End-to-End Flow Visibility Across Service Appliances
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network analytics tools face challenges in providing end-to-end flow visibility across networks that include service appliances, as data flows appear as multiple separate flows due to Network Address Translation (NAT) and the presence of service appliances, making it difficult to recognize the entire path from source to destination.
Innovation Solution
A central ingest engine is used to collect, aggregate, and enrich network flow data from various network devices and appliances, stitching together flow records to provide a unified end-to-end flow path, even when Network Address Translation is performed, by leveraging hardware telemetry export functionality on cloud-scale switches and routers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service appliances perform Network Address Translation (NAT) on data packets, then network security and flexibility are improved, but flow visibility and path recognition are degraded
Solution Approach 1:
The patent introduces an intermediary mechanism (flow visibility system) that captures and correlates flow information at multiple points in the network path, including before and after service appliances. This intermediary system maintains flow state information and uses correlation keys to track packets through NAT transformations, thereby preserving flow visibility despite the address translation performed by service appliances.
2Adaptability or versatility
If service appliances are inserted into the network fabric, then network functionality and security are improved, but flow path complexity and visibility are degraded
Solution Approach 1:
The patent segments the flow tracking function into multiple distributed components located at different network points (ingress points, egress points, and intermediate devices). Each segment captures local flow information and contributes to the overall flow picture, allowing the system to handle complex paths through service appliances without requiring a single centralized tracking mechanism.
Solution Approach 2:
The patent adds an additional dimension to flow tracking by introducing flow correlation keys and state information that exist alongside traditional network headers. This extra dimension allows the system to track flows through service appliances even when standard header fields are modified, effectively adding a parallel tracking layer that bypasses the complexity introduced by service appliances.
3Ease of manufacture
If traditional network analytics tools are used, then implementation simplicity is maintained, but end-to-end flow visibility across service appliances is degraded
Solution Approach 1:
The patent creates a universal flow visibility system that can operate across diverse network configurations, including those with and without service appliances. The system uses standardized flow correlation mechanisms that work independently of the specific network architecture, allowing it to provide end-to-end visibility in multi-vendor, multi-device environments without requiring appliance-specific modifications.
Data Source
AI summary
A system and method for providing end-to-end data flow analytics in a network flow that includes network appliances. Information regarding one or more network appliances is received by a flow collector and analyzed by an enrichment module. The network information regarding the one or more network appliances can be stored. Network flow data is received from various nodes within the network and stitched or aggregated in light of the enriched network appliance information to provide an end-to-end data flow that can be useful to understand one or more performance parameters of the unified network flow.


