents perform redundant network management operations, the control center may not need to allocate external hosts and / or servers to manage the redundancy or network operations (because the redundancy and network operations are managed by the FAS agents).

[0035] A control center administrator may execute commands across the entire fabric network by executing the command on a single device managed by a FAS agent. The FAS agent may identify the command to a primary FAS agent. The primary FAS agent may authenticate the command and propagate the command to other FAS agents. The other FAS agents may then execute the command on the devices they manage. A peer-to-peer selection protocol (e.g., over a VLAN) may provide synchronization within the fabric network. In some cases, a state machine may be used by FAS agents to manage configuration and command synchronization.

[0036] FIG. 3 illustrates an example process for selecting a primary FAS agent according to aspects of the present disclosure. In block 304, the process begins when the FAS agent is initialized. The FAS agent may be initialized when it is first provisioned (e.g., when the FAS agent first runs on the network device) or when the network device is added to a fabric (or any other type of network). For example, when a network device is added to a network, a FAS agent already running on the network device may be initialized. In block 304, the FAS agent may determine a priority value based on characteristics of the network device on which the FAS agent runs. The priority value may be based on one or more performance metrics of the network device, including, but not limited to, currently available processing resources (e.g., memory and / or processor resources), throughput, bandwidth, signal quality for one or more devices managed by the network device, the number of devices managed by the network device, physical proximity to other network devices, or a combination thereof.

[0037] The FAS agent may compare the priority value with a current priority value, which may be the priority value of the current primary FAS agent. If the FAS agent determines that the network device's priority value is higher than the current priority value, the process continues to block 308. If the FAS agent determines that the network device's priority value is lower than the current priority value, the process continues to block 320, where the FAS agent may start a timer and wait for a predetermined time interval (e.g., n seconds).

[0038] In block 308, the FAS agent claims the role of primary FAS agent in response to determining that the priority value of the FAS agent is higher than the current priority value. The current priority value may be set to the priority value of the FAS agent. The FAS agent may send a priority control packet upon expiration of a predetermined time interval (e.g., every i seconds). The priority control packet is used to notify the FAS agent of the fabric network priority. The priority control packet may be sent across a VLAN established by the agent. The priority control packet may provide an indication to other FAS agents running on the fabric network that this FAS agent is the current primary FAS agent.

[0039] The FAS agent may then execute two parallel processes. During the first process, the FAS agent may compare the priority value of the FAS agent with the current priority value. If the priority of the FAS agent is greater than or equal to the current priority value, the process waits for a predetermined time interval and returns to block 208. This process may be repeated as long as the priority value of the FAS agent is greater than or equal to the current priority value.

[0040] The (now) primary FAS agent may then proceed to block 312, where the FAS performs the duties of the primary FAS agent (e.g., synchronizing the operation of the network device with other FAS agents in the fabric network). In block 312, the primary FAS agent may send a keep_alive control packet every x seconds. The keep_alive control packet may include an indication of the current configuration of the primary FAS agent's network device (which should be the configuration of each network device in the fabric network). FAS agents running on other network devices may then determine whether the network device is running the configuration version indicated in the keep_alive control packet. If the network device is running the configuration version indicated in the keep_alive control packet, those FAS agents may not perform any additional processing. If a FAS agent determines that the network device on which it runs is not running the configuration version identified by the keep_alive control packet, that particular FAS agent may retrieve the current configuration version.

[0041] In some examples, a fabric network may operate in a pull model. In those cases, a particular FAS agent may use a keep_alive control packet to determine where to obtain the current configuration version. For example, the keep_alive control packet may include an identification of a control base or repository from which the particular FAS agent can obtain the current configuration version. A particular FAS agent may send a control packet to a primary FAS agent indicating that the particular FAS agent is in the process of updating the configuration of the network device on which the particular FAS agent executes. The particular FAS agent may send another control packet to the primary FAS agent indicating that the configuration version of the network device is now current. In a push model, a particular FAS agent may receive the current configuration version from the primary FAS agent (e.g., in a keep_alive control packet, at the request of the particular FAS agent).

[0042] The primary FAS agent may periodically receive priority values ​​from the other FAS agents. For example, each FAS agent may transmit its priority value at predetermined time intervals (e.g., every n seconds according to block 320) upon receiving user input and / or detecting the occurrence of an event (e.g., a change in network topology, such as a new device being added to or removed from the fabric network, a predetermined change in throughput, a predetermined change in bandwidth, a predetermined change in processing resources, a predetermined change in signal or channel quality, a combination thereof, etc.). In some instances, the primary FAS agent may also update its priority value at predetermined time intervals upon receiving user input and / or detecting the occurrence of an event.

