Application-Centric Switch Policy Delegation Across Multi-Site Fabrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deploying security policies across multiple geographically dispersed data center sites in a network fabric is resource-intensive and leads to service downtime and uneven distribution, especially as the network grows in size and complexity.
Innovation Solution
Centralize security policy application to a network switch connected to the host providing a service, allowing other switches to delegate enforcement, thereby reducing resource consumption and ensuring consistent policy deployment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are deployed across multiple geographically dispersed data center sites, then security coverage is improved, but resource consumption increases and service downtime occurs
Solution Approach 1:
The patent segments security policy enforcement by site, designating one site as the home site that exclusively manages and enforces security policies for multi-site workloads. Other non-home sites delegate security policy enforcement to the home site, avoiding redundant policy deployment and resource consumption across all sites while maintaining comprehensive security coverage.
2Reliability
If security policies are deployed across multiple sites, then security coverage is improved, but service downtime occurs
Solution Approach 1:
The patent implements preliminary action by pre-designating a home site for each multi-site workload before security policy enforcement is needed. The home site is identified based on the workload's virtual infrastructure identifier, and security policies are pre-configured at the home site. This eliminates the need for time-consuming policy deployment and service interruptions when workloads move between sites.
3Ease of operation
If security policies are maintained at multiple sites, then local enforcement capability is improved, but device complexity increases
Solution Approach 1:
The patent extracts security policy management from non-home sites, concentrating it exclusively at the home site. Non-home sites remove security policy enforcement capabilities for multi-site workloads and delegate to the home site, which maintains the complete security policy set. This reduces device complexity at individual non-home sites while preserving centralized security management at the home site.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure provides for application-centric enforcement for multi- tenant workloads with multi-site data center fabrics by: receiving, at a local switch at a first site, a packet from a first host at the first site intended for a second host located at a second site; identifying class identifiers (ID) for the hosts; determining, based on the class IDs, a security policy for transmitting data between the hosts; in response to determining that the security policy indicates that the second site exclusively manages security policies for the hosts' network: setting a policy applied indicator on the packet indicating that enforcement of the security policy is delegated from the first switch to a second switch connected to the second host; including the class IDs in the packet; and transmitting the packet to the second site.