MAC-Based VLAN Assignment With PVLAN Support on Trunk Ports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network environments struggle to implement Private VLANs (PVLANs) effectively on trunk ports of network devices, which are typically used for multiple VLAN assignments, necessitating a solution that allows these ports to behave like access ports to enhance security and segmentation.

Innovation Solution

Network devices are configured to promote trunk ports based on triggering events, such as authentication or configuration changes, to associate them with VLANs as if they were access ports, supporting PVLANs by maintaining data on allowed traffic directions and promoting ports to conform to PVLAN standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If trunk ports are used for multiple VLAN assignments, then network versatility and traffic handling capability are improved, but the ability to implement PVLAN segmentation and access port behavior is lost

Engineering Contradiction:
ImproveVLAN assignment capabilityVSAvoidPVLAN implementation capability
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The port configuration is made dynamic by allowing trunk ports to be promoted to access port behavior through triggering events. The system dynamically adjusts port functionality based on authentication status or configuration changes, enabling the same port to operate in different modes (trunk vs. access) as needed for PVLAN implementation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the operational parameters of the port by modifying its behavior from standard trunk port mode to access port mode when promotion conditions are met. This parameter change enables PVLAN segmentation while maintaining the underlying trunk port configuration for multiple VLAN assignments.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If trunk ports behave as access ports for PVLAN segmentation, then network security and segmentation are improved, but port configuration complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidport configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary configuration by pre-defining triggering events and promotion conditions. When authentication occurs or configuration changes are detected, the port promotion is automatically triggered without requiring manual reconfiguration, thereby reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by monitoring authentication status and configuration changes. When specific conditions are met (such as successful authentication or configuration updates), the system automatically triggers port promotion, creating a closed-loop control system that reduces manual intervention and simplifies configuration management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250365230A1Virtual Local Area Network (VLAN) Support, Including Private VLAN (PVLAN) Support In Association With Media Access Control (MAC) Based VLAN Assignment
Publication Date: 2025.11.27 ARISTA NETWORKS INC
  • US20250365230A1 patent drawing
  • US20250365230A1 patent drawing
  • US20250365230A1 patent drawing

AI summary

Network devices and methods for their operation are disclosed whereby embodiments may allow a trunk port on the network device to behave as an access port with respect to conforming with the standards of Virtual Local Area Networks (VLANs), including Private VLANs (PVLANs). In this manner PVLANs can be supported on ports that are associated with multiple untagged VLANs, such as when using Media Access Control (MAC) based VLAN assignment (MBVA) with those ports.