Bypass Switch Evaluation Mode for In-Line Network Traffic Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing in-line network monitoring systems face challenges in providing reliable fail-safe protection and comprehensive traffic monitoring, as they can become points of failure and have limited functionality in mirroring network traffic for out-of-band analysis.

Innovation Solution

The implementation of a bypass switch with enhanced functionality that mirrors network traffic from multiple points, allowing for the configuration of tap output ports to receive and output copies of both ingress and egress packets, enabling evaluation of in-line tools and providing fail-safe protection by routing traffic around the in-line tool during failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If an in-line network tool is deployed to monitor network traffic, then network traffic monitoring capability is improved, but the risk of the in-line tool becoming a point of failure increases

Engineering Contradiction:
Improvenetwork traffic monitoring capabilityVSAvoidnetwork availability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

A bypass switch is introduced as an intermediary device between the network and the in-line network tool. The bypass switch monitors the operational status of the in-line tool and automatically routes traffic around it when failure is detected, thereby protecting the network from tool failures while maintaining monitoring capability when the tool is healthy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The bypass switch is pre-configured with failure detection mechanisms and automatic failover capabilities. Before actual network failure occurs, the system detects tool unresponsiveness or errors and proactively switches to bypass mode, preventing temporary tool outages from escalating into costly network outages.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If a bypass switch is implemented to provide fail-safe protection, then network reliability is improved, but the functionality for comprehensive traffic monitoring is reduced

Engineering Contradiction:
Improvenetwork availabilityVSAvoidtraffic monitoring comprehensiveness
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The bypass switch provides segmented monitoring capabilities by offering separate bypass paths for different traffic types (inbound, outbound, bidirectional). This segmentation allows selective monitoring of specific traffic flows while maintaining overall network protection, enabling comprehensive monitoring without compromising reliability.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If existing bypass switches mirror network traffic to out-of-band tools, then traffic analysis capability is improved, but the ability to evaluate in-line tool operation is limited

Engineering Contradiction:
Improvetraffic analysis capabilityVSAvoidin-line tool evaluation capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The bypass switch adds a new dimension to traffic mirroring by providing separate tap ports that can independently mirror inbound traffic, outbound traffic, or both directions simultaneously. This multi-dimensional mirroring capability enables out-of-band tools to perform comprehensive evaluation of in-line tool operation by comparing original and processed traffic across multiple dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10778508B2Bypass switch with evaluation mode for in-line monitoring of network traffic
Publication Date: 2020.09.15 KEYSIGHT TECHNOLOGIES INC
  • US10778508B2 patent drawing
  • US10778508B2 patent drawing
  • US10778508B2 patent drawing

AI summary

Bypass switch systems and methods are disclosed for in-line monitoring of network traffic. Network ports receive ingress packets from a network and transmit processed packets as egress packets back to the network. Tool ports send the ingress packets to in-line network tools and receive the processed packets back from the in-line network tools. Tap output ports operate in a first configuration setting to output copies of ingress packets received by a network port and in a second configuration setting to output copies of processed packets transmitted as egress packets by a network port. For one embodiment, copies of ingress packets received by a network port are output through one tap output port, and copies of processed packets transmitted as egress packets by a network port are output through another tap output port. These packets copies are then analyzed to evaluate the operation of the in-line tools.