MAC-Based VLAN Assignment With PVLAN Support on Trunk Ports
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network environments struggle to implement Private VLANs (PVLANs) effectively on trunk ports of network devices, which are typically used for multiple VLAN assignments, necessitating a solution that allows these ports to behave like access ports to enhance security and segmentation.
Innovation Solution
Network devices are configured to promote trunk ports based on triggering events, such as authentication or configuration changes, to associate them with VLANs as if they were access ports, supporting PVLANs by maintaining data on allowed traffic directions and promoting ports to conform to PVLAN standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If trunk ports are used for multiple VLAN assignments, then network versatility and traffic handling capability are improved, but the ability to implement PVLAN segmentation and access port behavior is lost
Solution Approach 1:
The port configuration is made dynamic by allowing trunk ports to be promoted to access port behavior through triggering events. The system dynamically adjusts port functionality based on authentication status or configuration changes, enabling the same port to operate in different modes (trunk vs. access) as needed for PVLAN implementation.
Solution Approach 2:
The invention changes the operational parameters of the port by modifying its behavior from standard trunk port mode to access port mode when promotion conditions are met. This parameter change enables PVLAN segmentation while maintaining the underlying trunk port configuration for multiple VLAN assignments.
2Reliability
If trunk ports behave as access ports for PVLAN segmentation, then network security and segmentation are improved, but port configuration complexity increases
Solution Approach 1:
The system performs preliminary configuration by pre-defining triggering events and promotion conditions. When authentication occurs or configuration changes are detected, the port promotion is automatically triggered without requiring manual reconfiguration, thereby reducing operational complexity while maintaining security.
Solution Approach 2:
The system implements feedback mechanisms by monitoring authentication status and configuration changes. When specific conditions are met (such as successful authentication or configuration updates), the system automatically triggers port promotion, creating a closed-loop control system that reduces manual intervention and simplifies configuration management.
Data Source
AI summary
Network devices and methods for their operation are disclosed whereby embodiments may allow a trunk port on the network device to behave as an access port with respect to conforming with the standards of Virtual Local Area Networks (VLANs), including Private VLANs (PVLANs). In this manner PVLANs can be supported on ports that are associated with multiple untagged VLANs, such as when using Media Access Control (MAC) based VLAN assignment (MBVA) with those ports.


