ACL Table Generation for Data Center Network Expansion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing two-level full mesh architecture in data centers faces challenges in expanding network capacity due to the requirement for hyperscale TCAM, which cannot be produced with current technology, making it difficult to manage large ACL tables effectively.
Innovation Solution
A method and apparatus for generating an ACL table by determining port types, selecting target ports, generating corresponding ACL entries, and adding them to the ACL table, reducing the number of entries and lowering TCAM resource requirements, thereby facilitating network expansion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a two-level full mesh architecture is implemented to meet rapid data growth requirements, then network connectivity and communication capability are improved, but the size of ACL tables increases significantly, requiring hyperscale TCAM which cannot be produced with current technology
Solution Approach 1:
The patent segments the ACL table into multiple smaller ACL tables, each stored in a different network device within the mesh architecture. Instead of requiring one large hyperscale TCAM in a single device, the ACL enforcement functionality is distributed across multiple devices, allowing each device to have a manageable TCAM size while collectively providing comprehensive ACL coverage for the entire network.
Solution Approach 2:
The patent introduces a new dimension to ACL table management by utilizing the network topology itself as a storage dimension. Rather than expanding the capacity of a single TCAM device, the solution distributes ACL entries across multiple devices in the mesh network, effectively using the network's spatial structure to accommodate the large ACL table requirements.
2Measurement precision
If ACL entries are configured for each flow through each port to ensure precise access control, then security and access control precision are improved, but the quantity of ACL entries increases, making it difficult to manage and requiring larger TCAM capacity
Solution Approach 1:
The patent segments both the ACL table and the network devices, distributing the management complexity across multiple devices. Each device manages a portion of the ACL entries relevant to its local traffic, reducing the complexity burden on any single device while maintaining comprehensive access control precision across the entire network.
Solution Approach 2:
The patent implements partial action by configuring ACL entries only where needed in the network rather than duplicating full ACL tables across all devices. Each network device receives and enforces only the subset of ACL rules relevant to its local traffic flows, reducing overall complexity while maintaining necessary security precision.
3Reliability
If a large number of ACL entries are stored in a single switch to handle all network traffic, then comprehensive access control is achieved, but the requirement on TCAM resource specifications increases to hyperscale levels which are not currently manufacturable
Solution Approach 1:
The patent segments the large ACL table into multiple smaller tables distributed across multiple network devices. This segmentation allows each device to use standard, manufacturable TCAM components rather than requiring unproven hyperscale TCAM technology, while the collective system maintains comprehensive access control coverage through coordinated enforcement across the mesh network.
Solution Approach 2:
The patent introduces a controller as an intermediary that manages the distribution and coordination of ACL entries across the mesh network. The controller receives ACL policies, distributes appropriate subsets to relevant network devices, and coordinates their enforcement, enabling comprehensive access control without requiring any single device to have hyperscale TCAM capacity.
Data Source
AI summary
A method and an apparatus are disclosed for generating an ACL table. A controller obtains a port type of each port of a first network device, and selects, based on the port type of each port, a target port whose port type is a preset type from all ports of the first network device. The controller generates a corresponding first-type access control list ACL entry for each target port, and generates one second-type ACL entry corresponding to a routing table of the first network device, where an action of the second-type ACL entry is redirecting to the routing table. The controller adds the second-type ACL entry and each first-type ACL entry to an ACL table of the first network device.