[0043] (If the primary FAS agent's priority value is greater than the received priority value, the primary FAS agent may continue to send a keep_alive control packet every x seconds.) If the primary FAS agent's priority value is not greater than either of the received priority values, the two parallel processes may stop processing blocks 308 and 312, respectively. For example, the first parallel process may stop execution of block 308 and continue to block 320, where the FAS agent may start a timer (e.g., of length n seconds) and wait. The second parallel process may stop execution of block 312 and continue to block 316.

[0044] In block 316, the primary FAS agent may send an m_yield control packet to the FAS agent with the highest priority value. The Mari FAS agent may send an m_yield control packet to each FAS agent in the Fabric network, which then establishes a new primary A new primary control packet may be expected from the FAS agent that is to become the FAS agent. The primary FAS agent's designation may then be modified to remove the primary role (e.g., the primary FAS agent becomes a regular FAS agent). The process for the (currently non-primary) FAS agent proceeds to block 320. In some examples, a second parallel process may reach block 320 at the same time as the first parallel process. The two parallel processes of the FAS agent may then merge into a single process (e.g., one of the parallel processes may terminate).

[0045] In some cases, the FAS agent may generate a new priority value upon expiration of the timer in block 320 (e.g., after n seconds). Alternatively, the FAS agent may generate a new priority value during the timer's time interval (e.g., before the timer expires). Alternatively, the FAS agent may still retain the previous priority value. For example, if the fabric network and / or the network device on which the FAS agent runs has not changed since the last time the FAS agent generated a priority level, the FAS agent may continue to use that priority level for future primary FAS agent determinations.

[0046] The FAS agent may then compare the FAS agent's priority value with the priority value of the current primary FAS agent. If the FAS agent's priority value is greater than the priority value of the current primary FAS agent, the process returns to block 308. The FAS agent becomes the primary FAS agent and sends a primary control packet to the previous primary FAS agent indicating that the FAS agent is the new primary FAS agent. If the FAS agent's priority value is greater than the priority value of the current primary FAS agent, the process remains at block 320. The FAS agent restarts a timer (e.g., corresponding to a time interval of n seconds) and waits. (e.g., upon expiration of the timer after n seconds), the FAS agent may again determine whether the FAS agent's priority value is greater than the priority value of the current primary FAS agent. The timer in block 320 may repeat indefinitely until, at the expiration of the predetermined time interval, the FAS agent determines that the FAS agent's priority value is greater than the priority value of the current primary FAS agent.

[0047] FIG. 4 illustrates an example process for managing the configuration of a fabric of network devices according to aspects of the present disclosure. A FAS agent may synchronize the configuration state of network devices in a fabric network. In some cases, the FAS agent may use a state machine that characterizes the current configuration as a separate state. Any change to the configuration may be characterized by the state machine as a new state, and the change to the configuration is identified as a means to transition from the previous state to the new state. FAS agents may store the identification of the change locally (e.g., in each FAS agent) or in a repository. A FAS agent running on a network device operating an old configuration state may upgrade to the current state by implementing the identification of the change to the configuration. That FAS agent may obtain the identification of the change to the configuration from a FAS agent running on a network device operating the current state (e.g., that is the primary FAS agent or an agent that has already been upgraded) or from the repository.

[0048] Alternatively, a network device's configuration may be assigned a version identifier. When a configuration is changed, the configuration's version identifier may be incremented to indicate the new configuration. FAS agents may store an identification of changes to the configuration with each FAS agent and / or in a repository accessible by the FAS agent. A FAS agent operating on a network device with an older version identifier may upgrade to the current version identifier by obtaining an identification of changes to the configuration from an already upgraded FAS agent or from the repository. Additionally, if the current configuration has a failure, the FAS agent undoes the change to a fix by using the identification of the change to roll back (e.g., decrement) the version identifier. Each change to the configuration may increment the version identifier by a predetermined amount. As a result, a FAS agent may determine the extent to which the configuration may have changed from the difference between the current version identifier of the network device on which it operates and an incremented version identifier associated with another network device.

