Aggregated Networking Station Move Control via Static MAC Entries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional station move control functionality in aggregated networking device subsystems, such as those using the Virtual Link Trunking (VLT) protocol, is limited to a single switch device and fails to provide secure MAC address management across multiple nodes, leading to reduced security as 'orphan' ports are not recognized, allowing unauthorized MAC address moves.
Innovation Solution
An Information Handling System (IHS) with a processing system and memory that includes instructions to generate a static MAC address entry associating learned MAC addresses with an Inter-Chassis Link (ICL) and program rules to manage MAC address associations on non-ICL ports, ensuring secure MAC address movement control across aggregated networking devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If station move control functionality is implemented in a single switch device, then MAC address security is improved on that device, but security is weakened across aggregated networking device subsystems due to orphan port recognition failures
Solution Approach 1:
The patent merges station move control functionality across multiple switch devices in an aggregated networking subsystem. The first switch device shares MAC address information with the second switch device through inter-chassis links, enabling coordinated security enforcement. When a MAC address is learned on a port-security-enabled port at the first switch device, this information is propagated to the second switch device, which then enforces the same security policy on its non-ICL ports, effectively extending station move control across the aggregated subsystem.
Solution Approach 2:
The patent introduces an intermediary information sharing mechanism between aggregated switch devices. The first switch device acts as the primary controller that learns MAC addresses and generates security policies, while the second switch device acts as a follower that receives and enforces these policies. This intermediary communication through shared memory or messaging protocols enables coordinated security enforcement without requiring complex peer-to-peer coordination between all devices in the aggregate.
2Reliability
If port security is enabled on all ports to prevent unauthorized MAC moves, then security is improved, but network flexibility deteriorates as legitimate MAC address movements are blocked
Solution Approach 1:
The patent applies different security policies to different ports based on their security requirements. Port-security-enabled ports enforce strict station move control to prevent unauthorized MAC address movements and potential security threats. In contrast, ports with port security disabled allow legitimate MAC address movements for devices that need to move between ports. This localized quality approach ensures that security is enforced only where necessary, maintaining both security and network flexibility.
3Reliability
If static MAC address entries are created for all learned MAC addresses, then MAC move control is improved, but system performance deteriorates due to increased memory and processing requirements
Solution Approach 1:
The patent implements partial station move control by creating static MAC address entries only for MAC addresses learned on port-security-enabled ports, rather than for all learned MAC addresses. This selective approach ensures that security-critical MAC addresses are controlled while avoiding the performance penalty of creating static entries for every MAC address in the network. The system applies the computationally intensive static entry creation only where security requirements demand it.
Data Source
AI summary
An aggregated networking device subsystem station move control system includes first and second aggregated networking devices connected via an ICL. The first aggregated networking device receives a MAC address from the second aggregated networking device that was learned on an orphan port that has port security enabled and a station-move-deny configuration, and generates a static MAC address entry in its MAC address table that associates the MAC address with the ICL. The static MAC address entry causes data packets received on non-ICL ports on the first aggregated networking device that include the MAC address to generate a static MAC move violation. The first aggregated networking device also programs rule(s) that, in response to data packets being received on its non-ICL ports that have port security disabled and generating a static MAC move violation, causes the association of the MAC address with that non-ICL port.


