Aggregation Switch ACL Rule Centralization for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control methods in enterprise networks are inefficient in managing user access authorities across multiple sub-networks and resource groups, leading to complexities in configuring and enforcing access control policies, especially when users move between different network segments.
Innovation Solution
The implementation of Software-Defined Networking (SDN) controller that configures user groups, resource groups, and access control policies, using overlay technology to establish VLAN and VXLAN identifiers, and applies ACL rules on aggregation switches to manage network access, ensuring that users access only authorized network segments and resources, regardless of their location within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ACL rules are configured on access switches to control network access, then network security is improved, but device complexity and configuration workload increase
Solution Approach 1:
The patent extracts the ACL rule configuration and management functions from individual access switches and centralizes them on aggregation switches. This allows access switches to focus on basic forwarding while aggregation switches handle the complex access control policy management, reducing overall network complexity while maintaining security.
Solution Approach 2:
The patent implements a universal ACL rule template mechanism where a single ACL rule template can be applied to multiple user groups and network segments simultaneously. This multi-functionality reduces the number of individual ACL rules needed and simplifies configuration management across the enterprise network.
2Manufacturing precision
If ACL rules are updated frequently to accommodate user movements, then network access control accuracy is improved, but configuration time and operational efficiency deteriorate
Solution Approach 1:
The patent pre-configures ACL rule templates on aggregation switches that define access control policies for different user groups and network segments. These templates are prepared in advance and can be quickly applied or modified without requiring frequent individual rule updates, reducing configuration time while maintaining accuracy.
Solution Approach 2:
The patent implements dynamic user group management where user memberships and ACL rule associations can be automatically updated based on user movements and role changes. This dynamic approach maintains accurate access control without requiring manual intervention for each user movement, reducing operational time.
3Reliability
If multiple VLANs and ACL rules are configured to manage different user groups, then network security and access control are improved, but the number of configuration elements and system complexity increase
Solution Approach 1:
The patent merges multiple ACL rules into unified ACL rule templates that can cover multiple user groups and network segments. By combining related access control policies into single templates, the number of individual configuration elements is reduced while maintaining comprehensive security coverage.
Solution Approach 2:
The patent creates universal ACL rule templates that can be applied across multiple VLANs and user groups simultaneously. This multi-functionality reduces the total number of ACL rules needed compared to configuring separate rules for each user group and VLAN combination.
Data Source
AI summary
This disclosure provides a method and device for controlling network access. According to the method, an aggregation switch may configure thereon an ACL rule comprising a first network segment and a second network segment, wherein the first network segment and the second network segment correspond to a same user group or different user groups, or the first network segment corresponds to a user group and the second network segment corresponds to a resource group. The aggregation switch may, after receiving a user packet from an access switch, match a source IP address of the user packet with the first network segment, and a destination IP address of the user packet with the second network segment. If the source IP address of the user packet matches with the first network segment and the destination IP address of the user packet matches with the second network segment, the user packet is discarded.


