Flexible Virtual Local Area Network Using Global VLAN Encapsulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VLAN implementations, such as IEEE 802.1Q, face challenges in scalability, security, and connectivity, especially in multi-tenant and multi-site data center environments, where the limited 12-bit VLAN IDs become insufficient, and managing VLAN configurations becomes complex, failing to provide desired services in larger-scale networks.
Innovation Solution
A method and apparatus for implementing a flexible VLAN by determining a global VLAN for data frame transmission, encapsulating data frames based on this determination, and transmitting them over a global VLAN to switch serving other local VLANs, using a directory server to manage VLAN memberships and ensure compatibility with existing standards like IEEE 802.1Q.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If conventional VLAN implementations (IEEE 802.1Q) are used, then VLAN isolation and connectivity are provided, but the 12-bit VLAN ID limit causes insufficient scalability in multi-tenant environments
Solution Approach 1:
The patent introduces a hierarchical VLAN structure with global VLAN IDs and local VLAN IDs, effectively adding a dimensional layer to the traditional flat VLAN ID space. This allows the system to overcome the 12-bit limitation by distributing VLAN identification across multiple levels: global VLANs provide broad segmentation across the entire network, while local VLANs provide fine-grained isolation within sites. The mapping between global and local VLAN IDs enables scalability without sacrificing the isolation properties of traditional VLANs.
Solution Approach 2:
The patent segments the VLAN identification space into global and local components. Global VLAN IDs are used for cross-site traffic and overall network segmentation, while local VLAN IDs are used for site-specific isolation. This segmentation allows each component to be optimized independently: global VLANs can be allocated from a large address space to support many tenants, while local VLANs maintain compatibility with existing 12-bit constraints and device behaviors.
2Reliability
If the number of VLANs increases to support more tenants, then multi-tenant isolation is improved, but configuration management complexity increases
Solution Approach 1:
The patent introduces global VLANs as an intermediary layer between the control plane and the data plane. Instead of configuring numerous local VLANs directly at each switch, the system uses global VLANs to represent multi-tenant networks, which are then mapped to local VLANs at site boundaries. This intermediary structure simplifies configuration management by providing a unified view of multi-tenant networks while maintaining local isolation requirements.
Solution Approach 2:
The patent makes global VLANs multi-functional: they serve as both isolation boundaries for different tenants and as routing identifiers for cross-site communication. A single global VLAN ID can represent an entire multi-tenant network spanning multiple sites, eliminating the need to configure and manage separate VLANs at each location. This universality reduces configuration complexity while maintaining strong isolation guarantees.
3Adaptability or versatility
If VLAN configurations are changed to support VM migration across VLAN boundaries, then connectivity is improved, but configuration overhead and complexity increase
Solution Approach 1:
The patent uses global VLAN configurations as templates that can be replicated across multiple sites. When a VM needs to migrate across VLAN boundaries, the system leverages the global VLAN mapping structure to automatically determine the appropriate local VLAN at the destination site, avoiding the need for manual configuration changes at each switch. This copying approach ensures consistent VLAN behavior across the distributed network.
Solution Approach 2:
The patent implements a control plane that maintains global VLAN mapping information and provides feedback to data plane devices. When VM migration is detected or planned, the control plane can pre-establish the necessary global-to-local VLAN mappings, allowing seamless migration without configuration changes at the switches. The feedback mechanism ensures that the network infrastructure is always ready to support VM mobility.
4Adaptability or versatility
If traditional VLAN approaches are used in data centers, then existing device compatibility is maintained, but security and scalability requirements cannot be satisfied
Solution Approach 1:
The patent applies local quality by allowing different VLAN behaviors at different locations in the network. At site boundaries and access switches, traditional 12-bit local VLAN IDs are used to maintain compatibility with existing devices. At core routers and boundary devices, global VLAN IDs are used to provide enhanced scalability and security. This local differentiation allows the system to optimize for both compatibility and advanced requirements in appropriate locations.
Solution Approach 2:
The patent uses global VLANs as intermediaries that translate between the traditional local VLAN space and the extended global VLAN space. Existing devices continue to operate with familiar local VLAN IDs, while the global VLAN layer provides the scalability and security features needed for modern data centers. The intermediary global VLAN structure is transparent to legacy devices, maintaining ease of operation while enabling advanced capabilities.
Data Source
AI summary
A method and apparatus for implementing a virtual local area network. The method includes determining a global virtual local area network for transmitting a broadcast data frame in response to receiving the broadcast data frame at a first switch, encapsulating the broadcast data frame based at least in part on said determination and transmitting it to at least one second switch over the determined global virtual local area network. The broadcast data frame is received at the second switch and an identifier of the global virtual local area network is obtained according to the broadcast data frame. Based at least in part on the identifier of the global virtual local area network, it is determined that which local virtual local area network served by the second switch the de-capsulated broadcast data frame can be sent to.


