Multisite Interconnect Using Translation Mappings and Security Contracts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Datacenter fabrics with independent switching fabrics at multiple sites face challenges in providing uniform network connectivity and policy management, leading to difficulties in managing and maintaining these sites as a whole due to conflicting namespaces and lack of redundancy.
Innovation Solution
A unified fabric is created by using translation mappings and security contracts to interconnect switching fabrics across sites, allowing for namespace translation and security policy enforcement, enabling communication between hosts and applications across different sites while presenting a unified view to administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If independent switching fabrics are deployed at multiple sites to enlarge capacity and provide redundancy, then reliability and capacity are improved, but uniform network connectivity and policy management deteriorate
Solution Approach 1:
The patent introduces a global fabric controller as an intermediary that manages multiple independent switching fabrics across sites. This controller enables uniform policy management and namespace translation without requiring changes to the independent fabric architecture, thus maintaining redundancy while improving ease of operation.
Solution Approach 2:
The global fabric controller provides universal management capabilities across multiple independent switching fabrics, enabling a single policy framework to manage diverse fabrics at different sites. This multi-functional approach allows uniform connectivity and policy enforcement while preserving the benefits of independent fabric deployment.
2Quantity of substance
If independent switching fabrics are deployed at multiple sites, then capacity is improved, but uniform network connectivity deteriorates
Solution Approach 1:
The global fabric controller acts as a mediator that translates namespaces and enforces policies across independent switching fabrics, creating uniform network connectivity while preserving the capacity benefits of multiple independent fabrics at different sites.
3Reliability
If multiple sites are created to mitigate single point of failure, then reliability is improved, but management complexity increases
Solution Approach 1:
The global fabric controller serves as a central intermediary that simplifies the management of multiple sites by providing unified policy enforcement and namespace translation, reducing management complexity while maintaining the reliability benefits of multi-site deployment.
Solution Approach 2:
The patent merges the management functions of multiple independent sites into a single global fabric controller, combining policy management, namespace translation, and connectivity enforcement into one unified system, thereby reducing overall management complexity.
Data Source
AI summary
Embodiments herein describe using translation mappings and security contracts to establish interconnects and policies between switching fabrics at different sites to create a unified fabric. In one embodiment, a multi-site controller can stretch endpoint groups (EPGs) between the sites so that a host or application in a first site can communicate with a host or application in a second site which is assigned to the same stretched EPG, despite the two sites have different namespaces. Further, the shadow EPGs can be formed to facilitate security contracts between EPGs in different sites. Each site can store namespace translation mapping that enable the site to convert namespace information in packets received from a different site into its own namespace values. As a result, independent bridging and routing segments in the various sites can be interconnected as well as providing application accessibility across different fabrics with independent and private namespaces.


