Layer-2 Virtual Networking Through Distributed ACLs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualized cloud environments lack efficient Layer 2 networking functionality, limiting the flexibility and performance of virtual networks.
Innovation Solution
Implementing an infinitely scalable distributed switch that emulates a single switch connecting compute instances, utilizing Layer 2 virtual network interface cards (VNICs) and local switches, and supporting Layer 2 access control lists (ACLs) to enhance network connectivity and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Layer 2 networking functionality is added to virtualized cloud environments, then network connectivity and security are improved, but device complexity increases
Solution Approach 1:
The patent combines Layer 2 switching functionality with the existing virtualized network infrastructure by integrating virtual switches into the cloud environment. This merging allows Layer 2 networking to be provided using existing physical switches and virtual network interface cards, avoiding the need for separate dedicated Layer 2 hardware while still achieving the desired connectivity and security features.
Solution Approach 2:
The virtual switches and network interface cards are designed to perform multiple functions including Layer 2 switching, security filtering through virtual ACLs, and integration with both physical and virtual networks. This multi-functionality reduces the need for separate specialized devices, thereby managing complexity while providing comprehensive networking capabilities.
2Reliability
If access control lists are implemented at Layer 2, then network security is improved, but processing overhead increases
Solution Approach 1:
Instead of implementing full packet inspection for every traffic flow, the system uses virtual ACLs that copy and apply simplified filtering rules at the virtual switch level. This allows security policies to be enforced efficiently without requiring deep packet inspection of all traffic, reducing processing overhead while maintaining security.
Solution Approach 2:
The system applies partial security filtering by implementing ACLs that focus on most critical security scenarios rather than exhaustive packet analysis. This partial action approach provides sufficient security protection for typical workloads while minimizing the processing overhead that would result from complete packet inspection of all traffic types.
3Adaptability or versatility
If a distributed switch architecture is used, then scalability is improved, but system complexity increases
Solution Approach 1:
The distributed switch architecture segments the network into multiple virtual switches, each managing a specific subset of virtual machines or network segments. This segmentation allows the system to scale by adding more virtual switches rather than requiring a single monolithic switch to handle all traffic, thereby improving scalability while managing complexity through modular design.
Solution Approach 2:
The virtual switches act as intermediaries between physical network infrastructure and virtual machines, abstracting the complexity of the distributed architecture from end users. This intermediary layer presents a simplified interface for network connectivity while handling the complex routing and switching decisions internally, thus improving scalability without proportionally increasing user-visible complexity.
Data Source
AI summary
Techniques are described for communications in an L2 virtual network. In an example, the L2 virtual network includes a plurality of L2 compute instances hosted on a set of host machines and a plurality of L2 virtual network interfaces and L2 virtual switches hosted on a set of network virtualization devices. An L2 virtual network interface emulates an L2 port of the L2 virtual network. Access control list (ACL) information applicable to the L2 port is sent to a network virtualization device that hosts the L2 virtual network interface.