[0049] The process may begin with a primary FAS agent running on the network device retaining its primary role (e.g., waiting to process input from another FAS agent or a user device) (step 1). In step 2, a command line interface (CLI) command may be received by network device 2. The CLI command may be received from the user device and may correspond to a modification to the configuration of network device 2. The FAS agent running on network device 2 may detect the modification and authenticate the modification before it is implemented. Authenticating the modification may include determining that the modification was received from an authenticated user device and / or an authenticated user (e.g., a network administrator with appropriate credentials). Alternatively, or in addition, authenticating the modification may also include determining that the modification will not prevent communications from reaching devices in the network (e.g., the modification will not break the network). Authenticating the modification in this manner may include determining that the modification will not disrupt network operation, for example, from previous configurations, from simulations of the modification, from confirmations (e.g., from user input, etc.), from hash values, or the like.

[0050] In step 3, the FAS agent of network device 2 may forward an identification of the modification to the primary FAS agent of network device 2. In step 4, the primary FAS agent may authenticate the modification. The primary FAS agent may authenticate the modification in the same manner as described above with respect to the FAS agent of network device 2. In some cases, the primary FAS agent may authenticate the modification on behalf of the FAS agent of network device 2. In other examples, the primary FAS agent may authenticate the FAS agent after the FAS agent of network device 2 authenticates the modification. In yet other examples, the primary FAS agent and the FAS agent of network device 2 Modifications may be authenticated in parallel. To be authenticated, a modification may be authenticated by both the primary FAS agent and the FAS agent of network device 2. Alternatively, a modification may be authenticated if either the primary FAS agent or the FAS agent of network device 2 authenticates the modification.

[0051] If the modification is authenticated, then (step 5) the primary FAS agent implements the modification to the configuration of network device 1 and updates the state of the configuration (e.g., via a state machine). Alternatively, if a version identifier is used, the primary FAS agent increments the version identifier of the configuration of network device 1. The primary FAS agent may store the modification in a repository that may be accessible to other FAS agents in the network.

[0052] In step 6, the primary FAS agent may broadcast a keep_alive control packet indicating the current state (or version identifier) ​​of the configuration of network device 1. The keep_alive control packet may be received by FAS agents connected to the primary FAS agent. If there are other FAS agents operating in the network that are not connected to the primary FAS agent, the FAS agents connected to the primary FAS agent may forward the keep_alive control packet to those FAS agents.

[0053] In step 7, the FAS agent of network device 2 (like any other FAS agent operating in the network) may obtain the modifications to its configuration upon receiving the keep_alive control packet. In some examples, the FAS agent of network device 2 may obtain the modifications from a FAS agent running on a network device operating the updated configuration (e.g., based on a state or version identifier that matches the keep_alive control packet), such as the primary FAS agent. Alternatively, the FAS agent of network device 2 may perform a query on the repository using the state or version identifier. The repository may return the modifications to the requesting FAS agent. The FAS agent may then implement the modifications to the configuration and synchronize the state (or version identifier) ​​with other network devices in the network.

[0054] 5 illustrates an example process for updating a fabric configuration of a network device according to aspects of the present disclosure. At block 504, a first network device of a fabric network may receive an identification of a command from a second network device. The command may correspond to a modification of a current configuration of the second network device. The first network device may operate the same current configuration as the second network device. In some examples, the second network device may receive the command from a user device via a command line interface.

[0055] A fabric network may include two or more network devices (e.g., a first network device and a second network device, and optionally any number of additional network devices). Each network device may include a device that facilitates communication for one or more other devices. Examples of network devices may include, but are not limited to, routers, gateways, switches, servers, etc.

[0056] The first network device may receive commands from the second network device over a virtual local area network. For example, the network devices in the fabric network may each have a management controller that manages the operation of the respective network device. A VLAN may include a management channel. A FAS agent running on a network device may establish a VLAN over a management channel. A VLAN may be isolated from the devices with which the network device facilitates communication. That is, a VLAN may not be operated over the same communication channel that the network device uses for devices for which the network device provides communication services. A VLAN may be accessible only to manage the operation of the fabric network.

[0057] In block 508, a first FAS agent executing on the first network device may authenticate the command. Authenticating the modification may include determining that the modification was received from an authenticated user device and / or an authenticated user (e.g., a network administrator with appropriate credentials). Alternatively, or in addition, authenticating the modification may also include determining that the modification will not prevent communications from reaching devices in the network (e.g., the modification will not break the network). The first FAS agent may determine that the command will not disrupt the fabric network by, for example, analyzing previous configurations, simulating the modification, receiving confirmation (e.g., from user input, etc.), comparing hash values ​​with stored hash values, etc. If the command is not authenticated, the command may be discarded, and the process may return to block 504 to wait for a new command to be received. If the command is authenticated, the process proceeds to block 512.

