Dual-NIC Security Fabric Architecture for Scalable Network Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The scalability issue arises from the need for multiple node ports on each network node in a cluster of virtual machines or containers, which increases proportionately with the number of customers, leading to inefficiencies in network traffic management.
Innovation Solution
A security fabric platform with dual-NIC virtual machines and containers, utilizing service chaining and NAT routing, allows for flexible deployment and instantiation of VNFs and CNFs, enabling high scalability and efficient network service provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple node ports are opened on each network node to support network traffic transmission, then network service functionality is improved, but the number of ports increases proportionately with the number of customers, leading to scalability issues
Solution Approach 1:
The patent segments network traffic processing by introducing dedicated ingress and egress VMs that handle network traffic separately from compute workloads. Each VM in the cluster only needs a single node port, and the dedicated network VMs aggregate traffic from multiple customers, eliminating the need for multiple ports on each compute node while maintaining full network service functionality.
Solution Approach 2:
The patent introduces dedicated ingress and egress VMs as intermediary components between network infrastructure and compute workloads. These intermediary VMs act as network translators and traffic aggregators, allowing compute nodes to communicate with external networks through a single port while the intermediary handles the complexity of multi-customer traffic management.
2Adaptability or versatility
If the number of node ports increases proportionately with the number of customers, then network service coverage is improved, but scalability and operational efficiency deteriorate
Solution Approach 1:
The patent merges network traffic processing functions into dedicated ingress and egress VMs that aggregate traffic from multiple customers. Instead of distributing multiple ports across many compute nodes, the system combines all network traffic through a centralized virtual networking layer, improving operational efficiency while maintaining comprehensive network service coverage.
Solution Approach 2:
The dedicated ingress and egress VMs serve multiple functions simultaneously: they act as network translators, traffic aggregators, security gateways, and service orchestrators. This multi-functionality eliminates the need for multiple specialized ports on each node, improving operational efficiency while maintaining universal network service coverage across all customers.
3Reliability
If traditional node port configuration is used for network traffic, then network connectivity is established, but scalability becomes problematic as customer base grows
Solution Approach 1:
The patent segments network connectivity into two distinct paths: a simplified compute node path with a single node port, and a dedicated network VM path that handles all traffic aggregation and translation. This segmentation maintains reliable network connectivity while eliminating scalability problems by preventing the complexity of multiple ports from propagating through the entire cluster.
Solution Approach 2:
The dedicated ingress and egress VMs serve as intermediaries that translate between the simplified single-port compute node interface and the complex multi-customer network infrastructure. This intermediary layer maintains reliable network connectivity for each customer while protecting the scalability of the system by centralizing all connectivity complexity in specialized VMs rather than distributing it across all nodes.
Data Source
AI summary
Novel tools and techniques are provided for implementing security fabric platform network services architecture and functionalities. In various embodiments, at least one VM among a plurality of virtual machines (“VMs”) that is hosted on a security fabric platform includes dual network interface controllers (“NICs”) or virtual NICs (“VNICs”). A request to perform a set of tasks may be routed to a VM of the plurality of VMs via one of the NICs or VNICs. Two or more VMs and/or one or more containers hosted on the security fabric platform and/or on one or more worker nodes may be service chained from one to another of the NICs or VNICs of the VMs and/or containers. Results of the set of tasks as processed by virtual or cloud-native network functions may be routed via a firewall, via network address translation, from and to a destination network address associated with a destination device.


