Multi-path Network Traffic Filtering Reducing Frame Loss

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network traffic filtering devices often experience substantial frame losses during transitions between active and inactive nodes in multi-node active/passive high availability clusters, leading to communication disruptions.

Innovation Solution

Implementing a multi-path network traffic filtering device with at least two fully operational filter processing paths, where incoming network traffic is sent to and filtered by multiple paths, and only one output is forwarded, ensuring redundancy and minimizing frame loss by processing duplicate traffic sets independently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional active/passive high availability clustering is used, then network continuity is maintained during node failure, but substantial frame loss occurs during node transition

Engineering Contradiction:
Improvenetwork continuityVSAvoidframe loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the single active node into multiple active nodes (first active network node and second active network node), each handling different traffic flows. This segmentation allows parallel processing of traffic on multiple paths simultaneously, eliminating the transition frame loss inherent in single-node failover while maintaining network continuity through distributed active nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-establishing multiple active nodes with synchronized traffic flow tables before any failure occurs. Each node maintains ready-to-process traffic flow configurations, so when a node needs to be replaced, the standby node is already configured and can immediately take over without frame loss, rather than requiring transition time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-node active/passive clustering is implemented, then node redundancy is achieved, but device complexity increases

Engineering Contradiction:
Improvenode redundancyVSAvoidcluster configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the functionality of multiple active nodes with a single standby node into a unified cluster architecture. All nodes share a common control plane and synchronized traffic flow tables, allowing them to operate as a coordinated unit rather than independent devices. This merging reduces operational complexity while maintaining the redundancy benefits of multiple active nodes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Each node in the cluster is designed with universal functionality, capable of serving as active, standby, or replacement node depending on operational needs. The nodes use standardized interfaces and synchronized traffic flow tables, allowing any node to perform any role in the cluster. This multi-functionality simplifies cluster management and reduces complexity compared to specialized node configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of repair

If traditional failover methods are used, then node replacement is possible, but sub-second UDP frame loss occurs

Engineering Contradiction:
Improvenode replacementVSAvoidUDP frame loss
Core Design Contradiction:
Ease of repairVSLoss of information

Solution Approach 1:

The system performs preliminary action by pre-configuring standby nodes with complete traffic flow tables and synchronization with active nodes before any failure occurs. This advance preparation ensures that when node replacement is needed, the standby node is already fully configured and can immediately assume the active role without any UDP frame loss, enabling easy repair while maintaining data integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuity of useful action by keeping standby nodes in a ready state with synchronized traffic flow information, ensuring that network traffic processing continues without interruption during node replacement. The standby node continuously receives and processes traffic flow table updates, maintaining readiness to take over immediately, thus preserving UDP frame continuity throughout the repair process.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20240236039A1Systems and methods for reducing frame loss in a network processing system
Publication Date: 2024.07.11 FORTINET INC
  • US20240236039A1 patent drawing
  • US20240236039A1 patent drawing
  • US20240236039A1 patent drawing

AI summary

Various embodiments provide multi-path traffic filtering devices and methods for using such.