[0058] In block 512, the first FAS agent may cause a modification of the current configuration of the first network device based on the command. For example, modifying the current configuration of the first network device defines a new configuration of the first network device. In some cases, the first network device may test the new configuration. For example, testing the new configuration may include running unit tests, sending packets to a predetermined device (e.g., a user device) and monitoring responses, running a test application, etc. If the test fails, the configuration of the first network device may be rolled back from the new configuration to the previous configuration.

[0059] An identification of the command may be stored in block 516. In some examples, the identification of the command may be stored by the first FAS agent (or, optionally, all FAS agents that implement the command on their respective network devices). In other examples, the command may be stored in a control base accessible to the network devices of the fabric network. The FAS agent may query the control base with a state associated with the command (e.g., a new state, such as described below) and / or an identification of the command to retrieve the command from the control base.

[0060] At block 520, a state identifier associated with the first network device's current configuration may be updated to correspond to a new state identifier associated with the new configuration. The state identifier indicates the state of the network device's configuration. Because each network device configuration may be a finite combination of properties, the number of unique combinations of properties (e.g., configurations) may also be finite. As a result, a particular configuration of the network device may be represented as one of a finite set of states in the state machine. When the network device's configuration is changed, the state of the configuration changes (corresponding to the change being made and corresponding to the new combination of properties). The state identifier indicating the state of the network device's old configuration may be updated to the new state identifier to indicate the new state. Examples of properties that may be included in the combination of properties that make up a configuration include a hostname, a console password, enabling or disabling a specific port, assigning a default gateway, and so on. Including, but not limited to, management channel enablement, Internet Protocol address configuration, subnet mask configuration, etc.

[0061] The state identifier may be used to query a control base (or another FAS agent). The control base may return an identification of one or more commands that may be implemented by the network device to upgrade the network device's current configuration to the new configuration. In some cases, the query may also include a state identifier (e.g., associated with the current state before any modifications to the configuration were performed). The control base may use the state identifier associated with the current state and the new state identifier to return commands that may upgrade a network device operating in a given configuration to the new configuration.

[0062] In some examples, the one or more commands may correspond to commands received by the second network device. In other examples, the one or more commands may be identified based on characteristics of the device generating the query. For example, some network devices may operate different hardware and / or firmware than other network devices. While each network device may be configured according to the same configuration, commands for operating the network devices in the new configuration may be different for different network devices. As a result, the control base may generate a query response that includes identification of one or more commands that, when implemented by the requesting network device, may cause the requesting network device to upgrade to the same new configuration as the other network devices.

[0063] In block 524, the first FAS agent executing on the first network device may send a control packet including the new state identifier over the VLAN to a second FAS agent executing on the second network device. When the second FAS agent receives the control packet, the second FAS agent may retrieve the identification of the command. In some examples, the second FAS agent may request the identification of the command from the first FAS agent (or another FAS agent that already implemented the command). In other examples, the second FAS agent may query a control base using the new state identifier. The second FAS agent may then implement the command on the second network device to upgrade the configuration of the second network device to the new configuration.

[0064] If the second FAS agent determines that the new configuration is not operational (e.g., detects a predetermined amount of dropped packets, a communications failure, a software failure, etc.), the second FAS agent may send a communication to the first FAS agent indicating that the configuration of the fabric network should be rolled back to the previous configuration. The first FAS agent may authenticate the communication and send a new control packet with a state identifier of the previous known good configuration. The new control packet may also cause other network devices in the fabric network to revert to the previous known good configuration so that the configurations of the fabric network may be consistent.

[0065] In some examples, if the first FAS agent detects a connectivity failure associated with a network device of the fabric network, the first FAS agent may not modify the configuration of the first network device (or may not allow modifications to any network devices of the fabric network). For example, if a command is received after the first FAS agent detects a connectivity failure at a network device, the first network device may store the command. When connectivity is restored for the affected network device, the first FAS agent may update the command. The first FAS agent may retrieve the command and implement the command (e.g., perform blocks 508-524). Alternatively, the first FAS agent may discard the command. Once connectivity for the affected network device is restored, the first network device may accept the command to modify the network device's configuration on the fabric network.

[0066] In the above description, specific details are given to provide a thorough understanding of the embodiments. However, it will be understood that the embodiments may be practiced without these specific details. For example, circuits may be shown in block diagrams in order to avoid obscuring the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.

