Hybrid Services Insertion via ACL Traffic Redirection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current service chaining technologies require hardware changes and lack efficient methods for selective traffic redirection and hybrid services insertion without additional packet headers, limiting their flexibility and performance.
Innovation Solution
The implementation of service chaining techniques that allow switches to redirect network traffic based on Access Control List (ACL) configurations, enabling selective traffic redirection and hybrid services insertion by configuring switches and applications in different modes (L2 and L3) without modifying packet headers, using existing ASICs and linecards for wire-speed performance and health monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service chaining is implemented using traditional hardware-based methods, then network service functionality is provided, but hardware changes are required and flexibility is reduced
Solution Approach 1:
The patent replaces traditional hardware-based service chaining mechanisms with a software-based approach using Access Control Lists (ACLs) on network switches. Instead of requiring physical hardware changes or specialized service chaining hardware, the invention uses software-configurable ACL rules to redirect traffic to service appliances, thereby eliminating the need for hardware changes while maintaining service chaining functionality.
Solution Approach 2:
The invention changes the configuration parameters from hardware-level settings to software-based ACL parameters. By using ACL match criteria (such as source/destination IP addresses, ports, protocols) and associated actions (redirect to specific service appliances), the system achieves flexible service chaining through parameter-based control rather than fixed hardware configurations.
2Productivity
If service chaining requires additional packet headers, then traffic can be redirected to services, but packet header overhead increases and performance decreases
Solution Approach 1:
The patent extracts the service chaining functionality from the packet data plane by implementing redirection at the network layer using ACLs. Instead of embedding service chaining information within packet headers (which would increase overhead), the invention separates the redirection logic into switch-based ACL rules that operate independently of the actual data packets, thereby eliminating additional packet header requirements.
3Adaptability or versatility
If selective traffic redirection is implemented without ACL configurations, then service insertion is simplified, but traffic selection capability is reduced
Solution Approach 1:
The patent leverages the universal ACL functionality already present in modern network switches to achieve service chaining. By utilizing the existing multi-functional ACL capability (which can already perform traffic filtering, routing, and policy-based forwarding), the invention adds service insertion functionality without requiring dedicated service chaining hardware or complex proprietary configuration systems.
4Reliability
If health monitoring is not implemented, then system complexity is reduced, but failure handling capability is weakened
Solution Approach 1:
The patent implements a self-service health monitoring mechanism where the system automatically detects and responds to service appliance failures. The switch monitors the health of connected service appliances through ACL rule evaluations and automatically redirects traffic away from failed appliances without requiring external monitoring systems or complex manual intervention, thereby achieving reliable failure handling with minimal additional complexity.
Data Source
AI summary
In an embodiment, a method is provided. The method includes: storing, in at least one hardware module of a network device having a plurality of ports, attributes for at least one access control list and associated actions that cause network packets received at one of the plurality of ports that match the attributes for the at least one access control list, to be directed into a service chain that includes at least a first network processing application specified according to a port and a second network processing application specified according to an internet protocol (IP) address; and directing a received network packet that matches the attributes for the at least one access control list into the service chain.


