Switch Port Security with LLDP MAC Association for Uplink Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The conflict between port security mechanisms and redundancy mechanisms in network devices, such as access points (APs) and switches, leads to undesired interface shutdowns due to violations when multiple uplinks are used for failover, as port security rules restrict multiple MAC addresses on a single interface.
Innovation Solution
Utilizing organizationally specific TLV fields in LLDP control packets to associate and recognize multiple MAC addresses of a bonded interface as connected to a single AP, allowing these addresses to move between secure interfaces without triggering security violations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If port security mechanism is implemented to restrict MAC addresses on interfaces, then security is improved, but failover capability between multiple uplinks deteriorates due to interface shutdowns
Solution Approach 1:
The patent introduces LLDP control packets as an intermediary mechanism between the AP and switch. These packets carry MAC address association information that mediates the conflict between port security (which needs to identify legitimate devices) and failover capability (which requires MAC addresses to move between interfaces). The LLDP packets enable the switch to understand that multiple MAC addresses belong to the same AP, allowing failover without security violations.
Solution Approach 2:
The system performs preliminary action by establishing MAC address associations through LLDP control packets before failover occurs. The switch learns and stores the relationships between multiple MAC addresses and the single AP in advance. When failover happens, the switch already has this information and can immediately allow the MAC addresses to move to different interfaces without triggering security violations, thus preventing interface shutdowns.
2Adaptability or versatility
If multiple MAC addresses are allowed on a single interface for redundancy, then failover is improved, but port security rules are violated leading to interface shutdowns
Solution Approach 1:
LLDP control packets serve as the intermediary that resolves the conflict between redundancy requirements (multiple MAC addresses on interfaces) and port security rules. The packets provide the switch with information about which MAC addresses belong to the same AP, enabling the switch to make informed decisions about allowing multiple MAC addresses without violating security policies, thus preventing unnecessary interface shutdowns while maintaining redundancy.
Solution Approach 2:
The system establishes MAC address associations through LLDP packets in advance, before any failover or security violation events occur. This preliminary action populates the switch's knowledge base with the relationships between MAC addresses and the AP. When redundancy operations occur (such as moving MAC addresses between interfaces during failover), the switch can immediately proceed without triggering security violations because the associations were already established, ensuring interface stability while maintaining redundancy capability.
3Ease of operation
If port security restricts MAC address movement between interfaces, then security control is improved, but seamless failover deteriorates due to security violations
Solution Approach 1:
LLDP control packets act as the intermediary mechanism that enables seamless coordination between security control and failover operations. The packets carry association information that allows the switch to maintain security control (by knowing which MAC addresses belong to the same AP) while permitting MAC address movement between interfaces during failover. This eliminates security violations that would otherwise interrupt data transmission, ensuring continuity while maintaining security oversight.
Solution Approach 2:
The system performs preliminary action by establishing MAC address associations through LLDP packets before failover events. This advance preparation enables the switch to recognize legitimate MAC address movements as part of normal failover operations rather than security threats. When failover occurs, the switch can immediately allow MAC addresses to move between interfaces without triggering security violations, thus maintaining data transmission continuity while preserving security control through the pre-established associations.
Data Source
AI summary
A first switch port receives a first control packet, a header having a source media access control (MAC) address of a first MAC of a first interface of a sending device and a payload containing a second MAC of a second interface of the same sending device. The first and second interfaces form a bonded interface for failover purposes on the sending device. A second switch port receives a second control packet, a header having the second MAC as its source MAC and a payload containing the first MAC. The switch associates the first and second MAC addresses as related MAC addresses associated with the bonded interface. The switch facilitates failover between the secure interfaces via multiple uplinks while maintaining the port security on the switch by allowing transmission of data from either the first or second MAC address, associated as related MAC addresses, without triggering a port security violation.