[0067] The implementation of the above-described techniques, blocks, steps, and means may be performed in various ways. For example, these techniques, blocks, steps, and means may be implemented in hardware, software, or a combination thereof. In the case of a hardware implementation, the processing unit may be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processors (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, other electronic units, and / or combinations thereof, designed to perform the above-described functions.

[0068] Also, it should be noted that the embodiments may be described as a process that is depicted as a flowchart, flow diagram, swim diagram, control flow diagram, structure diagram, or block diagram. While the depiction may describe operations as a sequential process, many of the operations can occur in parallel or simultaneously. Additionally, the order of operations may be rearranged. A process terminates when its operations are completed, but may have additional steps not included in the diagram. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination corresponds to a return of the function to the calling function or the main function.

[0069] Furthermore, embodiments may be implemented by hardware, software, scripting languages, firmware, middleware, microcode, hardware description languages, and / or any combination thereof. When implemented in software, firmware, middleware, scripting languages, and / or microcode, the program code or code segments to perform the necessary tasks may be stored in a machine-readable medium such as a storage medium. A code segment or machine-executable instructions may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a script, a class, or any combination of instructions, control structures, and / or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing and / or receiving information, control, arguments, parameters, and / or memory contents. Information, arguments, parameters, control, etc. may be passed, forwarded, or transmitted via any suitable means including memory sharing, message passing, token passing, network transmission, etc.

[0070] For a firmware and / or software implementation, the methodologies may be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. Any machine-readable medium tangibly embodying instructions may be used in implementing the methodologies described herein. For example, software code may be stored in memory. Memory may be implemented within the processor or external to the processor. As used herein, the term "memory" refers to any type of long-term, short-term, volatile, or non-volatile memory. or other storage medium, and is not limited to any particular type or number of memories or the type of medium on which the memories are stored.

[0071] Additionally, as disclosed herein, the term "storage medium" may refer to one or more memories for storing controls, including read-only memory (ROM), random-access memory (RAM), magnetic RAM, core memory, magnetic disk storage media, optical storage media, flash memory devices, and / or other machine-readable media for storing information. The term "machine-readable medium" includes, but is not limited to, portable or fixed storage devices, optical storage devices, and / or various other storage media capable of storing or carrying instructions and / or controls.

[0072] While the principles of the present disclosure have been described above in connection with specific apparatus and methods, it is to be clearly understood that this description is made only by way of example and not as a limitation on the scope of the disclosure.

Claims

1. 1. A method comprising: and receiving, at a first network device in a fabric network, from a second network device in the fabric network, an identification of a command to modify a current configuration of the second network device, wherein the first network device is configured according to the current configuration, the method further comprising: a first Fabric Availability and Synchronization (FAS) agent executing on the first network device authenticating the command; and and in response to authenticating the command, the first network device modifying the current configuration of the first network device based on the command, wherein modifying the current configuration of the first network device defines a new configuration, the method further comprising: storing an identification of said command; In response to modifying the current configuration of the first network device, updating a state identifier associated with the current configuration of the first network device to correspond to a new state identifier associated with the new configuration; and the first FAS agent sending a control packet including the new state identifier to a second FAS agent executing on the second network device of the fabric network, wherein upon receiving the control packet, the second FAS agent retrieves the identification of the command and implements the command on the second network device to upgrade the current configuration of the second network device to the new configuration.

2. The method of claim 1 , wherein the control packets are transmitted over a virtual local area network operating in parallel with a network connection managed by the first network device.

3. The method further comprises: receiving, by the first network device, from a third network device of the fabric network, an identification of a second command; the first network device determining that the second command is invalid; and preventing the second command from modifying the new configuration.

4. The method further comprises: the first network device detecting a failure in the new configuration; and automatically reverting the new configuration of the first network device to a previous configuration in response to detecting the failure in the new configuration; and the first network device transmitting a second control packet that includes an identification of a state identifier associated with a previous known good configuration.

5. The method of claim 1 , wherein network devices of the fabric network that operate in a configuration different from the new configuration are removed from the fabric network.

6. The method further comprises: the first FAS agent executing on the first network device detecting a connection failure of a fourth network device of the FAS network; The first FAS agent running on the first network device and preventing modifications to the new configuration of the first network device while the connectivity failure persists.

7. The method further comprises: receiving a priority packet including a priority value associated with a new network device in the fabric network, the priority value associated with the FAS agent of the new network device being greater than a priority value associated with the first FAS agent; 2. The method of claim 1, further comprising the first FAS agent broadcasting a third control packet over the fabric network indicating that the first network device is relinquishing primary network device status to the new network device.

