Monitoring Appliance Simulates Network Failure via Firewall Traffic Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network configurations in large data center networks are complex and error-prone, making it difficult to test and troubleshoot without disrupting active users, as conventional methods require interrupting services or killing network components.

Innovation Solution

A monitoring appliance simulates network failure events by blocking specific ports or services using firewalls, allowing for stress testing without suspending services, thereby avoiding disruptions to active users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional fault testing methods are used to test network configurations, then network reliability can be improved, but service disruption occurs and active users are affected

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidservice disruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a virtual copy of the network device within the monitoring appliance. This virtual device replicates the network failure condition without affecting the physical device or active services. The virtual machine or container simulates the faulty behavior, allowing safe testing of network configurations and fault tolerance mechanisms while users remain unaffected.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The monitoring appliance acts as an intermediary between the network device and the testing process. It intercepts and analyzes traffic related to the virtual device, enabling fault testing through a controlled intermediate environment rather than directly on the production network, thus preventing service disruption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If network components are interrupted for testing, then fault detection capability is improved, but network operation is disrupted

Engineering Contradiction:
Improvefault detection capabilityVSAvoidnetwork operation
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

Instead of interrupting actual network components, the patent creates virtual replicas of network devices that can be safely interrupted and tested. These virtual machines or containers within the monitoring appliance simulate failure conditions, enabling comprehensive fault detection while the real network continues operating normally.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the testing function from the production network by isolating it within a virtual machine or container environment in the monitoring appliance. This segmentation allows independent fault testing without impacting the main network operations, maintaining productivity while improving detection capability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If stress testing is performed on network fabric, then network resilience can be assessed, but service quality degrades

Engineering Contradiction:
Improvenetwork resilienceVSAvoidservice quality degradation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates virtual copies of network devices and traffic patterns within the monitoring appliance to perform stress testing. These virtual representations allow aggressive testing of network resilience limits without actually degrading service quality for users, as all stress is applied to the virtual environment rather than production systems.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11469986B2Controlled micro fault injection on a distributed appliance
Publication Date: 2022.10.11 CISCO TECHNOLOGY INC
  • US11469986B2 patent drawing
  • US11469986B2 patent drawing
  • US11469986B2 patent drawing

AI summary

Aspects of the technology provide methods for simulating a failure in a tenant network. In some aspects, a monitoring appliance of the disclosed technology can be configured to carry out operations for receiving packets at a virtual device in the monitoring appliance, from a corresponding network device in the tenant network, and instantiating a firewall at the virtual device, wherein the firewall is configured to selectively block traffic routed from the network device to the virtual device in the monitoring appliance. The monitoring appliance can simulate failure of the network device by blocking traffic from the network device to the virtual device using the firewall, and analyze the tenant network to determine a predicted impact a failure of the network device would have on the tenant network. Systems and machine-readable media are also provided.