Agentless Service Insertion in Virtual Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network service solutions in virtualized environments face challenges in scalability and dynamic provisioning due to the limitations of inline network appliances, which do not scale well with virtual machine instantiation, migration, and mobility.
Innovation Solution
A system and method for dynamically and transparently inserting virtual service nodes into virtual networks by associating interface ports with service policies, allowing data traffic to be directed as raw traffic to the service node without requiring control functions, enabling agentless service nodes that can operate without embedded agents and supporting both agentless and agent-based service nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If inline network appliances are used to provide network services, then service functionality is achieved, but scalability and adaptability to virtual machine dynamics deteriorate
Solution Approach 1:
The patent introduces a service gateway as an intermediary component that mediates between virtual machines and service nodes. The service gateway handles service insertion, policy enforcement, and traffic steering, allowing service nodes to be dynamically added or removed without modifying virtual machine configurations or control plane mechanisms. This intermediary approach enables scalable service deployment while maintaining simplicity in service node implementation.
2Adaptability or versatility
If service nodes are dynamically inserted into virtual networks, then service mobility is improved, but control plane complexity increases
Solution Approach 1:
The patent extracts control plane functionality from service nodes and centralizes it in the service gateway and existing network controllers. Service nodes become simple data plane entities that forward traffic according to policies defined by the control plane, without requiring embedded agents or complex control logic. This separation enables service mobility while keeping individual service nodes simple.
3Ease of operation
If agents are embedded in service nodes for integration, then service control is improved, but service node complexity and third-party integration barriers increase
Solution Approach 1:
The service gateway acts as an intermediary that provides standardized interfaces and protocols for service node integration. Instead of requiring custom agents in each service node, the gateway handles communication, authentication, and policy enforcement using standard network protocols. This approach simplifies service node implementation while maintaining effective control.
4Productivity
If inline network appliances are deployed for each service, then service functionality is achieved, but resource utilization and scalability deteriorate
Solution Approach 1:
The patent implements a universal service gateway that can handle multiple service types and protocols through a single platform. The service gateway provides a common framework for service insertion, traffic steering, and policy enforcement that works across different service nodes and virtual machine configurations. This multi-functional approach improves resource utilization by consolidating service infrastructure while maintaining deployment simplicity through standardized interfaces.
Data Source
AI summary
An example method for service insertion in a network environment is provided in one example and includes configuring a service node by tagging one or more interface ports of a virtual switch function to which the service node is connected with one or more policy identifiers. When data traffic associated with a policy identifier is received on a virtual overlay path the virtual switch function may then terminate the virtual overlay path and direct raw data traffic to the interface port of the service node that is tagged to the policy identifier associated with the data traffic.


