Dynamic Service Insertion in Layer-2 Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy data center designs face challenges in scaling service devices like firewalls and implementing network-level security policies between hosts within the same layer-2 domain, limiting flexibility and scalability in service device deployment.

Innovation Solution

The dynamic insertion of network service devices into the network allows for flexible placement and configuration, enabling services to be provided to any network location without requiring physical repositioning, using a network management system to monitor and configure network elements for real-time data redirection and policy implementation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If service devices are deployed physically at the network boundary, then network traffic for specific VLANs can flow through the service devices, but the service devices cannot be scaled out and additional firewall capacity cannot be added

Engineering Contradiction:
Improvefirewall capacityVSAvoidservice device scalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent transitions service devices from physical boundary deployment to virtual deployment within the layer-2 domain. By introducing virtual service instances that can be dynamically inserted into the network fabric, the system adds a virtualization dimension that allows multiple service devices to coexist and scale without being constrained by physical boundary locations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces a service gateway as an intermediary component that mediates between the layer-3 network and layer-2 domain. This gateway enables service devices to be inserted dynamically into the network path without requiring physical reconfiguration, allowing traffic redirection to virtual service instances while maintaining network transparency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service devices are fixed at the network perimeter, then security policies can be implemented at the boundary, but no network level security policies can be implemented between hosts within the same layer-2 domain

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity policy flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network security function by introducing virtual service instances that can be deployed at different logical locations within the layer-2 domain. This segmentation allows security policies to be applied granularly between specific hosts or groups of hosts rather than only at the network perimeter, enabling fine-grained security zones and policies within the same broadcast domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a logical security dimension within the layer-2 domain by introducing virtual service instances. These instances create security boundaries and policy enforcement points that exist in the logical network space rather than requiring physical separation, enabling security policies between hosts that would traditionally be in the same security zone.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If physical reconfiguration is required to add service devices, then service devices can be physically deployed, but the network cannot respond dynamically to host movement or policy changes

Engineering Contradiction:
Improvedynamic responsivenessVSAvoidphysical reconfiguration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces dynamic service insertion capabilities where virtual service instances can be inserted, moved, or removed from the network path through software configuration rather than physical reconfiguration. The service gateway dynamically redirects traffic to appropriate service instances based on current network state, host location, and policy requirements, enabling real-time adaptation without physical changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces the mechanical system of physical cable reconfiguration and device relocation with a software-based control plane. The network management system uses configuration data and control protocols to dynamically insert and redirect traffic to service devices through the service gateway, eliminating the need for physical network changes while maintaining service functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If service devices are deployed at the layer-3 to layer-2 boundary, then network traffic can flow through service devices, but the deployment lacks flexibility and requires frame format changes

Engineering Contradiction:
Improveservice device deploymentVSAvoidframe format requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a universal service insertion mechanism through the service gateway that can handle multiple service device types and deployment scenarios without requiring different frame formats or protocol changes. The gateway provides a standardized interface for inserting virtual service instances into the network path, making service device deployment independent of specific service types or network configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10341185B2Dynamic service insertion
Publication Date: 2019.07.02 ARISTA NETWORKS INC
  • US10341185B2 patent drawing
  • US10341185B2 patent drawing
  • US10341185B2 patent drawing

AI summary

Various embodiments are described herein to enable physical topology independent dynamic insertion of a service device into a network. One embodiment provides for a network system comprising a set of network elements to interconnect a set of host devices, the set of network elements having a physical topology defined by the physical links between network elements in the set of network elements, and a network management device including a network management module to monitor and configure the set of network elements, the network management module to configure the set of network elements to enable dynamic insertion of a network service device into the network to logically couple to one or more host devices in the set of host devices to the network service device independently of a location of the one or more host devices and the network service device within the physical topology.