End-to-End Flow Visibility Across Service Appliances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network analytics tools face challenges in providing end-to-end flow visibility across networks that include service appliances, as data flows appear as multiple separate flows due to Network Address Translation (NAT) and the presence of service appliances, making it difficult to recognize the entire path from source to destination.

Innovation Solution

A central ingest engine is used to collect, aggregate, and enrich network flow data from various network devices and appliances, stitching together flow records to provide a unified end-to-end flow path, even when Network Address Translation is performed, by leveraging hardware telemetry export functionality on cloud-scale switches and routers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service appliances perform Network Address Translation (NAT) on data packets, then network security and flexibility are improved, but flow visibility and path recognition are degraded

Engineering Contradiction:
Improvenetwork securityVSAvoidflow visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary mechanism (flow visibility system) that captures and correlates flow information at multiple points in the network path, including before and after service appliances. This intermediary system maintains flow state information and uses correlation keys to track packets through NAT transformations, thereby preserving flow visibility despite the address translation performed by service appliances.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If service appliances are inserted into the network fabric, then network functionality and security are improved, but flow path complexity and visibility are degraded

Engineering Contradiction:
Improvenetwork functionalityVSAvoidflow path complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the flow tracking function into multiple distributed components located at different network points (ingress points, egress points, and intermediate devices). Each segment captures local flow information and contributes to the overall flow picture, allowing the system to handle complex paths through service appliances without requiring a single centralized tracking mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds an additional dimension to flow tracking by introducing flow correlation keys and state information that exist alongside traditional network headers. This extra dimension allows the system to track flows through service appliances even when standard header fields are modified, effectively adding a parallel tracking layer that bypasses the complexity introduced by service appliances.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of manufacture

If traditional network analytics tools are used, then implementation simplicity is maintained, but end-to-end flow visibility across service appliances is degraded

Engineering Contradiction:
Improveimplementation simplicityVSAvoidend-to-end flow visibility
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent creates a universal flow visibility system that can operate across diverse network configurations, including those with and without service appliances. The system uses standardized flow correlation mechanisms that work independently of the specific network architecture, allowing it to provide end-to-end visibility in multi-vendor, multi-device environments without requiring appliance-specific modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12047269B2End-to-end flow visibility in a data network including service appliances
Publication Date: 2024.07.23 CISCO TECHNOLOGY INC
  • US12047269B2 patent drawing
  • US12047269B2 patent drawing
  • US12047269B2 patent drawing

AI summary

A system and method for providing end-to-end data flow analytics in a network flow that includes network appliances. Information regarding one or more network appliances is received by a flow collector and analyzed by an enrichment module. The network information regarding the one or more network appliances can be stored. Network flow data is received from various nodes within the network and stitched or aggregated in light of the enriched network appliance information to provide an end-to-end data flow that can be useful to understand one or more performance parameters of the unified network flow.