8. 1. A system comprising: one or more processors; and a non-transitory computer-readable medium storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, including: receiving, at a first network device in a fabric network, from a second network device in the fabric network, an identification of a command to modify a current configuration of the second network device, the first network device being configured according to the current configuration, the operations further comprising: a first Fabric Availability and Synchronization (FAS) agent executing on the first network device authenticating the command; and and in response to authenticating the command, the first network device modifying the current configuration of the first network device based on the command, wherein modifying the current configuration of the first network device defines a new configuration, the operations further comprising: storing an identification of said command; In response to modifying the current configuration of the first network device, updating a state identifier associated with the current configuration of the first network device to correspond to a new state identifier associated with the new configuration; the first FAS agent sending a control packet including the new state identifier to a second FAS agent executing on the second network device of the fabric network, wherein upon receiving the control packet, the second FAS agent retrieves the identification of the command and implements the command on the second network device to upgrade the current configuration of the second network device to the new configuration.

9. 9. The system of claim 8, wherein the control packets are transmitted over a virtual local area network operating in parallel with a network connection managed by the first network device.

10. receiving, by the first network device, from a third network device of the fabric network, an identification of a second command; the first network device determining that the second command is invalid; 9. The system of claim 8, further comprising: preventing the second command from changing the new configuration.

11. the first network device detecting a failure in the new configuration; and automatically reverting the new configuration of the first network device to a previous configuration in response to detecting the failure in the new configuration; The system of claim 8 , further comprising: the first network device transmitting a second control packet that includes an identification of a state identifier associated with a previous known good configuration.

12. The system of claim 8 , wherein network devices of the fabric network that operate in a configuration different from the new configuration are removed from the fabric network.

13. the first FAS agent executing on the first network device detecting a connection failure of a fourth network device of the FAS network; 9. The system of claim 8, further comprising: the first FAS agent executing on the first network device preventing modifications to the new configuration of the first network device while the connection failure persists.

14. the first FAS agent executing on the first network device receiving a priority packet including a priority value associated with a new network device in the fabric network, the priority value associated with the FAS agent of the new network device being greater than the priority value associated with the first FAS agent; and 9. The system of claim 8, further comprising the first FAS agent broadcasting a third control packet over the fabric network indicating that the first network device is relinquishing primary network device status to the new network device.

15. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations, including: receiving, at a first network device in a fabric network, from a second network device in the fabric network, an identification of a command to modify a current configuration of the second network device, the first network device being configured according to the current configuration, the operations further comprising: a first Fabric Availability and Synchronization (FAS) agent executing on the first network device authenticating the command; and and in response to authenticating the command, the first network device modifying the current configuration of the first network device based on the command, wherein modifying the current configuration of the first network device defines a new configuration, the operations further comprising: storing an identification of said command; In response to modifying the current configuration of the first network device, updating a state identifier associated with the current configuration of the first network device to correspond to a new state identifier associated with the new configuration; and the first FAS agent sending a control packet including the new state identifier to a second FAS agent executing on the second network device of the fabric network, wherein upon receiving the control packet, the second FAS agent retrieves the identification of the command and implements the command on the second network device to update the current configuration of the second network device. A non-transitory computer readable medium for upgrading to the new configuration.

16. 16. The non-transitory computer-readable medium of claim 15, wherein the control packets are transmitted over a virtual local area network operating in parallel with a network connection managed by the first network device.

17. receiving, by the first network device, from a third network device of the fabric network, an identification of a second command; the first network device determining that the second command is invalid; and preventing the second command from modifying the new configuration.

18. the first network device detecting a failure in the new configuration; and automatically reverting the new configuration of the first network device to a previous configuration in response to detecting the failure in the new configuration; and the first network device transmitting a second control packet that includes an identification of a state identifier associated with a previous known good configuration.

19. the first FAS agent executing on the first network device detecting a connection failure of a fourth network device of the FAS network; 16. The non-transitory computer-readable medium of claim 15, further comprising: the first FAS agent executing on the first network device preventing modifications to the new configuration of the first network device while the connection failure persists.

20. the first FAS agent executing on the first network device receiving a priority packet including a priority value associated with a new network device in the fabric network, the priority value associated with the FAS agent of the new network device being greater than the priority value associated with the first FAS agent; and 16. The non-transitory computer-readable medium of claim 15, further comprising the first FAS agent broadcasting a third control packet over the fabric network indicating that the first network device is relinquishing primary network device status to the new network device.