Dynamic Service Device Insertion in Data Center Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy data center designs face challenges in scaling service devices like firewalls and implementing network-level security policies between hosts within the same layer-2 domain, limiting flexibility and scalability in service device deployment and security policy enforcement.
Innovation Solution
The dynamic insertion of network service devices into the network, allowing service devices to be coupled to any network element and providing services independently of physical location, with a network management system that discovers service policies using native APIs and automatically configures network elements to implement these policies, enabling flexible and scalable service deployment and security policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service devices are deployed physically at the network boundary in historic legacy designs, then network traffic for specific VLANs can be routed through configured service devices, but the system lacks scalability to add more firewall capacity and cannot implement network level security policies between hosts within the same layer-2 domain
Solution Approach 1:
The patent implements dynamic service insertion that allows service devices to be inserted into the network path dynamically without manual reconfiguration. The system automatically discovers service devices, determines their service policies, and configures network elements to implement these policies in real-time, transforming the static network boundary deployment model into a dynamic one that adapts to changing service requirements
Solution Approach 2:
The patent introduces a service policy module as an intermediary that mediates between service devices and network elements. This module automatically discovers service policies from service devices using native APIs and translates them into network configuration changes, eliminating the need for manual configuration and enabling seamless integration of service devices anywhere in the network
2Reliability
If service devices are fixed at the network perimeter in historic designs, then security policies can be enforced at the boundary, but the system cannot scale out service devices or implement security policies between hosts within the same layer-2 domain
Solution Approach 1:
The patent makes service devices universal by enabling them to provide security services regardless of their physical location in the network. The dynamic service insertion mechanism allows the same service device to serve multiple functions and protect multiple VLANs or host groups by dynamically configuring network elements to redirect traffic to the service device based on service policies rather than fixed perimeter locations
Solution Approach 2:
The service policy module continuously monitors service policies and automatically configures network elements in response to changes. This feedback mechanism ensures that security policies are consistently enforced by detecting policy changes from service devices and automatically translating them into appropriate network configurations, maintaining reliability while enabling location independence
3Reliability
If manual configuration is used for service device integration in historic designs, then network elements can be configured to route traffic through service devices, but the process is time-consuming and lacks real-time responsiveness to service policy changes
Solution Approach 1:
The system implements self-service by enabling service devices to automatically register themselves with the service policy module and have their service policies automatically discovered and implemented. The service policy module autonomously monitors for new service devices, discovers their policies using native APIs, and automatically generates and distributes network configuration changes without human intervention, dramatically reducing integration time from manual processes to automatic real-time operations
Data Source
AI summary
Various embodiments are described herein to enable physical topology independent dynamic insertion of a service device into a network. One embodiment provides for a network system comprising a set of network elements to interconnect a set of host devices, the set of network elements having a physical topology defined by the physical links between network elements in the set of network elements and a logical topology defined by a flow of network data between a network service device and a client of the network service device, wherein the physical topology differs from the logical topology, and a network management device including a service policy module to monitor a service policy of the network service device and automatically configure the logical topology of the network elements based on a change in the service policy.


