Dynamic Service Insertion in Layer-2 Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy data center designs face challenges in scaling service devices like firewalls and implementing network-level security policies between hosts within the same layer-2 domain, limiting flexibility and scalability in service device deployment.
Innovation Solution
The dynamic insertion of network service devices into the network allows for flexible placement and configuration, enabling services to be provided to any network location without requiring physical repositioning, using a network management system to monitor and configure network elements for real-time data redirection and policy implementation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If service devices are deployed physically at the network boundary, then network traffic for specific VLANs can flow through the service devices, but the service devices cannot be scaled out and additional firewall capacity cannot be added
Solution Approach 1:
The patent transitions service devices from physical boundary deployment to virtual deployment within the layer-2 domain. By introducing virtual service instances that can be dynamically inserted into the network fabric, the system adds a virtualization dimension that allows multiple service devices to coexist and scale without being constrained by physical boundary locations.
Solution Approach 2:
The patent introduces a service gateway as an intermediary component that mediates between the layer-3 network and layer-2 domain. This gateway enables service devices to be inserted dynamically into the network path without requiring physical reconfiguration, allowing traffic redirection to virtual service instances while maintaining network transparency.
2Reliability
If service devices are fixed at the network perimeter, then security policies can be implemented at the boundary, but no network level security policies can be implemented between hosts within the same layer-2 domain
Solution Approach 1:
The patent segments the network security function by introducing virtual service instances that can be deployed at different logical locations within the layer-2 domain. This segmentation allows security policies to be applied granularly between specific hosts or groups of hosts rather than only at the network perimeter, enabling fine-grained security zones and policies within the same broadcast domain.
Solution Approach 2:
The patent adds a logical security dimension within the layer-2 domain by introducing virtual service instances. These instances create security boundaries and policy enforcement points that exist in the logical network space rather than requiring physical separation, enabling security policies between hosts that would traditionally be in the same security zone.
3Adaptability or versatility
If physical reconfiguration is required to add service devices, then service devices can be physically deployed, but the network cannot respond dynamically to host movement or policy changes
Solution Approach 1:
The patent introduces dynamic service insertion capabilities where virtual service instances can be inserted, moved, or removed from the network path through software configuration rather than physical reconfiguration. The service gateway dynamically redirects traffic to appropriate service instances based on current network state, host location, and policy requirements, enabling real-time adaptation without physical changes.
Solution Approach 2:
The patent replaces the mechanical system of physical cable reconfiguration and device relocation with a software-based control plane. The network management system uses configuration data and control protocols to dynamically insert and redirect traffic to service devices through the service gateway, eliminating the need for physical network changes while maintaining service functionality.
4Ease of operation
If service devices are deployed at the layer-3 to layer-2 boundary, then network traffic can flow through service devices, but the deployment lacks flexibility and requires frame format changes
Solution Approach 1:
The patent creates a universal service insertion mechanism through the service gateway that can handle multiple service device types and deployment scenarios without requiring different frame formats or protocol changes. The gateway provides a standardized interface for inserting virtual service instances into the network path, making service device deployment independent of specific service types or network configurations.
Data Source
AI summary
Various embodiments are described herein to enable physical topology independent dynamic insertion of a service device into a network. One embodiment provides for a network system comprising a set of network elements to interconnect a set of host devices, the set of network elements having a physical topology defined by the physical links between network elements in the set of network elements, and a network management device including a network management module to monitor and configure the set of network elements, the network management module to configure the set of network elements to enable dynamic insertion of a network service device into the network to logically couple to one or more host devices in the set of host devices to the network service device independently of a location of the one or more host devices and the network service device within the physical topology.


